Last updated 16 July 2026
This policy explains how Champ Fitness Ltd, trading as UN1T Dublin (“we”, “us”) responds when a public authority — such as a police force, court, regulator, tax authority, or other government body — asks us to disclose personal data we hold. It applies to personal data we process as a data controller for our own operations, and to personal data we process on behalf of business customers who connect their own accounts through our platform. We handle every such request under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
We do not disclose personal data to a public authority simply because it is asked for. We disclose it only where we are satisfied there is a valid legal basis to do so — for example a court order, a statutory power exercised correctly, or another lawful obligation that genuinely applies to us. A request on letterhead, by phone, or by email, without a proper legal basis, is not on its own sufficient.
Every request from a public authority is reviewed before we respond. That review is carried out by a named responsible person within UN1T Dublin (our data protection contact, reachable at the address below), who checks:
Where the request relates to data we process on behalf of a business customer, we will, wherever we are lawfully permitted to do so, direct the authority to that business customer (the controller of that data) and notify the customer, rather than disclosing the data ourselves.
If, after review, we consider a request to be unlawful, invalid, overbroad, or otherwise improper, we will not comply with it as made. Depending on the circumstances we will push back on the authority, ask for it to be narrowed or properly authorised, seek our own legal advice, and where appropriate formally object to or challenge the request through the available channels before any disclosure is made.
Where we are lawfully required to disclose data, we apply data minimisation: we disclose only the specific personal data that falls within the scope of the request and its legal basis, and no more. We do not hand over a person’s entire record, or unrelated data about other people, when a narrower disclosure answers the request.
We keep a record of each request from a public authority, including the authority involved, the date, the legal basis claimed, the review we carried out, the people involved in the decision, our response, and exactly what (if anything) was disclosed. These records let us account for our decisions to the Irish Data Protection Commission and to the individuals concerned.
In a genuine emergency involving a risk to life or serious harm, we may respond more quickly, but we still record the request, the emergency relied on, and the disclosure made, and we still limit the disclosure to what is necessary to address the emergency.
Where we are lawfully allowed to do so, and it would not prejudice an investigation, we aim to notify a person whose personal data has been requested by a public authority, so that they can seek their own advice. We will not give notice where the law prohibits us from doing so.
Public authorities should send requests in writing, with the relevant legal basis and any required order or authorisation, to:
Champ Fitness Ltd (trading as UN1T Dublin) — Data Protection Contact
First Floor Unit, Stillorgan Village Centre, Lower Kilmacud Road, Dublin, A94 AC67
Email: privacy@un1tdublin.com
This policy sits alongside our main privacy policy. It describes our standing process; it is not legal advice to any authority or individual. Individuals can also complain to the Irish Data Protection Commission at dataprotection.ie.