6membership6membershipA 6clement Joshua service™Legal & Trust Center
Authority Requests · Legal document

Law-Enforcement, Regulatory and Government Requests Policy

Detailed terms governing applications, membership relationships, payment review, benefits, conduct, verification and status.

Version 0.9-draftUpdated 6 August 202620 sections142 detailed clauses
Statusdraft
Effective dateNot yet effective
Change typeinitial publication
ReacceptanceNot required yet
Before you continue

Understanding this document

This Law-Enforcement, Regulatory and Government Requests Policy explains how 6membership receives, authenticates, reviews, preserves, challenges, fulfils and records requests from courts, law-enforcement agencies, regulators, tax authorities and other competent public bodies.

It establishes safeguards intended to ensure that personal information, application records, payment information, membership records, identity evidence, security logs and other protected material are not disclosed merely because a requester uses an official title or government email address.

6membership is a membership service operated under its registered parent company, 6Clement Joshua, under the laws of the Federal Republic of Nigeria, with mandatory privacy, constitutional, criminal-procedure, regulatory, consumer and statutory rights preserved where they apply.

6membership will cooperate with valid and binding legal obligations while assessing the identity, authority, jurisdiction, scope, specificity and authenticity of each request. Where personal data is involved, the review also considers necessity, proportionality, minimum required disclosure, less-intrusive alternatives and applicable data-subject safeguards.

A request must be limited to information that 6membership actually controls or can retrieve lawfully. 6membership does not guarantee that every requested record exists, remains within its retention period or is technically recoverable.

A preservation request is different from a disclosure request. Preserving identified records does not by itself authorise disclosure of those records.

6membership does not provide standing, unrestricted or direct government access to its production database, administrative console, storage, accounts, encryption material, payment credentials or internal systems.

Nothing in this Policy authorises concealment, destruction or alteration of records after a valid preservation duty, legal hold, court order or other binding obligation applies.

An official-looking message is not automatically a valid request

6membership will verify the requester, legal authority, jurisdiction, affected records and required process before disclosing protected information. Informal telephone calls, social-media messages, personal email accounts and unsupported demands do not automatically authorise disclosure.

Scope

Who these Terms apply to

01

Courts and judicial officers issuing legally binding orders.

02

Nigerian law-enforcement agencies acting within lawful authority.

03

The Nigeria Data Protection Commission and other competent regulators.

04

Consumer, tax, financial, sanctions and public authorities acting within jurisdiction.

05

Foreign authorities seeking information held in connection with Nigeria.

06

Applicants, guardians, payers and members whose information may be requested.

07

Administrators receiving or processing an authority request.

08

Service providers storing or processing information for 6membership.

09

Legal advisers and authorised representatives supporting request review.

10

Persons seeking information through civil proceedings or other formal legal processes.

Jump toDocument sections
1

Purpose and governing principles

The principles used to balance lawful cooperation, privacy and procedural fairness.

1.1

Lawful cooperation

6membership will comply with a valid and binding legal obligation applicable to 6Clement Joshua, the 6membership service, the relevant records and the circumstances.

Cooperation must remain connected with the authority and purpose stated in the request.

1.2

Privacy remains the starting point

Application, membership, identity, guardian, payment, complaint and security information is treated as protected information unless a lawful basis permits or requires disclosure.

The existence of a government investigation does not make every record public or remove applicable privacy safeguards.

1.3

Necessity

A disclosure should be reasonably necessary for the lawful purpose identified by the requesting authority.

Information unrelated to the identified person, event, offence, transaction, proceeding or regulatory matter should not be disclosed merely because it is technically available.

1.4

Proportionality

The scope and sensitivity of the disclosure should remain proportionate to the legal authority, seriousness of the matter, affected rights and information requested.

A request for one verified transaction should not ordinarily result in disclosure of an applicant’s complete identity-document history.

1.5

Data minimisation

6membership should disclose only the categories, fields and period necessary to satisfy the valid request.

Where a smaller record can satisfy the legal obligation, a larger collection should not be supplied.

1.6

Accountability

Material preservation and disclosure decisions should be recorded with the request, reviewer, legal basis, scope, action, date and transmission result.

An administrator must not make an unrecorded disclosure through a personal email account or messaging service.

1.7

Related policies

The Privacy Notice governs ordinary personal-information processing.

The Security Policy governs secure access and transmission.

The Retention Policy governs legal holds and preservation periods.

Related documents
Privacy and Data Protection NoticeSecurity, Account Access and Incident Response PolicyData Retention, Deletion and Records Policy
2

Authorities and processes covered

The public bodies and formal legal processes addressed by this Policy.

2.1

Courts and tribunals

This Policy applies to valid orders, warrants, summonses, subpoenas, production orders, preservation orders and other binding processes issued by a court or tribunal with appropriate jurisdiction.

The exact terminology and effect depend on the applicable law and proceeding.

2.2

Law-enforcement agencies

This Policy applies to requests from Nigerian police, cybercrime, anti-fraud and other law-enforcement bodies acting within powers granted by law.

The agency name alone does not establish that the individual officer or requested action is authorised.

2.3

Regulators

This Policy applies to lawful requests from the Nigeria Data Protection Commission, consumer authorities and other competent regulators responsible for matters affecting 6membership.

2.4

Financial and tax authorities

This Policy applies to valid tax, payment, financial-crime, sanctions, accounting and transaction-related requests issued under applicable authority.

A request for financial records must remain limited to the relevant legal or regulatory purpose.

2.5

Other government bodies

A ministry, department, agency, commission or other government body may submit a request where it possesses legal authority over the subject matter.

A general public function does not automatically authorise access to private membership records.

2.6

Foreign authorities

A foreign authority request is assessed under the cross-border provisions of this Policy.

A foreign official’s direct email is not automatically binding on a Nigerian operator.

2.7

Private parties using legal process

A private person, company, lawyer or litigant may seek information through a valid civil, criminal or regulatory process.

A private demand letter or allegation does not by itself create authority to disclose another person’s protected information.

3

Requests and actions covered

The legal and operational actions that may arise from an authority request.

3.1

Preservation requests

A preservation request asks 6membership to prevent specified records from being deleted or altered while lawful process is obtained or an investigation continues.

Preservation alone does not authorise disclosure.

3.2

Production and disclosure

A production or disclosure request seeks identified records or information.

6membership will determine whether the process is valid, binding and sufficiently specific before producing protected information.

3.3

Testimony and certification

A request may seek testimony, a records certification, an affidavit or confirmation concerning how identified records are maintained.

6membership may require appropriate notice, legal process and reasonable preparation time.

3.4

Restriction or disabling requests

An authority may seek restriction of an account, application, membership, card, certificate, verification record or communication route.

The request must identify the legal authority and affected resource sufficiently.

3.5

Notification and information requests

A regulator may request information about compliance controls, incidents, policies, providers, audits or responses to affected persons.

6membership may provide explanatory or aggregate information where the request does not require individual records.

3.6

Inspection and audit requests

A competent authority may seek inspection of relevant records, controls or evidence within its legal mandate.

Inspection access should be supervised, documented and limited to the authorised scope.

3.7

Emergency requests

A request alleging imminent danger, serious physical harm, child exploitation or another urgent threat may receive accelerated review.

Urgency does not remove the requirement for authenticity, lawful authority and necessity.

4

Requests that do not automatically authorise disclosure

Informal, unsupported or private demands requiring additional legal authority.

4.1

Telephone demands

An unsolicited telephone call claiming to be from an authority does not automatically authorise disclosure.

The caller may be directed to submit the request through an authenticated written channel.

4.2

Personal email accounts

A request sent from an unrelated personal email account will not ordinarily be treated as authenticated official process.

The requester may be required to use a verifiable agency, court or professional channel.

4.3

Social-media messages

A direct message, public comment or social-media post is not an appropriate channel for requesting private applicant or member information.

4.4

Unsupported consent claims

A requester’s statement that the affected person agreed does not automatically establish valid consent or authority.

Where disclosure relies on the person’s authorisation, 6membership may require a verifiable written instruction and identity confirmation.

4.5

Private investigators and employers

Private investigators, employers, landlords, lenders and other private persons do not receive government authority merely because they are investigating a matter.

They must provide an appropriate lawful basis, consent or valid legal process.

4.6

Media enquiries

A journalist or media organisation may request public information or comment but is not entitled automatically to private application, identity, payment or membership records.

4.7

Political or unofficial influence

A request must not be granted merely because it is supported by a politically influential person, public official, donor, member or associate.

The same legal review standards apply regardless of status or personal relationship.

5

Submission, service and request channels

The authorised routes for delivering and managing formal requests.

5.1

Electronic intake

Electronic authority requests may be submitted to legal@6membership.com unless a different legally required method applies.

Security incidents and urgent technical concerns may also be copied to security@6membership.com.

5.2

Formal service of process

The availability of an email address does not mean that every court document may be served validly by email.

A requester remains responsible for complying with applicable procedural and service requirements.

5.3

Complete and readable request

The request should include a complete, readable copy of the instrument, supporting authority and any referenced schedule defining the records sought.

An incomplete screenshot or cropped page may be insufficient.

5.4

Official contact information

The request should identify the issuing body, responsible officer, official position, agency address, official email, telephone number and reference number.

5.5

Secure delivery

Sensitive orders and produced records should use a secure transmission method appropriate to their content.

A requester may be asked to provide an approved secure exchange route rather than ordinary unencrypted email.

5.6

Acknowledgement

6membership may acknowledge receipt and assign an internal Authority Request Reference.

Acknowledgement does not confirm validity, compliance or the existence of responsive records.

5.7

No use of ordinary user forms

Application, privacy-request, complaint and general-contact forms should not be used to transmit sealed warrants, confidential orders or sensitive authority material unless the form expressly supports that function.

6

Requester identity and authenticity verification

Controls used to confirm that the requester and instrument are genuine.

6.1

Agency verification

6membership may verify the requesting body through an official directory, published contact channel, known provider route or independently obtained contact information.

Contact details supplied only inside the disputed request should not be the sole verification method where fraud is suspected.

6.2

Officer or official verification

The identity, position and authority of the named requester may be verified before information is disclosed.

An official email address supports verification but may not be sufficient where compromise or impersonation is suspected.

6.3

Document authenticity

6membership may examine signatures, stamps, seals, reference numbers, issuing court, dates, schedules and other indicators of authenticity.

The service may contact the issuing office independently where confirmation is required.

6.4

Electronic signatures and records

An electronically issued instrument may be accepted where its authenticity, issuing authority and legal validity can be established.

A pasted image of a signature does not prove validity by itself.

6.5

Suspected impersonation

A suspected fake authority request may be restricted, preserved as evidence and reported through appropriate security or lawful channels.

No protected record should be disclosed while authenticity remains materially unresolved.

6.6

Reconfirmation

6membership may reconfirm an unusual, high-volume, highly sensitive or technically intrusive request even where the requester was authenticated previously.

6.7

Verification record

The method and result of requester verification should be recorded without copying unnecessary official identity information.

Related documents
Brand, Intellectual Property and Anti-Impersonation PolicySecurity, Account Access and Incident Response Policy
7

Legal authority and jurisdiction

Assessment of whether the requester can lawfully compel the requested action.

7.1

Identified legal basis

A compulsory request should identify the written law, court power, regulatory mandate or other authority supporting the requested action.

A general statement that the information is needed for investigation may be insufficient where formal process is required.

7.2

Authority over the subject matter

The requesting body must possess authority concerning the offence, proceeding, regulatory function, tax matter, consumer issue or other stated subject.

7.3

Authority over the operator or records

The process must be capable of binding 6Clement Joshua, the 6membership service or the relevant record holder under applicable law.

A body’s authority over another company or country does not automatically extend to 6Clement Joshua, 6membership or records outside the body’s lawful reach.

7.4

Court jurisdiction

A court order should come from a court with jurisdiction over the proceeding, person, operator, records or legally relevant connection.

6membership may seek legal clarification where jurisdiction is uncertain.

7.5

Effective dates and expiry

The request must remain effective at the time action is taken.

An expired, withdrawn, stayed, set-aside or superseded process should not be relied upon as current authority.

7.6

Conflicting obligations

Where a request conflicts with another law, order, privacy requirement, privilege or binding restriction, 6membership may seek clarification, narrowing or judicial direction.

7.7

Voluntary cooperation

Where compliance is not compulsory, any voluntary disclosure must still have a lawful basis, legitimate purpose, necessary and proportionate scope and appropriate safeguards.

Voluntary cooperation must not be used to bypass a legal process that would ordinarily be required, and personal-data disclosure must remain limited to what the applicable lawful basis actually permits.

7.8

Data-protection and legal review

Where a request involves personal data or creates a material privacy risk, 6membership may obtain documented review from its authorised privacy, data-protection or legal function before disclosure.

The review may address the legal competence of the requesting authority, the protection measures available, the scope of the order or directive, applicable data-subject rights, necessity, proportionality and whether a less intrusive method can satisfy the lawful purpose.

Where appropriate under Nigerian data-protection law, a documented DPO opinion may form part of that assessment. This internal review does not authorise disobedience of a finally binding court order.

8

Specificity and scope requirements

The identifiers, dates and categories needed to locate responsive records.

8.1

Identifying the person

The request should identify the relevant person through sufficient and lawful information, such as name, verified email, Application Reference or Membership ID.

A common name alone may be insufficient where it could identify several people.

8.2

Identifying the records

The request should describe the record categories sought, such as application status, payment record, policy acceptance, membership status or security event.

A demand for all information must explain why that breadth is authorised and necessary.

8.3

Relevant date range

The request should identify an appropriate date or event range where the matter does not require the complete history.

6membership may ask the requester to narrow an unlimited period.

8.4

Connection to the stated purpose

The requested records should have a reasonable connection with the investigation, proceeding, regulatory function or other lawful purpose.

8.5

Unrelated third parties

Information belonging to unrelated applicants, household members, guardians, payers or administrators should be excluded or redacted unless the legal process covers them.

8.6

Sensitive information

Requests for identity documents, younger-person records, security credentials, private photographs or detailed payment information require particularly clear authority and necessity.

8.7

No obligation to invent records

6membership may produce existing responsive records or provide an appropriate explanation of its systems.

The service does not create a false record, rewrite history or state facts not supported by the retained evidence.

9

Preservation requests and legal holds

Temporary protection of identified records from ordinary deletion.

9.1

Preservation is not disclosure

A preservation request may suspend ordinary deletion of identified records.

The preserved information remains protected and is not disclosed until separate lawful authority permits or requires disclosure.

9.2

Defined scope

The preservation request should identify the person, record categories, relevant period and legal authority.

6membership may seek clarification where the scope would preserve unrelated systems or records.

9.3

Duration

A preservation action remains effective only for the period stated by the applicable law or instrument, or for the justified period of a documented legal hold.

A legal hold should identify its scope, reason, responsible person, review date and release condition. It should be reviewed and released when the lawful basis or evidential need ends rather than remaining open indefinitely.

9.4

Existing records

Preservation applies to responsive records within 6membership’s possession or control when the duty is received.

It does not guarantee recovery of information already deleted lawfully before the request arrived.

9.5

Future records

A request to preserve future or continuously generated information requires clear legal authority and technical scope.

An ordinary preservation request should not be interpreted automatically as authority for continuous surveillance.

9.6

Security of preserved material

Preserved records remain subject to restricted access, integrity controls and confidentiality.

The hold must not make the records accessible to ordinary administrators who did not previously require them.

9.7

Hold audit trail

Creation, modification, review, responsible person, scope, reason, release and resulting deletion of a material hold should be recorded.

Related documents
Data Retention, Deletion and Records Policy
10

Production and disclosure of records

How responsive information is selected, reviewed and produced.

10.1

Responsive records

6membership will identify records reasonably responsive to the valid request.

Records outside the authorised scope should be excluded.

10.2

Pre-production review

Before disclosure, responsive material should be reviewed for scope, third-party information, privilege, security risk, technical secrets and legal restrictions.

10.3

Redaction

Information outside the authorised scope may be redacted where redaction permits lawful production of the remaining record.

A redaction should not alter the meaning of the produced information deceptively.

10.4

Production format

Records may be produced in a reasonably accessible electronic format supported by the production system.

6membership is not required to expose live database access merely because records are stored electronically.

10.5

Certification and explanation

Where authorised and appropriate, 6membership may certify that produced records were extracted from identified systems or explain relevant field meanings.

Certification must not claim certainty beyond what the records support.

10.6

Credentials and secrets

Passwords, secret keys, reusable tokens and protected provider credentials should not be produced as ordinary account records.

Where a court specifically addresses security material, 6membership may seek protective conditions or legal clarification.

10.7

Completion record

The production record should identify what was disclosed, when, by whom, under which authority and through which secure channel.

11

Emergency and serious-harm requests

Accelerated assessment where delay may expose a person to grave harm.

11.1

Emergency threshold

Emergency treatment may apply where the requester describes a credible and imminent risk of death, serious physical harm, child exploitation, abduction or another grave emergency.

General urgency or administrative convenience does not satisfy this threshold.

11.2

Required details

The request should identify the threatened person, nature of the emergency, connection to the requested records, information needed and reason ordinary legal process cannot be obtained in time.

11.3

Rapid authentication

6membership may use expedited methods to verify the requesting agency and officer.

Accelerated review must not become unauthenticated disclosure.

11.4

Limited emergency disclosure

Where lawful disclosure is justified, only the information reasonably necessary to address the emergency should be supplied.

Where disclosure is not compelled by a binding instrument, personal-data processing must still rest on an applicable lawful basis. In an appropriate emergency this may include vital interests or public interest where the legal conditions are satisfied, and the processing must remain necessary and proportionate.

The emergency does not create authority for unrelated historical or commercial information.

11.5

Follow-up process

6membership may require the requester to provide confirming legal process or written documentation after an urgent disclosure where applicable.

11.6

Affected-person notice

Notice to the affected person may be delayed where immediate disclosure would worsen the danger, compromise the response or violate law.

The notice position should be reviewed when the emergency ends.

11.7

Emergency decision record

The emergency request, verification, decision, information disclosed and responsible reviewer should be recorded promptly.

12

Court orders, warrants and compulsory process

Review and execution of judicially authorised requests.

12.1

Complete instrument

A court process should include the issuing court, case or proceeding reference, date, authorised signature or authentication, affected person and required action.

12.2

Scope and command

The instrument should state clearly whether it requires preservation, production, testimony, restriction, non-disclosure or another action.

6membership should not infer a broader command than the document supports.

12.3

Compliance period

6membership will identify the stated compliance date and any procedure for seeking clarification, extension, variation or review.

A technically or legally impossible deadline may be raised with the issuing authority.

12.4

Sealed and confidential process

A sealed order or valid confidentiality restriction will be handled through restricted access.

Its existence and contents must not be disclosed contrary to the applicable order or law.

12.5

Clarification and challenge

6membership may seek clarification, narrowing, protective conditions, variation or lawful review where an instrument is ambiguous, overbroad, technically unsafe or jurisdictionally defective.

12.6

No obstruction

A good-faith legal challenge or request for clarification must not become concealment, alteration or destruction of responsive records.

12.7

Documented compliance

Final compliance should be documented against the specific command and records produced.

13

Regulatory, privacy and consumer requests

Cooperation with competent regulators exercising supervisory authority.

13.1

Regulatory mandate

A regulator request should identify the matter, statutory or regulatory mandate and information required for the regulator’s function.

13.2

Nigeria Data Protection Commission

6membership may provide records, explanations, assessments and evidence required lawfully by the Nigeria Data Protection Commission.

The response should remain accurate and should not conceal a known breach, complaint or processing activity.

13.3

Consumer authorities

A competent consumer authority may request records relating to disclosures, pricing, applications, payments, refunds, communications or complaint handling.

Another person’s private information should be limited where it is not necessary to resolve the consumer matter.

13.4

Audits and assessments

A regulator may request policies, audit records, risk assessments, provider details or evidence of corrective action.

Confidential technical material may require secure handling or protective arrangements.

13.5

Corrective requirements

Where a competent regulator issues a binding corrective requirement, 6membership will record, assign and track the required action.

The service must distinguish a recommendation from a legally binding direction.

13.6

Complaints referred by regulators

A regulator may refer or investigate a complaint submitted by an applicant, member, payer or other affected person.

The complainant must not be subjected to retaliation merely for using the regulatory process.

13.7

Accurate regulatory response

A regulatory response should distinguish verified facts, current implementation, planned work, unresolved issues and reasonable inference.

An intended future control must not be represented as already active.

14

Payment, tax and financial-crime requests

Special handling of transactions, refunds, payer information and financial evidence.

14.1

Available financial records

Responsive records may include an internal transaction reference, Flutterwave transaction identifier, amount, currency, verified status, payer relationship, refund record and associated application.

6membership ordinarily does not control complete card credentials processed by the payment provider.

14.2

Provider-held payment information

Some payment records may be held directly by Flutterwave, banks, card networks or other financial institutions.

6membership may identify the relevant provider where appropriate but cannot guarantee that it can obtain records outside its possession or control.

14.3

Tax and accounting requests

Valid tax and accounting requests may cover invoices, receipts, payment status, refunds and related financial records.

Identity documents unrelated to the financial requirement should not be included automatically.

14.4

Fraud and suspicious transactions

A competent authority may seek records connected with stolen payment methods, false identities, duplicate refunds, chargeback abuse or other suspected financial misconduct.

14.5

Sanctions and financial restrictions

Where applicable law requires restriction, reporting or disclosure connected with sanctions or financial-crime controls, 6membership will assess and document the obligation.

14.6

Refund status

A record must distinguish internal refund approval, submission to Flutterwave, provider acceptance, processing and final result.

The authority response must not describe an unsubmitted or rejected refund as completed.

14.7

Related payment controls

Payment and financial-compliance rules are governed further by the payment and anti-fraud policies.

Related documents
Payments, Taxes, Refunds, Chargebacks and Renewals PolicyAnti-Fraud, Anti-Money-Laundering, Sanctions and Source-of-Funds Policy
15

Foreign and cross-border authority requests

Assessment of requests originating outside Nigeria.

15.1

No automatic binding force

A request from a foreign authority does not automatically bind 6Clement Joshua or the 6membership service merely because it is valid under the foreign authority’s domestic law.

15.2

Applicable Nigerian process

A foreign requester may be required to use an applicable Nigerian court, authority, mutual-assistance, recognition or other lawful process.

The required route depends on the request and applicable law.

15.3

Voluntary cross-border disclosure

Any non-compulsory disclosure to a foreign authority must have a lawful basis, legitimate purpose and appropriate privacy and cross-border transfer safeguards under applicable Nigerian data-protection law.

Where personal data is transferred outside Nigeria, the transfer must satisfy the applicable cross-border transfer framework or a recognised special circumstance, such as a compelling legal duty, legal claim, qualifying vital interest or public interest where its conditions are met.

Voluntary disclosure must not be used to avoid protections that would apply through formal legal process.

15.4

Foreign emergencies

A credible foreign emergency request involving imminent serious harm may receive accelerated review.

The requester, emergency, lawful basis and minimum necessary information must still be verified.

15.5

Conflicting laws

Where a foreign request conflicts with Nigerian law, another binding obligation or affected-person rights, 6membership may seek legal advice, narrowing or appropriate judicial direction.

15.6

Secure international transfer

An authorised cross-border production must use appropriate technical and organisational safeguards for the information involved.

15.7

Foreign service providers

A service provider may receive a request directly under laws applying to that provider.

6membership may not be notified where the provider is legally prohibited from doing so.

16

Affected-person notice and confidentiality

When applicants or members may be told about a request.

16.1

Notice where lawful

Where lawful, appropriate and not prohibited, 6membership may notify an affected person before or after disclosing their information.

Notice may allow the person to seek legal advice or exercise an available right.

16.2

Legally prohibited notice

Notice will not be provided where a valid law, court order or binding confidentiality requirement prohibits it.

16.3

Risk-based delay

Notice may be delayed where it would create an imminent safety risk, facilitate destruction of evidence, compromise an investigation or expose another person unlawfully.

The reason for delay should be documented.

16.4

Review of non-disclosure

A temporary non-disclosure position should be reviewed when the stated restriction or risk ends.

6membership may seek permission to notify the person where appropriate.

16.5

Notice content

A notice may identify the requesting authority, general record categories, date and available contact or complaint route.

Details may be limited where fuller disclosure remains prohibited or unsafe.

16.6

No interference

An affected person must not use notice to alter, destroy or conceal lawfully preserved records.

The person retains the right to seek lawful review or advice.

16.7

Aggregate transparency

Where lawful and operationally appropriate, 6membership may publish aggregate information about authority requests without identifying affected persons or exposing investigations.

17

Clarification, challenge, refusal and narrowing

Circumstances in which 6membership may seek correction or decline disclosure.

17.1

Invalid or unauthenticated request

6membership may refuse or pause a request that cannot be authenticated or that lacks required legal authority.

17.2

Overbroad request

6membership may ask the requester to narrow a request that seeks unrelated people, unlimited time periods, entire databases or information disconnected from the stated matter.

17.3

Ambiguous request

A request may be paused while unclear identifiers, record categories, dates, technical terms or required actions are clarified.

17.4

Impossible or unavailable records

6membership may explain that specified records do not exist, were never collected, were deleted lawfully or are not within its possession or control.

The service must not fabricate responsive records.

17.5

Disproportionate rights impact

Where permitted, 6membership may seek narrowing or protective conditions where the request creates a disproportionate privacy, confidentiality, security or third-party-rights impact.

17.6

Legal privilege and protected material

Confidential legal advice, privileged communications and other protected material may be withheld or addressed through an appropriate legal process where applicable.

Privilege must not be asserted falsely to conceal ordinary business records or misconduct.

17.7

No unlawful defiance

Where a request is finally determined to be valid and binding, 6membership will comply according to its lawful terms.

Clarification or challenge must not be used to destroy evidence or evade a binding obligation.

18

Security, transmission and chain of custody

Controls protecting requested records during collection and disclosure.

18.1

Restricted reviewer access

Authority requests should be accessible only to authorised legal, privacy, security and administrative personnel whose role requires them.

18.2

Controlled export

Responsive records should be exported through a controlled server or administrative process.

An administrator should not copy entire production tables where a limited export satisfies the request.

18.3

Record integrity

Produced records should preserve relevant timestamps, identifiers and context without deceptive alteration.

Where a record is converted or redacted, the production process should be documented.

18.4

Secure transmission

Sensitive production should use encrypted or otherwise appropriately protected transmission.

Access links should be purpose-limited, expire where practical and be delivered to a verified recipient.

18.5

Recipient confirmation

6membership may request confirmation that the authorised recipient received or accessed the production.

Receipt does not determine how the authority may use the information under its own legal obligations.

18.6

Production-copy retention

A protected copy or production manifest may be retained while reasonably required for accountability, dispute resolution, an active legal hold, a legal claim or proof of compliance.

Temporary working exports should be deleted when they are no longer required. Retaining a production copy for possible future usefulness is not by itself a sufficient reason for indefinite storage.

18.7

Misdelivery or exposure

A production sent to an unauthorised recipient, exposed through an insecure link or otherwise compromised must be assessed as a security incident and possible personal-data breach.

Related documents
Security, Account Access and Incident Response Policy
19

Service providers, records and transparency

Provider-held information, internal audit records and aggregate reporting.

19.1

Direct requests to providers

A provider may receive a request directly concerning information held within its service.

The provider’s response is governed by applicable law, its role and its own authority-request process.

19.2

Provider notification to 6membership

Where permitted, 6membership may request that a provider notify it before disclosing information connected with the service.

A provider may be prohibited from giving notice.

19.3

No unrestricted provider access

A provider relationship does not authorise every provider employee to access or disclose 6membership information.

Provider access should remain limited to authorised operational and legal purposes.

19.4

Authority-request case record

The internal case record may include the Authority Request Reference, requester, legal instrument, verification, affected systems, legal basis, scope, decisions, disclosure manifest and communications.

19.5

Retention

Authority-request, preservation and disclosure records may be retained while the request, preservation duty, legal hold, compliance dispute or another applicable time-bound legal requirement remains active.

For Nigerian personal-data processing, when the original purpose has been accomplished and no separate law provides a time-bound retention obligation, continued storage must follow the post-purpose limits and safeguards in the Data Retention, Deletion and Records Policy, including the applicable six-calendar-month rule. Retention for the defence of a legal claim or due diligence must use appropriate technical and organisational safeguards.

Unnecessary duplicate exports should be deleted sooner, and every continuing legal hold should remain scoped, documented and periodically reviewed.

Related documents
Data Retention, Deletion and Records Policy
19.6

Transparency reporting

6membership may publish aggregate counts or categories of requests where reporting is lawful, accurate and does not expose protected investigations or individuals.

A zero figure must not be published unless the underlying records support it.

19.7

Provider transparency

The approved provider list explains the principal service categories that may hold or process relevant information.

Related documents
Third-Party Service Providers List
20

Contacts, complaints and policy updates

Official channels for requests, affected-person concerns and future changes.

20.1

Authority-request contact

Courts, law-enforcement agencies, regulators and other competent authorities may submit formal requests to legal@6membership.com.

The requester remains responsible for satisfying any separate formal-service requirement.

20.2

Urgent security contact

Urgent phishing, impersonation, exposed credentials, cybercrime and active security incidents may also be reported to security@6membership.com.

20.3

Affected-person privacy concerns

An applicant, member, guardian, payer or other person may raise a concern about authority-related processing through privacy@6membership.com.

20.4

Internal complaint

A person may complain about an inaccurate disclosure, excessive scope, failure to provide lawful notice, improper retention or another authority-request handling issue.

6membership may be unable to disclose a sealed request or legally restricted information while the restriction applies.

20.5

External rights

Nothing in this Policy prevents an affected person from contacting a competent court, the Nigeria Data Protection Commission, a consumer authority or another appropriate body where that right applies.

20.6

No obstruction or retaliation

A complaint or legal challenge must not be used to destroy preserved evidence or obstruct a binding process.

A person must not face retaliation merely for raising a genuine privacy or procedural concern.

20.7

Operational review

This Policy should be reviewed against actual request types, legal developments, provider arrangements, security controls and production capabilities.

20.8

Material policy updates

This Policy may be updated to reflect new laws, court processes, regulators, service providers, technical systems, reporting obligations and cross-border procedures.

A material update will be handled through the central policy-update framework.

Related documents
Complaints, Appeals and Dispute Resolution PolicyPolicy Updates, Effective Dates and Change Log
Cross-reference

Related policies

Membership Terms and Conditions

The underlying application and membership relationship.

Privacy and Data Protection Notice

Lawful processing, disclosure and transparency requirements.

Country-Specific Privacy Rights Addendum

Applicable privacy complaints and regulatory rights.

Eligibility, Age and Guardian Consent Policy

Requests involving younger applicants and guardians.

Application, Identity and Photograph Policy

Sensitive identity and photograph records.

Payments, Taxes, Refunds, Chargebacks and Renewals Policy

Payment, refund and transaction records.

Anti-Fraud, Anti-Money-Laundering, Sanctions and Source-of-Funds Policy

Fraud, sanctions and financial-crime enquiries.

Membership Card, Certificate and Public Verification Policy

Card, certificate and verification records.

Brand, Intellectual Property and Anti-Impersonation Policy

Fake authority communications and counterfeit records.

Acceptable Use, Code of Conduct and Non-Discrimination Policy

Prohibited conduct, cyber abuse and retaliation.

Security, Account Access and Incident Response Policy

Secure collection, review, disclosure and incident response.

Data Retention, Deletion and Records Policy

Preservation, legal holds and authority-request records.

Third-Party Service Providers List

Provider-held records and direct provider requests.

Complaints, Appeals and Dispute Resolution Policy

Challenges concerning disclosures and procedural handling.

Electronic Communications Consent

Electronic requests, notices, signatures and records.

Policy Updates, Effective Dates and Change Log

Future changes to the authority-request framework.

Official channels

Contact points

Formal authority requestslegal@6membership.com

Court orders, warrants, preservation requests, regulatory notices and other formal legal process.

Urgent security requestssecurity@6membership.com

Active cybercrime, phishing, impersonation, exposed credentials and urgent security incidents.

Privacy concernsprivacy@6membership.com

Concerns about disclosure, notice, retention, data minimisation and applicable privacy rights.

Membership administrationadmin@6membership.com

Ordinary membership-status and public-verification enquiries that do not require formal legal process.

6membershipA 6clement Joshua service™

© 2026 6clement Joshua. All rights reserved.