Policies
Government and Law Enforcement Data Requests
How Vaarta handles requests from public authorities for personal data — legality review, minimisation, and what we write down.
Last updated: 8 September 2026
Some of what passes through this platform is a patient telling a clinic what hurts. If a public authority asks us for it, this is what happens.
Every request is checked before anything is disclosed
We verify who is asking and on what authority, require the request in writing, and identify the specific legal provision relied on. A verbal request, an informal message, or a demand citing no legal basis is not actioned — we ask for a proper written demand instead.
We challenge requests we believe are unlawful
Where a request has no lawful basis, reaches further than its stated purpose, or conflicts with the Digital Personal Data Protection Act, 2023 or the confidentiality owed to a patient, we take legal advice and challenge or refuse it. We do not disclose data on the strength of a request we believe to be unlawful.
We disclose the minimum, never the database
A disclosure covers only the named individuals, the specific data and the period the request identifies. We do not hand over whole records, contact lists or bulk exports where something narrower answers the question.
Every request is written down
We log the date received, the authority and officer asking, the legal basis cited, what was asked for, our reasoning, what we decided, what was disclosed and when we replied. Those records are kept for at least five years.
We tell you, unless we are forbidden to
Where the law does not prohibit it, we notify the affected person — or, for data we process on behalf of a business, that business — before disclosing anything, so they have the chance to respond themselves.
Who handles this
Archana Nair · hello@vaartatech.com
Requests should be sent in writing to that address and to the postal address in
the footer.