What to do if…
a regulator or official asks you to provide passwords or passcodes during an inquiry
Short answer
Do not share passwords, passcodes, PINs, 2FA codes, or authenticator approvals informally or verbally on the spot. Ask for the request in writing, including the legal power, scope, deadline, and exactly what they want accessed, then involve a solicitor or your organisation’s legal, compliance, and IT security leads before providing access.
Do not do these things
- Do not hand over your actual password, passcode, PIN, 2FA code, authenticator approval, recovery key, or password-manager access just because the request feels urgent.
- Do not guess what you have to do. The position can depend on who is asking, whether this is a regulator, police, HMRC, border officer, or another public authority, and whether a formal written notice has been served.
- Do not delete messages, wipe devices, change records, reset passwords, revoke access, or tidy up files after the request.
- Do not unlock a device or account and leave officials unsupervised with it unless the written power has been checked and a controlled process is agreed where possible.
- Do not mix personal and work accounts to be helpful, such as logging into personal email or cloud storage to retrieve work material.
- Do not volunteer extra devices, accounts, backups, or systems beyond the written request.
What to do now
-
Move the request into writing. Calmly say: “I’m not able to share passwords or passcodes verbally. Please put the request in writing, including the legal basis, scope, deadline, and what information, device, account, or system it covers.”
-
Verify who is asking. Ask for the person’s name, organisation, role, ID if available, contact details, and case or reference number. Write down the time, place, who was present, and the exact words used for the password or access request.
-
Ask what exact power or notice they are relying on. Keep the questions short:
- Are you asking for documents or data to be produced?
- Are you asking me to unlock a device or account?
- Are you asking for the actual password, passcode, encryption key, recovery key, 2FA code, or authenticator approval?
- Is this voluntary, or is there a formal notice, warrant, court order, or statutory power?
-
Bring in legal and organisational support immediately.
- If you have a solicitor, contact them now and ask the official to wait while you get advice.
- If this is a workplace matter, contact your organisation’s legal or compliance lead and IT security lead, and say that the organisation will respond through them.
- If you are personally named in a notice, tell your solicitor that the notice is addressed to you, not just to the organisation.
-
Offer safer ways to cooperate if the written power allows. Instead of handing over credentials, ask whether the request can be met by:
- producing specific documents or data exports within the written scope;
- supervised access while you remain present;
- access carried out by an IT administrator using a time-limited account with the minimum permissions needed;
- device collection, imaging, or copying under the stated authority rather than disclosure of your passcode;
- a written protocol for what will be accessed, copied, searched, or excluded.
-
If a formal notice is served, slow down and read only what matters first. Check:
- who issued it and whether it is addressed to you;
- the legal power named in it;
- exactly what device, account, information, key, password, or assistance is demanded;
- the deadline and how compliance is meant to happen;
- whether it says failure to comply may be an offence;
- whether it limits who may receive the disclosed information.
In the UK, a notice under Part III of the Regulation of Investigatory Powers Act 2000 may, in some circumstances, require disclosure connected with protected electronic information, including a key or assistance to make information intelligible. If section 49, section 53, encryption, a key, protected information, or a secrecy requirement is mentioned, contact a solicitor immediately and do not alter or destroy anything.
-
If the request happens during a search, raid, inspection, or visit, keep the moment controlled. Say that you are not refusing to cooperate, but you need the request recorded in writing and legal support involved. Keep one person taking notes if possible, and ask for a copy of any warrant, notice, inventory, or written authority before any access is given.
-
If this is at a UK port or border, treat it as legally different from ordinary regulator contact. Border examination powers can involve duties to answer questions or provide information and may operate without ordinary suspicion. Stay polite, ask which power is being used, ask for legal advice as soon as possible, and record what was requested when you safely can.
What can wait
- You do not need to decide broad access to whole systems, devices, email accounts, cloud drives, password managers, or backups right now.
- You do not need to explain your entire IT setup, name every account, or volunteer extra devices or personal accounts on the spot.
- You do not need to negotiate the full scope in real time; get the request written down and reviewed first.
- You do not need to decide today how the wider inquiry will be handled, who is at fault, or what the long-term legal strategy should be.
Important reassurance
A request for a passcode can feel routine when it comes from an official, but pausing is normal. Asking for written authority, scope, and legal support helps prevent accidental over-disclosure, damage to evidence, or loss of control over personal and work accounts.
Scope note
These are first steps for the moment a regulator or official asks for passwords, passcodes, keys, 2FA codes, authenticator approvals, or device access during an inquiry. The right response may depend on the regulator, the legal power being used, whether you are acting personally or for an organisation, and whether a formal notice, warrant, court order, police power, or border power is involved. Later decisions may need specialist legal and technical help.
Important note
This is general information, not legal, financial, technical, professional, or other specialist advice. If you are served with a formal notice, warrant, court order, or secrecy requirement, or you are in a police, custody, search, or border setting, get legal advice immediately and avoid irreversible actions such as deletion, wiping, password changes, or informal credential sharing.
Additional Resources
- GOV.UK — Ukpga 20000023 en
- GOV.UK — RIPA Part III Code of Practice
- GOV.UK — Examining officers and review officers under Schedule 7 to the Terrorism Act 2000 (accessible)
- Counter Terrorism Policing — Schedule 7
- GOV.UK — CH20150 - Information & Inspection Powers: Overview: Schedule 36 FA 2008 - HMRC internal manual
- National Cyber Security Centre — Top tips for staying secure online
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.