------------------------------------------------------- prop-173-v001: Copyright and Acceptable Use Terms for APNIC Directory Services ------------------------------------------------------- Proposer: Jonathan Brewer jon@xn--t-0la.nz 1. Problem statement ------------------------------------------------------- APNIC provides access to its whois database through WHOIS, RDAP, and web-based services. Although APNIC publishes an Acceptable Use Agreement for bulk Whois data, it does not publish a separate, clearly scoped policy governing ordinary ad-hoc queries. Users of WHOIS and RDAP therefore cannot readily determine: - what uses of query results are permitted; - whether results may be stored, compiled, republished, or incorporated into other services; - what constitutes excessive or abusive querying; - what enforcement action APNIC may take; or - whether APNIC asserts copyright or other intellectual-property rights in its directory database and services. Current WHOIS and RDAP responses refer users to terms associated with the bulk-access agreement, but that agreement is designed for applicants seeking bulk downloads or mirrors. It does not clearly establish terms for users making ordinary queries. APNIC has also previously indicated that specific terms of use for WHOIS and RDAP would be implemented, but no distinct policy appears to have been published. This is inconsistent with APNIC’s historical practice. During its first decade, APNIC published copyright and restricted-rights statements applying broadly to data retrieved from APNIC databases. These statements restricted reproduction, storage, and transmission outside agreed Internet-operational purposes, prohibited targeted advertising, and allowed APNIC to limit or deny access for excessive querying. APNIC should restore a clear policy position on its WHOIS database by asserting the rights available to it under Australian law and publishing specific acceptable-use terms for ordinary WHOIS, RDAP, and web-query access, separate from the existing bulk-access agreement. 2. Objective of policy change ------------------------------------------------------- APNIC will publish a clear, public, versioned APNIC Directory Services Acceptable Use Policy governing ordinary access to WHOIS, RDAP, and web-based directory searches. The policy will: - be separate from the existing agreement governing bulk downloads and mirroring; - assert APNIC’s copyright and other applicable intellectual-property rights in the directory database; - clearly define permitted and prohibited uses; - be presented to users through every directory-service interface and interaction; - provide protections at least as strong as those contained in APNIC’s early database copyright and restricted-rights statements. 3. Situation in other regions ------------------------------------------------------- RIPE NCC publishes both comprehensive RIPE Database Terms and Conditions and a separate Acceptable Use Policy. Accessing the database constitutes agreement to the terms. Permitted purposes are enumerated, advertising and direct marketing are prohibited, and users may not repackage, download, compile, redistribute, or reuse a significant part of the database without permission. The terms also assert RIPE NCC ownership of all copyright, trademarks, database rights, and other intellectual-property rights subsisting in the database, its data, software, and accompanying documents. ARIN publishes Whois Terms of Use that apply to any use of its Whois service, including compilation, repackaging, and dissemination. Use of the service constitutes acceptance of the terms. The document enumerates operational and technical-research uses and prohibits advertising, direct marketing, marketing research, republication, resale, and use as part of an unauthorised commercial data product or service. LACNIC includes a copyright and lawful-use statement directly in its WHOIS responses. Users are told that the data is provided for information concerning IP address and AS number registrations and that submitting a query constitutes agreement to use the data only for lawful purposes. AFRINIC publishes terms applying to access, querying, compilation, repackaging, dissemination, and other uses of its Whois Database. Its terms enumerate permitted operational and research purposes, prohibit commercial data products, advertising, direct marketing, market research, and illicit uses, reserve the right to rate-limit or terminate access, and treat bulk access under a separate agreement. AFRINIC also asserts that copyright, trademarks, database rights, and other intellectual-property rights subsisting in the database, its contents, software, documents, and agreements remain AFRINIC property. 4. Proposed policy solution ------------------------------------------------------- 1. Scope APNIC will publish an APNIC Directory Services Acceptable Use Policy applying to any person or system that accesses, queries, receives, or uses APNIC-authoritative directory data through: WHOIS; RDAP; APNIC web-based directory searches; APIs providing equivalent registration data The policy will apply to APNIC-authoritative data and objects identified as having APNIC as their source. Data mirrored or referred from another registry will remain subject to the terms of the authoritative source registry. The policy will define “user” broadly enough to include a person who directly accesses the service and a person or organisation that causes automated access to be made on its behalf. 2. Separation from bulk access The ordinary-query policy will be a separate document from the existing bulk-access agreement. The policy will state that it does not grant bulk-download or mirroring rights. Users requiring high-volume access, a significant extract, a mirror, or a substitute database will apply through APNIC’s separately governed bulk-access process. 3. Copyright and intellectual-property statement The policy will state that APNIC must assert all copyright and other rights available to it under Australian law. 4. Permitted uses The policy will expressly permit ordinary low-volume queries for defined Internet-operational and technical-research purposes, including: evaluating routing policies and routing-policy compliance; network troubleshooting and operational coordination; identifying the holder or operator of Internet number resources; maintaining the uniqueness and accurate registration of Internet number resources; providing and troubleshooting reverse DNS; reporting, investigating, and mitigating network abuse or security incidents; identifying resources suspected of unlawful or harmful use; conducting scientific or technical research into Internet operations, routing, security, resilience, or topology; supporting lawful resource-registration disputes; and responding to legally valid requests from competent authorities. 5. Prohibited uses The policy will prohibit: advertising, targeted advertising, direct marketing, lead generation, marketing research, or similar activity; compiling contact or marketing lists; harassment, intimidation, surveillance, or unlawful activity; using directory data to build demographic profiles; using directory data to infer or represent the geographic location of an address, network, organisation, or individual; selling, licensing, or republishing directory data as a data product; making directory data available as part of a commercial enrichment, profiling, or lookup service without written permission; systematic harvesting through ordinary query interfaces; using distributed hosts, addresses, accounts, or intermediaries to evade rate limits; interference with the availability, integrity, or security of the directory services; and any use inconsistent with the stated purposes of the APNIC Directory Database. Ordinary operational use by a commercial network operator or security provider will not be prohibited merely because the organisation operates commercially, provided the directory data is not itself resold, republished, or made into a separate commercial data product. 6. Reproduction, storage, and redistribution Except as necessary for a permitted Internet-operational or technical-research purpose, users will not reproduce, persistently store, compile, transmit, repackage, redistribute, or make available a substantial part of the database without APNIC’s prior written permission. The policy may permit limited and temporary caching of individual query results where necessary for a permitted use. APNIC will publish any applicable retention, refresh, security, and deletion requirements. Caching will not be used to assemble a substitute directory database or circumvent the bulk-access process. Any permitted onward disclosure will remain subject to restrictions at least as protective as the APNIC policy. 7. Query conduct and rate limits APNIC may establish and enforce reasonable query-volume, rate, concurrency, and result-size limits for security, privacy, and operational purposes. The policy will prohibit attempts to evade those limits. APNIC will publish: the general principles used to identify excessive querying; how a blocked user can identify the reason for a restriction; a contact or review process for legitimate operational and research users; and the process for obtaining approved high-volume or bulk access. APNIC need not publish limits where doing so would materially assist evasion or threaten service security. 8. Notice through each service The policy will be readily available before or at the time directory data is supplied. WHOIS responses will contain a concise notice substantially equivalent to: % APNIC Directory Services data is subject to the APNIC % Directory Services Acceptable Use Policy. % By querying or using this service, you agree to those terms. % Copyright APNIC. See: RDAP responses will include: a notices entry identifying the policy; a link with rel set to terms-of-service; a copyright or intellectual-property notice; and the current policy URL. Web query interfaces will display a link to the policy and state that submitting a query and using the results is subject to it. The notices will use a stable, maintained HTTPS URL that will not be subject to HTTP redirection. 9. Enforcement and review APNIC may warn, throttle, suspend, block, or terminate access where it reasonably believes that a user has breached the policy. This may happen via automated means. Repeated or deliberate circumvention may result in long-term or permanent denial of ordinary query access. The policy will provide a review mechanism for a user who believes that access has been restricted in error or who can demonstrate a legitimate operational or technical-research requirement. 10. Historical protection floor and future amendments The policy will not be materially less protective than APNIC’s copyright and restricted-rights statements published during its early operation, particularly in relation to: the assertion of copyright; reproduction and persistent storage; transmission and redistribution; targeted advertising and similar activities; use outside agreed Internet-operational purposes; and excessive automated querying. The wording may be modernised and adapted to WHOIS, RDAP, privacy law, and contemporary Internet operations, but the substantive level of protection will not be weakened. The policy will include a version number, effective date, revision history, and archive of previous versions. APNIC will provide reasonable advance public notice of amendments. Any amendment that materially expands permitted reuse or materially weakens protections will be subject to the APNIC Policy Development Process or an equivalent community-consultation process. APNIC should implement this policy within six months of adoption. 5. Advantages / Disadvantages ------------------------------------------------------- Advantages: The proposal would restore the clear copyright and restricted-use position that APNIC maintained during its early years of operation. Disadvantages: APNIC would incur legal, documentation, and software-development costs to draft the terms, update all query interfaces, maintain stable policy links, and operate a review process. 6. Impact on resource holders ------------------------------------------------------- Resource holders that operate automated WHOIS or RDAP clients may need to ensure that their querying, caching, and redistribution practices comply with the published policy. 7. References ------------------------------------------------------- https://www.apnic.net/manage-ip/using-whois/bulk-access/ https://www.apnic.net/manage-ip/using-whois/bulk-access/copyright/ https://www.apnic.net/community/policy/proposals/prop-167/ https://docs.db.ripe.net/HTML-Terms-And-Conditions https://docs.db.ripe.net/RIPE-Database-Acceptable-Use-Policy https://www.arin.net/resources/registry/whois/tou/ https://web.archive.org/web/20260514102154/https://afrinic.net/whois/terms https://web.archive.org/web/19991128203448/http://www.apnic.net/db/dbcopyright.html https://web.archive.org/web/20050531210605/http://www.apnic.net/db/dbcopyright.html https://web.archive.org/web/20080000000000*/http://www.apnic.net/db/dbcopyright.html https://web.archive.org/web/20100125052321/http://www.apnic.net/apnic-info/whois_search/about-whois/protecting-whois/copyright https://web.archive.org/web/20110728054323/http://www.apnic.net/db/dbcopyright.html https://web.archive.org/web/20161009105427/https://www.apnic.net/db/dbcopyright.html https://web.archive.org/web/20161009105430/https://www.apnic.net/apnic-info/whois_search/using-whois/bulk-access/copyright