NIS2: Spain and Ireland go to the EU Court, and what it means for WHOIS

On 8 July 2026, the European Commission referred Spain, Ireland, France and the Netherlands to the Court of Justice of the EU for failing to fully transpose the NIS2 Directive, and asked for financial sanctions. For brand owners, the delay has a concrete effect through NIS2 Article 28 on domain registration data: the rule that requires registries and registrars to keep accurate data and to answer legitimate access requests within 72 hours. Where NIS2 has not been transposed, that obligation has no national law behind it yet.

Key takeaways

  • The Commission is asking the Court for a lump sum and daily penalties until each country notifies full transposition; the deadline was 17 October 2024.
  • Article 28 requires accurate, verified registration data and an answer to legitimate access requests within 72 hours.
  • Registries and registrars fall under the law of the Member State of their main establishment in the EU, so the registrar’s location decides which rules apply.
  • NIS2 does not name trade mark owners as legitimate access seekers; whether they qualify depends on national law.

What did the Commission decide on 8 July?

According to the Commission’s announcement, the four Member States had not notified full transposition of Directive (EU) 2022/2555, known as NIS2, which sets cybersecurity rules for entities in 18 critical sectors. The Law Society Gazette reported the same day that Ireland’s draft bill, published in 2024, is still pending.

Step Date
Transposition deadline (Article 41) 17 October 2024
Letters of formal notice 28 November 2024
Reasoned opinions 7 May 2025
Referral to the Court of Justice, with a request for financial sanctions 8 July 2026

What does NIS2 Article 28 require for domain registration data?

Article 28 of the Directive applies to top-level domain registries and to entities providing domain name registration services, a term that covers registrars and their resellers and privacy or proxy services. Article 2(4) applies NIS2 to registration service providers regardless of their size. Member States must require them to:

  1. Keep accurate and complete registration data, in line with EU data protection law.
  2. Include at least the domain, registration date, the registrant’s name, email and telephone, and any separate point of contact.
  3. Have public policies and procedures, including verification.
  4. Publish, without undue delay after registration, the data that are not personal data.
  5. Give access to specific data on lawful and duly justified requests from legitimate access seekers, and reply without undue delay and in any event within 72 hours.
  6. Avoid duplicate collection, cooperating with each other.

Recital 110 defines a legitimate access seeker as any natural or legal person making a request under Union or national law, and recital 112 adds that, for legal persons, at least the registrant’s name and contact telephone should be public, and that access should be free of charge.

Why Article 28 matters to trade mark owners

A UDRP complaint does not require knowing the holder: the provider obtains the registrant’s details from the registrar once it is filed. Most other steps do. A court claim, a demand letter or linking several names to the same cybersquatter all depend on identifying the holder, and Article 28 is the first EU-wide rule that sets a deadline to answer a justified request.

Two limits apply. NIS2 does not say that trade mark owners are legitimate access seekers, so national law decides. And under Article 26, a registrar or registry is subject to the law of the Member State of its main establishment in the EU; a registrar outside the EU that offers services in the Union must designate a representative there.

Spain and Ireland: where NIS2 transposition stands

Country Status at the referral Effect on Article 28
Spain The draft Law on Cybersecurity Coordination and Governance was notified to the Commission on 21 February 2025 (TRIS 2025/0104/ES); not yet in force No national 72-hour duty for registrars established in Spain
Ireland Draft bill published in 2024; listed as a priority, still pending No national 72-hour duty for registrars established in Ireland

In practice, requests to registrars established in these countries still depend on each registrar’s own disclosure policy. For generic domains, ICANN’s Registration Data Request Service (RDRS) routes requests from intellectual property professionals and others, but registrar participation is voluntary.

What this means for your business

  • Check where the registrar holding the infringing domain has its main EU establishment; that tells you which law applies.
  • Write each request as a lawful, duly justified request: your rights, the domain, the specific data needed and why.
  • Keep dates. If the registrar is in a Member State that has transposed, the 72-hour clock is a useful lever.
  • Do not wait for disclosure to act: a UDRP complaint can be filed against an unidentified holder.

Our team for domain disputes and registrant identification can prepare and track these requests across registrars. Within the same group, META Channel also advises on NIS2 compliance for companies that are themselves in scope.

Where companies get this wrong

  • Assuming NIS2 applies everywhere already. A directive binds registrars through national law, and four Member States had not completed it.
  • Sending vague requests. Without a clear legal basis and purpose, a registrar can refuse.
  • Looking at the wrong country. The registrar’s main establishment counts, not the extension or the holder’s address.
  • Delaying the UDRP while chasing data, which gives the holder time to move the name.

Frequently asked questions

What does NIS2 Article 28 require from domain registrars?

It requires Member States to make TLD registries and registration service providers collect accurate and complete registration data, verify it, publish non-personal data and give access to specific data on lawful, duly justified requests from legitimate access seekers. They must reply without undue delay and in any event within 72 hours.

Can a trade mark owner use Article 28 to identify a cybersquatter?

Possibly. NIS2 defines a legitimate access seeker as anyone making a request under Union or national law, without naming trade mark owners. Whether a brand owner qualifies depends on the transposing law of the registrar’s Member State. In any case, the request must be lawful, justified and limited to the data needed.

Why were Spain and Ireland referred to the EU Court of Justice?

Because they had not notified full transposition of NIS2, due by 17 October 2024. After letters of formal notice in November 2024 and reasoned opinions in May 2025, the Commission referred them, with France and the Netherlands, on 8 July 2026 and asked the Court for financial sanctions.

Can IP Global Guard help us identify and act against a domain holder?

Yes. We prepare and track disclosure requests to registrars, file UDRP and ccTLD complaints without waiting for disclosure where that is faster, and coordinate court action with qualified local correspondents across Europe, Latin America and Africa, from a single point of contact.

Acting on infringing domains with IP Global Guard

Identifying the person behind a domain is still uneven across the EU. IP Global Guard, the IP services line of META Channel Corporation Limited, combines disclosure requests, UDRP and ccTLD complaints and IP enforcement in one strategy across more than 25 jurisdictions in Europe, Latin America and Africa.

Send us the domains that concern you and the registrars that hold them. We will tell you which rules apply, what data you can realistically obtain and how to act in parallel. Talk to our domain team.

This article is general information, not legal advice, and reflects the position on the date of publication.

Sources