How should a provider respond to a government request?
Route the request to authorized legal review before anyone searches for or discloses PII. Verify the issuer, service, customer, subject or account, requested data, time period, legal authority, jurisdiction, recipient obligations, binding effect, deadline, and any available challenge or narrowing procedure. Under the 2019 guidance, reject requests that are not legally binding, consult the customer before disclosure where legally permissible, and honor contractually agreed disclosures authorized by the customer.
The contract should require customer notice within its agreed process and time periods unless notice is prohibited. The standard gives criminal-law confidentiality as an example of a possible prohibition. It does not decide whether a particular request is valid, whether it must be challenged, or which law controls.
- Validate the request and escalate to legal review before disclosure.
- Limit disclosure to the customer, service, PII categories, subjects or accounts, and time period covered by the validated authority; data minimization or a challenge depends on the governing law and available procedure.
- Notify the customer when law and the request allow it, and document any restriction on notice.
- Record the request, the decision, the data disclosed, the approvals, and the reason for any exception.
Primary ISO listing for the 2025 edition of ISO/IEC 27018.
ISO's withdrawn 2019 edition contains Annex A.6.1 on legally binding law-enforcement disclosure requests and A.6.2 on disclosure records.