📚 CS Learning Board

Authority Requests

Handling law-enforcement & regulatory requests, legal-process review, disclosure rules, and internal escalation

🏛️
Basic Overview

What are Authority Requests? These are formal requests received from police, government bodies, regulatory agencies, courts, or international bodies (e.g., ICANN, WIPO, RRT, INDECOPI) asking Hostinger to provide customer data, take action on an account/domain, or respond to a legal/compliance inquiry.

As a CS specialist, your role is not to investigate or respond to these requests directly. Your job is to route them correctly and protect customer data until the proper team handles it.

Hostinger operates globally, so authority requests can come from Lithuanian police, Brazilian PROCON, Peruvian INDECOPI, EU regulators (DSA/GDPR), ICANN, WIPO, and many more. Each has a specific handling path.

👮 Police / Law Enforcement Criminal investigations, data requests
🏢 Regulatory Bodies RRT, INDECOPI, PROCON, VVTAT, DSA
⚖️ Court Orders Domain suspensions, data preservation
🌐 ICANN / WIPO / UDRP Domain disputes, arbitration decisions
🔒 GDPR / LGPD Data protection, deletion, DPA requests
📋 Legal Statements Formal confirmations for legal proceedings
🔑
Most Important Things to Remember

🚫 What You Must NEVER Do

Never share customer data with authorities Do not provide any account or user information to the requester, even if they claim to be police or government.
Never share compliance@hostinger.com with customers This email is for internal routing only. Customers should not be given this address directly.
Never create a ticket directly for Compliance Use the Quality inbox → assign to TL. Do not open a ticket addressed to the Compliance team.
Never verify caller identity over phone Even if someone claims to be police on the phone, you cannot verify them. Always ask them to email.
Never disclose that a suspension came from a court order or police Use predefine #abuse-permanent-police-request-insist. Reference ToS only — not the authority source.

✅ What You Must Always Do

Direct police/gov requests to Compliance via email Ask the authority to email compliance@hostinger.com. Use predefine #report-police-government-requests.
Direct GDPR/LGPD requests to gdpr@hostinger.com Use predefine #gdpr-email. GDPR deletion, DPA requests, and data questions all go here.
Escalate legal threats immediately to TL If a customer mentions legal action, ICANN complaints, regulatory complaints, or court proceedings — flag to TL immediately.
During UDRP: freeze the domain Domain must NOT be unlocked, moved, or transferred while a UDRP/ADNDRC proceeding is active.
For urgent legal matters: ping #legal-team-firefighter If the issue is causing active damage and escalating fast, contact the Legal team urgently via Slack.
⚠️
Email backups CAN be shared for law enforcement Email devs can share backups for verified law enforcement requests. Regular customers do not get this unless escalated (e.g., GDPR threat).

📋 Standard Escalation Flow

1
Receive the request

Authority contacts you via chat, email, or phone. Do NOT share any information yet.

2
Identify the request type

Is it police/gov? GDPR? UDRP? Court order? Regulatory inspection? Each has a different path.

3
Route to the correct channel

Police/Gov →   GDPR →   Legal/Urgent →

4
If customer-facing escalation needed

Create hSupport ticket → Quality issue type → Assign to TL. Inform customer using #escalated-TL predefine.

5
Do NOT follow up independently

Once routed, the Compliance or Legal team owns the case. Do not investigate or respond further without their guidance.

🧠
Cases Where Critical Thinking Is Needed

Click each scenario to reveal the correct approach.

🚨 Tricky A caller says they're from the Lithuanian police and needs account info NOW

A person calls and identifies themselves as a Lithuanian police officer. They say it's urgent and demand you provide the account details of a specific customer immediately.

✅ Correct approach: You cannot verify the caller's identity over the phone — even if they sound official. Politely explain that you cannot share any information via phone. Ask them to email support@hostinger.com (or pagalba@hostinger.lt for LT) with their official request. Do NOT share any customer data. The Compliance team will handle the formal request once received in writing.
⚠️ Edge Case Customer's domain was suspended due to a court order — they're demanding to know why

A customer contacts you furious that their domain was suspended. You can see in CRM that the suspension was triggered by a court order. They're demanding a full explanation and threatening to sue.

✅ Correct approach: Do NOT disclose that the suspension came from a court order. Use predefine #abuse-permanent-police-request-insist: explain the decision was made following an abuse report from a higher authority, that you cannot share further details due to confidentiality, and that the decision is final and non-negotiable. Reference ToS only. If they escalate with legal threats, create a Quality ticket and assign to TL.
🔍 Judgment Call A cybersecurity organization (not police) asks for customer account details

An external cybersecurity organization that regularly reports abuse to Hostinger contacts you and asks for specific customer information to help with their investigation. They mention a former Hostinger manager gave them access before.

✅ Correct approach: This is NOT a law enforcement or government entity. Disclosing customer information to them may be legally prohibited. Do NOT share any data. Escalate to verify whether any special rules or exceptions apply. The fact that a former manager may have done this previously does not make it policy. When in doubt, always protect customer data and escalate.
⚡ Urgent UDRP decision received — the losing party is asking you to transfer the domain out

A UDRP proceeding is active on a domain. The losing registrant contacts CS and asks you to unlock the domain and provide the EPP code so they can transfer it to another registrar before the decision is implemented.

✅ Correct approach: Absolutely do NOT unlock, move, or transfer the domain during an active UDRP proceeding. Check CRM for the Compliance note. If the CRM note says "UDRP proceeding – DO NOT UNSUSPEND," follow it strictly. Inform the customer that the domain is under a dispute process and cannot be modified. Escalate to Compliance if the authority is not mentioned on the CRM note.
🌍 Regulatory Lithuanian RRT sends a regulatory inspection request — it lands in the abuse inbox

A ticket arrives from the Lithuanian Communications Regulatory Authority (RRT) about a scheduled inspection under the Digital Services Act (DSA). A previous similar ticket was closed as spam without investigation.

✅ Correct approach: This is a legitimate regulatory authority request — do NOT close as spam. Translate the content if needed, then immediately escalate to the Legal team (forward to legal@hostinger.com or post in the legal-compliance-cases channel). A Jira ticket should be created for Legal to investigate and respond. The prior ticket being closed as spam was an error — flag this pattern so it can be audited.
📄 Legal Statement Customer needs a formal legal statement from Hostinger for court proceedings

A customer is involved in a legal dispute and needs Hostinger to issue a formal written statement confirming that certain emails were inbound (not sent by Hostinger). They've been waiting over a month and are threatening to cancel.

✅ Correct approach: CS cannot issue formal legal statements independently. Do NOT share compliance@hostinger.com with the customer. Instead, escalate via a Quality ticket to TL, who will coordinate with the Compliance team. The Compliance team will draft and send the formal statement. Make sure the case summary is complete — what's needed, what was verified technically, and why it's been pending. Urgency should be flagged clearly.
🚨 High Stakes Customer claims Brazilian law entitles them to phone support due to a disability

A Brazilian customer with dyslexia invokes Federal Decree No. 11,034/2022 and the Brazilian Inclusion Law, demanding phone support. They threaten to file a complaint with consumer authorities if you refuse.

✅ Correct approach: The decree applies to specific regulated sectors (telecoms, energy, aviation, financial) — not web hosting companies. However, the customer is entitled to accessible service. Do not simply refuse. Offer to assign a dedicated agent for more personalized, patient assistance. If the case becomes complex, escalate to Compliance who can provide a specialized response. Acknowledge their needs empathetically while being clear about what Hostinger's support channels are.
⚠️ Compliance Customer demands €6,750 compensation and wants to contact the Legal department directly

A customer is threatening legal action, regulatory complaints, and public exposure. They've rejected all goodwill offers and are demanding to speak directly with Hostinger's legal department. They haven't provided any supporting documentation for their claimed losses.

✅ Correct approach: Do not provide a direct legal contact. Inform the customer that if they wish to pursue this formally, they should contact compliance@hostinger.com (this is the one case where the email can be shared — when the customer is explicitly pursuing legal/compliance escalation). Ask them to provide supporting documentation for their claimed losses. Create a Quality ticket and escalate to TL. Hostinger does not provide monetary compensation for indirect losses under ToS.
🎯
Knowledge Quiz (10 Questions)

Test your understanding. Click an answer to see if you're right!

Question 1 / 10
A police officer contacts you via live chat and asks for a customer's account details. What should you do?
Question 2 / 10
A customer asks for the email address of the Compliance team. What do you do?
Question 3 / 10
A customer's domain is under an active UDRP proceeding. They ask you to unlock it so they can transfer it. What do you do?
Question 4 / 10
A customer asks why their domain was suspended. You can see in CRM it was suspended due to a court order. What do you tell them?
Question 5 / 10
Where should GDPR/LGPD data deletion or privacy requests be directed?
Question 6 / 10
A ticket arrives from the Lithuanian RRT (Communications Regulatory Authority) about a DSA inspection. A previous similar ticket was closed as spam. What should you do?
Question 7 / 10
Can email backups be shared with law enforcement agencies?
Question 8 / 10
A customer mentions they've filed a PROCON complaint (Brazil). What is the correct escalation path?
Question 9 / 10
When is domain transfer-out NOT allowed for mass-suspended accounts?
Question 10 / 10
A customer demands to speak directly with Hostinger's Legal department and refuses to communicate through CS. What is the correct response?
💬
Real Cases from Slack Channels (Last 30 Days)

These are real situations from the past month. Learn from what actually happened.

#legal-compliance-cases DSA / Regulatory Inspection Aug 17–18, 2026
RRT (Lithuanian Regulator) Scheduled Inspection — Ticket Closed as Spam
A ticket from Lithuania's Communications Regulatory Authority (RRT) about a DSA inspection was initially closed as spam without investigation. A follow-up ticket was correctly identified and escalated to Legal, who created a Jira (LEG-5075) and confirmed it would be handled via document/Q&A response — not a physical inspection. A separate DSA-related request from Belgium's digital coordinator was also received and forwarded to legal@hostinger.com.
🔗 View Thread   🔗 DSA/RRT Thread
#legal-compliance-cases Court Order + Customer Dispute Aug 9–10, 2026
Domain Suspended by Court Order — Customer Demands €2,000 Compensation
A customer's account was suspended (KYC failure) and two domains were suspended pursuant to a court order. The customer sent a pre-litigation notice demanding €2,000. Compliance confirmed: (1) do NOT inform the customer the suspension was due to a court order — reference ToS only; (2) Hostinger does not provide monetary compensation for indirect losses; (3) EPP codes for other domains (not court-ordered) can be provided. The case was moved to the Compliance inbox.
🔗 View Thread
#legal-compliance-cases Accidental Data Change + Legal Escalation Aug 20, 2026
Specialist Accidentally Reset Customer's Email Password — Customer Demands Compliance Review
A specialist reset a customer's mailbox password before receiving authorization. The customer demanded a compliance/legal review. Legal confirmed: ToS gives CS the right to make changes during troubleshooting, but since the specialist asked for authorization first, the customer reasonably expected confirmation before action. Compliance sent the formal response (with TL CC'd) to de-escalate. Key lesson: when a customer specifically requests Compliance/Legal involvement, route it — don't try to handle it alone.
🔗 View Thread
#legal-compliance-cases ADNDRC / Domain Dispute Jul 27 – Aug 18, 2026
ADNDRC Decision Not Implemented — Domain Lost Due to Internal Process Failure
An ADNDRC decision required a domain transfer to the winning party. Due to internal errors (registrant details not updated before transfer, FOA sent to the losing party who rejected it twice), the domain expired and was registered by a third party. Legal concluded: Hostinger must attempt to buy the domain back (up to ~$1,000–3,000), cover UDRP costs if needed, and offer compensation to the winning party. Critical lesson: UDRP/ADNDRC implementation requires careful step-by-step execution — errors can have serious legal and financial consequences.
🔗 View Thread
#legal-compliance-cases GDPR / Unauthorized Domain Transfer Aug 11–14, 2026
Customer Claims Unauthorized Domain Transfer — GDPR Art. 32 & 33 Invoked
A customer claimed Hostinger transferred their domain to another company without consent, invoking GDPR data breach articles. Investigation showed the domain was moved to the person listed as registrant (personal, not business), following standard document verification. The move was legitimate per Hostinger's process. Key lesson: document verification must match the registration type (personal vs. business). When customers invoke GDPR in domain disputes, escalate to Compliance immediately.
🔗 View Thread
#legal-compliance-cases Regulatory / Consumer Law Aug 19, 2026
Peru Customer Invokes Ley N° 32495 — Libro de Reclamaciones Virtual
A Peruvian customer formally invoked a local consumer law requiring digital platforms to provide access to a virtual complaints book (Libro de Reclamaciones Virtual). No internal procedure existed for this. The case was escalated to Legal (LEG-5136). Additionally, the customer raised a valid point about ICANN's 60-day lock not being disclosed at the point of contact email change. Key lesson: local consumer protection laws vary by country and can create compliance obligations CS is not aware of — always escalate to Legal when local regulations are invoked.
🔗 View Thread
#legal-compliance-cases Legal Statement Request Aug 8–11, 2026
Customer Needs Formal Legal Statement About Email Routing for Court Use
A customer needed a formal written statement from Hostinger confirming that two specific emails were inbound (not sent by Hostinger) for use in a legal dispute. The case had been pending ~1 month. Compliance team was asked to send the statement. Key lesson: compliance@hostinger.com should NOT be shared with customers proactively. CS should not issue formal legal statements. Escalate via Quality ticket → TL → Compliance handles the formal communication.
🔗 View Thread
#legal-compliance-cases Brazilian Consumer Law / Accessibility Aug 10–11, 2026
Brazilian Customer with Dyslexia Demands Phone Support Under Federal Law
A customer invoked Brazilian Federal Decree No. 11,034/2022 and the Inclusion Law to demand phone support. Compliance clarified: the decree applies to regulated sectors (telecoms, energy, aviation, financial) — not web hosting. However, the customer is entitled to accessible service. Resolution: assign a dedicated agent for personalized assistance; if needed, escalate to Compliance for specialized handling. Key lesson: legal claims citing local laws require careful assessment — don't dismiss them, but also don't assume they apply without verification.
🔗 View Thread
#legal-compliance-cases Lithuanian Police Request Jul 30, 2026
Lithuanian Police Request Sent to pagalba@hostinger.com
A CS specialist was notified that Lithuanian police had sent a request to pagalba@hostinger.com. The Compliance team confirmed they received the ticket and would respond. The email address pagalba@hostinger.com was unfamiliar to the team — highlighting that authority requests can arrive through unexpected channels. Key lesson: any communication that appears to be from police or government must be escalated to Compliance immediately, regardless of which email it arrived at.
🔗 View Thread
#abuse-fraud-team Automation / Police Reports Aug 18, 2026
Decision Engine Automation: Police/Gov Reports Always Go to Human Review
A new automation (Decision Engine) was deployed to auto-handle abuse reports where the reported resource is not on Hostinger's network. Importantly: police/government reporters and billing disputes are explicitly excluded from automation and always routed to human review. This confirms the policy: authority requests must never be auto-closed or handled by bots — they require human judgment and proper escalation.
🔗 View Thread