You need to enable JavaScript to use the communication tool powered by OpenWidget

How we process personal data

When you register a domain, information (such as your name, address, and phone number) is published in the Whois database. Sometimes, government officials and even other clients contact NIC.UA for more detailed information. Learn in this article how we handle such requests and why your personal data will never fall into the wrong hands.

This diary and passport are the personal data of the author of the article :)

What is personal data?

From a legal perspective, personal data is information or a collection of information about an individual who is identified or can be specifically identified. Simply put, it's any information about you, from your first and last name to your health status. In Ukraine, personal data is collected, for example, from company employees or clients, and companies are legally required to maintain personal databases.

How is information protected?

Personal data is protected by the laws "On Information," "On Access to Public Information," and "On the Protection of Personal Data." Some of these laws seem outdated in a developed information society. At the same time, the protection of clients' personal data is guaranteed by our public agreement.

We strive to protect data from unauthorized access and modification: we audit the processes of collecting, storing, and processing information, comply with security measures, and use encryption.

Why is personal information collected?

We register domains and therefore hold our clients' personal data. In accordance with ICANN requirements, users provide this data in their administrative and other contact information when registering domains. This is important from a cybersecurity perspective. Subsequently, the domain's contact information—first name, last name, phone number, and address—is published in the Whois database and is generally accessible to other internet users. This publication does not violate the Law on Personal Data Protection.

Under the law, government officials have access to personal data. We and other registrars occasionally receive requests for domain owner data, for example, from the cyber police, the police, or the Security Service of Ukraine (SBU). If the request is properly completed and complies with legal requirements, law enforcement officials receive the necessary information about the client. The police use this information in their further investigation, the lawyer prepares and files a lawsuit against the appropriate defendant, and the court determines who owns the domain to proceed with the hearing.

Sometimes, individuals are interested in our clients' personal data—for example, in the case of a complaint about a fraudulent resource. Even despite obvious violations on the part of the domain owner, we act within the law and do not disclose their data. Instead, we ask that they contact a lawyer, the police, or the court.

Changes to the public contract

We will soon be amending our public agreement, including the clause on personal data protection. This is due to incomplete wording regarding data transfer:

The Contractor has the right to provide access and transfer his personal data to third parties without any additional notifications...

In the new version of the public agreement, we will list a limited list of persons who can access personal data and eliminate the imprecise wording of "third parties."

 

  • Helpful articles

    • Glossary

      • Latest news & promotions

          Loading…