The Professional Golfers’ Association Limited successfully regained control of the domain pga-international.com after a respondent impersonated a membership association to harvest sensitive user data. The WIPO panel ordered a transfer, finding that the unauthorized use of the PGA trademark for data collection demonstrated clear bad faith.
Case Snapshot
| Case Number | D2026-2201 |
|---|---|
| Complainant | The Professional Golfers’ Association Limited |
| Respondent | Eric van der Burg, Nomads Concepts |
| Disputed Domain | pga-international.com |
| Threat Tactic | Corporate Impersonation |
| Decision Date | 2026-07-15 |
| Panelist | Ganna Prokhorova |
| Outcome | Transfer |
| Official Source | https://www.wipo.int/amc/en/domains/search/text.jsp?case=D2026-2201 |
Operational Risks of Corporate Impersonation and Data Harvesting
The registration and active use of pga-international.com demonstrates a sophisticated attempt to erode brand equity by mimicking the Professional Golfers’ Association’s established licensing structure. By adopting the trade name ‘Continental Professional Golfers’ Association’ and utilizing the complainant’s protected ‘PGA’ trademark within the domain string, the respondent successfully projected a false affiliation. For professional membership organizations, this tactic poses an acute business threat: it exploits the trust inherent in the brand to deceive members and industry stakeholders into believing they are interacting with an authorized regional entity of a century-old institution.
Beyond the immediate dilution of trademark rights, the respondent’s use of the domain as a data collection portal introduces substantial risk to the complainant’s security protocols and member data integrity. The website specifically targeted individuals by soliciting sensitive contact information, including email addresses, home addresses, and personal details under the guise of an official membership portal. Even without verified reports of subsequent financial losses, such phishing-based infrastructure undermines the professional reliability of the organization. The use of a domain name that incorporates a well-known mark to facilitate this collection process represents a malicious encroachment on the complainant’s operational security and necessitates aggressive enforcement to prevent the weaponization of member identity.
Legal Reasoning and Panel Findings on Trademark Impersonation
In the dispute over pga-international.com, the WIPO panel determined that the domain name is confusingly similar to the complainant’s established PGA trademark. The panel held that the inclusion of the term ‘international’ and a hyphen, alongside the generic top-level domain ‘.com’, fails to distinguish the disputed domain from the complainant’s intellectual property. This finding reinforces the precedent that modifying a well-known mark through minor descriptive additions does not mitigate the potential for consumer confusion in online commerce.
The panel found that the respondent possessed no rights or legitimate interests in the disputed domain name. The evidence demonstrated that the respondent had no affiliation with the Professional Golfers’ Association, held no authorization to use the protected mark, and was not commonly known by the name ‘PGA’. By masquerading as an entity entitled to solicit sensitive member data, the respondent’s conduct explicitly negated any potential claim of legitimate business interest or fair use under UDRP policy.
The panel concluded that the domain was both registered and used in bad faith. The respondent’s decision to adopt a name so closely tied to a century-old professional body constituted clear evidence of intent to exploit the complainant’s goodwill. By utilizing the domain to resolve to a webpage harvesting personal email addresses and home addresses from unsuspecting visitors, the respondent demonstrated an intent to engage in deceptive data collection. This predatory use of the brand further solidified the panel’s decision to mandate the transfer of the domain name to the complainant.
Strategic Enforcement: Establishing Bad Faith Through Impersonation and Data Harvesting
The success of the Professional Golfers’ Association Limited in this UDRP action relied on demonstrating a clear nexus between the unauthorized domain registration and active consumer deception. By documenting how the domain ‘pga-international.com’ utilized the protected ‘PGA’ trademark alongside a deceptive layout to masquerade as an official membership portal, the complainant effectively negated any potential claims of legitimate interest. The strategy was reinforced by highlighting the specific nature of the harm: the respondent’s website actively harvested sensitive personal data, including home addresses and contact details, which the panel recognized as a direct threat to the association’s established reputation and its global framework of licensed regional affiliates.
Furthermore, the complainant’s evidence-gathering process proved instrumental in securing a transfer. By establishing the long-standing nature of the ‘PGA’ mark—dating back to 1901—and contrasting this with the respondent’s recent, unauthorized registration, the complainant successfully framed the case around the intent to deceive. The panelist found that the mere inclusion of the term ‘international’ and a hyphen did not distinguish the site from the complainant’s legitimate assets, such as ‘pga.info.’ By focusing on the respondent’s failure to respond and the overt nature of the impersonation, the complainant ensured the panel had sufficient grounds to conclude that the registration and use of the domain constituted bad faith under the UDRP policy.
Practical Recommendations
- Deploy automated domain monitoring tools that specifically flag registrations combining your core trademark with regional or descriptive suffixes like ‘international’ or ‘global’.
- Establish a clear digital footprint of your authorized licensing structure online, making it easier for WIPO panels to identify ‘impersonation’ when a respondent claims an unaffiliated international status.
- Prioritize the preservation of evidence (via screenshots or archived web captures) at the moment an impersonation site is discovered, as respondents often take sites down once they receive notice of a UDRP filing.
- Draft UDRP complaints to explicitly highlight that the collection of personal contact information (PII) on a site constitutes bad faith use, even if the registrant lacks a commercial storefront.
- Proactively monitor for ‘look-alike’ membership portals that mimic your organizational naming conventions, as these are high-risk vectors for credential harvesting and phishing attacks against your registered members.
Frequently Asked Questions (FAQ)
Why did the panel determine that pga-international.com was confusingly similar to the PGA trademark?
The panel ruled that the disputed domain name incorporated the well-known ‘PGA’ mark in its entirety. The inclusion of a hyphen and the suffix ‘international’ was insufficient to distinguish the domain from the complainant’s established trademarks, nor did the ‘.com’ gTLD mitigate this confusing similarity.
What evidence established that the respondent lacked rights or legitimate interests in the disputed domain?
The respondent had no affiliation, license, or authorization from The Professional Golfers’ Association Limited to use the ‘PGA’ mark. Furthermore, the respondent was not commonly known by the name ‘PGA,’ and their use of the domain to host a fraudulent membership portal negated any claim of legitimate interest.
How did the complainant successfully prove bad faith registration and use?
Bad faith was evidenced by the respondent’s intentional impersonation of the PGA to solicit sensitive personal data, including email and home addresses. The panel found that registering a domain so obviously connected to a well-known mark to facilitate such data harvesting constitutes clear evidence of bad faith.
What was the tactical outcome of the UDRP filing for the complainant?
The WIPO panel ordered the immediate transfer of the domain pga-international.com to the complainant. This action effectively neutralized the respondent’s ability to continue using the domain to impersonate the organization and harvest user information, thereby mitigating further risk of phishing or reputational damage.
Facing corporate impersonation through a domain?
Protect your brand from fraudulent data harvesting and unauthorized entities mimicking your professional association. Learn how to secure your digital assets.
This case note is for informational purposes only and is not legal advice.



