Law Enforcement, Regulatory and Emergency Disclosure Protocol
How Perfect Mate handles requests from law-enforcement, regulatory and emergency authorities.
PERFECT MATE
Confidential Internal Compliance Document
Website: www.perfectmate.uk
Effective Date: 18th September 2026
Policy Owner: Director Bushra Anwar
Review Date: 18th September 2028
1. Purpose
1.1 This Protocol establishes the procedure Perfect Mate must follow when:
- a.the police or another law-enforcement authority requests information;
- b.a court or tribunal requires information;
- c.a regulator or statutory authority makes a lawful request;
- d.Perfect Mate identifies suspected criminal conduct requiring proactive reporting;
- e.there is an immediate safeguarding or serious-harm concern; or
- f.information must be preserved in anticipation of legal proceedings or investigation.
1.2 The purpose is to balance:
- a.member privacy and confidentiality;
- b.data-protection obligations;
- c.safeguarding;
- d.prevention and detection of crime;
- e.lawful regulatory cooperation; and
- f.the legitimate interests of Perfect Mate and its members.
2. Fundamental Rule
2.1 Perfect Mate must not disclose personal data simply because a person claiming to be a police officer, investigator, solicitor, journalist, member or other third party asks for it.
2.2 The identity and authority of the requester must be verified.
2.3 Perfect Mate must identify the lawful basis for disclosure before personal data is disclosed, except where an emergency requires immediate action and the lawful basis is documented as soon as practicable.
2.4 Disclosure must be limited to information that is reasonably necessary and proportionate for the stated purpose.
3. Verification of Requests
3.1 Staff receiving a request should obtain:
- a.the requester's full name;
- b.organisation;
- c.rank, position or role;
- d.official contact details;
- e.reference or incident number;
- f.statutory or legal authority relied upon;
- g.identity of the person concerned;
- h.precise information requested;
- i.purpose of the request;
- j.deadline; and
- k.whether disclosure is voluntary or legally compelled.
3.2 Requests should, wherever practicable, be made through an official organisational email address or formal legal process.
3.3 Staff must not rely solely upon telephone calls, social-media messages or informal communications.
3.4 Any doubt regarding authenticity must be escalated to the Data Protection Lead or a Director.
4. Lawful Basis
4.1 Before disclosure, Perfect Mate must identify an applicable lawful basis under Article 6 UK GDPR.
4.2 Depending upon the circumstances, the lawful basis may include:
- a.compliance with a legal obligation;
- b.protection of vital interests;
- c.performance of a task carried out in the public interest or exercise of official authority, where applicable;
- d.legitimate interests, where applicable; or
- e.another lawful basis permitted by the UK GDPR.
4.3 Where the information constitutes special category data, an additional Article 9 condition must also be identified.
4.4 Where criminal-offence data is involved, the requirements of Article 10 UK GDPR and the Data Protection Act 2018 must also be considered.
5. Sexual Orientation and Sensitive Information
5.1 Perfect Mate recognises that matchmaking profiles may contain highly sensitive information.
5.2 Information revealing sexual orientation or sex life is special category personal data.
5.3 Staff must therefore exercise particular care before disclosing such information.
5.4 A request for a person's name or identity does not automatically authorise disclosure of the entirety of that person's matchmaking profile, photographs, videos, messages or sensitive information.
5.5 Disclosure should be restricted to what is reasonably necessary for the lawful purpose.
6. Emergency Requests
6.1 Where there is an immediate threat to life, serious injury, kidnapping, exploitation, trafficking, terrorism or other serious harm, Perfect Mate may disclose relevant information to the police or emergency services where there is an appropriate lawful basis.
6.2 In an emergency, staff should:
- a.contact the police/emergency service where appropriate;
- b.verify the requesting officer or authority where practicable;
- c.record the circumstances;
- d.identify the information disclosed;
- e.record the lawful basis relied upon; and
- f.notify the Data Protection Lead as soon as reasonably practicable.
7. Crime Reports Initiated by Perfect Mate
7.1 Perfect Mate may proactively report suspected criminal conduct.
7.2 Examples include:
- a.credible threats of serious violence;
- b.blackmail or extortion;
- c.fraud;
- d.identity theft;
- e.romance fraud;
- f.sexual exploitation;
- g.trafficking;
- h.stalking;
- i.coercive or controlling conduct where relevant;
- j.non-consensual intimate imagery;
- k.money laundering or suspected proceeds of crime;
- l.sanctions evasion; or
- m.other serious criminal conduct.
7.3 The decision to report should be based upon the seriousness and credibility of the information and the applicable legal framework.
8. Court Orders and Compulsory Disclosure
8.1 Where Perfect Mate receives a court order, warrant, statutory notice or other legally binding requirement, the document must immediately be escalated to a Director and, where appropriate, legal advisers.
8.2 Perfect Mate must comply with valid legal obligations.
8.3 The response should be limited to the scope of the order or legal requirement.
8.4 If the request appears defective, excessively broad or unclear, Perfect Mate may seek clarification or legal advice before disclosure, unless the circumstances require immediate compliance.
9. Voluntary Requests
9.1 A voluntary request from law enforcement does not automatically require disclosure.
9.2 Before complying, Perfect Mate must establish:
- a.the identity of the requester;
- b.the purpose of the request;
- c.the lawful basis relied upon;
- d.whether the information is necessary and proportionate; and
- e.whether disclosure would comply with UK GDPR and the Data Protection Act 2018.
9.3 Perfect Mate should request a formal written information request where appropriate.
10. Data Preservation
10.1 Where Perfect Mate reasonably believes that information may become relevant to an investigation or legal proceedings, it may preserve relevant information in accordance with its retention procedures and applicable law.
10.2 Preservation does not itself authorise disclosure.
10.3 Staff must not delete, alter or destroy relevant information once a legitimate preservation requirement has arisen.
10.4 Access to preserved material must be restricted to authorised personnel.
11. What May Be Disclosed
Depending upon the lawful purpose and request, information may include:
- a.registration information;
- b.identity information;
- c.account records;
- d.dates of account creation and use;
- e.relevant messages;
- f.profile information;
- g.photographs or videos;
- h.payment records held by Perfect Mate;
- i.records of complaints;
- j.records of reported conduct;
- k.relevant IP/device information where lawfully held and requested; and
- l.other information reasonably necessary for the investigation.
12. Data Minimisation
12.1 Perfect Mate must not provide an entire member file merely because a narrower disclosure would satisfy the lawful purpose.
12.2 Staff should identify the minimum information reasonably necessary.
12.3 Where appropriate, irrelevant information concerning third parties should be redacted or withheld.
13. Third-Party Information
13.1 Particular care must be taken where requested information relates to multiple members.
13.2 Staff must consider the privacy rights of third parties before disclosure.
13.3 Where practicable, unnecessary third-party information should be redacted.
14. Requests for Member Contact Details
14.1 Perfect Mate will not ordinarily provide a member's private contact details to another member.
14.2 A request from a law-enforcement authority for contact information must be handled under this Protocol.
14.3 The fact that a member has previously consented to Perfect Mate sharing information for matchmaking purposes does not constitute blanket consent to disclose information to third parties.
15. Payment and Financial Crime Requests
15.1 Perfect Mate may receive requests concerning suspected payment fraud, chargebacks, stolen cards, money laundering, sanctions or other financial crime.
15.2 Such requests must be escalated to the Director responsible for compliance and, where appropriate, the payment provider.
15.3 Perfect Mate must not knowingly facilitate:
- a.money transmission;
- b.unlicensed financial services;
- c.investment schemes;
- d.lending between members;
- e.escrow arrangements;
- f.cryptocurrency transfers;
- g.payment-card testing;
- h.proceeds-of-crime transactions; or
- i.sanctions evasion.
15.4 Perfect Mate should cooperate with its payment provider and competent authorities where legally required or otherwise lawfully appropriate.
16. Stripe and Payment-Provider Compliance
16.1 Perfect Mate must accurately describe its business to Stripe.
16.2 Perfect Mate's business model is matchmaking and associated services; it is not a financial-services business.
16.3 Perfect Mate must not use Stripe to process transactions outside the approved business model.
16.4 Any request from Stripe for information concerning the business model, services, ownership, transaction flows, refunds, chargebacks, customers or compliance must be referred to the Director responsible for Stripe/payment compliance.
16.5 Any proposed change to the business model involving financial products, member-to-member payments, money transmission, lending, investment, cryptocurrency or escrow must be reviewed before implementation.
17. Confidentiality and Tipping-Off
17.1 Information concerning law-enforcement or regulatory enquiries must be treated confidentially.
17.2 Staff must not disclose the existence or substance of a confidential investigation to the affected member where doing so could prejudice an investigation or breach a legal restriction.
17.3 Where there is a legal prohibition on disclosure, staff must not inform the member.
18. Internal Record of Disclosure
Every disclosure must be recorded internally, including:
- a.date and time;
- b.identity of requester;
- c.organisation;
- d.legal authority or lawful basis;
- e.information requested;
- f.information disclosed;
- g.reason for disclosure;
- h.person authorising disclosure;
- i.method of transmission;
- j.any redactions;
- k.any relevant emergency circumstances; and
- l.date on which the matter is closed.
19. Secure Transmission
19.1 Personal data must be transmitted securely.
19.2 Staff should use the secure method specified by the requesting authority where appropriate.
19.3 Passwords or encryption keys should be communicated separately where necessary.
19.4 Staff must not send sensitive personal information through unsecured personal email accounts.
20. Data Subject Requests
20.1 A member may have rights to access personal data held by Perfect Mate.
20.2 Where disclosure of information to a member would prejudice the prevention or detection of crime, legal proceedings or another applicable exemption, Perfect Mate will consider whether a statutory restriction or exemption applies.
20.3 Any such request must be referred to the Data Protection Lead.
21. Complaints
21.1 Complaints concerning the handling of personal data or disclosure to law enforcement must be dealt with under Perfect Mate's complaints procedure and applicable data-protection law.
21.2 A complaint should be investigated independently of the original decision where reasonably practicable.
22. Staff Responsibilities
All Perfect Mate staff who have access to member information must:
- a.maintain confidentiality;
- b.follow this Protocol;
- c.complete appropriate data-protection training;
- d.report suspected data breaches immediately;
- e.escalate unusual or high-risk requests;
- f.maintain accurate disclosure records; and
- g.not make unauthorised disclosures.
23. Data Breaches
23.1 Any accidental or unauthorised disclosure of personal data must immediately be reported internally.
23.2 Perfect Mate will assess whether the incident constitutes a personal-data breach requiring notification to the ICO or affected individuals.
23.3 Staff must not attempt to conceal or independently resolve a serious data breach without escalating it.
24. Review
This Protocol must be reviewed at least annually and sooner where there is:
- a.a material change in law;
- b.a significant data breach;
- c.a change in Perfect Mate's business model;
- d.a material change to Stripe/payment-provider requirements;
- e.a significant safeguarding incident; or
- f.relevant regulatory guidance or enforcement action.
25. Authorisation
Approved by: Bushra Anwar
Position: Director
Date: 18th September 2026
Next Review: 18th September 2028