When copyright holders pursue piracy cases, they often face a fundamental obstacle: the operators hide behind domain privacy services. A recent case involving the Premier League and registrar Tucows illustrates how DMCA subpoenas work to pierce that veil—and what it means for anyone relying on anonymous domain registration.
How DMCA Subpoenas Target Domain Operators
The Premier League filed a DMCA subpoena against Tucows, one of North America's largest domain registrars, demanding the personal details of operators behind 25 pirate sports streaming domains. The subpoena mechanism allows copyright holders to request registrar records without first proving infringement in court—a lower bar than traditional litigation.
From a technical standpoint, this process is straightforward. Domain registrars maintain WHOIS records linking domain names to registrants. Most registrars offer privacy masking services that shield the actual owner's identity behind a proxy service. When a DMCA subpoena lands, however, the registrar is legally obligated to disclose the real registrant information to the rights holder or their legal representatives.
The registrar itself becomes the weak link. Tucows cannot simply refuse; US law compels compliance. The question isn't whether disclosure will occur, but how quickly the registrar processes the request and whether its internal systems can accurately retrieve the data.
The Paradox of Leaked Evidence
What makes this case unusual is the Premier League's own evidence: the pirate streams were sourced from legitimate CDNs operated by Amazon and Google. This detail cuts to the heart of infrastructure abuse. Rather than running streaming servers on offshore hardware, the pirate operators appear to have exploited misconfiguration or account takeovers on mainstream cloud platforms.
This reveals a gap in the enforcement strategy. Pursuing domain registrars addresses only one layer of the operation. The actual hosting infrastructure—where streams are cached and delivered—sits on platforms with far greater technical capability to block content. Yet subpoenaing Amazon or Google for customer details involves far higher legal complexity and less predictable outcomes than targeting a domain registrar.
Privacy Registration and Registrar Obligations
For infrastructure operators who use privacy registration services, this case underscores a critical reality: domain privacy is a business-layer shield, not a technical guarantee. Privacy masking works against casual WHOIS lookups and automated scrapers. It does not protect against legal process.
Registrars are intermediaries caught between two forces. Privacy customers pay for anonymity; rights holders demand disclosure. When a DMCA subpoena arrives, the legal obligation to disclose overrides the privacy agreement. Most registrars make this explicit in their terms, though many privacy customers don't read carefully enough to understand the limitation.
The subpoena itself costs nothing to file and triggers a mechanical disclosure process. No judge must review the merits. No hearing is required. The registrar receives a properly formatted legal demand and complies.
What This Means for Legitimate Operations
The broader implication is worth noting: privacy domain registration protects your identity from automated crawlers and casual adversaries, but not from determined legal action. If your jurisdiction takes copyright enforcement seriously—and the US clearly does—a DMCA subpoena is a reliable tool for unmasking operators.
This doesn't mean privacy domains are useless. They raise the cost of targeting you by forcing an adversary to file legal paperwork rather than simply querying WHOIS. But anyone registering domains for sensitive purposes should understand that privacy registration is a delay mechanism, not a wall.
From the registrar's perspective, the compliance burden is real. Tucows must locate 25 sets of records, verify their accuracy, and prepare disclosure documents. Scaling this to hundreds or thousands of subpoenas strains internal processes. Some smaller registrars have exited markets rather than shoulder these compliance costs.
The technical infrastructure of domain registration—WHOIS databases, privacy masking layers, legal request processing—was never designed for the volume of automated subpoena filing that exists today. Registrars operate in an uncomfortable middle position: profitable enough to attract enforcement action, but not large enough to absorb the compliance overhead indefinitely.

