Recital 110
Directive on the security of network and information systems · UE 2022/2555
| (110) | The availability and timely accessibility of domain name registration data to legitimate access seekers is essential for the prevention and combating of DNS abuse, and for the prevention and detection of and response to incidents. Legitimate access seekers are to be understood as any natural or legal person making a request pursuant to Union or national law. They can include authorities that are competent under this Directive and those that are competent under Union or national law for the prevention, investigation, detection or prosecution of criminal offences, and CERTs or CSIRTs. TLD name registries and entities providing domain name registration services should be required to enable lawful access to specific domain name registration data, which are necessary for the purposes of the access request, to legitimate access seekers in accordance with Union and national law. The request of legitimate access seekers should be accompanied by a statement of reasons permitting the assessment of the necessity of access to the data. |
In Luxembourg, the ILR (Institut Luxembourgeois de Regulation) is the NIS 2 competent authority that may itself file access requests and that supervises registries (.lu operated by RESTENA) and registrars established in the Grand Duchy. The law of 28 July 2023 on cybersecurity, as amended by the law of 28 July 2025, transposes Article 28 NIS 2 and requires TLD registries and domain name registration service providers established in Luxembourg to respond to legitimate requests without undue delay, under penalty of administrative sanctions.
Luxgap practice: for actors operating .lu or a Luxembourg registrar, we calibrate the WHOIS Disclosure Gateway on the combined requirements of RESTENA, ILR and the national CSIRT GOVCERT.LU, with a priority route to GOVCERT.LU and the Police judiciaire for ongoing incidents.