Free consultation

A registrar or hosting provider in Ukraine operates under several regimes at once: the ICANN requirements (the 2024 RAA, the Registration Data Policy — for accredited registrars and gTLD registries), Ukrainian law (Law No. 2811-IX on copyright, the Criminal Code) and — if you offer services to customers in the EU — EU law (NIS2 and the DSA, to the extent your type and size of service brings you within them). Each is checked separately, and a procedure that "just grew" does not pass an audit. We write procedures that pass, and we know a registrar's work from the inside.

Who it is for

  • ICANN-accredited registrars and their resellers
  • hosting and CDN providers
  • domain zone administrators

What we do

  • Audit. We check your agreements, policies and actual practice against the 2024 RAA and the Registration Data Policy (if you are an accredited registrar or a gTLD registry), Law No. 2811-IX and — for those on the EU market — NIS2 and the DSA in the part that applies to your type and size of service, and hand you a prioritised list of gaps.
  • Abuse policy and procedure. Intake of complaints, triage, the standard of evidence, lock statuses (clientHold, serverHold), repeat infringers and abusive complainants — Art. 23 of the DSA, if you are an online platform and not a micro or small enterprise. Separately, the registrar's role in a domain dispute: it does not decide who is right — within 2 business days it confirms the registrant's data and the lock to the provider, and after the decision under UA-DRP or UDRP it implements it.
  • Data disclosure. For accredited registrars and gTLD registries — a procedure under the Registration Data Policy: confirmation of the request within 2 working days, a reply within 30 calendar days of the acknowledgment save for exceptional circumstances, working through RDRS; for hosts, resellers and .UA zones — under contract and the law; law-enforcement requests apart.
  • NIS2. Who it reaches: top-level domain registries and DNS service providers (including a registrar that gives its customers authoritative DNS) — regardless of size; registrars and resellers — Art. 28 on registration data: accuracy and verification, publication of non-personal data, a reply to access requests within 72 hours; hosts — only medium-sized and large enterprises of the covered types (cloud services, data centres, CDNs). Art. 26(3) — an EU representative for a registrar, registry or DNS provider outside the EU: the documents are ours, the representative is appointed with a partner in the EU.
  • Art. 56 of Law No. 2811-IX for hosts. A procedure for handling copyright infringement notices: verifying the notifier, forwarding a copy to the site owner within 24 hours, the 48- and 24-hour deadlines, when the host must restrict access itself and when the site owner loses the liability shield.
  • Training. We prepare the abuse team to work under the new procedure — on your real cases.

How we work

  1. NDA. First we sign a non-disclosure agreement — before that we do not see your data.
  2. Audit. Documents, processes, a sample of real complaints and requests over an agreed period.
  3. Documents. Policies, internal procedures, reply templates — in two languages if needed.
  4. Roll-out and training. We help launch the procedure and train the team to work under it.
  5. Annual review. The rules change: we update the documents once a year, or whenever an ICANN policy or the law changes.

What matters

Audits are no longer theory. Since April 2024 ICANN has run about 530 DNS abuse investigations, issued 4 breach notices, and action has been taken on more than 25,000 domains (as of October 2026). For a registrar the consequence goes as far as suspension or termination of accreditation.

We do not decide for the registrar and do not replace its abuse department: we provide the procedure and the legal position, and the decision on each complaint is yours. We file such complaints ourselves on behalf of rights holders, so we know what a well-founded complaint looks like and which one can be rejected.

The director of Broodex owns the registrar NIC.UA. With other registrars we work under NDA and behind an information barrier: your data does not reach NIC.UA.

Write a few words about what is being checked and when — a lawyer replies, not a manager.

What it costs

Audit of abuse procedures and contractsRAA 2024, the Registration Data Policy, NIS2, the DSA, Law 2811-IX; a report with priorities
on request
Abuse-policy document packthe policy, the complaint-handling procedure, the evidence standard, reply templates, hold statuses, the repeat-infringer record (DSA, Art. 23)
on request
Registration-data disclosure procedurelaw-enforcement and rights-holder requests, the 2025 Registration Data Policy deadlines, RDRS, the log
on request
NIS2: data accuracy under Art. 28 and an EU representative under Art. 26(3)the documents and the procedure are ours; the representative is appointed with a partner in the EU
on request
Art. 56 (Law 2811-IX) notice-handling procedure for hosting providers48 hours for the site owner, then access is restricted
on request
Abuse-team trainingone session, the materials
on request

The price is agreed before we begin, depending on the scope of work. Official fees and duties are paid separately.

Not sure where to start?

Leave your phone number — we will call back at a convenient time, answer your questions and suggest the right procedure. The consultation is free.