- We review the legality and authority of each request.
- We challenge, refuse or narrow unlawful, unclear or excessive requests.
- We disclose only the minimum information lawfully required.
- We document requests, decisions, legal reasoning, reviewers and disclosures.
1. Scope
These guidelines apply to requests for information held by Swish from police forces, courts, regulators, tax authorities, government departments, intelligence or security bodies and other public authorities. They apply whether the request relates to Swish account data, tenant-controlled CRM data, Meta Platform Data, technical records or other personal information.
2. What a request should contain
Requests should be made in writing through an official channel and should identify the requesting body and officer, relevant jurisdiction, legal power relied upon, purpose, categories of data requested, affected account or person, applicable date range and any confidentiality restriction. We may require identity verification, supporting documentation, a court order, warrant or other valid legal authority.
3. Legal and proportionality review
Every request is referred to an authorised senior reviewer. We assess whether the requester has authority, whether the request is binding on the relevant Swish entity, whether a lawful basis exists, whether special-category or criminal-offence data is involved, and whether disclosure is necessary and proportionate. We may seek external legal advice.
4. Challenge, refusal and narrowing
We may refuse, challenge or ask for clarification where a request is informal, invalid, unlawful, overbroad, disproportionate, technically impossible, directed to the wrong entity or inconsistent with applicable law. Where only part of a request is valid, we may narrow the scope, redact unrelated information or require a more specific legal instrument.
5. Data minimisation and secure disclosure
Where disclosure is lawful, we provide only the minimum information necessary for the stated lawful purpose. Irrelevant records and information about unrelated people are withheld or redacted where appropriate. Information is transferred using an appropriately secure method and access is restricted to authorised recipients.
6. Customer and user notice
Where legally permitted and operationally appropriate, we may notify the relevant tenant or affected person before disclosure so they can seek advice or challenge the request. We may delay or withhold notice where prohibited by law, where a valid non-disclosure requirement applies, or where notice would create a demonstrable risk of harm, obstruction or evidence loss.
7. Emergency requests
Requests involving an imminent risk of death or serious physical harm may be prioritised. The requester must explain the emergency and why the requested information is necessary. Emergency handling does not remove the requirement to verify authority, assess necessity, minimise disclosure and document the decision as soon as practicable.
8. Requests from outside the United Kingdom
Foreign authorities should normally use an applicable international cooperation, mutual legal assistance or UK-recognised legal process. We may decline direct foreign requests that are not binding on us or that conflict with UK law, data-protection obligations or the rights of affected people.
9. Documentation and accountability
We maintain a restricted record of requests and responses, including the requesting authority, dates, scope, legal power, reviewers, decision, reasoning, challenge or clarification, information disclosed, secure transfer method and closure. Records are retained for accountability, legal claims, security and regulatory obligations.
10. Contact and service
Requests should be sent to info@swish.click. Email alone does not constitute valid service of legal process unless we expressly confirm otherwise.
These guidelines describe our general approach and do not create rights beyond applicable law or prevent Swish from taking a different lawful approach in a particular case.