Table of contents
- 1. Definitions and Interpretation
- 2. Purpose and Scope
- 3. Our Approach to Lawful Requests
- 4. Verification of Requesting Authority
- 5. Review of Legal Basis and Scope
- 6. Confidentiality and Privilege Considerations
- 7. Data Minimization in Responses
- 8. Notice to Affected Individuals Where Permitted
- 9. Emergency Requests
- 10. Preservation Requests
- 11. Cross-Border Requests
- 12. Sanctions and Anti-Money-Laundering Considerations
- 13. Mandatory Reporting Obligations
- 14. Record-Keeping
- 15. Cooperation Does Not Waive Objections
- 16. Contact for Authorities
- 17. Changes to This Policy
This Compliance and Law Enforcement Requests Policy ("Policy") explains, in general terms, how salamandralab (the "Firm") approaches requests for information from courts, regulators, law enforcement, and other government authorities. It is intended to give affected individuals and requesting Authorities a clear, predictable account of the Firm's approach, while preserving the confidentiality and privilege obligations the Firm owes its Clients.
1. Definitions and Interpretation
Capitalized terms used but not defined in this Policy have the meanings given in Section 1 of the Website Terms of Use. In addition, in this Policy:
- "Authority" means a court, tribunal, regulator, law enforcement agency, or other government body with lawful power to request or compel information.
- "Request" means a request, order, subpoena, warrant, summons, or similar instrument issued or presented by an Authority seeking information or documents held by the Firm.
- "Compelled Disclosure" means disclosure the Firm is legally required to make in response to a valid Request, notwithstanding an otherwise applicable duty of confidentiality.
- "Privileged Information" means information protected from disclosure by attorney-client privilege, legal professional privilege, work-product protection, or an equivalent protection under Applicable Law.
2. Purpose and Scope
This Policy applies to Requests directed at the Firm concerning information relating to the Website, prospective clients, or Clients. It does not itself waive, and should not be read as waiving, any privilege, confidentiality obligation, or objection available to the Firm or a Client under Applicable Law. It is a statement of process, not a substitute for legal analysis of any specific Request, which the Firm conducts on a case-by-case basis.
This Policy is addressed to two audiences at once. For Clients and prospective clients, it explains the principles the Firm intends to apply if it ever receives a Request touching their information, so that the Firm's approach is predictable rather than discretionary. For Authorities, it explains what the Firm will generally expect before treating a Request as valid, so that legitimate Requests can be processed efficiently and consistently.
3. Our Approach to Lawful Requests
The Firm respects the legitimate role of Authorities and intends to cooperate with valid, properly issued Requests to the extent required by Applicable Law. At the same time, the Firm owes independent professional duties of confidentiality and privilege to its Clients that survive receipt of a Request, and Applicable Law in most jurisdictions provides specific protections for attorney-client communications and work product. The Firm's general approach is to: verify the Request, assess its legal basis and scope, protect Privileged Information to the fullest extent Applicable Law permits, disclose no more than is required, and give notice where permitted. This approach reflects general principles of professional responsibility; specific procedures depend on the Firm's home jurisdiction and the Authority's jurisdiction, identified at [GOVERNING JURISDICTION(S) — PLACEHOLDER].
This approach is designed to hold two objectives together rather than to favor one over the other: respecting the legitimate investigative and regulatory functions that Authorities perform, and safeguarding the confidentiality and privilege that make it possible for clients to obtain candid legal advice. The Firm does not treat receipt of a Request as, by itself, a reason to disclose information informally or outside a proper legal process, and does not treat its professional duties of confidentiality as a basis for ignoring a validly issued and binding legal order.
4. Verification of Requesting Authority
Before responding substantively to a Request, the Firm intends to take reasonable steps to verify that it was issued by a genuine Authority with jurisdiction to make it, including confirming the issuing body, the signatory's authority, and the formal validity of the instrument (such as proper form, signature, and seal where applicable). Requests that cannot be verified, or that appear defective on their face, will not be treated as valid until the defect is resolved.
5. Review of Legal Basis and Scope
The Firm intends to review each Request to confirm it has a valid legal basis and is properly scoped, and to seek clarification or narrowing where a Request is vague, overbroad, or appears to exceed the Authority's lawful power. Where Applicable Law permits, the Firm may object to, seek to quash, or seek a protective order in respect of a Request it considers improper, excessive, or inconsistent with its professional obligations, before making any disclosure.
6. Confidentiality and Privilege Considerations
The Firm intends to assert applicable privilege and confidentiality protections on behalf of its Clients to the fullest extent permitted by Applicable Law, and to disclose Privileged Information only where: (a) Applicable Law does not recognize the privilege in the relevant context; (b) a valid, binding order requires disclosure notwithstanding the privilege and all available objections have been considered; (c) the Client has consented; or (d) a recognized exception applies, such as a narrowly defined crime-fraud or future-harm exception under Applicable Law. Where the Firm is uncertain whether information is privileged, it intends to treat the information as privileged pending clarification, consistent with its professional obligations.
Confidentiality obligations owed to a Client are distinct from, and generally broader than, attorney-client privilege: confidentiality typically covers all information relating to a representation regardless of its source, while privilege more narrowly protects certain confidential communications and related work product from compelled disclosure. The Firm's response to a Request accounts for both protections separately, since information that is not privileged may still be confidential and may still warrant objection, redaction, or a request for a protective order before disclosure, where Applicable Law allows.
7. Data Minimization in Responses
Where the Firm is required to respond to a valid Request, it intends to disclose only the information reasonably necessary to satisfy the specific, valid scope of that Request, and to withhold or redact information that is out of scope, privileged, or protected, to the extent Applicable Law permits withholding or redaction. This includes reviewing responsive material to separate information about the specific individual or matter identified in the Request from information about unrelated clients or matters that may happen to appear in the same file or system, and excluding the latter from the response unless it is itself within the valid scope of the Request.
8. Notice to Affected Individuals Where Permitted
Where Applicable Law permits and does not prohibit it (for example, through a valid non-disclosure or gag order), the Firm intends to notify an affected Client or individual of a Request concerning their information before responding, so that they may have an opportunity to object or seek protective relief through their own counsel. Where Applicable Law prohibits notice, or where notice would be inconsistent with a valid order, the Firm will comply with that restriction.
9. Emergency Requests
Where an Authority asserts an emergency involving imminent risk to life or safety, the Firm intends to apply heightened but still careful scrutiny appropriate to the urgency, aiming to verify the request and the claimed emergency as quickly as reasonably possible, consistent with Applicable Law, while avoiding unnecessary delay where a genuine emergency is credibly established. Even in an emergency, the Firm intends to disclose only information reasonably necessary to address the asserted emergency, and to complete the fuller verification and scope review described above as soon as practicable afterward.
10. Preservation Requests
Where an Authority requests preservation of information pending a formal Request, the Firm intends to consider such preservation requests in light of Applicable Law and its own record-retention obligations, recognizing that preservation is generally distinct from, and does not itself authorize, disclosure. Agreeing to preserve information in response to such a request does not constitute a waiver of any objection the Firm may later raise to a subsequent, formal Request for that same information.
11. Cross-Border Requests
Where a Request originates from an Authority outside the Firm's home jurisdiction, the Firm intends to assess whether the Request should proceed through an applicable mutual legal assistance treaty, letters rogatory, or other recognized cross-border mechanism, rather than through direct informal cooperation, particularly where direct cooperation could conflict with the law of the jurisdiction where the information is held or where the Client is located. Cross-border Requests raise additional considerations that the Firm intends to weigh before responding, including whether disclosure would violate blocking statutes, data-localization requirements, or professional-secrecy rules of another jurisdiction with a legitimate connection to the information, and whether the requesting Authority's own domestic law authorizes it to seek the information directly from a foreign firm. The specific cross-border mechanisms applicable to the Firm depend on its jurisdiction and are not exhaustively catalogued in this Policy.
12. Sanctions and Anti-Money-Laundering Considerations
Where applicable, the Firm may be subject to sanctions, anti-money-laundering, and counter-terrorist-financing obligations that require client identification, ongoing due diligence, and, in defined circumstances, reporting to a designated financial intelligence unit or equivalent body. Such obligations commonly require the Firm to screen prospective and existing Clients against restricted-party and sanctions lists, to understand the source of funds involved in certain transactions, and, where a suspicious pattern is identified in specifically defined circumstances recognized under Applicable Law, to file a report with the competent authority without necessarily notifying the Client that a report has been made, where such notification ("tipping off") is itself unlawful. These obligations are addressed at a general level in Section 17 of the Website Terms of Use, and, where applicable to the Firm, are further described at [APPLICABLE AML / SANCTIONS REGIME AND SUPERVISORY BODY — PLACEHOLDER].
13. Mandatory Reporting Obligations
Nothing in this Policy limits any mandatory reporting obligation imposed on the Firm by Applicable Law, including obligations that may require disclosure notwithstanding an otherwise applicable duty of confidentiality (for example, defined anti-money-laundering reporting obligations, or narrowly drawn obligations to prevent serious future harm, where recognized under Applicable Law). Where such an obligation applies, the Firm will comply with it, while continuing to protect Privileged Information and Client confidentiality to the maximum extent the obligation and Applicable Law permit.
14. Record-Keeping
The Firm intends to keep a record of Requests received and the Firm's response to each, including the verification and legal-basis review described above, for a period consistent with Applicable Law and the Firm's general record-retention practices described in the Privacy Policy. These records allow the Firm to demonstrate, if necessary, that a given disclosure was made only after appropriate verification and scope review, and support the Firm's ability to respond to any subsequent question a Client may raise about how a Request concerning their information was handled, to the extent the Firm is permitted to discuss it.
15. Cooperation Does Not Waive Objections
Compliance with a valid Request does not waive, and should not be understood as waiving, any objection, privilege, or right the Firm or a Client may have with respect to that Request or any future Request, except to the extent Applicable Law provides otherwise.
16. Contact for Authorities
An Authority seeking to submit a Request, or anyone with a question about this Policy, may contact the Firm at contact@salamandralab.example. Requests should be submitted in writing and should identify the issuing Authority, the legal basis relied upon, and the specific scope of information sought.
17. Changes to This Policy
The Firm may update this Policy from time to time to reflect changes in Applicable Law or its practices. The effective date at the top of this page reflects the date of the most recent update. Where a change materially affects how the Firm handles Requests concerning existing Clients, the Firm intends to consider whether additional notice to affected Clients is appropriate, consistent with the applicable Engagement Agreement.