Recital 109

Recital 109

Directive on the security of network and information systems · UE 2022/2555

(109)

Maintaining accurate and complete databases of domain name registration data (WHOIS data) and providing lawful access to such data is essential to ensure the security, stability and resilience of the DNS, which in turn contributes to a high common level of cybersecurity across the Union. For that specific purpose, TLD name registries and entities providing domain name registration services should be required to process certain data necessary to achieve that purpose. Such processing should constitute a legal obligation within the meaning of Article 6(1), point (c), of Regulation (EU) 2016/679. That obligation is without prejudice to the possibility to collect domain name registration data for other purposes, for example on the basis of contractual arrangements or legal requirements established in other Union or national law. That obligation aims to achieve a complete and accurate set of registration data and should not result in collecting the same data multiple times. The TLD name registries and the entities providing domain name registration services should cooperate with each other in order to avoid the duplication of that task.

Luxembourg specificity
loi luxembourgeoise du 28 juillet 2023 relative a la cybersecurite

In Luxembourg, the law of 28 July 2023 on cybersecurity (amended by the law of 28 July 2025) designates the ILR as the competent authority to supervise TLD registries and entities providing domain name registration services established in Luxembourg, which notably includes the .lu registry operator (Restena). ILR may audit WHOIS database quality and impose corrective measures under daily penalty.

Luxgap practice: if you manage or resell .lu or gTLD domains from Luxembourg, document your cooperation scheme with Restena to avoid duplication under Article 28 NIS 2, and maintain a register of lawful access granted to the national CSIRT (GOVCERT.LU) and judicial authorities.