Kate and Oliver’s article was published in Thomson Reuters Regulatory Intelligence, 17 December 2025, and can be found here.
Financial Institutions frequently receive court orders seeking urgent disclosure from them as third‑party intermediaries. This guide briefly and practically explains what to do if you are served with such an order or application, how to triage issues and preserve evidence, what arguments and safeguards to consider, and how to manage cost, confidentiality, and regulatory risk while complying with court orders and regulatory obligations.
The first 48 hours post-service
No matter the type of disclosure or discovery order, respondent financial institutions should consider the following issues and take appropriate steps:
- Immediate hold: Issue a litigation hold and suspend routine deletion on potentially responsive systems (core banking, payments, logs, email, chat, cloud).
- Triage: Identify the order type, scope, return date, and whether it was made without‑ Appoint a response lead (legal) and technical owner (data).
- Map data: Confirm what you actually hold, where it sits, and what retention or bank‑secrecy constraints apply.
- Risk/safeguards: Prepare a confidentiality and redaction protocol, proportionality objections, and privacy impact assessment.
- Engagement: Contact the applicant’s solicitors and propose timelines and steps for compliance.
- Governance: Brief responsible senior management and, where appropriate, notify regulators.
Document decisions and rationale contemporaneously. Keep an audit trail of searches run, datasets preserved, and communications with the applicant and court. Assemble a team of appropriate personnel to work together to comply and respond.
Norwich Pharmacal orders
These orders require intermediaries, including those innocently “mixed up” in wrongdoing, to disclose information necessary to identify wrongdoers or explain essential facts (eg subscriber/IP/login data, merchant/acquirer/PSP data, exchange/wallet KYC, host/email metadata). Respondents should expect applications that clearly target disclosure by reference to specific accounts, transactions and timeframes.
Respondents should verify service and jurisdiction issues and check if the application was made without‑notice and whether a return date is listed. Necessity and proportionality should also be considered and, if necessary, seek to narrow overbroad categories. Respondents could propose a confidentiality club, redactions (eg unrelated third‑party data), and staged production, and identify legal restraints (bank secrecy, data protection) and ask the court for protections to avoid breaches. Respondent financial institutions can consider seeking their costs of compliance, if appropriate.
Bankers Trust orders
These orders compel financial institutions to disclose transaction information to trace proprietary assets. They must be tightly confined to tracing (current location, route, and next institution), not general disclosure. Respondents should check the claimant’s proprietary basis and insist the order is limited to data actually held and which can be lawfully disclosed.
Practically, respondents should confirm key data (for example account numbers, merchant IDs, wallet hashes) to enable focused searches and raise objections if the order requires disproportionate or unduly burdensome steps to be taken, for example rebuilding data or bespoke reporting. Respondents may seek directions on costs and sufficient time to comply safely without operational risk.
Bankers’ Books Evidence Act orders
These orders require certified copies of entries from bank records for use as evidence. Respondents should identify the exact report formats you can certify, verify customer consent exceptions under applicable law, and agree search parameters and date ranges. They should also ask for a confidentiality club and handling directions to protect sensitive data, alongside recording costs of extraction and certification.
Search and imaging orders
These types of order are highly intrusive and, if a company is served with one, they must assemble a response team and ensure compliance strictly in accordance with the order. Teams should ensure the supervising solicitor is appointed and understands the company’s systems. Protect privilege by segregating legally privileged materials. Limit imaging to specified devices/accounts/date ranges, and maintain chain‑of‑custody and hashing. If the scope of the order is unworkable or risks regulatory breach, compliance response teams should seek urgent variation from the court.
Worldwide freezing orders (WFO)
WFOs are one of the most powerful weapons in the asset recovery arsenal and must be taken seriously. If a third party is notified of a WFO, legal advice should be taken immediately so that the order is understood and it can be confirmed whether the WFO is legally enforceable against the third-party, and what steps need to be taken to ensure compliance.
Breaching a legally enforceable WFO can result in contempt of the English courts, which has severe consequences (a fine or imprisonment). Regardless of whether the third-party is within the jurisdiction of the English courts, they must still consider their position carefully.
Conversely, by complying with a WFO that is not legally enforceable, parties could expose themselves to civil or regulatory claims from the respondent in the relevant local jurisdiction. Urgent advice on enforceability and local‑law requirements (for example: bank secrecy, data protection, blocking statutes) should be sought as a priority.
Proportionality, privacy, and data protection
Compliance teams should aim to minimise intrusion, comply lawfully, and reduce collateral impact by proposing limits by account/transaction/timeframe/custodian/field, setting up confidentiality clubs, redacting appropriately, and documenting personal‑data handling, retention, and deletion. Where bank secrecy, telecoms confidentiality or local laws apply, constraints should be explained and tailored protections or alternative mechanisms sought (eg anonymisation).
Cross‑border issues
If served with an English order but data sits overseas or with a foreign affiliate, compliance teams should identify conflicts with local law promptly, take advice, seek directions, phased compliance, or permission to use letters of request. They should maintain one cross‑border log of datasets, transfer paths, and safeguards (encryption, access controls) to demonstrate responsible handling.
Timelines, costs, and readiness
Respondent institutions and their compliance teams should plan to comply safely but efficiently, building a standard “response plan”, including an intake checklist, privilege and confidentiality protocol, standard preservation procedures, templates for narrowing submissions, secure transfer playbook, and cost‑tracking. Compliance teams should keep a time log and contemporaneous cost record for recovery applications. If compliance timelines are unrealistic or operationally risky, they should apply promptly to vary. Preparation shortens timelines, reduces cost, and minimises customer and reputational impact.