Government & Public Authority Data Request Policy
Last updated: 12 June 2026
This policy describes how Clarify handles requests from public authorities — including law enforcement, courts, and regulators such as the eSafety Commissioner — for the personal information of users, including content and data obtained from connected social accounts (Facebook, Instagram, Threads, and TikTok). It applies to every such request we receive.
We review the legality of every request
We do not disclose personal information to a public authority on an informal or voluntary basis. Before responding to any request, we review whether it is lawful, properly issued, and validly served — for example, that it comes from an authority with jurisdiction and is accompanied by the appropriate legal instrument (such as a warrant, subpoena, court order, or a power conferred by statute). Where a request is unclear, we seek clarification before acting.
We challenge requests we consider unlawful
Where we believe a request is unlawful, overbroad, vague, or otherwise improper, we will push back. This may include asking the authority to narrow or withdraw the request, requiring proper legal process, or, where appropriate, formally challenging or declining to comply. We comply only to the extent we are legally obliged to.
We disclose only the minimum necessary
When we are lawfully required to respond, we disclose only the specific information that the request lawfully compels — never more. We do not provide bulk access, and we scope our response to the narrowest set of data responsive to the request. This reflects the data minimisation principle that governs how Clarify collects and handles personal information generally.
We document every request
We keep a record of each request we receive, including the requesting authority, the date, the legal basis cited, the data sought, the action we took (including any decision to challenge or decline), our legal reasoning, and the people involved in handling it. This record allows us to account for our handling of personal information and to identify patterns over time.
Transparency and notification
Where it is lawful and safe to do so — that is, where we are not prohibited by law and notification would not prejudice an investigation or risk harm — we will inform the affected Clarify customer (the account's authorised team) that a request concerning their data was made. Where a legal prohibition (such as a non-disclosure order) prevents us from doing so, we comply with that prohibition.
Emergencies
In a genuine emergency involving an imminent risk of serious harm to a person, we may provide the minimum information necessary to help prevent that harm, consistent with applicable law. Such disclosures are documented in the same way as any other request.
Contact
Public authorities should direct requests to support@clarify.net.au. For more on how we handle personal information generally, see our Privacy Policy.
