Quad9
Quad9 is a nonprofit organization for the purpose of operating a privacy-and-security-centric public DNS resolver.
Score
Citation
Except as described in this Data Policy, Quad9 does not intentionally share, sell, or rent individual personal information associated with the requestor (i.e. source IP address or any other information that can positively identify the system using our infrastructure) with anyone without your permission.
Even if there is a reasonable delay before the data is fully deleted (as is common), the data still counts as "permanently deleted" and satisfies the parameters for this question.
Score
Notes
The only personally identifiable data that Quad9 collects is IP addresses; however, they are encrypted.
This may come in the form of outright data sharing or by using local third-party analytics software (such as Google Analytics, which collects a plethora of user information).
Note that whether the policy allows sharing aggregated user data does not affect this question.
If the personal data is encrypted when it passes through the third-party, it does not count as third-party access (as the data is inaccessible to that party).
If personal data has been made public by, for example, posting it to a blog, it does not count as private personal information (and is therefore not considered by this question).
Score
Citation
Except as described in this Data Policy, Quad9 does not intentionally share, sell, or rent individual personal information associated with the requestor (i.e. source IP address or any other information that can positively identify the system using our infrastructure) with anyone without your permission.
Quad9 DNS Services generate and share high level anonymized aggregate statistics including threat metrics on threat type, geolocation, and if available, sector, as well as other vertical metrics including performance metrics on the Quad9 DNS Services (i.e. number of threats blocked, infrastructure uptime) when available with the Quad9 threat intelligence (TI) partners, academic researchers, or the public.
Quad9 DNS Services share anonymized data on specific domains queried (records such as domain, timestamp, geolocation, number of hits, first seen, last seen) with its threat intelligence partners. Quad9 DNS Services also builds, stores, and may share certain DNS data streams which store high level information about domain resolved, query types, result codes, and timestamp. These streams do not contain IP address information of requestor and cannot be correlated to IP address or other PII.
Score
Citation
"It may be required by law, litigation, legal process, and/or legally binding requests from public and governmental authorities within or outside your country of residence for Quad9 to disclose your personal information."
"Quad9 believes that privacy and control of your personal information is critical to your trust and therefore to the success of the system. Quad9 does not store PII IP address data on permanent storage methods (disk) or transmit that data out of the datacenter in which the query was received. All logging and inter-datacenter traffic is encrypted. Quad9 makes available encryption between clients and the Quad9 system to further protect against data interception or modification."
Score
Citation
Quad9 believes that privacy and control of your personal information is critical to your trust and therefore to the success of the system. Quad9 does not store PII IP address data on permanent storage methods (disk) or transmit that data out of the datacenter in which the query was received. All logging and inter-datacenter traffic is encrypted. Quad9 makes available encryption between clients and the Quad9 system to further protect against data interception or modification.
Score
Citation
Updated February 7, 2018.
Note that all companies operating in the EU are subject to Art. 33 of the GDPR, which requires companies to notify their data protection authority of a data breach within 72 hours of discovering it.
Score
Notes
No contact information is collected.
Score
Notes
No contact information is ever collected.
This includes the use of data brokers and independent verification authorities (such as background check providers).
Score
Citation
As an open DNS resolver, there is no signup or requirement to disclose PII to us other than that which is provided by accessing the service.
Score
Notes
The service only collects technical data needed to operate.
Some services allow users to opt-out or opt-in to of non-critical collection or use of personal data, such as collecting data for personalized advertisements.
Score
Notes
All data used is explicitly for the purpose of providing the service.
Score
Citation
As an open DNS resolver, there is no signup or requirement to disclose PII to us other than that which is provided by accessing the service. The only method by which Quad9 can identify end user requests is by the IP address of the client. IP addresses may represent individual persons or devices, or they may represent (via NAT or forwarding resolvers) large groups of end users. Quad9 does not and cannot distinguish between single and multiple users behind a single IP address. [...] Our normal course of data management does not have any IP address information or other PII logged to disk or transmitted out of the location in which the query was received.
[...]
When you use Quad9 DNS Services, here is the full list of items that are included in our logs:
- Request domain name, e.g. example.net
- Record type of requested domain, e.g. A, AAAA, NS, MX, TXT, etc.
- Transport protocol on which the request arrived, i.e. TCP, UDP, and encryption status of the protocol
- Origin IP general geolocation information: i.e. geocode, region ID, city ID, and metro code
- Protocol version IP address – IPv4, or IPv6
- Response code sent, e.g. SUCCESS, SERVFAIL, NXDOMAIN, etc.
- Absolute arrival time
- Name of the Quad9-operated machine that processed this request
- Quad9 target IP to which this request was addressed (no relation to the user’s IP address)
We may keep the following data as summary information, including all the above EXCEPT for data about the DNS record requested:
- Currently-advertised BGP-summarized IP prefix/netmask of apparent client origin
- Autonomous system number (BGP ASN) of apparent client origin
Last Updated
May 26, 2021
Sources
Contributors