Purpose and Scope
This Legal Process Response Procedure is adopted by Integrity Now Insurance Brokers, Inc., effective September 16, 2026. It describes how the organization receives, verifies, evaluates, responds to, and records subpoenas, summonses, court orders, warrants, civil investigative demands, and requests from law enforcement or other governmental bodies (collectively, “legal process”) seeking personal data held by the organization. It applies to every employee, volunteer, and contractor who may receive such a request, in any form — by mail, email, fax, telephone, in person, or through a registered agent.
Responsible Person
CEO (the “Responsible Person”) is responsible for administering this Procedure and can be reached at kedwards@integritynowins.com. Only the Responsible Person, or a person the Responsible Person designates in writing, may respond to legal process or disclose personal data under it.
Legal Counsel
The Responsible Person escalates to licensed legal counsel any legal process that is unclear in scope or origin, that seeks the contents of communications or sensitive data, that the organization may wish to challenge or narrow, that is accompanied by a non-disclosure or gag order, or that falls within the Maryland section of this Procedure where the basis for a determination is uncertain.
Step 1 — Receipt and Routing
Any person who receives legal process forwards it to the Responsible Person the same business day and does not respond to the requester, confirm or deny that any record exists, disclose any data, or alter or delete any data that the request may cover. Receipt of legal process suspends any routine deletion of the data it describes until the Responsible Person decides otherwise. The Responsible Person opens an entry in the Legal Process Register (see Step 6) on the day the request is received and notes any response deadline.
Step 2 — Verify Who Is Asking
Before acting on any request, the Responsible Person confirms the identity and authority of the requester. This includes: (a) identifying the issuing court, agency or party and the individual official or attorney named on the request; (b) confirming the request through contact information obtained independently — for example, from the court’s or agency’s official website or directory — and not through a telephone number, email address or link supplied in the request itself; (c) confirming that the request was delivered by a method of service the organization is obliged to accept; and (d) recording which governmental unit, if any, the request originates from. A request that cannot be verified is not acted upon.
Step 3 — Identify the Type of Legal Process
The Responsible Person records what kind of instrument has been received, because each carries different obligations: (a) a subpoena or summons, which may be issued by an attorney, a court clerk or an agency without review by a judge and which may be objected to or narrowed; (b) a court order signed by a judge; (c) a search warrant issued by a federal or state court; (d) an administrative warrant or demand signed by an agency official rather than by a judge, which is not treated as a court-issued warrant under this Procedure; or (e) an informal request for voluntary cooperation that is not backed by any compulsory process.
Step 4 — Check the Scope and Particularity of the Request
For every request, the Responsible Person confirms what data is actually being demanded before anything is gathered. For a warrant, this includes confirming that it was issued and signed by a judge of a federal or state court, that it has not expired, and that it particularly describes the personal data to be accessed — for example, by identifying the specific individuals, accounts, record types, and date range. Where a request is overbroad, ambiguous or does not particularly describe the data, the organization seeks clarification or narrowing, or escalates under the Legal Counsel section, rather than producing more than the request clearly covers. Data outside the verified scope of a request is not disclosed.
Step 5 — Voluntary and Emergency Requests
The organization does not disclose personal data in response to an informal request for voluntary cooperation that is not backed by compulsory legal process, except where disclosure is required by law.
Notice to Affected Individuals
Before disclosing an individual’s personal data in response to legal process, the organization notifies that individual of the request, so that they have an opportunity to seek legal protection, unless notice is prohibited by law or by court order, or the Responsible Person determines that notice would create a risk of death or serious physical injury. Where notice is delayed for one of those reasons, the organization provides it once the restriction ends.
Maryland Consumers — Immigration-Enforcement Limit
Where a request concerns the personal data of a Maryland consumer, the Responsible Person applies the following additional checks before any disclosure.
(a) The organization does not disclose a Maryland consumer’s personal data in response to a subpoena, summons, inquiry or investigation that pertains solely to immigration enforcement, or that originates from a governmental unit that has engaged in or supported civil immigration enforcement within the preceding six months, unless the organization is presented with a valid warrant issued by a federal or state court that particularly describes the personal data to be accessed.
(b) The organization applies the same limit to requests for voluntary cooperation from a law-enforcement agency that the organization knows to have engaged in or supported civil immigration enforcement within that period.
(c) For every such request, the Responsible Person records in the Legal Process Register: whether the request pertains solely to immigration enforcement; which governmental unit it originates from; what information was consulted to determine whether that unit has engaged in or supported civil immigration enforcement within the preceding six months, including any resources published by the Maryland Division of Consumer Protection, and the date it was consulted; and, where a warrant is relied on, how it satisfies Step 4. Where that determination cannot be made with confidence, the request is escalated under the Legal Counsel section before any disclosure.
Step 6 — Legal Process Register
The Responsible Person maintains a Legal Process Register recording, for each request: the date and method of receipt; the requester and the issuing court, agency or party; how the requester’s identity was verified; the type of instrument; the data requested and any response deadline; any clarification, narrowing, objection or escalation; any determination made under the Maryland section of this Procedure; whether and when affected individuals were notified; what data, if any, was disclosed, to whom and on what date; and the name of the person who approved the response. A copy of the request and of any data produced is kept with the entry. Register entries are retained for 10 Years.
Step 7 — Responding
Once Steps 2 through 5 are complete, the Responsible Person approves the response. Data is produced only through a secure method, only to the verified requester, and only within the verified scope. Where the organization objects to, seeks to narrow, or declines a request, it does so in writing before any response deadline, with legal counsel where the Legal Counsel section applies.
Training and Review
Every person who may receive legal process on the organization’s behalf — including reception, customer-support and registered-agent contacts — is told that legal process is routed to the Responsible Person under Step 1 and is not answered directly. The Responsible Person reviews this Procedure at least once a year, whenever a law that applies to it changes, and after any request that exposed a gap in it, and records the date of each review.