NEW DELHI / GLOBAL — GoDaddy, the world’s largest domain registrar, has filed a legal challenge against sweeping directives issued by the Delhi High Court aimed at curbing brand-impersonating scam websites. In non-public court filings, the domain giant warned that the court’s strict mandates could severely disrupt global domain administration, expose legitimate website owners to safety risks, and trigger direct conflicts with international data privacy regulations.
The legal battle stems from a lawsuit brought by over 20 major multinational corporations—including Microsoft, Amazon, McDonald’s, and Colgate-Palmolive—seeking to halt rampant cyber fraud. In India, cybercrime complaints reached 2.4 million last year, causing an estimated $2.4 billion in financial losses.
While the Delhi High Court initially blocked more than 1,100 fake websites, it went further by issuing broad operational mandates for domain registrars that GoDaddy argues fundamentally rewrite global internet governance.
Key Directives Facing Appeal
GoDaddy’s appeal before a larger bench of the Delhi High Court targets three primary directives:
- Elimination of Privacy-by-Default: Domain registrars would no longer be permitted to automatically redact registrant contact information (WHOIS privacy). Registrar services would be required to collect and retain verified "Know Your Customer" (KYC) identity documentation for all buyers.
- 72-Hour Data Disclosure Window: Registrars must hand over a domain owner’s full contact details—including name, address, phone number, and email—to any third party claiming a "legitimate interest" within 72 hours of a request.
- Blanket Ban on Brand-Name Variations: Registrars would be prohibited from selling domain names that contain minor spelling variations or additions to protected trademarked names.
The Arguments: Privacy, Compliance, and Commercial Realities
In its court filings, GoDaddy argues that removing default WHOIS privacy exposes ordinary domain buyers, small businesses, journalists, and researchers to severe risks, including harassment, stalking, and identity theft—while bad actors will simply seek out non-compliant offshore registrars.
- Conflict with Global Privacy Frameworks: GoDaddy emphasizes that removing privacy-by-default creates a direct legal clash with India’s Digital Personal Data Protection Act and Europe’s General Data Protection Regulation (GDPR), both of which enforce strict "privacy-by-default" mandates.
- Overreach on Trademarks: GoDaddy pointed out the practical impossibility of enforcing a automated ban on name variations. For example, restricting variations of common brand names or short acronyms like "HUL" (Hindustan Unilever) would inadvertently block over 100 legitimate English words (such as "hulk") and grant virtual monopolies over common family surnames.
- Cross-Border Enforcement Risks: Because domain names function globally without strict geographic borders, GoDaddy warned that enforcing a single nation’s judicial order across global domain inventories creates an unworkable standard and described the mandates as "commercially destabilizing."
Implications for Due Diligence & Court Research
For background screeners, corporate investigators, and due diligence professionals, the outcome of this case represents a critical pivot point for online record access:
- WHOIS Data Availability: If upheld, the ruling could reopen public or semi-public access to registrant identity data in India, partially reversing the widespread WHOIS "blackouts" that followed the implementation of GDPR in 2018.
- Corporate Risk & Due Diligence: Conversely, if registrars are forced to restructure operations or exit specific markets due to compliance conflicts, identifying the true beneficial owners of domain assets across international jurisdictions could become even more fragmented.
The larger bench of the Delhi High Court is scheduled to hear arguments in the appeal mid-July.
