What the registrar is contractually required to hold
An accredited registrar is a company under contract with ICANN to sell and manage registrations in generic top-level domains. Resellers are not accredited, and that distinction decides who a request should be directed to. The contract is the Registrar Accreditation Agreement, and its record-keeping section is the baseline for everything below.
Under the 2013 RAA, a registrar must maintain the data specified in the Data Retention Specification for the period stated there, and must maintain, during the term of the agreement and for two years afterwards, records including submission dates, times and content of registration data submitted electronically; written communications constituting registration applications, confirmations, modifications and terminations; and records of Registered Name Holder accounts — the agreement's term for registrants.
The Data Retention Specification divides that obligation into two tiers. One set of elements is kept for the life of the registration plus two years: registrant legal name, the administrative, technical and billing contacts with their addresses and telephone numbers, the published registration data, the services purchased, and recurring payment references. A second, shorter-lived set covers payment means and source information, log files, billing records, and communication source and destination data.
The retention clocks, and how quietly they run
This is the part that decides whether an investigation has anything to work with, and it is the part discovered too late most often. Four floors matter, and they run on the domain's own history rather than the litigation calendar.
- 180 days for log files, billing records, communication source and destination data, and records of communication dates, times and session information. This is the tier showing who logged in and from where: the shortest and the most valuable.
- Two years after a registration's deletion or transfer away, past which the RAA provides that a registrar is not obliged to maintain records relating to it.
- Fifteen months after a registrar's sponsorship ends, the Registration Data Policy floor for data elements needed in transfer disputes.
- Twelve months from an alleged Transfer Policy violation, the transfer dispute filing window.
Nothing warns anybody when one of these expires. There is no notice and no acknowledgment; the record is simply gone the next time it is asked for. In a live matter I treat the shortest applicable window — in practice the 180-day log tier — as the governing deadline, and put it in writing at the start of the engagement.
Channel one: legal process served on the registrar
Registrars publish their own legal-process pages, and reading the relevant one before anything is drafted saves more time than any other single step. Those pages specify the service address, the courts whose process the registrar accepts, what it will and will not produce, its practice on notifying the customer, and its charges.
Two features recur. First, jurisdiction is enumerated rather than assumed: a registrar may accept process only from courts in a defined list of countries, and a registrar outside the forum may be beyond that forum's reach altogether. Second, customer notice is standard practice. Major registrars state that on receipt of a valid civil subpoena they will notify the customer whose information is sought, expressly so that the customer has an opportunity to move to quash. Production is rarely silent, and a timeline should not assume it is.
Registrars also charge for research time and copying on their own published terms. That friction is set by the provider, and it is a scheduling fact worth knowing in advance. Whether any particular process is available or appropriate is a question for counsel.
Channel two: ICANN's Registration Data Request Service
ICANN operates a centralized, free channel for requesting nonpublic registration data for generic top-level domains, open to requesters with a legitimate interest — the named categories include consumer protection advocates, cybersecurity specialists, government officials, intellectual property professionals and law enforcement. The pilot ran from November 2023, and ICANN's Board has directed that operations continue while policy work on a standardized access framework proceeds (ICANN RDRS).
The service's own published results are the reason to set expectations carefully. Participation is voluntary. In the first reporting year, 93 registrars participated, covering roughly 60 percent of domains under management. Of 2,416 requests, 23 percent were approved, 65 percent denied, 1 percent partially approved, and 10 percent answered as already publicly available. ICANN's report notes that registrars are on average leaving requests open longer and that more than half of disclosure requests are denied.
It is free and quick, so it belongs early. It is not a substitute for a channel that compels anything, and should not be planned around as though it were.
Channel three: registrar verification in a filed UDRP
The third channel is not a discovery mechanism at all, which is why it is easy to overlook. Once a UDRP complaint is filed, the dispute provider requests verification from the registrar and requests that the domain be locked. Under the UDRP Rules, within two business days the registrar must supply the full registration data and confirm the lock, and must not notify the respondent until the lock is applied.
What arrives in that verification is often the unredacted registrant data, including the customer behind a privacy or proxy service. WIPO's guidance is specific about timing: any update to the respondent's data, including a privacy or proxy provider's disclosure of the underlying customer, must be made before the two business day period concludes or before the registrar verifies and confirms the lock, whichever occurs first; a modification after that period may be addressed by the panel in its decision.
For an expert this matters in one narrow way: registration data that was redacted the day before a complaint was filed may be on the record days later, and the verification response is a dated document from the registrar. Whether and when to file anything is for counsel.
What a United States provider will not produce
US-SPECIFIC. The Stored Communications Act, part of the Electronic Communications Privacy Act, restricts what a covered provider may disclose. Section 2702(a) prohibits a covered provider from knowingly divulging the contents of communications, and from divulging subscriber records, except as the section enumerates (18 U.S.C. § 2702). The enumerated exceptions include disclosure with the lawful consent of the subscriber, and disclosure of a record pertaining to a subscriber to any person other than a governmental entity.
The distinction that governs practice is content versus non-content — the message itself versus the record about it. Major registrars state in their published policies that they will not produce the content of email absent a court order or warrant, citing the statute. A request framed broadly enough to sweep in communication content will predictably be narrowed or refused in part.
One further point is regularly misunderstood. The preservation mechanism in section 2703(f), obliging a provider to preserve records for 90 days on request and a further 90 on renewal, operates on the request of a governmental entity. It is not a civil-party tool. Whether a given registrar or hosting provider is a covered provider at all is a legal question for counsel.
What registrar records cannot establish
They cannot establish that a registrant is who the record says. Registrar accuracy obligations require validation and verification of certain contact fields, which may include contacting the registrant by telephone, email or postal mail, with suspension or deletion where verification does not occur in time. That tests whether a contact point functions, not identity, and a complete record can name a person who does not exist.
They cannot be assumed uniform. Retention obligations have been waived for registrars in some jurisdictions on the strength of a legal opinion or a governmental ruling, with at least one determination reducing a post-registration retention period from two years to one. Retention is registrar-specific.
They cannot be assumed to exist at all for country-code domains, whose registries sit outside the Registrar Accreditation Agreement entirely; retention and disclosure follow each registry's rules and national law.
They cannot be compelled through ICANN. Its contractual compliance function addresses a registrar's breaches of its agreements with ICANN; it is not a mechanism for compelling production to a private party.
And they are rarely produced silently. Customer notification is standard practice, jurisdictional reach is enumerated by each registrar rather than universal, and fee and scheduling friction is set by the provider.
Asking for records by the names the policies use
The most productive thing an expert contributes before a request goes out is vocabulary. A request for "WHOIS records" produces what is already public. A request that enumerates records by their policy names produces something else.
The terms that map onto records a registrar is expected to hold include: Registered Name Holder account records; registration data submission dates, times and content; written communications constituting applications, confirmations, modifications and terminations; the Form of Authorization and associated transfer documentation; modification history; inter-registrar communications; payment means and source information; and log files documenting communication dates, times and session information.
Two further requests are the ones people forget. Ask the custodian to state its retention periods and whether any responsive record has already been deleted — "no responsive records" means something different from "the records aged out in March." And ask it to certify the production, because a certified production is a different document from an emailed spreadsheet. Drafting and serving is counsel's work; the enumeration is where an expert is useful.
Assessing the production once it arrives
A production set typically comprises the registrar's cover letter or certification, the account record, registration and modification history, transfer documentation, correspondence, payment records and any log extracts. The expert's work product is the analysis of it, and that analysis has two halves.
The first is substantive: what the records show about the account, the changes, the timing and the authorizations, mapped onto the timeline the matter turns on. The second is a completeness assessment, and it is the half that gets undervalued. It compares what the Registrar Accreditation Agreement, the Transfer Policy and the Registration Data Policy indicate a registrar should hold against what was produced, and categorizes every gap: the record never existed, the retention window expired, the custodian declined, or it was not asked for. Those are four different findings.
In United States federal practice, custodian-produced records are generally approached through the certification routes for records of a regularly conducted activity and for records generated by an electronic process. An expert can describe what a record is, how it is generated, and what its limits are. Whether any rule applies in a given matter is for counsel.