1. Scope
This policy sets out how Orcas Informatica Ltd (“Orca”, “we”, “us”) responds when a public authority asks us to disclose personal data. It covers requests from UK police forces, government departments, regulators, courts and equivalent bodies overseas.
It applies to all personal data we hold, whether that is data about our own customers, data our customers hold about their drivers and clients on our platform, or data we receive from third party services such as the DVLA Access to Driver Data service or the Meta messaging platforms.
We are registered with the Information Commissioner’s Office under registration number ZC207794 and this policy sits alongside our Privacy Policy.
2. Reviewing the Legality of a Request
We do not disclose personal data to a public authority on request alone. Every request is reviewed before any data is released. That review checks:
- that the request comes from a body with the legal power to make it, and that the person making it is who they say they are
- that it cites the specific legal power being relied on, such as a court order, a warrant, or a statutory disclosure provision
- that it has been properly served, in writing, through a channel we can verify
- that the data sought is actually within the scope of that legal power
- that we in fact hold the data described
Where we act as a data processor for one of our customers rather than as the controller, our default position is to direct the request to that customer, and to notify them, unless we are legally prohibited from doing so.
3. Challenging Unlawful or Overbroad Requests
If a request appears to be unlawful, improperly served, or wider than the legal power it relies on, we will say so in writing and ask for it to be narrowed, corrected or properly authorised before we disclose anything.
Where a request is pressed and we still consider it unlawful, we will take legal advice and, where appropriate, resist or formally challenge it. We will not treat an informal approach, a verbal request or an unexplained demand as sufficient grounds for disclosure.
4. Disclosing the Minimum Necessary
Where a request is lawful and we are required to comply, we disclose only the data the request actually requires. In practice that means:
- answering the specific question asked rather than exporting whole records or whole accounts
- limiting disclosure to the date range, individuals or transactions named
- redacting third party personal data that is not within scope
- providing data in a form that does not reveal more than is needed
5. Documentation and Records
We keep a written record of every request we receive from a public authority. Each record notes:
- the date, the requesting body and the individual who made the request
- the legal power relied on and the data sought
- our assessment of the request and the reasoning behind our decision
- what we disclosed, when, and to whom, or our reasons for refusing
- who within Orca handled it and who approved the outcome
These records are retained so that we can account for our decisions to the ICO, to our customers, or to a court.
6. Notifying Affected People
Where we are permitted to do so, we notify the customer whose data is affected before we disclose anything, so that they have the opportunity to respond or to challenge the request themselves.
We will not give that notice where a court order, a statutory gagging provision or a genuine risk to life prevents it. In those cases we record the reason for not notifying, and we notify once the restriction ends.
7. Emergency Requests
Where an authority states that there is an immediate risk of death or serious physical harm, we may disclose limited data without the usual written process. Any such disclosure is still restricted to what is necessary to address the emergency, is recorded in the same way as any other request, and is reviewed afterwards.