A registrar or hosting provider in Ukraine operates under several regimes at once: the ICANN requirements (the 2024 RAA, the Registration Data Policy — for accredited registrars and gTLD registries), Ukrainian law (Law No. 2811-IX on copyright, the Criminal Code) and — if you offer services to customers in the EU — EU law (NIS2 and the DSA, to the extent your type and size of service brings you within them). Each is checked separately, and a procedure that "just grew" does not pass an audit. We write procedures that pass, and we know a registrar's work from the inside.
Who it is for
- ICANN-accredited registrars and their resellers
- hosting and CDN providers
- domain zone administrators
What we do
- Audit. We check your agreements, policies and actual practice against the 2024 RAA and the Registration Data Policy (if you are an accredited registrar or a gTLD registry), Law No. 2811-IX and — for those on the EU market — NIS2 and the DSA in the part that applies to your type and size of service, and hand you a prioritised list of gaps.
- Abuse policy and procedure. Intake of complaints, triage, the standard of evidence, lock statuses (clientHold, serverHold), repeat infringers and abusive complainants — Art. 23 of the DSA, if you are an online platform and not a micro or small enterprise. Separately, the registrar's role in a domain dispute: it does not decide who is right — within 2 business days it confirms the registrant's data and the lock to the provider, and after the decision under UA-DRP or UDRP it implements it.
- Data disclosure. For accredited registrars and gTLD registries — a procedure under the Registration Data Policy: confirmation of the request within 2 working days, a reply within 30 calendar days of the acknowledgment save for exceptional circumstances, working through RDRS; for hosts, resellers and .UA zones — under contract and the law; law-enforcement requests apart.
- NIS2. Who it reaches: top-level domain registries and DNS service providers (including a registrar that gives its customers authoritative DNS) — regardless of size; registrars and resellers — Art. 28 on registration data: accuracy and verification, publication of non-personal data, a reply to access requests within 72 hours; hosts — only medium-sized and large enterprises of the covered types (cloud services, data centres, CDNs). Art. 26(3) — an EU representative for a registrar, registry or DNS provider outside the EU: the documents are ours, the representative is appointed with a partner in the EU.
- Art. 56 of Law No. 2811-IX for hosts. A procedure for handling copyright infringement notices: verifying the notifier, forwarding a copy to the site owner within 24 hours, the 48- and 24-hour deadlines, when the host must restrict access itself and when the site owner loses the liability shield.
- Training. We prepare the abuse team to work under the new procedure — on your real cases.
How we work
- NDA. First we sign a non-disclosure agreement — before that we do not see your data.
- Audit. Documents, processes, a sample of real complaints and requests over an agreed period.
- Documents. Policies, internal procedures, reply templates — in two languages if needed.
- Roll-out and training. We help launch the procedure and train the team to work under it.
- Annual review. The rules change: we update the documents once a year, or whenever an ICANN policy or the law changes.
What matters
Audits are no longer theory. Since April 2024 ICANN has run about 530 DNS abuse investigations, issued 4 breach notices, and action has been taken on more than 25,000 domains (as of October 2026). For a registrar the consequence goes as far as suspension or termination of accreditation.
We do not decide for the registrar and do not replace its abuse department: we provide the procedure and the legal position, and the decision on each complaint is yours. We file such complaints ourselves on behalf of rights holders, so we know what a well-founded complaint looks like and which one can be rejected.
The director of Broodex owns the registrar NIC.UA. With other registrars we work under NDA and behind an information barrier: your data does not reach NIC.UA.
Write a few words about what is being checked and when — a lawyer replies, not a manager.
What it costs
- Audit of abuse procedures and contractsRAA 2024, the Registration Data Policy, NIS2, the DSA, Law 2811-IX; a report with priorities
- on request
- Abuse-policy document packthe policy, the complaint-handling procedure, the evidence standard, reply templates, hold statuses, the repeat-infringer record (DSA, Art. 23)
- on request
- Registration-data disclosure procedurelaw-enforcement and rights-holder requests, the 2025 Registration Data Policy deadlines, RDRS, the log
- on request
- NIS2: data accuracy under Art. 28 and an EU representative under Art. 26(3)the documents and the procedure are ours; the representative is appointed with a partner in the EU
- on request
- Art. 56 (Law 2811-IX) notice-handling procedure for hosting providers48 hours for the site owner, then access is restricted
- on request
- Abuse-team trainingone session, the materials
- on request
The price is agreed before we begin, depending on the scope of work. Official fees and duties are paid separately.