Law Enforcement & Government Data Request Guidelines

Last updated: 24 July 2026

Movari is a UK-based practice-management platform for independent healthcare practitioners. Much of the data on our platform is sensitive medical data, and we protect it accordingly. These guidelines explain how Movari responds to requests from law enforcement agencies, government bodies, and other public authorities for user data. They are written for authorities making such requests and for users who want to understand how their data is protected. They do not create rights for any third party and do not limit any objection or challenge Movari or an affected user may raise.

Our role: controller and processor

Movari operates under UK data protection law (UK GDPR and the Data Protection Act 2018).

  • For information about our own customers (the practitioners who subscribe to Movari) and visitors to our website, Movari is the data controller.
  • For patient and clinical records, and for messages exchanged between a practitioner and the people who contact them via WhatsApp, Instagram, or Messenger, Movari is only a data processor. The practitioner is the controller of that information.

Where a request concerns data for which a practitioner is the controller, our default position is that it should be directed to that practitioner. We will only disclose such data where we are independently compelled to do so by valid legal process and, where lawful, after notifying the practitioner.

Valid legal process is required

We do not disclose user data voluntarily. We require appropriate, valid legal process before disclosing any personal data — such as a court order, warrant, or other instrument issued under the law of England and Wales (or another applicable UK jurisdiction), or a formal request that is valid and enforceable under applicable UK law.

Requests from authorities outside the UK must come through a recognised legal channel, such as a Mutual Legal Assistance Treaty or an applicable international agreement. We do not action informal or voluntary requests for personal data.

How we assess a request

Every request we receive is:

  • Reviewed for legality. We verify that the request is valid, issued under proper legal authority, and correctly served before we take any action.
  • Assessed for scope. We apply data minimisation — disclosing only the specific data we are legally required to provide, and no more. We object to requests that are overbroad, vague, or disproportionate.
  • Challenged where appropriate. Where we consider a request unlawful, overbroad, or otherwise improper, we will seek to narrow or challenge it through the appropriate legal channels before disclosing any data.
  • Documented. We keep a record of each request, our assessment of it, our response, and the legal reasoning and personnel involved.

Notice to affected users

Our default is to notify an affected user (or, for processor data, the relevant practitioner) before disclosing their data, so they have an opportunity to respond — unless we are legally prohibited from doing so, or there is a genuine emergency involving a risk to life or serious harm.

Emergency requests

We may voluntarily disclose limited data to a public authority without legal process where we have a good-faith belief that doing so is necessary to prevent an imminent risk of death or serious physical harm to a person. Emergency requests should clearly explain the emergency and the specific data required.

How to submit a request

Law enforcement and government requests should be made in writing on official letterhead and sent to privacy@movariapp.com. Please include the legal basis for the request, the specific data sought, and a point of contact. We aim to acknowledge valid requests promptly.

These guidelines are provided for transparency and do not constitute legal advice or a waiver of any right or protection available to Movari or its users under applicable law.