Summary

  • RDAP was designed to support security services that traditional Whois lacked. Since 2015 its standards have contemplated anonymous access, authenticated clients and different responses according to policy and need. The technical ability to tier access is therefore a feature, not an accidental deviation.
  • Authentication is not the same as entitlement. A server can establish an identity yet still make an unfair decision about purpose, fields or permitted volume. The constitutional question is who writes those rules, how refusals are explained and whether outsiders can test the result.
  • Registration evidence has mixed risk. A person's direct phone number can expose them to harassment; a resource range, current organisation, registration status and chain of recognised authority are needed to test uniqueness and accountability. Treating the whole record as one privacy unit obscures that difference.
  • Tiered access can favour governments, major platforms, incumbent operators and commercial intelligence firms if recognised credentials, accepted purposes and application costs are available mainly to them. Small networks, journalists, independent security researchers and civil society may then receive a thinner version of the same public institution.
  • A defensible model should classify fields by harm and public function, not classify people by institutional prestige. High-risk personal data can require a stated purpose and stronger assurance while authority-bearing organisational facts remain broadly visible.
  • Every protected-field decision needs an auditable receipt: policy version, field requested, requester class, declared purpose, decision, reason, expiry and review route. Aggregate publication should reveal unequal treatment without exposing sensitive investigations or query histories.
  • NRS can contribute positively by advocating a portable assurance vocabulary and fair criteria for multiple identity providers. RIR RDAP operators, competent authorities and authorised assurance providers must adopt, operate and oversee any reciprocal access system; NRS cannot accredit them or compel treatment.

The access decision now sits between the question and the fact

Traditional public registration lookup presented a blunt bargain. The record was either reachable or it was not, and much of what was reachable appeared to every visitor. That openness made personal details too easy to collect, but it also let an engineer, a reporter and a large company begin with substantially the same observable record.

RDAP permits a more discriminating arrangement. A client can be anonymous, identified or authenticated. Once the server knows something about the client, it can decide whether the person is authorised to receive a particular registration entity or field. In the federated model published as RFC 9560, identity information and accepted purpose claims can support a response suited to the user's level of access. A server may refuse the query or omit information the user is not authorised to receive.

The useful innovation is granularity. An operator investigating a route leak may have a sound need for a current operational contact, while an automated collector has no equivalent need for a private home address. A holder may need to see the evidence attached to its own record. A member of the public may need enough information to establish which organisation is recognised for an address range. Different needs need not produce identical disclosure.

Yet the same machinery creates a new point of institutional power. The decisive fact is no longer simply what the registry holds. It is what the registry shows this client after assessing identity, credentials, purpose and policy. Two people can submit the same resource query and receive materially different evidence.

That difference is legitimate only if it can be explained. Otherwise authentication becomes a velvet rope around a public record. Privacy language may describe the result, while the practical allocation of knowledge follows organisational status, legal budgets and established relationships.

The issue is not whether every field should be public. It should not. The issue is whether the right to verify registration authority remains public in substance once access is divided into tiers.

RDAP made differentiated access possible before policy made it trustworthy

RFC 7481, published in March 2015, described security services for RDAP. It required an authentication framework able to accommodate anonymous access as well as verified identities and allowed server operators to offer varying degrees of access according to policy and need. Where differentiated access is supported, the standard calls for granular controls per registration data entity. Its examples include no contact information for an anonymous user and fuller access for a special authenticated group.

This was a major improvement over the older Whois protocol. Whois did not provide a common security mechanism for assigning access levels by authenticated identity. RDAP could use HTTP, encrypted transport, structured errors and machine-readable responses. It created the technical room for privacy protection without forcing every query into a single public exposure rule.

The standard did not settle the political questions. It did not decide which groups deserve fuller access, which evidence they must provide, whether a rejected applicant can appeal or how an independent observer should compare decisions across operators. It warned that access policy would likely vary from one operator to another. That prediction matters more now that authentication can become practical at scale.

RFC 9560, published in April 2024, supplies a federated authentication method based on OpenID Connect. It addresses the unwieldy prospect of a client maintaining separate credentials for many RDAP servers. Identity providers can assert information about a user, including optional allowed-purpose claims; servers remain responsible for deciding whether to trust those claims and what access follows. The standard also recognises that some authorised users may need a do-not-track treatment for sensitive queries, subject to policy and law.

These are protocol capabilities, not evidence of uniform RIR deployment. The presence of farv1 in the IANA RDAP Extensions registry shows that the method is standardised. It does not show that every regional registry accepts the same identity providers, purpose values or access classes. Nor does it establish that current public number-resource responses have already become a single global tiered system.

Policy legitimacy therefore cannot be borrowed from technical maturity. A secure login proves that a person controls a credential. It does not prove that the person's research is less valuable than a bank's investigation or that a registry's field decision is proportionate.

Authentication, authorisation and disclosure are three separate judgments

Public debate often compresses three decisions into the word “access”. That compression hides where unfairness enters.

Authentication asks whether the claimant is the person or organisation represented by a credential. It can involve an account, certificate, token or federated identity. A sound result reduces impersonation. It says little about what the person should see.

Authorisation asks whether the authenticated claimant has a permitted relation or purpose. A holder may be entitled to inspect its own protected details. An incident responder may be allowed to obtain a contact route. A researcher may be allowed to run bounded queries under an approved study. The answer depends on rules and evidence beyond identity.

Disclosure asks which fields, result limits and uses follow from that authorisation in this particular query. Even an authorised investigator may need only a contact relay, not a private telephone number. A holder's lawyer may need historical authority evidence for one range but no personal details about another organisation. The least harmful sufficient response can differ by field.

Accountability requires a separate record for each judgment. “Access denied” is too coarse. Was the credential invalid, was the identity provider unrecognised, was the stated purpose outside policy, did the field carry excessive risk, was the requested volume disproportionate or did the service merely fail? Each answer points to a different remedy.

The separation also protects privacy. If a server discloses too much, an auditor should be able to determine whether authentication failed, the purpose was misclassified or the field rule was overbroad. A generic assertion that the requester was authorised cannot excuse disclosure of every value attached to the record.

For users, the distinction prevents circular application processes. A researcher should not be told to acquire an institutional credential without being told which identity attributes are needed. An operator should not prove a legitimate incident purpose only to discover that its credential class is ineligible. Rules should identify the minimum assurance for each field and purpose before a query is made.

Tiering becomes governable when these judgments are visible as separate, reviewable acts. Without that separation, identity becomes a convenient explanation for discretion exercised elsewhere.

The public core of a number record is not the same as a person's contact card

Number-resource registration serves coordination. RFC 7020 describes uniqueness and registration accuracy as core requirements of the Internet Numbers Registry System. A useful record helps establish that an address range or autonomous system number is registered once, which party is recognised and where operational coordination can begin. These functions do not require universal exposure of every personal field.

A number record contains several kinds of information with different risks. The resource itself, its range, status, parent relation, registration events, source registry and current organisational holder support public verification. So do clear statements about the nature of the registration and any visible qualification on the result. Hiding those facts makes it difficult to test whether a claim of authority matches the recognised record.

Direct personal contact details are different. A named employee's residential address, individual telephone number or personal mailbox can invite harassment, fraud and bulk profiling. The risk rises when fields can be collected across many records. A contact relay, role account or authenticated incident channel can often support operations with less exposure.

Authority evidence sits between those categories. A full transfer instrument, identity document or private mandate should not be open merely because it supports a registration. But the public may still need to know that an authority change occurred, when it became effective, which organisation succeeded which and what kind of evidence was accepted. A bounded attestation can preserve verifiability without publishing the underlying document.

The policy mistake is to treat the entire entity entity as either personal or public. An organisation name may be necessary for accountability, while the employee represented inside the same entity deserves protection. An abuse role may need a reliable contact path, while the direct address behind that path need not be displayed. One structured response can contain both low-risk institutional facts and high-risk personal values.

RDAP's structured form is well suited to this distinction. The governance task is to use the granularity honestly. If personal risk in one field becomes the reason to hide every authority-bearing field, privacy has been used to shelter the institution rather than the person.

Tiered public records can recreate a club even without charging admission

An access tier does not need a fee to exclude. It can demand a credential available only through recognised employers, a legal purpose expressed in specialised terms, insurance, a local presence, a compliance department or a history of dealings with the registry. Each condition can sound reasonable alone. Together they can reserve useful registration evidence for incumbents.

Large network operators can maintain registry accounts, legal contacts and automated clients. Major platforms can employ investigators and negotiate service arrangements. Public authorities can present official credentials. Commercial intelligence companies can spread application costs across customers. Small operators and independent researchers have less institutional surface with which to prove themselves.

This is especially troubling because those outsiders often test the institutions that insiders rely upon. Academic researchers compare records over time. Civil-society groups examine concentration and representation. Journalists investigate disputed control. Volunteer operators trace abuse across networks. A small access provider may need to verify a new counterparty before accepting a route or service relation. Their need is not made trivial by the absence of a famous letterhead.

Tiering can also produce geographical inequality. An identity provider familiar in one region may not serve users elsewhere. Documents accepted in one legal system may be difficult to obtain in another. English-only purpose categories can favour applicants with specialist counsel. A requirement for a corporate entity can exclude individual experts whose work is publicly valuable.

The remedy is not to waive authentication for everyone. It is to avoid using institutional class as a substitute for risk analysis. A researcher can submit a bounded purpose, retention plan and publication commitment. A small operator can prove control of an ASN and an incident relation. A journalist can seek specific authority fields without receiving bulk personal data. Civil society can use an accredited intermediary without surrendering editorial independence.

Access rules should ask what harm the field creates, what purpose the query serves and what safeguards the user can actually provide. Prestige is a poor proxy for all three. A system that recognises only established institutions will verify the already powerful and leave everyone else to trust them.

Purpose claims need evidence, limits and an expiry date

RFC 9560 allows an identity provider to assign accepted RDAP purpose values to a user's credential. The server may consider those claims when deciding access. Purpose can improve privacy because it connects disclosure to a task rather than to identity alone. It can also become ceremonial if a broad label unlocks fields indefinitely.

A useful purpose has four properties. It is specific enough to test, linked to fields needed for the task, bounded in time and attributable to a responsible user. “Security” is too broad if it provides continuing access to every contact. “Investigating a route-origin incident affecting these prefixes during this period” can support a narrower disclosure. “Research” says little without a question, population, safeguards and end date.

The burden should remain proportionate. A person seeking one organisational authority field should not submit a research protocol suitable for a bulk longitudinal study. A holder checking its own record should not prove public interest. The greater the personal sensitivity, query volume and retention period, the more assurance is justified.

Purpose must also be revisable. A study ends. An employee changes role. A court order expires. An incident closes. Credentials should not accumulate permanent powers because an identity provider once assigned a claim. The access service should require renewal and make revocation effective across participating servers.

The server, not the identity provider, remains accountable for disclosure. RFC 9560 leaves acceptance of purpose values to the operator. A provider's claim is evidence about the user; it is not a command to reveal data. Conversely, the server should not reject a recognised purpose by invoking an unpublished local preference.

Users need to know which purposes exist, who can obtain them, what evidence is required, which fields they can support and how long they last. IANA's registry of RDAP query purpose values can make shared labels visible, but a label alone cannot supply due process. Local implementation must add clear eligibility and review.

Purpose limitation works only when the institution can say no precisely and can also be challenged when it says no unfairly.

A field-risk matrix is fairer than a hierarchy of trusted organisations

The central design choice should be a matrix of fields and harms, not a ladder of prestigious users. Such a matrix would begin with the data, identify why it exists and ask what exposure could do.

The first measure is coordination value. Resource range, registration status, source registry, organisational holder and effective dates carry high value for public verification. An individual's direct telephone number often carries lower general value because a role address or relay can serve the operational purpose.

The second measure is subject harm. Could the value expose a home, identify a vulnerable employee, enable credential attacks or reveal a protected association? Harm depends on context, not merely on whether a field is traditionally public. A business address can be safe for a large company and dangerous for an individual operator working from home.

The third is aggregation risk. One public contact may be benign while unrestricted reverse search across a region enables profiling. Query rate, result size and reverse-search capability can therefore receive stronger controls without hiding the single-record authority core.

The fourth is volatility and correction risk. A stale direct contact can misdirect complaints and expose a former employee. A stable organisation identifier is less likely to create the same personal harm. Fields that change rapidly need visible update dates and easier correction.

The fifth is evidentiary necessity. If a field is the only practical way to verify who controls a resource, hiding it imposes a large accountability cost. The service should consider whether a less harmful attestation, relay or proof can provide equivalent assurance.

Users then receive access according to the risk created by the requested combination. An anonymous visitor can see low-risk authority facts. An authenticated operator with a specific incident can obtain a protected contact route. A vetted researcher can receive a bounded set with aggregation safeguards. A data subject can see and challenge the values relating to them. A court can compel defined information under applicable law.

This model still creates tiers, but the tiers attach to risk and purpose. They do not declare one profession inherently worthy of the complete record. That distinction is the difference between privacy engineering and institutional privilege.

Redaction notices should tell a client what kind of evidence is missing

A blank response is not privacy transparency. It leaves the client unable to distinguish an absent field, an uncollected value, a policy redaction and a service error. That ambiguity harms both the person protected and the user relying on the record.

RFC 9537, published in March 2024, defines an RDAP extension that identifies redacted fields. It supports methods including removal, empty value, partial value and replacement value, with paths identifying the affected location and optional names and reasons. This allows a response to say that a field exists but has been altered or withheld, rather than quietly making it disappear.

For number-resource records, the notice should answer practical questions. Which field or entity was affected? Was the value removed, masked or replaced by a relay? Which published policy class authorised the treatment? Is a fuller view potentially available to an authenticated user? Where can the person represented by the data seek correction? Where can a requester challenge a denial?

The reason should not expose the protected value. Nor should it reveal that a covert investigation is underway. A concise code such as personal-contact risk, legal restriction, security sensitivity or requester not authorised can be sufficient if the policy behind each code is public.

Consistency matters. If one server represents an organisation name as absent while another marks the same field as redacted, researchers may draw a false conclusion about registration quality. The redacted extension can reduce this ambiguity, but only where operators implement it consistently and clients preserve the notices in their analysis.

The public core also needs completeness signals. A response could identify the policy version and view class, allowing a client to compare like with like. “Public view under policy 4.2” is more honest than a response that appears complete but is not.

Redaction should leave a visible institutional footprint. A private person can remain private while the registry remains answerable for the act of concealment.

Auditability begins with a receipt for each consequential decision

Tiered access cannot be assessed from policy documents alone. Reviewers need evidence of how rules affect real requests. The necessary evidence is not a public list of who searched for whom. It is a controlled record of decisions and a safe aggregate account of patterns.

Each protected-field request should create a receipt containing the server, time, authenticated requester class, identity-provider class, declared purpose, resource queried, fields requested, fields returned, decision code, policy version, credential expiry and review route. Sensitive identity and query details can be encrypted, segregated and retained for a justified period. The requester should receive a human-readable subset.

The receipt serves several functions. A user can identify what to challenge. A privacy officer can reconstruct an excessive disclosure. An auditor can test whether similar requests received similar outcomes. A registry can discover that one purpose category produces more errors or that one identity provider's claims are unreliable.

It also prevents invisible policy drift. If the operator changes a field from public to protected, the policy version and effective time should change. Historical analysis can then distinguish a real registration change from a change in visibility. Without this marker, an apparent disappearance may be mistaken for an organisational event.

Aggregate reporting should include the number of eligible requests, requester classes, purpose classes, approval and partial-approval counts, denial reasons, response times, reviews and reversals within the measured service. Results must preserve their denominators. A registry should not infer global fairness from one participating population.

Certain queries deserve exceptional handling. RFC 9560 includes a do-not-track claim for authorised users whose identity should not be associated with queries, subject to law and service policy. That protection can be necessary for sensitive investigations. It also creates an audit challenge. The system can record that a policy-compliant untracked request occurred, what fields were disclosed and which control approved it without recording an association the standard says must not be kept.

Auditability is not maximum logging. It is enough evidence, under divided access, to test institutional conduct without creating a second privacy hazard.

Researchers need a route that is rigorous without requiring institutional sponsorship

Research access is often discussed as if “researcher” were a credential. It is a purpose with widely varying quality. A university team studying allocation history, an independent engineer measuring stale contacts and a company building a prospect list can all claim to analyse data. The rules should distinguish method and risk rather than employer type.

A bounded research application can state the question, fields, population, query method, retention period, security controls and publication plan. It can explain whether individual records will be quoted, whether findings will be aggregated and how subjects can raise an error. These commitments provide evidence that a purpose is genuine and proportionate.

Independent applicants should be able to make the same showing. An ethics review or institutional sponsor may strengthen assurance, but it should not be the only route. A recognised professional body, civil-society organisation, qualified access intermediary or documented public track record can support identity and competence. Smaller studies involving low-risk fields should face lighter requirements.

The access grant should be scoped. It can limit fields, queries, rate, period and onward disclosure. The system should offer a test environment or synthetic examples so applicants can prepare clients without touching protected records. Clear rejection codes should identify whether the problem is identity, method, proportionality or security.

Publication rights matter. A registry should not condition access on approval of findings or prohibit criticism. It can require protection of personal values and prohibit reidentification outside the approved purpose. It should not acquire editorial control over conclusions about its own accuracy.

Researchers also need stable view information. If an authenticated response differs from the public view, the study should be able to state which class and policy version produced it. Otherwise results cannot be reproduced by another authorised team.

Good research access is demanding but contestable. It asks applicants to reduce harm and gives the institution no quiet power to select only friendly observers.

Operators need fast contact assurance, not indiscriminate personal disclosure

Network incidents compress time. A route leak, hijack suspicion or abuse campaign may require contact with the organisation responsible for a prefix. Authentication can improve the exchange if it confirms that the requester operates an affected network and if the response provides a reliable channel. A lengthy case-by-case application can make the protection useless.

The first layer should remain public: resource identity, current organisational holder, registration status, source service and a functioning role contact or relay. These facts let an operator direct a report without proving institutional standing.

An authenticated incident tier can provide more where necessary. A network proving control of an ASN or contact domain could state the affected resources, incident class and limited period. The service might return an escalated role channel, confirmation that a report reached the responsible holder or a protected technical contact where the risk justifies it. It need not disclose a private home address.

Speed should be measurable. The service can publish acknowledgement and response objectives by incident class. Emergency access should expire automatically and undergo later review. Repeated misuse should lead to proportionate restrictions with reasons, not permanent exclusion by an opaque blacklist.

Technical identity cannot prove the entire claim. Control of an ASN may show an operational relation, but not that every allegation about another network is correct. The server should disclose the least sufficient contact information and leave incident merits to the relevant parties.

Cross-regional incidents expose interoperability problems. An operator should not need five unrelated credential processes to contact five responsible networks. Federated authentication can reduce that burden if RIRs recognise common assurance levels and purpose claims. Reciprocal recognition must not reduce all regions to the most permissive policy; field-risk floors and local legal limits still apply.

The aim is a narrow operational gain: reach the right institution quickly, prove enough to receive the right channel and leave a record of the disclosure. Tiered access fails if a major operator can do this automatically while a small network waits outside the system during the same incident.

The data subject must not occupy the weakest tier of their own record

The person represented in a registration record has a different claim from a third-party researcher. They need to know what is held, what is public, what authenticated users may receive and how to correct an error. A public view alone may conceal the very field that exposes them in another tier.

A subject-access view should therefore display each relevant field and its disclosure class. It should show the source of the value in ordinary institutional terms, the last update, the purposes under which it can be disclosed, the retention period and any active restriction. Identity checks are justified because this view may contain protected data.

The subject should also see material disclosure history without receiving an unsafe list of sensitive investigators. An account might show that a technical-contact field was disclosed under a defined incident purpose on a date, while withholding a requester identity where law or an authorised do-not-track rule applies. Exceptional secrecy needs an independent basis and later review.

This is essential to accuracy. A former employee may discover that an old telephone number remains available to authenticated users even though the public response uses a relay. A holder may learn that a legal-person field has been classified as personal without explanation. A sole trader may find that a business label exposes a home location.

Correction must operate at the field and disclosure-class level. Replacing a telephone number is different from disputing whether it should be public. Correcting the organisation attached to a resource is different again because it affects authority. Each request requires the right evidence and a decision limited to the disputed matter.

The person should not be told that privacy prevents them from seeing the treatment of their own data. Nor should subject status permit alteration of institutional facts without authority. The system must authenticate the claimant, distinguish personal correction from registration change and provide review for both.

Tiered records are defensible only when the person bearing the privacy risk has a stronger remedy than the institution consuming the data.

NRS can advocate a portable tier without becoming a gatekeeper

The Number Resource Society's positive opportunity lies in standardising assurance while limiting institutional concentration. Its public emphasis on accurate registration, operator rights and bounded registry authority supports a model in which protected fields can be accessed for justified purposes without making one incumbent the universal judge of identity.

NRS could publish proposed assurance classes for holders, operators, researchers, incident responders and data subjects. Each class would specify the evidence required, fields it can potentially support, expiry, audit duty and minimum appeal right. A shared vocabulary would let a credential carry intelligible meaning across qualified services.

Multiple identity providers should be able to issue claims under those rules. Universities, network associations, civil-society intermediaries, professional bodies and commercial providers may serve different communities. Accreditation by a competent, independent authority would test identity practice, security, conflicts, revocation and equal access. NRS should not operate or accredit a provider, or reserve approval to its sponsors.

Reciprocity can then reduce repeated applications. An operator verified to a common level could present the same assurance to several participating RDAP services. The receiving service would still decide disclosure under applicable policy, but it would explain any departure from the shared baseline. A researcher could move a bounded credential without becoming dependent on one regional relationship.

NRS should also publish an access-equity report. It could compare, within participating services, approval rates, partial disclosures, processing time, review outcomes and provider coverage by requester and region. The report would identify denominators and refrain from global claims where non-participating services are unobserved.

This proposal remains prospective. NRS materials do not establish that a federated, multi-provider RDAP access service is deployed, legally recognised or independently audited across RIR regions. A pilot would need to demonstrate secure claims, interoperable revocation, fair applications and protection against query surveillance.

The institutional principle is nevertheless concrete. NRS should campaign for legitimate credentials to be portable and gatekeepers replaceable. It can standardise its proposed reasons for trust; recognised RDAP operators and lawful authorities must decide access under adopted rules.

Independent review must test the rule, not merely repeat the first decision

An appeal against access denial is weak if it returns to the same employee with no additional authority. The reviewer needs the competence to inspect identity evidence, privacy risk, operational purpose and the policy applied to the field. It also needs independence from commercial or reputational pressure to protect the original decision.

The first review can be internal but separate. It should check whether the requester met the published criteria, whether less intrusive disclosure was considered and whether similar cases were treated consistently. The result should identify the field, purpose, policy and remedy. A reviewer may grant a partial view rather than choosing only between full disclosure and denial.

A second route should exist outside the service for consequential or repeated disputes. It could be a jointly funded panel with user, privacy, operational and technical expertise, subject to conflict rules. Applicable courts and regulators remain available; the panel should not claim authority it does not possess.

Privacy complaints require equal seriousness. A data subject should be able to challenge an excessive tier, an inaccurate value or a disclosure made outside purpose. The review body should be able to order correction of the access decision, restriction pending investigation and notification where harmful disclosure occurred, consistent with law.

Precedent can be published in anonymised form. Decisions should explain why a field's coordination value outweighed or did not outweigh the risk in a defined context. Over time, users can see the rule develop instead of relying on private institutional memory.

Review statistics reveal structural barriers. If independent researchers frequently win appeals that large institutions rarely need to bring, the initial process is unequal. If data subjects repeatedly discover protected fields disclosed under stale credentials, revocation is weak. Reversal is not merely a service failure; it is evidence for policy improvement.

An appeal button is not enough. The reviewer must be able to see the full decision record and change the outcome. Tiered access becomes legitimate when the institution can be corrected by someone other than itself.

A pilot should measure unequal access before celebrating privacy

A credible pilot would test the field-risk model with a bounded set of volunteer holders, operators, researchers and data subjects across disclosed services. It should not begin by assuming that successful authentication equals successful governance.

The cases should include anonymous public lookup, holder access, a small-operator incident, independent and institutional research applications, subject correction, a rejected purpose, credential revocation, cross-provider recognition and protected-field appeal. Synthetic personal data can test severe disclosure conditions. Selected live records can test ordinary coordination with consent and safeguards.

Measurements should include application completion time, evidence burden, authentication failures, purpose acceptance, fields requested and returned, partial disclosures, denials by reason, review time, reversals, unauthorised disclosures, stale credentials, subject complaints and service availability. Each figure should state the eligible and observed population.

Equity needs deliberate tests. Comparable applications from a university team and an independent team should be assessed against the same safeguards. A small operator and a large operator should seek the same incident field. Applicants from regions served by different identity providers should attempt cross-service access. Differences require explanation.

Privacy outcomes must be measured too. Did public exposure of direct personal details fall? Did relays function? Could subjects discover and correct protected values? Did authorised users retain data beyond purpose? Did audit records themselves create a sensitive collection? A privacy claim unsupported by these observations remains an aspiration.

The pilot should publish negative results. If accepted purpose claims are inconsistent across servers, portability is incomplete. If a field-risk rule is too complex for clients, the standard is not usable. If independent users abandon applications at a higher rate, formal eligibility has not produced equal access. If do-not-track treatment prevents every meaningful audit, the control design needs revision.

No volunteer pilot can establish global prevalence or fairness. The population of all registration queries, private harms and abandoned requests is not observable from participating services alone. The pilot can establish whether specified controls work for specified cases and what must change before expansion.

NRS would strengthen its institutional case by publishing those limits. A modest measured success is more valuable than an untested declaration that privacy and accountability have already been reconciled.

The constitutional test is whether an outsider can still verify authority

Authentication is a valuable answer to a real problem. Public registration systems should not expose every personal field to every collector. Operators need secure ways to reach responsible contacts. Holders need protected access to their own evidence. Researchers using large result sets should accept safeguards proportionate to aggregation risk.

None of those propositions requires a record system in which only established institutions can verify authority. The public function survives only if a person without privileged relationships can still establish the resource, recognised organisation, registration status, effective history, source service and route to challenge. Protected evidence can support that public core through bounded attestations.

The standards now provide many of the technical pieces. RFC 7481 allows differentiated access. RFC 8982 permits field sets that reflect authorisation. RFC 9537 can identify what has been redacted. RFC 9560 can federate identity and purpose claims. IANA registries make extensions and purpose values discoverable. None of them chooses a fair social boundary on its own.

That boundary should be expressed field by field. Personal harm, operational value, aggregation risk, evidentiary need and correction difficulty are defensible criteria. Employer prestige, institutional familiarity and ability to endure a long application are not.

An auditable service will leave evidence of each consequential choice. It will tell the user which view was returned, why a field was withheld, when a credential expires and where review lies. It will let the data subject inspect the treatment of their information. It will publish aggregate outcomes without exposing sensitive searches.

NRS can make the case for opening assurance to multiple providers, carrying credentials across services and requiring reciprocal reasons. It would make it worse if it became one more institution whose approval outsiders must obtain. Its positive value lies in making trust explainable and gatekeepers replaceable.

The future of public registration records will not be a return to universal exposure. It will be a contest over the terms of differentiated visibility. The sound test is simple: protect the person at risk, preserve the facts needed for coordination and never make institutional membership the price of verifying institutional power.

Sources