- Cookies that enable provisioning of services you require.
- Cookies that inform NIC.LV about your visit on the website www.nic.lv - your consent is necessary for use of these cookies.
Riga, 25. 08.2026
The purpose of this Domain Name Data Disclosure Policy (hereinafter - the Disclosure Policy) is to establish the principles and general conditions under which the Registry Operator for the .lv top-level domain and .lv Registrars disclose registration data concerning Registrants to third parties, in compliance with applicable laws and regulations.
The Disclosure Policy applies to registration data concerning .lv domain names that are not publicly available through the NIC Whois service and to all data disclosure requests received from:
law enforcement authorities and other state institutions and public law entities, for the performance of functions assigned to them by laws and regulations, for the purpose of preventing and combating domain name system abuse, as well as preventing and detecting cyber incidents;
institutions responsible for the prevention of cyber incidents, for the performance of functions assigned to them by laws and regulations, for the purpose of preventing and combating domain name system abuse, as well as preventing and detecting cyber incidents
other private law entities, where a legal justification is provided and in cases involving infringements of the domain name system in the field of private law.
The Disclosure Policy shall be applied by the Registry Operator for the .lv top-level domain and .lv Registrars.
According to the definition adopted by the Internet Corporation for Assigned Names and Numbers (ICANN), domain name system abuse comprises the following technical infringements associated with a specific domain name:
Botnetsi,
Malwareii,
Pharmingiii,
Phishingiv,
Spamv, where used as a delivery mechanism for the above forms of DNS abuse.
Data shall be disclosed only where the request for disclosure of domain name data is legally justified and complies with the principles of data minimisation and proportionality.
Data shall be disclosed only for specific, legitimate purposes consistent with the stated legal basis.
Data shall not be disclosed where disclosure could pose an unjustified risk to the rights of the Registrant or where the request is insufficiently substantiated.
All instances of data disclosure shall be recorded, and the traceability of data processing shall be ensured.
Data Subjects shall be afforded the rights laid down in Regulation (EU) 2016 / 679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95 / 46 / EC, subject to the exceptions provided therein.
Data shall be disclosed by the holder of the data relating to the relevant domain name - the Registry Operator for the .lv top-level domain or the Registrar managing the domain name.
The requester shall address the data disclosure request to the appropriate Registrar or the Registry Operator on the basis of the information available in the NIC Whois database.
Requests shall be sufficiently detailed to identify the domain name, the law or regulation and the specific provision under which the requester is entitled to request and receive the particular personal data, as well as why the data are required and the purpose for which they will be used. Where applicable, documents substantiating the need to obtain the data shall be attached.
The request shall be made in writing, shall be legally valid and shall include information identifying the requester.
Data disclosure requests may be submitted to the Registry Operator for the .lv top-level domain in Latvian or English, and to .lv Registrars in the languages indicated by them.
Requests shall be accepted through the communication channels specified by the recipient of the request.
The recipient of the request shall have the right to verify the identity of the requester before assessing the legal basis for data disclosure.
Data shall not be disclosed where the identity of the requester cannot be verified, there is no sufficient legal basis for receiving the data, or another ground for refusing disclosure exists.
Requests shall be reviewed within the time limits prescribed by laws and regulations.
The decision to disclose data or refuse disclosure shall be documented and made on the basis of the requirements of laws and regulations and the principles laid down in the Disclosure Policy.
The Disclosure Policy shall be applied together with the Policy for acquisition of the right to use domain names under the top-level domain .lv, the NIC Privacy Policy, other rules of the Registry Operator published on its website, and applicable laws and regulations.
The Disclosure Policy shall not restrict the right of a Registrar to introduce more detailed procedures, provided that they comply with applicable laws and regulations and the Disclosure Policy.
The Disclosure Policy shall enter into force on 1 September 2026.
The Disclosure Policy may be reviewed and amended at any time, in which case the amended Disclosure Policy shall enter into force upon its publication on the website of the Registry Operator for the .lv top-level domain.
In the event of any conflict between the Disclosure Policy and the Policy for acquisition of the right to use domain names under the top-level domain .lv, the Policy for acquisition of the right to use domain names under the top-level domain .lv shall prevail.
i A botnet is a collection of devices (bots) infected with malware that operates under the commands of a botnet command-and-control (C&C) server. A botnet C&C server typically instructs members of the network to obtain information from their host systems or to carry out malicious activities, such as a distributed denial-of-service (DDoS) attack.
ii Malware is any software that, once installed, performs unwanted or malicious activities, often for the benefit of a third party. Adware, spyware and computer viruses are some of the best-known types of malware.
iii Pharming is a form of fraud in which an attacker redirects Internet users to a fraudulent website in order to steal their login credentials and other sensitive information. In a pharming attack, the attacker changes the IP address of a trusted domain name by hijacking the domain name registration or poisoning the cache of a name server (DNS server). The altered IP address redirects users to a website created by the attacker and disguised to appear to be the website of the legitimate Registrant. Once on the fraudulent website, users are deceived into entering their login credentials, credit card numbers or other sensitive information, which is then obtained by the attacker.
iv Phishing is a form of fraud in which an attacker impersonates a trusted person or organisation in order to infect a computer with malware or obtain sensitive information, such as a username, password or credit card details. Attackers often deceive victims by sending e-mails or other electronic messages that appear to originate from a trusted person or reputable organisation. Phishing messages usually contain a link directing the victim to a fraudulent website, where the victim is deceived into disclosing login credentials or other private information.
v Spam consists of unsolicited bulk electronic mail messages that the recipient has not consented to receive and that are sent as part of a wider messaging campaign in which all or most messages have substantially identical content. Put simply, spam is unsolicited e-mail sent simultaneously to a large number of recipients without their consent.