Domain

Domain Privacy in Singapore: RDAP, Registrant Data and Account Security

Domain Privacy Protection

Domain privacy is about the contact information exposed through registration data services. It is separate from website security, mailbox protection and control of the registrar account. A privacy option can be useful, but buying it does not automatically make a business compliant with the PDPA or GDPR.

Understand public registration data before buying an add-on

ICANN’s Registration Data Policy governs registration data processing by ICANN-accredited registrars and contracted generic top-level domain registries. Publication and disclosure are governed by that policy; it is inaccurate to assume every registrant’s personal contact details must always be publicly displayed.

RDAP is the registration data access protocol used for modern lookups. Redacted public data and a privacy or proxy service are not the same thing. Ask what information is already withheld and what an optional service changes. Country-code domains can have different registry rules, so check the chosen extension rather than applying a .com assumption to .sg.

Ask the registrar these questions

  • Which registration fields will appear in a public lookup for this extension?
  • Is the offered service a privacy service, a proxy arrangement or standard redaction?
  • Who is recorded as the registrant, and what evidence confirms the business’s rights?
  • How are legitimate enquiries and important registry notices forwarded?
  • What are the annual renewal cost and cancellation terms?
  • What changes during a transfer or a request for non-public information?

Use ICANN’s privacy and proxy service guidance to understand the distinction, then review the actual provider agreement.

Protect ownership even when public details are hidden

Privacy is not a substitute for registrar account security. Register business domains under a documented company-controlled account, use multi-factor authentication where supported and restrict who can change nameservers or approve a transfer. Maintain a recovery contact that does not depend entirely on the domain being operational.

Keep a register of domains, registrars, expiry dates and authorised contacts. Test that renewal notices reach the right people. When an employee or agency leaves, review their access rather than merely changing the website password.

Handle business contact information deliberately

Use accurate registration information and an authorised administrative contact. Do not enter fabricated details to avoid publication. Ask your data protection adviser which privacy obligations apply to your organisation and processing activities; owning a domain alone is not enough to determine that legal scope.

Review the domain before registration or transfer

For a new address, explore QUAPE domain registration and confirm the selected extension’s contact requirements. For an existing address, use the domain transfer service to discuss eligibility, ownership and DNS continuity. Keep privacy, account security and renewal management as three separate items in your checklist.