Agent · nis2-2022-2555-28
NIS2 artikel 28: Database of domain name registration data
Structural tree: the article's own paragraphs, verbatim.
CELEX 32022L2555 · 2026-08-18 · Weight 79 · minimal-risk
ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.
- What this page is
- Agent, NIS2 artikel 28
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does NIS2 Article 28 require, and what outcome does the rule tree give?
NIS2 Article 28 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32022L2555. The outcome is a machine classification, not a compliance decision.
NIS2 Article 28Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. For the purpose of contributing to the security, stability and resilience of the DNS, Member States shall require TLD name registries and entities providing domain name registration services to collect and maintain accurate and complete domain name registration data in a dedicated database with due diligence in accordance with Union data protection law as regards data which are personal data.
- Paragraph 2 applies. 2. For the purposes of paragraph 1, Member States shall require the database of domain name registration data to contain the necessary information to identify and contact the holders of the domain names and the points of contact administering the domain names under the TLDs. Such information shall include:
- Paragraph 3 applies. (a)
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. For the purpose of contributing to the security, stability and resilience of the DNS, Member States shall require TLD name registries and entities providing domain name registration services to collect and maintain accurate and complete domain name registration data in a dedicated database with due diligence in accordance with Union data protection law as regards data which are personal data.
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
2. For the purposes of paragraph 1, Member States shall require the database of domain name registration data to contain the necessary information to identify and contact the holders of the domain names and the points of contact administering the domain names under the TLDs. Such information shall include:
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
(a)
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
the domain name;
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
(b)
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
the date of registration;
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
(c)
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
the registrant’s name, contact email address and telephone number;
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
(d)
Paragraph 9
If: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
the contact email address and telephone number of the point of contact administering the domain name in the event that they are different from those of the registrant.
Paragraph 10
If: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
3. Member States shall require the TLD name registries and the entities providing domain name registration services to have policies and procedures, including verification procedures, in place to ensure that the databases referred to in paragraph 1 include accurate and complete information. Member States shall require such policies and procedures to be made publicly available.
Paragraph 11
If: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
4. Member States shall require the TLD name registries and the entities providing domain name registration services to make publicly available, without undue delay after the registration of a domain name, the domain name registration data which are not personal data.
Paragraph 12
If: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
5. Member States shall require the TLD name registries and the entities providing domain name registration services to provide access to specific domain name registration data upon lawful and duly substantiated requests by legitimate access seekers, in accordance with Union data protection law. Member States shall require the TLD name registries and the entities providing domain name registration services to reply wi…
Paragraph 13
If: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
6. Compliance with the obligations laid down in paragraphs 1 to 5 shall not result in a duplication of collecting domain name registration data. To that end, Member States shall require TLD name registries and entities providing domain name registration services to cooperate with each other.
Paragraph 14
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. For the purpose of contributing to the security, stability and resilience of the DNS, Member States shall require TLD name registries and entities providing domain name registration services to collect and maintain accurate and complete domain name registration data in a dedicated database with due diligence in accordance with Union data protection law as regards data which are personal data.
- 22. For the purposes of paragraph 1, Member States shall require the database of domain name registration data to contain the necessary information to identify and contact the holders of the domain names and the points of contact administering the domain names under the TLDs. Such information shall include:
- 3(a)
- 4the domain name;
- 5(b)
- 6the date of registration;
- 7(c)
- 8the registrant’s name, contact email address and telephone number;
- 9(d)
- 10the contact email address and telephone number of the point of contact administering the domain name in the event that they are different from those of the registrant.
- 113. Member States shall require the TLD name registries and the entities providing domain name registration services to have policies and procedures, including verification procedures, in place to ensure that the databases referred to in paragraph 1 include accurate and complete information. Member States shall require such policies and procedures to be made publicly available.
- 124. Member States shall require the TLD name registries and the entities providing domain name registration services to make publicly available, without undue delay after the registration of a domain name, the domain name registration data which are not personal data.
- 135. Member States shall require the TLD name registries and the entities providing domain name registration services to provide access to specific domain name registration data upon lawful and duly substantiated requests by legitimate access seekers, in accordance with Union data protection law. Member States shall require the TLD name registries and the entities providing domain name registration services to reply without undue delay and in any event within 72 hours of receipt of any requests for access. Member States shall require policies and procedures with regard to the disclosure of such data to be made publicly available.
- 146. Compliance with the obligations laid down in paragraphs 1 to 5 shall not result in a duplication of collecting domain name registration data. To that end, Member States shall require TLD name registries and entities providing domain name registration services to cooperate with each other.
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32022L2555 art. 28, Database of domain name registration data. ExploreWorld Legal, https://legal.exploreworldai.com/agent/nis2-2022-2555/artikel-28 (hämtad 2026-08-18, bevis sha256:a365421b7e9e4ec7, bygge legal-2026-08-25).