On 19 August 2026, the Department for Combating Online Infringements of Copyright and Related Rights (BAPO), part of the FPS Economy, issued five decisions: 260819-BAPO-D-FR-020, 021, 022, 023 and 024. Each one implements an order of the President of the French-speaking Business Court of Brussels issued in 2026 under reference RR/26/…, whose date and number have been redacted. The decisions are addressed to four registrars and one registry, all established in the European Union. Three of them could be identified only because the redaction was incomplete: Hosting Concepts, Hostinger and Key Systems. The rightsholder remains anonymous. The court nonetheless relies on the protection of the “sports economy” and of the “European solidarity model” funded by broadcasting rights, which leaves little doubt about the content at stake.
These decisions rest on a disclosure mechanism of unprecedented scope (1). Their considerable reach calls for weighing effectiveness against proportionality (2). It remains to be seen whether the method can serve online brand protection.
1 An Unprecedented Disclosure Mechanism
The mechanism implemented by the Belgian decisions stands out both for the breadth of the information that may be requested, extending far beyond the data traditionally associated with WHOIS (1.1), and for its legal basis, which combines Article 10 of the DSA with the powers provided under Belgian law (1.2).
1.1 The Scope: Far Beyond WHOIS
Registrars must disclose, “no later than 10 working days” after receiving the decision, the name, postal address, email address and telephone number of the holders of the targeted domain names. The request also covers billing data and payment methods: full IBAN and exact name of the account holder, issuing bank, country and type of card, and PayPal accounts. It extends to crypto wallet addresses and transaction IDs. Finally, it covers IP addresses, device type, operating system, browser and all connection logs over twelve months. The registry, for its part, must provide the registrant’s details, the registrar’s identity, the name servers and the history of changes.
In other words, the data sought goes far beyond the WHOIS directory, which the General Data Protection Regulation (EU) 2016/679 of 27 April 2016 (GDPR) largely removed from public view. The authorities no longer merely want to know who registered a domain name. They want to know who paid, by what means and from which device. They want, in short, to follow the money.
The decisions also prohibit their addressees from disclosing “any information concerning the very existence of these proceedings”, whether to customers or to third parties. Any breach carries the same sanctions as non-compliance with provisional measures. Secrecy is, of course, what makes such a measure useful: an operator who has been warned will quickly switch domain, registrar and wallet.
1.2 The Legal Basis: Article 10 DSA in the Service of Belgian Law
What is the legal basis for such a sweeping order? The decisions rely first on Article 10 of Regulation (EU) 2022/2065 of 19 October 2022 on a Single Market for Digital Services (Digital Services Act, DSA). This provision allows a national judicial or administrative authority to order a provider of intermediary services to provide information about specific recipients of its services. It generally requires that the person concerned be informed, except where this is necessary for the prevention, investigation, detection or prosecution of criminal offences. That exception is what justifies the silence imposed on the registrars.
The second basis lies in Belgian law itself. Book XI and Articles XVII.34/1 et seq. of the Code of Economic Law, in force since 1 June 2024, empower the President of the Brussels Business Court to order measures against “manifest and significant” online infringements of copyright and related rights. These measures are called dynamic because they extend to mirror sites and redirects. The BAPO, established by the Royal Decree of 18 April 2024, implements and updates them. The whole framework sits within Article 3 of Directive 2004/48/EC of 29 April 2004 on the enforcement of intellectual property rights, which requires measures that are “effective, proportionate and dissuasive”.
Moreover, the BAPO claims jurisdiction over any intermediary whose services give access to illegal content on Belgian territory, wherever that intermediary is established. A German, Lithuanian or Dutch registrar may therefore receive a Belgian decision.
2 A Reach Between Effectiveness and Proportionality
The Belgian measures illustrate both the potential and the limits of this evolving enforcement strategy. The domain name is increasingly becoming a new entry point for rights enforcement, beyond traditional blocking measures (2.1), while this expansion raises important questions of territoriality, personal data protection and secrecy (2.2).
2.1 The Domain Name as a New Entry Point for Rights Enforcement
This offensive is not an isolated one. It is part of a methodical escalation. By an order of 28 March 2025 (RR/25/00020), issued at the request of DAZN Limited and The 12th Player SRL, the President of the French-speaking Business Court of Brussels ordered the blocking of sites illegally streaming matches. The order targets not only internet access providers but also the public DNS resolvers operated by Cloudflare, Google and Cisco, which are the services that translate a domain name into an IP address. It carries a penalty of €100,000 per day. BAPO Decision 250401-BAPO-D-FR-001 of 1 April 2025 organised its implementation. Later measures, such as Decision 250730-BAPO-D-EN-004 of 30 July 2025, widened the circle of intermediaries to include search engines, advertising services, archiving services and payment service providers.
The DNS operators challenged the order. By four orders of 20 August 2026 (C/25/00022, C/25/00023, C/25/00024 and C/25/00026), the President of the court rejected most of their objections. He held that imposing the blocking on the main alternative resolvers “helps strengthen the effectiveness” of the injunction addressed to access providers. He did, however, limit the penalty to days on which matches are broadcast live, cap it at €20 million per addressee, and remove Cisco OpenDNS LLC from the proceedings. BAPO Decision 260907-BAPO-D-FR-025 of 7 September 2026 draws the consequences. This outcome is consistent with the case law of the Court of Justice, which accepts blocking injunctions provided they do not unnecessarily deprive internet users of access to lawful information (CJEU, 27 March 2014, UPC Telekabel Wien, C-314/12).
Why, then, turn to registrars? Because blocking, however useful, quickly reaches its limits. The Belgian blocklist now exceeds 1,500 domain names. That figure shows how vigorous the response has been. It also shows, conversely, how easily operators rebuild their sites under other names. Blocking treats the symptoms. Identification reaches the cause: the operator and the operator’s business model. The domain name, long seen as a mere object of blocking, thus becomes once again a gateway to those responsible.
2.2 The Open Questions: Territoriality, Personal Data and Secrecy
Effectiveness does not dispense with examining legitimacy. Three questions arise.
The first concerns territoriality. If the BAPO’s broad view of its jurisdiction were to prevail, nothing would prevent other Member States from following suit. Registrars would then face competing, and possibly conflicting, national decisions.
The second concerns personal data protection. The Court of Justice has long held that EU law does not require the disclosure of personal data in civil proceedings. It is for Member States to strike a “fair balance” between the fundamental rights at stake (CJEU, 29 January 2008, Promusicae, C-275/06). The Court accepts that IP addresses may be collected and disclosed to enforce copyright, in compliance with Article 8 of Directive 2004/48 and the GDPR (CJEU, 17 June 2021, Mircom, C-597/19; CJEU, 30 April 2024, La Quadrature du Net and Others, C-470/21). Bank data and twelve months of connection logs, however, sit at an entirely different level of sensitivity. That data must also have been retained in the first place, which directly raises the question of each intermediary’s retention policy.
The third concerns the secrecy imposed. The registrar is caught between its contractual commitments to its customer and the prohibition on informing that customer. Nor can it explain its position publicly. Indeed, no one knows at this stage whether the addressees have complied with the decisions or challenged them.
3 What About Online Brand Protection?
The question naturally arises for any trademark owner facing counterfeit shops, phishing sites or typosquatted domain names: can the Belgian method serve online brand protection? The answer calls for a distinction. The decisions themselves cannot be transposed as they stand (3.1). Their underlying mechanisms, on the other hand, largely can (3.2).
3.1 A Belgian Mechanism Limited to Copyright
As designed, the Belgian mechanism does not benefit trademark owners. Articles XVII.34/1 et seq. of the Code of Economic Law cover only copyright, related rights and the sui generis right of database makers. Trademark infringement is excluded, even though it uses the same channels: disposable domain names, accommodating hosts and crypto payments. There is a reason for this choice. Sports piracy is especially urgent, since the value of a match evaporates at the final whistle. Trademark infringement is rarely as pressing.
Nothing prevents an extension, however. The English courts showed long ago that blocking injunctions can protect a trademark just as well as a copyright work. They did so on the basis of Article 11 of Directive 2004/48/EC, which then applied in the United Kingdom (Court of Appeal, 6 July 2016, Cartier International AG v. British Sky Broadcasting Ltd, [2016] EWCA Civ 658). In Belgium, the obstacle is therefore legislative, not conceptual.
3.2 Largely Transposable Mechanisms
The method itself is not specific to copyright. It consists in tracing a domain name back to a person, and then that person back to their financial flows. And trademark law already offers several footholds for it.
The first is the right of information under Article 8 of Directive 2004/48, which applies to all intellectual property rights. In French law, it is implemented for trademarks by Article L. 716-4-9 of the Intellectual Property Code. It may be exercised against any person who provides, on a commercial scale, services used in infringing activities. A registrar, a host or a payment service provider may therefore be targeted. The Court of Justice has clarified its scope. A bank cannot rely on banking secrecy in an unlimited and unconditional manner to refuse to reveal the holder of an account used to sell counterfeit goods (CJEU, 16 July 2015, Coty Germany, C-580/13). Injunctions against intermediaries may also aim to make it easier to identify sellers (CJEU, 12 July 2011, L’Oréal v eBay, C-324/09). The Court has, however, limited the notion of “address” to the postal address alone, excluding email addresses, telephone numbers and IP addresses. It merely preserved the Member States’ option to go further (CJEU, 9 July 2020, Constantin Film Verleih, C-264/19). The ordinary right of information alone therefore cannot secure what the BAPO demands.
The second foothold is the DSA. Its Article 10 is not limited to copyright. It covers any “illegal content” within the meaning of Article 3(h), and thus also offers of counterfeit goods, provided that national or EU law empowers an authority to issue the order. Furthermore, Article 30 requires online marketplaces to collect the identity of the traders selling on them, along with their payment account details. Much of the data that Belgium is requesting from registrars therefore already exists on sales platforms. Article 22 also gives trusted flaggers’ notices priority treatment.
The third foothold, finally, is specific to domain names. Article 28 of Directive (EU) 2022/2555 of 14 December 2022 (NIS 2) requires registries and registrars to collect accurate and complete registration data. It also requires them to reply within 72 hours to lawful and duly substantiated access requests. A trademark owner can thus obtain the declared identity of a domain name holder without going to court.
What, then, is missing to transpose the Belgian method? At least two things. First, a central authority that tracks mirror sites and new domains over time, as the BAPO does. Second, a single legal basis for obtaining identity, payment data and connection logs in one request. As things stand, trademark owners must combine these instruments. They must also carefully document the infringement and the payment channels used, or their requests will gain no traction.
Conclusion
The Belgian case shows that the DSA now gives rightsholders an identification tool that traditional procedures provided only through long detours, ever since WHOIS data came under the protective wing of the GDPR. Although limited to copyright for now, the model is bound to spread. Yet the tool is only as good as the data collected at registration. Seasoned operators know how to use false identities, anonymised payment methods or registrars established outside the Union. For trademark and domain name owners, the lesson is twofold. Domain name monitoring remains the indispensable prerequisite for any action. As for the available toolbox, from the Uniform Domain Name Dispute Resolution Policy (UDRP) to the right of information and NIS 2 access requests, it is best conceived as a coherent whole rather than as a series of isolated responses.