Belgian Court Forces Registrars to Hand Over Site Owners' Bank and Crypto Data

29.08.2026 4 min 5

A court in Brussels has ordered domain registrars to hand over almost everything about the people behind certain websites: their real names, every address, bank account numbers, crypto wallets and a full year of connection logs. The owners are not allowed to be told. It is a sharp reminder of where online anonymity actually breaks, and it is not your IP address. It is the registrar and the payment trail behind the site.

What the court ordered

Belgium's anti-piracy body BAPO issued five decisions this week, based on an order from the Brussels Business Court, aimed at operators of sports-streaming sites. Three registrars are named, Hosting Concepts, Hostinger and Key Systems, along with another registrar and a registry that were redacted. What they must produce goes far beyond an IP address:

  • Identity. The customer's name and every postal address, email and phone number ever attached to the account.
  • Money. Full IBANs and the exact names on the bank accounts, plus card details.
  • Crypto. The wallet addresses used, the type of crypto-asset and the transaction hash IDs, which can be followed on the public blockchain.
  • Connection logs. The IP address, device type, operating system and browser used to create the account, plus all connection data kept over the last twelve months.

In other words, the chain of companies that registered the domain and processed the payments is being turned into a complete identity file.

The quiet part: nobody gets told

The registrars are under a gag order. They cannot tell the customer, or the press, that the proceedings or the order even exist. Normally, EU rules would require notifying the user whose data is handed over, but BAPO leans on an exception that applies when a criminal investigation is at stake. So the data can move to rightsholders while the person it describes never finds out. That combination, total disclosure plus enforced silence, is what makes this a precedent worth watching.

Why a VPN does not cover this

It is tempting to think a VPN makes you anonymous online, and for your browsing traffic a no-logs VPN genuinely helps. A privacy-first provider can even refuse data demands it cannot answer, as when Proton turned down dozens of deanonymization orders because it keeps no logs to hand over. But none of that touches the layer that fell here. If you registered a domain in your own name, or paid with a traceable bank card or an on-chain wallet, that identity lives with the registrar and the payment processor, outside the tunnel entirely. A court can compel those companies directly, and this is the same aggressive Belgian enforcement scene we saw when Belgium ordered Cloudflare and Google to block pirate IPTV at the DNS level.

Important: anonymity is layered, and the weakest link is usually the account you opened with real details, not the connection you made afterwards. A VPN hides where you connect from; it cannot un-give a name, a bank account or a wallet you already handed to a registrar or a shop. If a project genuinely needs to stay unlinked from you, the registration and payment are where that has to be true, from the start.
Does this affect ordinary website owners, or only pirates?
These specific orders target sports-piracy operators, but the mechanism is general. Any court order to a registrar or payment provider can expose whoever is behind a site, so the lesson about where identity really lives applies to anyone running something they would rather not have tied to their name.
Would a VPN have protected these operators?
Not from this. A VPN hides the IP of your connection, but the disclosure here came from the registrar and payment records, which hold your real name, bank account and wallet. Those sit outside anything a VPN can protect.
Can they really hand over the data without telling me?
In this case yes. The court imposed a gag order, and BAPO used an exception to the EU notification rules that applies when a criminal investigation is involved. The registrars are legally barred from informing the affected customers.
So what actually deanonymizes you?
Usually the real details you provide once: the name on a domain, the bank card or wallet behind a payment, an email reused across services. These persist with third parties and can be compelled later. Hiding your IP helps, but it does not erase those records.

anonymitydeanonymizationBelgiumdomain registrarprivacyVPNDSApiracy

Read also