home Home category Solutions
add_business
article Blog
arrow_back Home

Government requests

Procedure for handling requests to disclose user data — EzguSavdo service (EZGUPRO LLC)

history_edu Redaction of 30 July 2026.

This is a translation provided for convenience. The legally binding redaction is the Russian one, published at ezgusavdo.uz/ru/legal/government-requests. In case of any discrepancy, the Russian text prevails.

This Procedure sets out how EZGUPRO LLC (the “Operator”) handles requests from government authorities to disclose data of EzguSavdo users, including data the Operator receives from partner platforms (among them Meta Platforms, Inc.) in the course of operating messaging channels.

The Procedure is published openly so that users and partners can verify that the Operator has an established process in place.


1. General principles

1.1. The Operator does not give government authorities direct, automated or unsupervised access to user data. No technical means for such access are built into or maintained in the Service’s infrastructure.

1.2. Disclosure is possible only pursuant to a properly issued request, limited to the scope expressly provided for by law, and only after the process described in sections 2–5 has been completed.

1.3. The Operator’s chief executive is responsible for handling requests. No other employee may disclose user data to a government authority on their own initiative; any request received must be forwarded to the responsible person without delay.

1.4. This Procedure applies to requests from any authority, regardless of jurisdiction.

2. Mandatory legality review

2.1. Every request received is subject to a mandatory review before any action is taken on the data. The review covers:

  • whether the authority is empowered to demand the data requested;
  • proper form: the authority’s identifying details, the signature of an authorised officer, a date and a reference number;
  • a stated legal basis citing a specific provision of law;
  • relevance: whether the data requested matches the stated basis and subject matter;
  • specificity: whether the request identifies particular data subjects and a period, rather than demanding data on an open-ended group of people.

2.2. A request that fails the review on any one of these points is not executed. The Operator issues a reasoned refusal or a request for clarification.

2.3. The review is carried out before any data is disclosed. Urgency asserted in the request is not a ground for skipping it.

3. Challenging unlawful requests

3.1. Where the review finds a request unlawful, excessive in scope, or outside the authority’s powers, the Operator refuses to execute it and states its reasons.

3.2. The Operator may challenge such a request by the means available under the law, including before a court and before the competent personal data protection authority.

3.3. Where necessary, the Operator engages external legal counsel before responding.

3.4. The Operator does not execute a request while it is being challenged, unless execution is ordered by a court decision that has entered into force.

4. Minimising the scope disclosed

4.1. Only the minimum data necessary and expressly covered by the request’s legal basis is disclosed. Requests are not read expansively.

4.2. Where a request can be satisfied with anonymised, aggregated or partially redacted data, the Operator chooses that route.

4.3. Data outside the subject matter of the request is not disclosed, even where it technically resides in the same dataset. Data belonging to other users and to other tenants of the platform is excluded from any export.

4.4. The content of conversations is disclosed only where the request’s legal basis refers to it directly and explicitly.

5. Record keeping

5.1. The Operator maintains a register of government requests. For each request the following is recorded:

  • the date received and the means of receipt;
  • the authority that issued it and its identifying details;
  • the legal basis asserted;
  • the data subjects whose data was demanded and the period requested;
  • the outcome of the legality review and its reasoning;
  • the decision taken: execute, refuse, seek clarification, or challenge;
  • the scope actually disclosed and the date of response;
  • the person who took the decision.

5.2. Register entries are retained for no less than five years from the date of response.

5.3. The register is an internal document and is not published. It is made available to the competent personal data protection authority on demand, and to auditors and partner platforms to the extent needed to confirm compliance with this Procedure.

6. Notifying users

6.1. The Operator notifies the user that their data has been disclosed, unless such notification is prohibited by law or by an express direction of the authority.

6.2. Where notification is prohibited for a set period, the Operator sends it once that period expires.

7. Changes to this Procedure

7.1. The current redaction is published on this page together with its redaction date.

7.2. This Procedure is an internal document of the Operator. It creates no rights for government authorities beyond those provided by law, and no obligations for users that would limit the rights granted to them under the Privacy Policy.

8. Contact

EZGUPRO LLC Email: i@ezgupro.uz, i@ezgusavdo.uz

Government requests should be sent in writing to the addresses above, marked “Data disclosure request”.