Law Enforcement and Government Request Guidelines
The requirements and safeguards for court, police, government, CERT-In and preservation requests concerning SYNC.
5.1 Purpose
These Guidelines explain how RABC evaluates compulsory and voluntary requests for information, assistance, preservation or Content action. They do not enlarge the power of any authority and do not promise that requested information exists. Applicable Law and a valid binding order prevail.
5.2 Authoritative request channel
Official requests must be sent from an identifiable government or court domain to law.enforcement@rabcorp.co.in and, where necessary, delivered to the postal address in this Pack. Urgent follow-up may use +91 80555 00441, but a telephone call alone does not authorise disclosure. Requests sent to a personal address or obsolete number may not be treated as valid service.
5.3 Required information
A request should identify the requesting agency and officer, official contact details, legal authority and statutory provision, purpose, case or diary number, exact Account identifier, specific information sought, relevant period, required deadline and any confidentiality direction. A Content-action request should identify the specific URL, message, Account, group, channel or other electronic location rather than demand a general search.
A request for disclosure should distinguish Account information, metadata, reported Content, preserved records, call data and any other category sought. It should state the relationship between the identifier, period and investigation. RABC may require a certified translation, authenticated copy, preservation instruction or secure return channel where necessary to understand and lawfully complete the request.
5.4 Verification and scope
RABC may verify the officer, issuing authority, signature, jurisdiction, legal basis, necessity, proportionality and scope. RABC may reject, challenge or seek clarification of a request that is informal, overbroad, defective, inconsistent, technically impossible or seeks information outside RABC’s control. RABC may preserve relevant records while a defect is clarified where lawful.
5.5 Types of process
Depending on the request and law, RABC may require a court order, warrant, summons, authorised government order, section 69 process, CERT-In direction, preservation request or other compulsory instrument. A foreign request should ordinarily use an applicable mutual legal assistance, treaty, letters rogatory or Indian-law route unless immediate voluntary disclosure is lawfully permitted to prevent death or serious physical harm.
5.6 Information that may be available
Subject to retention and system design, RABC may hold registration information, verified phone number or email address, profile and handle data, device registration, public keys, login and IP records, session and security events, group membership and roles, message and delivery metadata, encrypted envelopes, call metadata, reports, grievances, voluntarily submitted Content, enforcement history and preserved records. Availability varies by Account channel, time and feature.
RABC does not promise that every listed category exists for every Account or remains available. Availability depends on the identifier supplied, Account channel, technical design, deletion, retention period, legal hold and whether the requested record is within RABC’s possession or control. A profile name or handle alone may be insufficient to identify the correct Account.
5.7 Information limited by E2EE
RABC does not have routine access to plaintext of supported CHAT or CONVERSE E2EE messages. RABC cannot provide plaintext it does not possess, decrypt on demand without keys it does not hold or create a backdoor. A participant’s voluntary report may make selected Content available. Encryption does not prevent disclosure of lawfully available Account, metadata, reported Content or security records.
5.8 Content action and actual knowledge
A qualifying court order or reasoned written intimation by the authorised government officer must identify the legal basis, unlawful act and specific electronic location. Where it creates actual knowledge under the intermediary rules, RABC will remove or disable access to the identified information within the applicable three-hour period. Temporary or transient transmission may limit RABC’s ability to remove Content that it does not host or control.
RABC may seek clarification where an order does not identify the electronic location or demands a general search. Action will be limited to information RABC hosts, stores, publishes, transmits or otherwise controls in the legally relevant manner. Disabling access does not require RABC to make a false representation that copies already received on another person’s device have been erased.
5.9 Information and assistance deadline
Upon receipt of a valid written order from a lawfully authorised government agency for investigative, protective or cyber-security activity, RABC will provide information under its control or possession, or lawful assistance, as soon as possible and not later than seventy-two hours unless a different binding period applies. The request must clearly state its purpose.
5.10 Emergency requests
RABC may prioritise a narrowly tailored request where the officer explains an imminent risk of death or serious physical injury, identifies the threatened person, provides the factual basis and certifies that ordinary process cannot arrive in time. RABC may disclose only what law permits and may require formal process after the emergency. An emergency label does not guarantee disclosure.
The request should come from a verifiable official channel and identify the officer, threatened person, factual basis, specific information sought and reason normal legal process cannot arrive in time. Telephone contact may accelerate triage but does not by itself authorise disclosure. Every emergency disclosure decision will be documented and limited to information reasonably connected with the imminent risk.
5.11 Preservation
A valid preservation request should identify the exact Account or record, time period, legal authority and duration. RABC may preserve information for one hundred and eighty days under intermediary obligations or for a longer period required by a competent court or lawfully authorised agency. Preservation does not itself authorise disclosure.
5.12 CERT-In
RABC will report qualifying cyber incidents to CERT-In within the applicable six-hour period, maintain required ICT logs for a rolling one hundred and eighty days within Indian jurisdiction, maintain a designated point of contact and provide assistance required by a valid CERT-In direction. Security-sensitive details may be handled through controlled channels.
5.13 First-originator requests
First-originator obligations apply only if RABC is legally classified as a Significant Social Media Intermediary providing messaging and receives the kind of qualifying judicial or section 69 order described by law. No such request should be made where less intrusive means are effective. Compliance must not require disclosure of message content, unrelated Users or information beyond the lawful scope.
If the obligation becomes applicable, RABC will require the qualifying judicial or section 69 process, legally permitted grounds and the conclusion that less intrusive means are ineffective. RABC may seek clarification or challenge a defective or excessive request. Nothing in this clause represents that RABC presently has SSMI status or promises a capability before the legal condition applies.
5.14 User notice
RABC may notify the affected User before or after disclosure unless prohibited by law, a valid confidentiality direction, risk to life or safety, risk of evidence destruction, or prejudice to an investigation. RABC may later notify when the restriction ends where lawful and practical.
5.15 Cost, format and authenticity
RABC may provide records in a reasonably secure electronic format with available business-record authentication. RABC may seek reimbursement of legally recoverable exceptional costs for technically burdensome production. RABC does not provide expert interpretation of records unless separately required and arranged.
5.16 No informal access
RABC does not provide authorities with direct, standing or bulk access to user databases, private keys or plaintext E2EE messages. Employees and contractors must not disclose information through personal relationships, unofficial chat, telephone pressure or a request that has not passed the verification process.
5.17 Data minimisation and protection of unrelated persons
RABC will disclose only information responsive to a valid request, within its possession or control, and legally permitted or required to be disclosed. RABC may narrow the period or identifiers, redact unrelated information, separate records, protect third-party privacy and refuse a demand for bulk or standing access. Disclosure of one Account does not authorise disclosure concerning unrelated Users.
5.18 Request records and evidence integrity
RABC may record receipt, verification, scope, legal basis, reviewer, decision, preservation action, information produced, secure delivery and completion time for each request. Preserved evidence will be protected against unauthorised alteration through appropriate access controls, hashes or equivalent integrity measures where available. A preservation request maintains information; it does not by itself authorise disclosure.
5.19 Transparency reporting
Subject to confidentiality, security and Applicable Law, RABC may publish aggregate transparency or compliance information about grievances, authority requests, preservation, Content actions, appeals, child-safety actions and Account restrictions. A public report will not identify a User, victim, officer or investigation unless disclosure is lawfully permitted and appropriate.
5.20 Contact and legal reservation
Questions and legal process must use law.enforcement@rabcorp.co.in. General corporate legal correspondence may use compliance@rabcorp.co.in. RABC reserves every lawful objection, privilege and right to seek clarification, narrow a request or challenge it before a competent forum.