Last updated: 23 September 2026
This page summarises how Ansvar Systems AB ("Ansvar") handles a request from a court, a law-enforcement body, a regulator or another government authority for data we hold or control about our customers and their users. It covers requests from Sweden, from other EU countries and from countries outside the EU, including emergency requests. It describes the policy our CEO approved in August 2026. Our contractual commitments to you are in the Data Processing Addendum and the Terms of Service.
Separate procedures handle content and copyright notices (Notice & Complaints Procedure), requests that individuals make in a private capacity about their own personal data (Privacy Notice) and our own incident notifications to authorities. If a government demand for data comes with a content notice, this page covers that demand.
Anyone at Ansvar who receives a request passes it to our CEO and security team at once, without answering on substance. Our staff do not acknowledge the substance of a request, confirm or deny that we hold data, search for responsive data, promise notice or disclose anything outside this process.
Our security team keeps the original request and its delivery details, and verifies the requester's identity through an independent official channel. Contact details the requester supplies are not enough to verify identity. A verified identity does not by itself give a request legal force.
Before we disclose anything, external legal counsel reviews the specific request: the instrument and the authority that issued it, jurisdiction, how it was served, whether it is enforceable, its scope, the applicable Swedish and EU law, the lawful basis under the GDPR, and any rules on transfers outside the EU. We do not treat a foreign court or authority decision as sufficient because it was served on us directly. Counsel considers Article 48 GDPR and any international agreement or EU mechanism that applies.
We do not disclose data in response to a phone call, a voluntary questionnaire, an unsupported email or any other informal or unverified request. Our CEO, advised by counsel, decides whether to refuse such a request in writing, ask for clarification, or put it on hold.
If a request appears unlawful, unauthenticated, outside the authority's jurisdiction, overbroad, disproportionate, or in conflict with privacy law or our duties to customers, our CEO and external counsel consider asking for clarification, narrowing the request, or challenging it. For third-country requests for non-personal data held in the EU, our Service Portability Register (section 5) also commits us to consult the competent national body where required and to raise a reasoned objection or challenge where grounds exist. Urgency does not make an invalid request valid.
A request that claims an imminent risk to life or safety gets faster preservation, identity verification, counsel review and decision. It still goes through legal review, minimum scope, a recorded decision, secure transfer and our request records. If the law allows an emergency disclosure without the usual order, counsel identifies and records that specific legal authority before we release anything.
Our CEO decides whether to disclose, narrow, challenge or refuse, and whether to notify the customer, and records that decision before any data leaves Ansvar. If the CEO is unavailable, has a conflict of interest or is the subject of the request, our board appoints an independent decision-maker and records the appointment.
If we disclose, we first establish which data we actually hold. We prepare only the named accounts, data categories and time range the request requires, and our CEO approves that final list. We send it to a verified recipient over a secure channel and keep evidence of what we sent, its integrity and its delivery.
If counsel confirms that notice is permitted and appropriate, we notify the affected customer before we disclose, with time to seek a remedy. If a binding legal prohibition prevents notice, we record its exact legal basis, scope, start, and its expiry or review trigger, and we review it at each management review and when that trigger occurs. Once counsel confirms the restriction no longer applies, we notify the customer promptly, unless another binding obligation prevents it.
Two published commitments go further for specific data. For personal data we process on your behalf, the DPA (section "Assistance to the Controller") commits us to notify you promptly of any request, inquiry, audit, investigation or other regulatory action, including notice of intent, by a supervisory authority or governmental body relating to that processing, and to give you the relevant information reasonably available to us, unless applicable law prohibits it. For third-country governmental access to non-personal data held in the EU, the Service Portability Register commits us to notify you before access or transfer unless law bars notice for the time needed to protect a law-enforcement activity.
We record every request and its outcome, whether we disclosed, narrowed, challenged or refused, the authority withdrew it, or it is still pending. The record lists the categories and volumes of data disclosed. It does not copy the disclosed content. We keep each record for at least seven years after the request is closed, unless a legal or retention requirement sets a different period.
At least once a year our CEO records a dated decision on whether we will publish an aggregate summary of requests, where the law permits one, based on reconciled records and current legal advice. Any summary will reconcile its counts to our records up to a stated date and will not reveal a request we are prohibited from disclosing.