Beyond Raw Data / TourIQ
Law Enforcement Request and Personal Data Audit Procedure
A controlled intake, validation, audit, disclosure, and chain-of-custody process for official requests.
1. Purpose
This procedure applies when a police officer, regulator, court officer, national security organ, prosecutor, or other public authority requests personal data held in TourIQ. The objective is to comply with lawful requests while protecting data subjects and preserving evidence integrity.
2. Intake form
Request ID
Date and time received
Requesting agency
Officer name and rank
Badge / service number
Official email and phone
Case / occurrence / court reference
Legal authority supplied
Court order / warrant / summons reference
Deadline or urgency claimed
Person / account / booking / payment subject
Specific records requested
3. Validation checklist
- Require written authority unless there is an immediate lawful emergency.
- Validate the officer and agency using official contact channels, not only the contact details in the request.
- Confirm whether the request is required by written law, court order, warrant, summons, preservation order, or other lawful authority.
- Escalate to management and counsel where the request is broad, sensitive, urgent, cross-border, or unclear.
- Do not disclose passwords, secret keys, unrelated customer data, or data outside the lawful scope.
4. Personal data audit map
Search only the systems and time period relevant to the lawful request.
Users / auth accounts checked
Customers checked
Bookings checked
Booking participants checked
Payments checked
Receipts / invoices checked
Files / storage checked
Support / email / SMS / WhatsApp records checked
IP / device / audit logs checked
Third-party processors checked
5. Disclosure control
- Place a legal hold on relevant records before exporting.
- Export only the records authorized by the request.
- Redact unrelated third-party data unless disclosure is legally required.
- Generate a file hash or checksum where possible.
- Use encrypted delivery or official secure handover.
- Record recipient identity and acknowledgement.
- Do not notify the data subject if notification is prohibited or would prejudice a lawful investigation; seek legal advice before notifying.
6. Chain of custody
Exporter name
Export date and time
Source systems
File names / bundle ID
Hash / checksum
Approver
Delivery method
Recipient acknowledgement
Online submission
Submit a law enforcement or official request
Request ID: TIQ-LEX-20260718-918022. Complete this online, download a copy for your records, then submit it to Beyond Raw Data.