Among the questions we most frequently receive from companies, professionals and public bodies is one concerning the Data Processing Agreement (DPA): is it necessary to sign one simply to register a domain name?
The answer is no: not only is it unnecessary, but in this context it is not even possible.
Let's see why.
What is a DPA?
A Data Processing Agreement (DPA) is the agreement required by Article 28 of Regulation (EU) 2016/679 (GDPR) governing the relationship between:
- Data Controller, i.e. the party that determines the purposes and means of processing personal data;
- Data Processor, i.e. the party that processes such data exclusively on behalf of the Data Controller and in accordance with its instructions.
A DPA is therefore required only when such a relationship exists.
Domain Name Registration Is a Special Case
The registration of a domain name differs significantly from services such as web hosting or email hosting.
When a domain name is registered, the Registrar collects certain information relating to the Registrant (such as name, postal address, email address and contact details), because this information is required by the policies of the relevant Registry and by applicable laws and regulations.
This information is used to:
- identify the domain name registrant;
- maintain the domain name registry database;
- manage renewals, transfers and updates;
- comply with the Registry's policies and contractual requirements;
- comply with applicable legal obligations or requests from competent authorities.
In this context, the Registrar does not process personal data following the customer's instructions, but rather in accordance with its own contractual and regulatory obligations.
For this reason, it acts as a Data Processor on behalf of the Registry, not on behalf of the Customer.
A Practical Example
Suppose that John Smith registers the domain name:
mydomain.it
The information required for the registration is processed by several parties, for example:
- the Reseller (if any), under the agreement between the Reseller and Mr. John Smith;
- DomainRegister, acting as a Registrar accredited by the .it Registry (Registro .it);
- Registro .it, acting as the Registry responsible for the .it top-level domain.
Each of these parties processes personal data within the scope of its own responsibilities and legal obligations.
Neither the Customer, the Reseller nor DomainRegister can, for example:
- decide which personal data must be collected;
- require that such data be retained for a different period;
- determine how the Registrant's identity must be verified;
- modify the procedures established by the Registry's policies.
These decisions are determined by the Registry, the accreditation agreements and the applicable legal framework.
For this reason, the simple registration of a domain name does not normally create the Data Controller → Data Processor relationship described in Article 28 of the GDPR.
When Is a DPA Required?
The situation changes when a provider offers services involving the processing of personal data on behalf of the customer.
Examples include:
- shared web hosting;
- VPS servers;
- dedicated servers;
- email hosting;
- cloud storage;
- backup services;
- SaaS or application hosting platforms.
In these cases, the customer decides:
- which personal data are stored;
- how those data are used;
- for which purposes they are processed.
The provider merely supplies the technical infrastructure and processes the data according to the customer's instructions.
In these circumstances, the relationship described in Article 28 of the GDPR normally exists, and a DPA may therefore be required.
NOTE: In most situations where a DPA is required, it is based on the provider's standard DPA, provided that it satisfies the customer's compliance requirements. Where the customer has specific or additional requirements, these will normally be addressed within a dedicated service agreement, which will also regulate any additional costs arising from the implementation of such specific requirements.
An Example
Let's imagine a company that registers the domain:
company.it
It subsequently purchases a hosting service and publishes a website containing:
- contact forms;
- customer information;
- orders;
- confidential documentation.
In this case:
- the company is the Data Controller, because it determines which personal data are collected and for what purposes;
- the hosting provider is the Data Processor, because it stores and processes those data on behalf of the customer.
For the hosting service, it is therefore generally appropriate to regulate the relationship by means of a DPA.
DomainRegister and the GDPR
For the sole purpose of domain name registration, DomainRegister usually processes the personal data required for the registration (either directly or indirectly) as a Data Processor acting on behalf of the relevant Registry, in accordance with the Registry's policies and the applicable legal framework.
For services involving the processing of personal data on behalf of the customer (such as hosting, VPS, email services, backup services and similar services), the relationship may fall within the scope of Article 28 of the GDPR and, where appropriate, be governed by a dedicated Data Processing Agreement (DPA).


