Summary
- Carrier-grade translation converts IPv4 scarcity into an attribution problem. A public address and time may identify a provider pool but not one subscriber; reliable matching often also needs the observed public source port, transport protocol, accurate clocks and the provider's internal assignment state.
- IETF RFC 6888 recognizes that per-mapping records can become very large under heavy use and advises against recording destination addresses and ports unless administratively required. It also shows why service-side recording of the public source port can be necessary when addresses are shared.
- Retention duties differ. Australia's 2015 regime requires covered providers to retain specified data for at least two years; the United Kingdom uses retention notices with a statutory maximum of twelve months; European Union law applies necessity, separation, security and access safeguards that cannot be reduced to a blanket logging instruction.
- Public evidence demonstrates that compliance is a material economic activity. Australia's one-off industry grant program awarded up to AUD 128.4 million, while later parliamentary reporting listed more than AUD 211 million in industry-reported compliance costs across four financial years, figures covering the wider regime rather than CGNAT alone.
- The cost stack includes translation capacity, redundant systems, time synchronization, record generation, storage, encryption, access control, lawful-request handling, error correction, breach response and deletion. Poor port or time data can make an expensive record set unreliable.
- Operators and users bear externalities that address-allocation debates often omit: higher access prices, shared reputation, blocked services, port scarcity, investigative errors and the privacy risk of large retained datasets. IPv6 reduces dependence but does not instantly remove legacy IPv4 sharing or legal duties.
- NRS should publish a scarcity-attribution account, promote measured transition to IPv6, support minimally sufficient and verifiable records, and give regulators comparable evidence about cost, error, security and service impact without asking number institutions to decide surveillance law.
Address shortage becomes an identity cost when users share
One public IPv4 address once often corresponded, for a useful interval, to one subscriber line or one customer device. The correspondence was never perfect. Addresses changed, household members shared connections, Wi-Fi could be compromised and business gateways represented many people. Even so, a provider's assignment log could often answer a basic question: which account held this public address at this time?
Carrier-grade translation weakens that simple association by design. Many subscriber connections can emerge from one public address simultaneously. The translator distinguishes them using transport ports and internal state. An outside service sees the public source address and source port, while the provider maintains the mapping to an internal subscriber identifier. If an inquiry supplies only the public address and time, several or many subscribers may fit.
This is why address sharing creates an identity cost rather than merely an equipment cost. The provider must preserve enough state to reconstruct which subscriber occupied the relevant translated tuple. The requesting authority or online service must preserve enough observation to ask a discriminating question. Both need compatible time. A record that omits one decisive element can be precise in appearance and ambiguous in fact.
RFC 6888, the IETF's common requirements for carrier-grade translators, explains the core data problem. It lists transport protocol, subscriber identifier, external source address, external source port and timestamp as information that could identify a subscriber behind a shared address. It warns that mapping records under heavy use can require large storage volumes. It also says a carrier-grade translator should not record destination addresses or ports unless an administrative reason requires them, reflecting privacy and volume concerns.
The cost begins before retention. Translators need sufficient address and port capacity, predictable behavior, redundancy, monitoring and protection against one user consuming disproportionate state. Record generation must keep pace with connections without degrading service. Time sources must be reliable. Subscriber identity must remain linked to access sessions. Failover must not create duplicate or untraceable mappings.
Retention then adds duration and governance. Records may need encryption, integrity protection, restricted access, searchable indexes, preservation against premature deletion and reliable destruction at the end of the applicable period. Staff must answer authorized requests and document disclosure. Security teams must treat the retained dataset as sensitive because it can connect people or accounts to network activity.
These costs are attributable to several causes. Scarcity encourages address sharing. The provider chooses a translation architecture. Law defines what must be kept and for how long. Online services decide what observations they preserve. Users generate traffic and expect affordable access. A serious governance analysis must resist assigning the entire bill to any one actor while still tracing which decisions enlarge it.
Address, port, protocol and time form the practical attribution key
An outside observer normally sees the post-translation source. For a TCP connection, that includes the public source address and source port, the destination and time. The translator knows which internal source and subscriber context were mapped to that public tuple. Accurate attribution joins the observer's record to the provider's state.
The port is often decisive. Two subscribers can use the same public address at the same second because their connections occupy different public source ports. A request that omits the port can return multiple candidates. This is not a minor administrative defect. It can produce a false accusation, an inconclusive answer or an expensive manual investigation.
Protocol matters because port spaces and mapping behavior differ. The same numeric port can exist simultaneously for TCP and UDP. Other protocols may not provide the same discriminator. A retention specification that says only "address and port" without protocol can preserve ambiguity. Systems should record the full meaning of each field, not assume operators will infer it later.
Time is equally important. Translation mappings can be short-lived and ports can be reused. A difference of seconds may point to another subscriber under heavy load. Records need a stated time zone, sufficient precision and known clock accuracy. The outside service and provider do not need perfectly identical clocks, but they need bounded uncertainty and a method for handling it.
Subscriber identity is not always one private address. In some architectures, internal addresses can also be shared or reused. RFC 6888 notes that a tunnel endpoint or another identifier may be needed. Mobile and wholesale networks can add layers in which an access provider, reseller and upstream translator each holds part of the answer. The evidence chain must identify where each translation occurred.
Port-block allocation can reduce record volume. A provider can assign a subscriber a defined block of public ports for an interval and record the block rather than every connection. RFC 7422 describes deterministic address mapping as one method of reducing the need for extensive records. The trade-off is that block size affects capacity, user experience and predictability. Determinism can also make subscriber behavior more linkable if implemented carelessly.
The practical attribution key should therefore be designed, tested and disclosed to authorized users before a case depends on it. Regulators should specify the observation they expect requesting bodies to supply. Providers should state uncertainty rather than force a unique answer from incomplete data. Courts and investigators should understand that a public address is evidence about network use, not proof of which human acted.
A logging duty cannot be inferred from technical possibility alone
Engineers can describe what a translator is capable of recording. That does not answer what a provider is legally required or permitted to retain. Communications-data law, privacy law, sector rules, court decisions and individual notices determine the obligation in each jurisdiction. The categories may also differ between ordinary business records and data created only to satisfy a state requirement.
This distinction is essential because carrier-grade systems can expose highly detailed behavior. Recording every mapping may be necessary for one attribution design. Recording every destination may reveal substantially more. RFC 6888's caution against destination recording recognizes that more data is not automatically better administration. Data minimization is a technical design principle as well as a legal one.
The phrase "logging mandate" can conceal several forms of compulsion. A statute may define a dataset all covered providers must retain. A minister or authorized official may issue a provider-specific notice after considering necessity and cost. A court may order preservation or disclosure of existing records. A license may require enough records to resolve shared addresses. Each form has different scope, safeguards and review.
Providers also keep records for security, billing, capacity and abuse management. A legal duty may extend the retention period or require fields that ordinary operations would not preserve. Conversely, an operator may keep more than the law requires. Cost analysis should separate the statutory increment from the operational baseline where possible. Otherwise, industry can attribute every network modernization expense to regulation, while government can assume records already exist at negligible cost.
Requests for attribution are another stage. Retention does not authorize every access. Proper law normally defines who may request data, for what purpose, with what approval, and how disclosure is audited. A secure store can still become abusive if access is broad or weakly supervised. A restrictive access regime can still impose large storage and engineering costs.
Comparative analysis must preserve these differences. Australia's two-year dataset, the United Kingdom's notice model and European Union proportionality doctrine are not three versions of one rule. They provide evidence of how states connect address attribution to communications-data governance, but conclusions about legality must remain jurisdiction-specific.
NRS should not decide which investigations justify retention. Its legitimate role is narrower: explain how scarcity and address sharing affect technical feasibility, cost, accuracy and security. Lawmakers can then make necessity and proportionality judgments using real network evidence rather than an assumption that an address identifies one subscriber for free.
Australia's regime demonstrates the scale of implementation cost
Australia's Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 established a mandatory regime for covered telecommunications providers. Official Home Affairs guidance says specified telecommunications data must be retained for at least two years, protected through encryption and safeguards against unauthorized interference or access. It identifies the allocated Internet address as particularly important for matching a device or service to a customer.
The statutory dataset covers categories including subscriber information, source and destination identifiers, date, time and duration, communication type and location information, subject to the detailed definitions and exclusions in the law. The regime does not require retention of communications content or ordinary web-browsing history. For shared-address access, the operative question is which prescribed identifiers and provider records are necessary to resolve the observed public use.
The Australian government recognized that implementation was not costless. Its Data Retention Industry Grants Program had a budget of AUD 131.3 million and awarded 180 grants totaling AUD 128.4 million in 2016, according to the Australian National Audit Office. The funding model was designed as a one-off contribution toward existing providers' capital costs, based on half the midpoint of an industry estimate.
Later parliamentary reporting presented industry-reported compliance costs, excluding the grants, of approximately AUD 212 million across financial years 2014-15 through 2017-18, alongside amounts recovered from criminal law-enforcement bodies. These figures cover the wider data-retention regime, not carrier-grade translation records alone. They nevertheless refute the idea that attribution retention is merely free use of data every provider already keeps.
The distribution matters. Large carriers can spread fixed engineering and security costs across millions of subscribers. Small providers face fewer mappings but may still need compliant storage, encryption, access controls, legal review and request capability. The Australian regime permits applications for exemptions or variations, which can address particular service circumstances, but the details of those decisions are not generally a public comparative dataset.
Reported cost recovery from requesting bodies may not match the provider's full expense. The correct conclusion is not one definitive cost per subscriber, but a demonstrated material burden requiring continued measurement.
Australia also illustrates the public-finance choice. Government paid a significant share of initial implementation while new entrants were expected to comply as part of entering the market. Over time, remaining costs flow through provider budgets, charges and investment decisions. Users may pay through higher prices, reduced service differentiation or delayed network upgrades even when no bill item is labelled data retention.
For number governance, the lesson is that an IPv4 conservation method can activate a large neighboring compliance system. Regional allocation decisions do not control that system, but scarcity analysis should acknowledge it. Counting only the market value of an address understates the cost of making one address safely usable by many subscribers under a legal attribution duty.
The United Kingdom links retention to notices, feasibility and cost
The United Kingdom's Investigatory Powers Act 2016 takes a different form. Part 4 permits the Secretary of State to give a telecommunications operator a retention notice requiring specified communications data for statutory purposes, with a maximum retention period of twelve months. The decision requires approval by a Judicial Commissioner under the statutory framework.
Section 88 requires consideration of likely benefits, the likely number of users, technical feasibility, likely compliance cost and other effects on the operator. It also requires reasonable steps to consult an affected operator. These factors are directly relevant to carrier-grade translation because the feasibility and cost of address resolution depend on network design, traffic, port allocation and existing records.
The Act and explanatory material include source addresses and Internet connection records within the communications-data framework. Earlier United Kingdom legislation had already addressed data necessary to resolve Internet addresses. Where subscribers share a public address, resolution may require more than the address itself. The exact obligation depends on the notice and applicable definitions rather than a universal command to retain every translation mapping.
This notice model can be more tailored than a single dataset applied identically to every service. It can account for provider architecture and public need. Tailoring also reduces public visibility because notice contents may be restricted. Independent approval, consultation and review therefore carry much of the legitimacy burden.
Cost consideration should be substantive. A provider may technically be able to generate vast records, but a less intrusive deterministic allocation or a better requesting-body observation could achieve the attribution purpose at lower cost. Feasibility analysis should include accuracy, not only whether storage can be purchased. A system that returns several subscribers because requests omit ports does not become adequate through longer retention.
The 2024 Investigatory Powers (Amendment) Act changed parts of the notice and Internet connection record framework. Any operational assessment through 2027 must use current notices and guidance rather than assume the 2016 text remained untouched. This is another reason to avoid presenting a national regime as a static technical requirement.
The United Kingdom example offers a governance principle beyond its borders: the body imposing a retention obligation should consider the network consequences it creates. Cost, user count, feasibility and other effects belong in the decision, not in an industry complaint after deployment. NRS can improve those decisions by supplying common technical evidence and independent cost measures.
European Union law makes data architecture part of proportionality
European Union case law has repeatedly examined retention of electronic communications data under the ePrivacy Directive and the Charter of Fundamental Rights. The resulting doctrine distinguishes categories of data, purposes and safeguards rather than treating all metadata as equivalent. Address-linked identity data can be highly useful for attribution, but combining it with traffic and location data can reveal much more about private life.
In the 2020 La Quadrature du Net judgment, the Court of Justice addressed national retention measures and recognized circumstances in which addresses assigned to the source of a connection may be retained, subject to the legal tests it set out. The court did not provide a general approval for unlimited communications-data stores. Purpose, duration, access and safeguards remain central.
The Court's April 2024 judgment in Case C-470/21 refined the analysis. It held that Union law does not preclude general and indiscriminate retention of addresses for combating criminal offenses generally where national rules ensure strict separation among address, civil-identity and other data categories; secure technical separation; an effective method for permitted linking; review by an independent public body; a period limited to what is strictly necessary; and safeguards against abuse and unlawful access or use.
This judgment matters to carrier-grade translation because data design becomes part of legality. A provider cannot treat one giant searchable store as equivalent to separated categories merely because access policy says staff should be careful. Architecture, independent review and controlled linking determine whether retained address data can be combined into a more revealing account.
The decision also requires precision about what is being retained. An address linked to civil identity is not automatically the same as a record of destinations, locations or every translated connection. Carrier-grade attribution may require port and time records, but expanding the dataset changes the privacy analysis. National lawmakers and courts must evaluate the actual system.
Separation has cost. Providers may need distinct stores, keys, permissions, audit systems and linking services. Independent review adds administration. These are not arguments against safeguards. They are part of the true scarcity bill. If address sharing makes richer records necessary, privacy-preserving controls must be funded rather than described as optional overhead.
The European evidence therefore complicates simple cost complaints. An operator cannot say that the cheapest store is automatically proportionate. Nor can a government say that address attribution is harmless because the data is not content. The legitimate design minimizes fields, separates categories, limits duration, controls access and measures whether the stated purpose is achieved.
NRS should use this example to encourage privacy-aware network evidence without offering legal conclusions for individual member states. The technical contribution is to show which records are necessary under each translation design and which additional fields would enable broader observation. That distinction helps legal institutions apply their own standards accurately.
Regional allocation policy and communications law meet at the provider
Regional Internet registries allocate and register public number resources under their applicable policies. Mature IPv4 regions operate in conditions shaped by exhaustion, waiting lists, transfers, recovery and conservation. Those policies influence how costly and available addresses are to access providers. They do not normally prescribe how a provider maps each subscriber to a shared public address.
Communications regulators and legislatures act from another mandate. They seek lawful investigative capability, privacy protection, market oversight or national security. They may require providers to retain attribution data or answer authorized requests. They do not allocate the public address pool. Each institution can therefore view the downstream cost as someone else's domain.
The access provider cannot separate the domains so neatly. It decides whether to buy or lease more IPv4 resources, share existing addresses more intensively, deploy IPv6, use translation variants, change retail products or accept service limitations. A retention duty changes the relative cost of those choices. More intensive sharing may save addresses while increasing mapping records, port pressure and attribution complexity.
The transfer price of IPv4 is only one scarcity signal. A provider comparing architectures should also account for translator equipment, redundancy, engineering, record storage, legal access, security, reputation problems and customer support. An address that appears expensive in the transfer market may reduce years of downstream costs if it allows less sharing. Conversely, buying more IPv4 can delay a more durable IPv6 transition.
Registry policy debates should not choose the provider's architecture. They should ask whether policy impact reports include downstream externalities. A proposal affecting transfer friction, allocation eligibility or recovery could change the address supply available to access networks. The analysis should at least identify likely effects on sharing intensity and transition incentives.
Regulators should reciprocate. Before imposing a retention period or address-resolution duty, they should ask how regional scarcity and cloud or carrier architectures affect record volume. A requirement written around one address per subscriber may fail technically in a shared environment. A demand for exhaustive connection records may cost far more than a port-block design that serves the same lawful purpose.
NRS can convene the boundary without absorbing either institution. It can publish neutral models showing how address availability, sharing ratio, port policy and retention duration interact. Regional registries retain authority over resources; public bodies retain authority over law. Shared evidence reduces the chance that each sets policy on a fictional network.
The cost stack extends far beyond storage capacity
Storage receives attention because mapping records can be numerous, but it is only one component. The translator must first generate accurate records at traffic speed. Logging cannot become a bottleneck or a single point of failure. Providers may need local buffers, redundant collectors, integrity checks and back-pressure behavior that does not silently discard evidence.
Time infrastructure is a separate cost. Translators, subscriber systems, access equipment and collectors need synchronized clocks with monitored drift. Time-zone handling and daylight-saving changes should not alter machine records, even if reports display local time. Audit evidence must show whether a clock was within tolerance during the queried interval.
Identity correlation requires stable joins among network and customer systems. A private address alone may be reused. A subscriber session may move. Wholesale access can place customer records with one company and translation state with another. Providers need documented identifiers and retention alignment so one system does not delete the link while another preserves the mapping.
Security costs grow with sensitivity and duration. Records should be encrypted in transit and at rest, keys protected, privileged access limited, queries logged and unusual access investigated. Backups need equivalent controls. Testing environments should not receive unrestricted copies. A breach can expose associations that ordinary network operation would have forgotten quickly.
Request handling adds people and software. Staff must validate legal authority, normalize addresses and time, check whether a port is present, search the correct system, review ambiguity, deliver securely and retain disclosure records. Automation can reduce labor but can also scale errors. High-impact results need quality controls and an escalation path.
Deletion is an active capability. Records distributed among indexes, backups, temporary exports and case files do not disappear because a database row expires. Providers need retention classes, legal holds, deletion verification and rules for derived data. Keeping everything indefinitely may seem operationally simple but enlarges security and privacy liability.
Resilience adds duplication. A provider must consider what happens if a collector fails, a data center is unavailable or the translator changes software. High availability can multiply storage and network transfer. Disaster recovery must preserve integrity and access restrictions. A record system that works only during ordinary conditions is weakest when a major incident creates the greatest demand.
Finally, opportunity cost matters. Capital and skilled engineers devoted to legacy IPv4 attribution are not available for IPv6 deployment, access upgrades or security improvements. This does not make the legal duty unjustified. It means impact assessment should compare alternatives and fund the chosen obligation honestly.
Poor data quality can make expensive retention dangerous
Large record sets create an appearance of certainty. A query returns one row, so the result looks exact. Yet accuracy depends on field completeness, clock quality, mapping semantics, software behavior and the observation supplied by the requester. A single row can be the wrong row.
Missing public source ports are the most visible failure. Online services historically recorded source addresses but not ports because one address often appeared sufficient. Under carrier-grade sharing, the omission can leave many subscribers. RFC 6302 recommends that Internet-facing servers record source ports along with addresses and time to support attribution in shared-address environments. The burden must therefore be shared with services that originate requests.
Clock uncertainty can create another candidate. If the server clock is two minutes fast and the port was reused during that interval, a literal lookup may identify the later user. Providers should report the accepted time window and any ambiguity. Requesting bodies should preserve clock calibration evidence for important observations.
Failover can disrupt mapping continuity. Two translators may allocate from the same pool under coordinated rules, or a standby may begin with fresh state. Record collectors must identify the device and mapping epoch. Software upgrades can change port allocation or log format. Long retention periods span several generations of equipment, so interpretation documentation must survive the hardware.
Subscriber records can also be wrong. Accounts change hands, wholesale identifiers are delayed, installation addresses become stale and credentials are shared. Network attribution identifies a service context, not necessarily a person. Disclosure language should preserve that limitation. Investigators need corroborating evidence before assigning human conduct.
Quality measurement should include false matches, ambiguous results, missing fields, clock exceptions, collector loss, delayed ingestion and corrected disclosures. Providers may be reluctant to publish these figures, but aggregate rates are necessary to judge whether a mandate achieves its purpose. A law that produces vast insecure data and frequent ambiguity would fail both efficiency and rights.
Independent testing can use synthetic subscribers and known connections. Auditors submit complete and incomplete observations, vary time accuracy, simulate failover and verify results. Tests should cover older records because indexes, archives and software readers change over the retention period. Success means a bounded, explainable answer, not merely a successful database query.
Scarcity costs reach users through more than monthly prices
Operators ultimately recover much of their cost from customers, owners or reduced investment. A recurring access price can include translation and retention without itemization. Smaller providers may charge more, accept lower margins or leave a market. Large providers may spread cost widely, making the per-user amount small while the aggregate remains substantial.
Users also pay through technical friction. Shared public addresses can trigger rate limits, abuse blocks and verification challenges when outside services treat all traffic from one address as one source. One compromised subscriber can affect others. Customer support must then explain why a user who did nothing wrong cannot access a service.
Port scarcity can degrade applications. Each public address has a finite transport-port space. Providers allocate ports among subscribers and connections, with reserves and exclusions. Heavy users, peer-to-peer applications, gaming, remote access and unusual protocols can encounter limitations. Adding public addresses reduces contention but increases scarcity cost.
Inbound reachability is another loss. Carrier-grade translation ordinarily prevents a subscriber from accepting unsolicited inbound IPv4 connections without a service provided by the operator. This affects self-hosting, some remote-support uses and innovation at the edge. Alternatives such as IPv6, relays or paid static addresses can restore capability, but they change price and dependence.
Privacy and security risks are costs even when no breach occurs. Subscribers bear the possibility that retained records are misused, exposed or interpreted incorrectly. Strong safeguards reduce probability but require funding. A public policy analysis should not count security spending as waste while also demanding low breach risk.
Investigative error imposes severe private cost. An incomplete address-only request may lead attention to several households or the wrong account. Clear ambiguity reporting and corroboration can prevent harm. Providers should not be pressured to give a unique identity when the network evidence does not support one.
Users can benefit from accurate attribution. It helps investigate abuse, protect children, respond to attacks and distinguish one subscriber from others sharing an address. The governance question is therefore not whether every cost is negative. It is whether benefits, burdens and safeguards are measured together and whether avoidable expense is reduced.
The distribution is often regressive. A business can buy dedicated addresses or customer-held resources. A low-cost residential plan is more likely to use intensive sharing. Its users then bear greater service friction and may have fewer support options. Scarcity management should make this distribution visible rather than present one average subscriber cost.
Deterministic mapping can reduce logs but creates new trade-offs
Deterministic address mapping assigns a predictable relationship between a subscriber and a set of public addresses or port ranges. Instead of recording every connection mapping, the provider records the subscriber's assigned block and interval. Given a complete outside observation, it can derive the responsible subscriber. This can dramatically reduce record volume.
The gain depends on design. A large fixed port block may support user demand but reduce the number of subscribers per public address. A small block increases sharing but can exhaust under busy use. Dynamic overflow restores capacity but reintroduces per-event records. Providers need empirical traffic distributions rather than arbitrary block sizes.
Predictability can assist troubleshooting and lawful attribution. It can also increase linkability if an outside observer learns that one port range corresponds persistently to one subscriber. Rotation or time-bounded assignments can reduce persistence, but then records must preserve the changing block history. Privacy analysis should compare the deterministic exposure with the larger store avoided.
Security behavior must account for port allocation. Randomization of source ports has protective value in some protocols. A deterministic scheme should not collapse the available entropy carelessly. Standards and equipment guidance address these engineering details; governance should verify that record reduction does not create a different vulnerability.
The approach also requires complete observations from outside services. If the request contains no source port, the provider still cannot identify one subscriber. Regulators considering deterministic designs should coordinate service-side retention guidance so the conserved provider records remain useful. One-sided optimization can move the data burden without solving attribution.
Hybrid models may be best. A provider can assign deterministic blocks for ordinary traffic, record exceptions, and keep session-level data only where necessary. The system should mark which attribution method applied. Auditors need to test transitions between blocks, overflow behavior, failover and software change.
NRS should not endorse one translation implementation for all networks. It can publish a comparison model covering public-address efficiency, port availability, record volume, privacy, failover, accuracy and migration to IPv6. Providers and regulators can then choose with an explicit view of trade-offs.
The broader lesson is that data minimization requires architecture. Telling providers to keep less while demanding exact results is not enough. Deterministic mapping, service-side port observation, precise time and narrower legal fields can jointly reduce volume. Governance should reward demonstrably sufficient design rather than the largest possible dataset.
IPv6 reduces the scarcity mechanism but not every retention duty
IPv6 gives networks enough address space to avoid many forms of public-address sharing. A subscriber can receive a prefix, devices can use globally unique addresses, and the provider can preserve end-to-end reachability subject to security policy. This removes the specific need to translate many users behind one scarce public IPv4 address.
It does not make attribution free. Providers still assign prefixes over time and may need to record which account held a prefix. Privacy extensions can change device interface identifiers. Home routers can delegate subnets. Mobile networks can use changing addresses. A legal duty concerning communications data may still require subscriber and time records even without translation.
Dual-stack transition often runs both systems. Users reach IPv6-capable destinations directly while legacy destinations use shared IPv4. Providers must maintain two attribution methods and identify which path a connection used. This can temporarily increase complexity. A cost model should not promise immediate savings the day IPv6 is enabled.
Nevertheless, retention cost strengthens the economic case for complete IPv6. A provider comparing investment should include avoided growth in translation capacity and mapping records, reduced port contention and fewer shared-reputation incidents. These benefits are distinct from address acquisition prices. Public support for transition can be justified partly by the compliance and security costs it avoids.
RIRs and NRS can support timely prefix allocation, routing security, operational training and measurement of IPv6 reachability. They should report whether networks have merely announced IPv6 or deliver reliable customer service across products. Partial deployment that leaves critical traffic on IPv4 may not reduce the logging burden significantly.
IPv6 is therefore structural relief, not a legal exemption. It attacks the scarcity mechanism that makes attribution expensive. Good governance uses that advantage while preserving proportional records and safeguards for the assignments that remain.
Regulators should specify outcomes, minimum fields and cost evidence
A defensible retention measure begins with purpose. The authority should state which attribution question must be answerable, for which serious public need, over what period and under which access safeguards. Technical fields follow from that purpose and the network architecture. Starting with "keep everything" avoids analysis rather than completing it.
For shared IPv4, a minimum technical request usually needs the observed public source address, source port, transport protocol and timestamp with time zone and precision. The provider needs the corresponding subscriber and mapping or port-block record. Destination data should not be collected by the translator merely because it might someday be interesting when the outside service already knows the connection it observed.
Impact assessment should model several network sizes and sharing ratios. It should estimate event rate, deterministic-block alternatives, retention volume, redundancy, security, request staffing and deletion. It should include small providers and wholesale chains. A single national total can hide market-entry barriers.
Cost recovery should align incentives. If requesting bodies pay a reasonable marginal cost for complex searches, they have reason to submit complete observations and avoid speculative queries. If providers receive full reimbursement regardless of efficiency, they may lack reason to minimize systems. If no recovery exists, users fund public investigations through access prices. A balanced model separates efficient baseline compliance from exceptional request cost.
Accuracy requirements should be explicit. Providers must be able to return ambiguity. Request forms should reject missing ports where sharing makes them necessary or state that only a candidate set is possible. Disclosure recipients should receive caveats about subscriber versus human identity. Oversight should sample results against known test events.
Security rules need resources and verification. Encryption alone is not sufficient; key management, access controls, separation, audit, incident response and deletion all matter. Regulators should avoid mandating long retention while treating protection as an unfunded secondary concern. The stored data exists because public authority required or influenced its preservation.
Sunset and review should use evidence. A retention period can be reduced if most authorized uses concern recent data and longer storage produces little benefit. Australia's privacy authority pointed to statistics showing that most disclosed data in early years was less than twelve months old when questioning proportionality of the two-year period. Such analysis should be routine rather than exceptional.
Finally, regulatory changes should allow realistic implementation. New fields, separation requirements or access rules may require equipment changes and testing. Timelines should reflect complexity without letting temporary transition become permanent noncompliance. Public reports should show what was achieved, at what cost and with what errors.
RIRs should account for externalities without becoming surveillance bodies
Regional registries possess useful evidence about IPv4 availability, transfers, allocations, returns and IPv6 distribution. They can help estimate scarcity pressure by region and network type. They should not collect subscriber translation records or decide who may access communications data. Doing so would exceed their role and create dangerous centralization.
Their contribution can begin with policy impact statements. When evaluating IPv4 allocation or transfer changes, staff can identify whether the proposal may alter incentives for intensive sharing, address leasing or transition. The statement need not calculate every provider's legal cost. It should prevent a claim that address conservation has no downstream administrative consequence.
Registries can also improve IPv6 access and operational support. Timely prefix distribution, clear registration, routing security and training lower one barrier to transition. Measurement can compare allocations with actual routing and customer capability. The public value lies in showing where address abundance has translated into reduced dependence on shared IPv4.
Abuse contacts and registration accuracy remain important. An outside service observing harmful traffic from a shared address needs to reach the responsible provider. Public registration will normally identify the network, not the subscriber. The provider then applies its internal evidence under applicable law. Clear delegation and current contacts reduce delay without exposing subscriber records publicly.
NRS can extend this boundary work by bringing regulators and operators into the same evidence forum. Its legitimacy depends on refusing two expansions: it must not use scarcity as a reason to normalize indiscriminate surveillance, and it must not use privacy as a reason to deny the real attribution problem created by sharing. Technical honesty supports institutional restraint.
NRS should publish a scarcity-attribution account
A scarcity-attribution account would connect number use to the downstream systems required for reliable operation. At network level, it would record public IPv4 pool size, approximate sharing ratio, translation method, IPv6 traffic and customer reachability, port-exhaustion events, shared-reputation incidents and address acquisition or lease cost. Sensitive configuration could remain confidential.
The account would separately record attribution burden: mapping or block records generated, retention classes, storage and security cost, authorized request volume, incomplete requests, ambiguous results, correction rate and disclosure time. Legal categories should remain distinct so a two-year national regime is not compared directly with a provider-specific twelve-month notice without context.
User impact belongs beside operator cost. Surveys and support data can measure blocked services, challenge frequency, inbound-reachability limitations, paid static-address adoption and small-provider pricing. Investigative benefits can be represented through authorized uses, successful attribution and cases where better port data prevented ambiguity, subject to lawful confidentiality.
The account is not a public surveillance inventory. It should use aggregates, ranges and independent assurance. No subscriber mappings, target details or secret security designs need publication. The objective is to let institutions see whether a conserved address imposes rising hidden cost and whether transition measures reduce it.
NRS can define common terms. "Mapping record" should not include a deterministic block assignment unless stated. "Attribution success" should distinguish a unique subscriber from a candidate set. "IPv6 deployment" should distinguish route announcement, customer availability and traffic share. Comparable definitions prevent favorable but meaningless reporting.
The account should trace cost recovery. It can show government grants, provider spending, requesting-body reimbursements and estimated subscriber allocation without revealing confidential contracts. This helps public authorities understand who pays. It also reveals whether small providers face disproportionately high fixed costs.
Annual publication through 2027 would establish trend rather than one snapshot. A healthy transition might show higher IPv6 traffic, lower mapping volume per subscriber, fewer port incidents, improved request completeness and reduced retained-data exposure. If address sharing intensifies while costs and ambiguity rise, policy institutions would have evidence to reconsider incentives.
The Society should invite independent critique of the method. Providers may overstate cost; governments may overstate benefit; privacy groups may identify omitted risks; investigators may identify missing operational value. A credible account makes assumptions visible and revises them when evidence changes.
Three cases expose cost, accuracy and continuity failures
Consider a regional provider that places fifty thousand subscribers behind a carrier-grade translator. A national rule requires address-attribution data for two years. The provider initially records one entry per translation mapping. Connection volume produces far more data than expected, collectors fall behind during peak periods and storage costs threaten network investment.
The correct response is not to abandon attribution or purchase storage blindly. The provider and regulator test deterministic port blocks, preserve exception records, improve service-side request requirements and validate known events. The revised design reduces volume while keeping unique results for complete observations. Security review confirms that block history is separated from broader subscriber data.
Now consider an investigation in which an online service supplies a public address and a minute-level time but no source port. Hundreds of subscribers shared the address. The provider's expensive two-year store contains every mapping, yet the query cannot identify one account. Pressure to return the "most likely" subscriber would convert technical ambiguity into institutional error.
The provider should return a candidate set or explain insufficiency. The requesting body should seek server records containing the port or other corroboration. Oversight should record the incomplete request as a system-performance failure. The lesson is that retention burden and evidence quality must be coordinated across the full attribution chain.
The third case is a small provider serving remote communities. It faces the same baseline security and request duties as national carriers but has limited engineering staff. Buying more IPv4 is costly, while replacing customer equipment for complete IPv6 will take years. Compliance spending delays a resilience upgrade that would improve service during emergencies.
A proportionate policy could provide shared accredited tooling, grants, staged IPv6 support and a tailored retention design without weakening access controls. Cost recovery might recognize fixed expense. NRS evidence could show that the provider's constraint is not unwillingness but the collision of scarcity, legal duty and public-service continuity.
These cases demonstrate why slogans fail. "Keep more data" does not fix missing observations. "Deploy IPv6" does not replace equipment overnight. "Buy addresses" may delay structural transition. "Protect privacy" must include secure design for records the law actually requires. Governance succeeds by matching the remedy to the source of cost and uncertainty.
The 2027 review should test whether cost and exposure are declining
The 2015-2027 period begins with Australia's legislation and a wider expansion of carrier-grade sharing under mature IPv4 scarcity. It ends as an observation point for whether institutions have learned to measure the combined system. The review should not assume that lower storage prices mean lower social cost.
The first measure is attribution efficiency: records generated and retained per subscriber, per public address and per successful authorized result. The second is request quality: the share of requests containing address, port, protocol and sufficiently precise time. The third is accuracy: unique matches, ambiguous returns, corrections and known errors.
The fourth is security exposure. Providers should report access violations, data-loss events, excessive privilege findings, overdue deletion and independent assessment results in appropriate aggregate form. A system that becomes cheaper by weakening controls has not improved. The fifth is duration: how often older retained data is lawfully used and whether that use justifies its continuing risk and cost.
Network transition measures should include IPv6 availability to subscribers, traffic share, IPv4 sharing ratio, port-exhaustion incidents and dedicated-address demand. A provider announcing an IPv6 prefix while most customer services remain IPv4-dependent should not receive full transition credit. Evidence must reflect actual paths.
Cost should be reported by category: translation infrastructure, record generation, storage, security, request handling, audit, deletion and customer support. Government contribution and request reimbursement should be visible. Small and large providers should be compared separately. Currency and accounting assumptions must be stated.
User outcomes should include access blocks caused by shared reputation, paid escape to static addresses, service limitations, privacy complaints and mistaken attribution. Benefits should include cases where complete evidence distinguished users and supported legitimate investigation. Balanced reporting will be more persuasive than presenting either cost or public safety alone.
Policy review should ask whether less data could achieve the same result. If deterministic allocation, shorter duration or better requesting-body records reduce exposure without harming authorized use, rules should adapt. If a serious public need demonstrably depends on older data, funding and safeguards should reflect that evidence.
The decisive trend is whether each year of scarcity management requires more sensitive data per user or less. A successful IPv6 and minimization strategy should reduce dependence on connection-level IPv4 mapping. If retained volume keeps rising despite transition claims, institutions should investigate what traffic and product gaps remain.
Scarcity governance must include the bill it sends outside the registry
IPv4 scarcity is not only the price of a transferable block or the length of a waiting list. It is also the translator installed in an access network, the public ports divided among subscribers, the records generated to restore attribution, the secure systems that hold those records and the support cases caused by shared reputation. These costs do not appear in a regional registry database.
Legal retention duties can amplify every component. Longer duration multiplies storage and security exposure. Broader fields increase privacy impact. Incomplete requests waste investment. Weak safeguards convert a public-safety measure into a breach target. Yet accurate, proportionate attribution can distinguish users and support legitimate investigations. The correct position is skeptical measurement, not categorical approval or dismissal.
Responsibility is distributed. Regulators must define necessity, minimum fields, duration, access and cost. Operators must choose efficient architecture, preserve accuracy and protect records. Online services must retain source ports and reliable time when they expect address resolution. Users should receive honest information about shared access and available alternatives. Regional registries should account for scarcity externalities while staying out of subscriber surveillance.
NRS can make the institutional boundary productive. A scarcity-attribution account would show where address policy, network design and communications law interact. Common metrics would expose ambiguity and fixed costs. IPv6 support would reduce the underlying need for intensive sharing. Evidence-led dialogue would let public authorities adjust obligations without asking number institutions to decide criminal or privacy law.
The central governance question is who pays for an address system that remains administratively intelligible after scarcity forces many users together. Today, operators pay first, users pay indirectly, public budgets sometimes contribute, and society carries breach and error risk. That distribution may be justified for a particular law, but it should never be invisible.
By 2027, mature policy should be able to state how much retained data shared IPv4 creates, how often it provides a unique and lawful answer, what it costs to secure, who funds it and how quickly IPv6 is reducing the burden. Without those facts, scarcity management exports costs while claiming conservation success. With them, number governance can support legitimate public needs while demanding minimization, accuracy, fair funding and a credible path beyond address sharing.

