VND-012 Government and Law Enforcement Data Request Handling
Description
A documented procedure governs requests from government bodies and law enforcement for customer or personal data, covering receipt, legal review of the authority relied on, narrowing of any response to the data the request compels, approval by a named role before anything is released and the record kept of each request and its outcome. Customers are notified of a request affecting their data unless notification is prohibited. Where it is prohibited, the prohibition and the date it lapses are recorded. The procedure is described to customers and the number and type of requests received and actioned are reported at defined intervals. For an instrument issued outside the jurisdictions the organisation is established in, the legal review records whether an international agreement in force between that country and the organisation's jurisdiction supports recognition of the instrument and, where none does, whether the requesting system requires the reasons, the proportionality and the specificity of the order to be set out, whether a reasoned objection can be reviewed by a competent court there and whether that court may weigh the legal interests the organisation's own law protects. The procedure names the route to the competent national body for an opinion, the period of silence after which a refusal is available and the ground each refusal is recorded against. Notification reaches the customer before the response is produced.
Rationale
A demand from an authority is the one disclosure a provider cannot refuse on contract grounds. Enterprise buyers ask how it is handled before they sign. The library had no home for it: VND-010 governs disclosure the organisation chooses to make, to a partner or a processor, under a data sharing agreement, where the test is authorisation and minimisation against an agreed purpose. VND-012 governs disclosure it is compelled to make, where the test is the validity of the legal instrument, the narrowing of the response to what that instrument compels and whether the customer can be told. Where the organisation acts as a processor the customer is the controller being notified. GDPR Art. 29 carries the carve-out that permits processing outside the controller's instructions when a law requires it. A review that reads only the issuing country's own law returns the wrong answer, because the prior question is whether the instrument is capable of recognition here at all. Recording the refusal ground matters as much as recording the release: a request refused on recognition and one refused for breadth are different facts about the same procedure, and only the first tells a customer the boundary held. Notification before production is the timing the customer needs to object while objecting is still useful. VND-011 publishes the standing measures that make such a request harder to satisfy; VND-012 handles the one that arrives. A demand for customer data is the only subject of this control. Cooperation with a customer's supervisory or resolution authority over the service itself, including access to premises, records and staff, is GOV-028; a request for customer data that arrives through that channel is still handled here.
Applicability (9 profiles)
Requests for customer data reach the provider because it hosts the tenant's data.
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, the data a request could compel is in its own custody and its procedure covers receipt, legal review, narrowing, approval and the record end to end. Under cloud-saas or cloud-single-tenant the deployer is the customer the provider notifies, it obtains the provider's request-handling terms under VND-004, and its own procedure still covers the personal data it controls directly.
Condition: deployment_model in cloud-saas, cloud-single-tenant
Requests for customer data reach the provider because it hosts the tenant's data. Conditional since 1.1: the profile lists every deployment model and this row is a commitment of a hosted service, so a provider that publishes weights or runs on infrastructure the customer controls has no hosted service to carry it (ADR-046 amendment, 2026-09-16).
Requests for customer data reach the provider because it hosts the tenant's data.
Condition: deployment_model in on-prem, hybrid, edge, on-device, embedded, air-gapped
Where the deployer runs the AI system on infrastructure it controls, the data a request could compel is in its own custody and its procedure covers receipt, legal review, narrowing, approval and the record end to end. Under cloud-saas or cloud-single-tenant the deployer is the customer the provider notifies, it obtains the provider's request-handling terms under VND-004, and its own procedure still covers the personal data it controls directly.
EX-102 written in S8 wave B (migration 057). The legal review now applies the recognition test to an instrument issued outside the jurisdictions the organisation is established in, covering the international agreement question and the three conditions that apply where none is in force; the procedure names the route to the competent national body, the period of silence after which a refusal is available and the ground each refusal is recorded against; and notification reaches the customer before the response is produced. Art. 32(2) and Art. 32(3) hold full. Two things remain. Art. 32(5)'s exception is narrower than the control's, which reads any prohibition on notification rather than a law enforcement purpose for as long as effectiveness requires. Art. 32(1)'s technical and contractual prevention measures sit on DAT-021, DAT-003 and, as a published description, on VND-011, which now holds Art. 28(1)(b) in full.
Requests for customer data reach the provider because it hosts the tenant's data.
Requests for customer data reach the provider because it hosts the tenant's data.
Requests for customer data reach the provider because it hosts the tenant's data.
Framework Mappings (9)
| DSP-18 | Disclosure Notification | full |
| DSP-18 | Disclosure Notification | full |
| EU-DA-Art.28.1.b | Measures Preventing International Governmental Access | informative |
| EU-DA-Art.32.1 | Measures Preventing Unlawful Third-Country Access | partial |
| EU-DA-Art.32.2 | International Agreement Basis for Third-Country Orders | full |
| EU-DA-Art.32.3 | Conditions for Transfer Without an International Agreement | full |
| EU-DA-Art.32.4 | Minimum Data in Response to a Third-Country Request | full |
| EU-DA-Art.32.5 | Customer Notification of a Third-Country Request | partial |
| GDPR-Art.29 | Processing Under Controller Authority | informative |
Evidence (3)
The documented procedure for handling government and law enforcement requests, covering receipt, legal review, minimisation, the approval role, customer notification and record keeping.
Example: Government and Law Enforcement Request Procedure v2.0, approved by the General Counsel on 2026-04-12, with the routing address, the review steps and the approval matrix.
Test: Request the procedure. Verify: (1) it names where a request is received and who reviews the legal instrument, (2) it requires the response to be narrowed to the data the instrument compels, (3) it names the role that approves release and requires approval before anything leaves, (4) it states when a customer is notified and how a prohibition on notification is handled and recorded, (5) it requires a record of each request and its outcome, (6) it names the review interval and the date of the last review. (7) it states the recognition test applied to an instrument issued outside the jurisdictions the organisation is established in, covering the international agreement question and the conditions that apply where no agreement is in force, (8) it names the competent national body, the period of silence after which a refusal is available and the grounds a refusal is recorded against, (9) it places customer notification before the response is produced rather than at an unstated point.
Register of requests received, recording the requesting authority, the instrument relied on, the legal review outcome, what was released, who approved it and whether the customer was notified. An entry for an instrument issued outside the jurisdictions the organisation is established in also records the recognition test applied, any opinion sought and the ground of any refusal.
Example: Law enforcement request register, entries for 2026, showing five requests: two refused as invalid, two narrowed and answered with customer notification, one under a non-disclosure order with its lapse date recorded.
Test: Request the register for the period and sample entries against the underlying correspondence. Verify: (1) every request has a recorded legal review before any release, (2) what was released is recorded and is no broader than the instrument compels, (3) the named approval role approved each release, (4) the customer was notified or the prohibition and its lapse date are recorded, (5) refusals are recorded with the reason, (6) the register entries reconcile to the totals in the periodic report. (7) each third-country instrument in the register carries the recorded recognition test and, where the opinion route was used, the request, the reply or the silence relied on, (8) where the customer was notified, the notification pre-dates the release rather than following it.
The periodic report of requests received and actioned that is made available to customers, with the description of the procedure it accompanies.
Example: Transparency report for the first half of 2026, published 2026-08-01, giving the count of requests by type and jurisdiction and the number in which data was released.
Test: Request the most recent periodic report and the customer-facing description of the procedure. Verify: (1) the report covers the period and was produced within the defined interval, (2) the counts reconcile to the request register, (3) the description of the procedure is reachable by the route a customer would use, (4) the description matches the approved procedure.
Questions (3)
Is there a documented procedure for handling government and law enforcement requests for customer data?
This is separate from the disclosure controls that govern sharing you choose to do. The question is what happens when a demand arrives that you cannot decline on contract grounds.
What does the procedure require before data is released?
Narrowing is the step most often missed: an overbroad demand answered in full is a disclosure the organisation chose to make. The recognition test is the step before that one and is missed more often still, because a review that satisfies itself the order is valid where it was issued has answered a different question. Notification counts here only where it runs before the response leaves.
How are requests reported to customers?
Options run from strongest to weakest. Reporting counts of requests is possible even where an individual request is under a non-disclosure order.