The New Black AI

Last updated · September 2026

Requests from Public Authorities for User Data

This policy describes how The New Black Kft. handles requests from public authorities — governments, law enforcement, courts, regulators and intelligence or national security bodies — for the personal data of the people who use The New Black. It applies to every category of personal data we hold, including data received from third-party platforms a user has connected to their account (for example Meta, Google or Shopify).

1. Scope and principles

The New Black Kft. (registration number 01-09-444904, Havas utca 2, 1056 Budapest, Hungary) is the data controller for the personal data of its users. We do not disclose personal data to any public authority voluntarily or on request unless we are legally required to do so, and then only under the conditions set out in this policy.

Every request is handled by the company's management, with external legal counsel where the request is unusual, contested, or comes from an authority outside the European Union.

2. Review of the legality of every request

No personal data is disclosed before the request has been reviewed. For each request we verify that it comes from an authority that is genuinely entitled to make it, that it relies on an identified legal basis under the law applicable to us (Hungarian law and the General Data Protection Regulation, and, where relevant, an applicable international agreement), that it is in writing and properly signed or authenticated, and that it identifies the person and the data concerned with enough precision.

Requests received by e-mail, telephone or through an intermediary are not acted upon until they have been confirmed through an official channel.

3. Challenging unlawful or excessive requests

If a request appears unlawful, unfounded, disproportionate, or too broad, we refuse it and, where appropriate, contest it before the competent court or supervisory authority. Personal data is not disclosed while a challenge is pending, unless a final and enforceable decision orders us to do so.

Where the law allows it, we inform the person concerned that a request has been made about them, before disclosure or as soon as a prohibition on notification is lifted.

4. Data minimisation

When a request is valid and must be honoured, we disclose only the minimum data strictly necessary to answer it: the specific fields, for the specific person, for the specific period the request identifies. We do not hand over whole records, databases or exports, and we do not disclose data received from a connected third-party platform beyond what the request lawfully requires.

5. Register of requests

Every request from a public authority is recorded in a register kept by the company's management, with the date received, the requesting authority and the identity of its representative, the legal basis invoked, the person and the data concerned, our legal analysis, the decision taken and its reasoning, the people involved in handling it, the data disclosed if any, and the date of our response. Requests we refused or challenged are recorded in the same register.

This register is available to the supervisory authority on request and supports the transparency statements we make to the platforms whose data we process.

6. National security requests

As of the date of this policy, The New Black has not received any request from a public authority relating to national security, and has not disclosed any user's personal data in response to such a request. Should this change, this section will be updated and, where the law permits, the number of requests received will be published.

7. Contact

Questions about this policy, and requests from authorities, are to be addressed to team@thenewblack.ai. This policy complements our Privacy Policy and is reviewed at least once a year.