Summary

  • prop-162-v003 asks APNIC to remove named contact fields from future bulk-WHOIS data, except abuse contacts, and to cause existing bulk users to remove earlier contact information.
  • APNIC’s impact assessment says it has limited ability to monitor previously downloaded or published data and that the existing agreement does not generally require deletion of prior data without evidence of misuse.
  • The live history records EC endorsement and “Technical components implemented – Awaiting WHOIS AUA”. A technical filter, a new agreement and remediation of old copies are separate states.
  • A privacy-safe completion account should report export tests, recipient re-accession, deletion notices or attestations, access expiry or revocation, known republication and unresolved legacy copies without exposing contact data or accusing recipients.

The next file is the easy part.

APNIC operates the system that generates a bulk-WHOIS dataset. It can change the export code, remove address, telephone, fax, email and notify fields from defined objects, retain the abuse-contact exception, generate a test file and compare the result with the specification. If an excluded field appears, the test fails. If the code is corrected, the next file changes.

The previous file is different. Once downloaded, it sits inside another organisation’s systems. It may have backups, extracts, research products or a downstream publication history. Editing APNIC’s source does not edit those copies. A new access condition can affect whether a known recipient receives another file.

It does not by itself prove what happened to yesterday’s data.

That difference is the central fact inside APNIC’s prop-162 record. The proposal is commonly described as WHOIS privacy. Its more revealing contribution is to expose two kinds of institutional power: power over future disclosure and leverage over people who already received information.

One proposal, two operations

Version 3 of the proposal says more than 400 organisations around the world have bulk access and may download the complete dataset as required. It names cybersecurity companies, Internet service providers, universities, researchers and law-enforcement agencies among them.

That number must remain inside its evidentiary boundary. It describes an access cohort in the proposer’s text. It does not prove that every organisation retained a copy, republished data or breached an agreement. The same proposal expressly says APNIC did not have evidence of abuse by parties with current bulk-access agreements. It also gives examples of organisations contacting APNIC members through details said to be published exclusively in WHOIS. Those propositions may motivate a policy discussion; they do not identify which distribution path produced any particular contact.

The proposed solution has a prospective limb. Except for abuse contact information, APNIC would remove address, phone, fax, email and notify fields from Org, IRT and role objects in the bulk dataset. Ordinary or authorised automated queries could still return contact information for network resources. The policy is therefore not a plan to make operational contact impossible. It changes the scale and default distribution of selected fields.

The second limb looks backward. APNIC should, the text says, cause existing bulk users to remove the contact information from their systems and from the Internet. This sentence describes an outcome. It does not itself supply the control mechanism that can prove the outcome.

APNIC published the limit

The Secretariat impact assessment deserves credit for refusing to treat deletion as a database switch. It says APNIC would have limited ability to monitor previously downloaded or published WHOIS data unless a clear breach of the acceptable-use agreement occurred and could be tied to a specific party.

Its legal assessment adds a sharper boundary. The existing agreement did not contemplate a requirement to delete prior data without evidence of misuse. APNIC could strengthen future terms and make continued access conditional on accepting them. It could remove ongoing access until a republisher acceded. But, the assessment says, this would not address prior issues.

This is the rare useful admission in an implementation document: control over the next transaction is not control over the last one.

The assessment also warns that contact information placed inside free-text desc or remarks fields of inetnum or inet6num objects would remain visible. Field-level filtering is necessary, but the output must be tested for content as well as schema. That warning does not prove that every record contains embedded contact data. It defines a test that a complete implementation should run.

Status is already component-shaped

The live proposal page labels the current status Reached Consensus at APNIC 60. Its dated history is more informative. It records consensus on 11 September 2025, the end of final comment on 14 October, Executive Council endorsement on 4 December and, on 11 February 2026, Technical components implemented – Awaiting WHOIS AUA.

None of those lines should be erased by a single later label. Consensus authorised a direction. EC endorsement moved it into institutional action. Technical implementation addressed a system component. The agreement remained a named dependency. Historical-copy remediation was a separate evidentiary problem from both.

APNIC’s current public bulk-access page says applicants sign and lodge an acceptable-use agreement. The linked APNIC-091 PDF identifies Version 005, dated 17 December 2010 and marked Active. It restricts use and onward bulk transfer. The checked text contains no general requirement to delete earlier downloads when APNIC later changes the dataset. That matches the assessment. It does not prove that no newer private draft, separate undertaking, law or case-specific remedy exists.

What completion would look like

A defensible record begins with the future export. It names the dataset version and generation time, the object types and excluded fields, the abuse-contact exception and the test used to find contact strings inside free-text fields. Corrections receive versions. A technical filter can then be verified without opening a member’s private case.

The second row concerns continued access. For each known recipient, APNIC can preserve a protected identifier, approved purpose, applicable agreement version, accession or renewal date, access state and later change. Public reporting needs only cohort counts: invited to new terms, acceded, pending, expired or revoked.

The third row concerns old copies. It records whether a deletion notice was sent, acknowledged and answered with an attestation or documented exception. An attestation proves that an identified actor made a statement under a defined process. It does not prove that every backup or downstream copy vanished. Unknown must remain unknown rather than being reported as zero.

A fourth row handles known republication. It preserves source attribution, applicable terms, notice, response, correction or removal and review. Absence of a known case is not proof that no other publication exists.

The public account should aggregate these states and publish a cutoff time, definitions and an unresolved count. It should not publish the contact data again, create a directory of bulk users or imply wrongdoing merely because a recipient needs time to test deletion across legitimate research systems.

Privacy cannot be certified by a disappearing column

Removing fields from future bulk downloads can reduce exposure without weakening the direct contact path needed for incident response. That is worth doing. The institutional error would be to describe the result as though one successful export test also closed the historical record.

APNIC’s own sources do not support that conclusion. They support something more disciplined: prospective filtering is testable; continued access is contractible; old-copy remediation is attestable only within known relationships; Internet-wide erasure is not demonstrable.

The correct completion statement is therefore allowed to contain limits. It may say that all new datasets passed field tests, all active recipients accepted a named agreement, a defined number attested deletion, another number received exceptions, and some legacy copies remain unresolved. That is not an embarrassing report. It is the only report that does not claim power APNIC cannot prove it possesses.

Sources