This page sets out how Postorb handles requests from public authorities (police, courts, regulators and other government bodies) for the personal data of its users. It applies to all data Postorb holds, including data obtained from connected social media platforms such as Facebook and Instagram. It should be read together with our Privacy Policy.
Our starting position
User data is disclosed to a public authority only where there is a valid legal obligation to do so. We do not provide voluntary or informal access, and we do not give any authority direct or standing access to our systems.
1. Legality review
Every request must be made in writing and must identify the requesting authority, the person responsible, the legal basis relied on, and the specific data sought.
Verbal, unsigned or unverifiable requests are not actioned. We will ask the authority to resubmit through a formal channel.
Before any disclosure, the data controller reviews the request to confirm that the authority has the legal power to make it, that the stated legal basis is valid in the jurisdiction concerned, and that the request is proportionate to its stated purpose.
Where the validity of a request is unclear, we obtain legal advice before responding.
2. Challenging requests
If a request appears unlawful, overbroad, vague, or inconsistent with applicable data protection law (including the UK GDPR and EU GDPR), we decline to disclose and tell the authority why.
Where appropriate we ask the authority to narrow the request, provide a court order or warrant, or clarify the legal basis.
We reserve the right to challenge a request through the courts or the relevant supervisory authority, and to seek legal representation to do so.
Requests that would require us to disclose data about users outside the requesting authority’s jurisdiction are treated as unlawful unless a recognised mutual legal assistance process is followed.
3. Data minimisation
We disclose only the specific data items named in a valid request, and only for the specific account or accounts named.
We do not provide full account exports, bulk data, or data about users who are not the subject of the request.
Data obtained from connected social media platforms is disclosed only where it is expressly covered by the request and is not otherwise available to the authority directly from that platform.
Where a request can be satisfied with less data, or with data in a less identifying form, we respond that way.
4. Documentation
We keep a written record of every request received, including:
the date received and the requesting authority and named contact;
the legal basis cited and a copy of the request;
the outcome of our legality review and the reasoning behind it;
any challenge made and the authority’s response;
what data, if any, was disclosed, when, and to whom;
any legal advisers involved.
These records are retained for at least five years and are available to a supervisory authority on request.
Notifying affected users
Unless we are legally prohibited from doing so, or doing so would put a person at risk, we notify the affected user that their data has been requested, before disclosure where possible and otherwise as soon as the prohibition is lifted.
Requests received to date
As of the date above, Postorb has received no requests from any public authority for user data.
Contact
Public authorities and users with questions about this policy: privacy@postorb.com