Legal Confidentiality: Interpol & CCF Guide 2026
Planet

Understanding Legal Confidentiality: A Complete Guide to Protected Information in Law and International Cooperation

A Malaysian businessman applied to challenge an Interpol Red Notice through the Commission for the Control of Interpol’s Files in August 2025. His submission included confidential financial records and witness statements. Under Article 20 of the Interpol Statute, those files remained excluded from the INTERPOL Information System, shielded from unauthorized disclosure throughout the nine-month processing period—even as parallel extradition proceedings unfolded in three jurisdictions.

Legal confidentiality is the binding obligation to protect data from unauthorized disclosure. It ensures that sensitive information stays accessible only to authorized persons and that disclosure risks are actively managed. In international police cooperation and extradition, this means controlling who sees Red Notice submissions, case files, correspondence—preventing operational compromise and protecting individual rights when police cooperation crosses borders.

Key Takeaways

  • Four-month access deadline: The CCF must decide on access requests within four months of admissibility; if you file in January, expect a decision by April at the earliest. Correction or deletion requests take the full nine months.
  • Article 20 protection: Files submitted to the CCF remain confidential under Interpol Statute Article 20(1) and (2), excluded from the INTERPOL Information System and invisible to the requesting state’s National Central Bureau
  • Three-tier responsibility: National Central Bureaus assign confidentiality levels, the General Secretariat processes data according to those levels, and both must observe confidentiality obligations under Articles 2–4 of the Rules on the Processing of Data
  • Confidentiality survives employment: Under Article 20(3), the duty persists after Commission members, Secretariat staff, and experts leave office—breach years later still carries legal consequences
  • Files are inviolable: The Headquarters Agreement 2008 (Articles 4–8) shields the Organization’s files, archives, and correspondence from external intrusion, even by domestic courts in member states

Legal confidentiality – the legally enforceable obligation to prevent unauthorized disclosure of data, determined according to the risks linked to the subject of the data, the sources of the data, and the Organization itself, with access restricted to authorized persons only (Interpol Rules on the Processing of Data, Article 1).

What Does Legal Confidentiality Mean in Legal Practice?

Legal confidentiality establishes controlled access—not total secrecy. The Interpol Rules on the Processing of Data, Article 1, define it through disclosure risks: risks to the individual whose data is held, risks to informants and cooperating agencies, and risks to Interpol’s operational integrity. Because these risks vary, confidentiality levels vary too. Authorized persons access protected data based on their defined role.

In extradition cases, the distinction matters urgently. When someone contests a Red Notice through request to access procedures, their CCF submission includes grounds for removal, supporting evidence, and often witness statements. Article 20(1) and (2) guarantees these files “shall not be recorded in the INTERPOL Information System.” The requesting state’s National Central Bureau cannot access the application. Your legal strategy—the weaknesses you’ve identified in the Red Notice, the evidence you’ll present—stays hidden from the prosecutor who wants you extradited.

How is confidentiality different from privilege?

Privilege and confidentiality solve different problems. Privilege (lawyer-client, for example) prevents compelled testimony in court—a lawyer cannot be forced to reveal a client’s confidential communications. Confidentiality is administrative: the data controller must restrict access and block unauthorized disclosure, but a court order or statutory exception may override it anyway.

Within Interpol’s framework, confidentiality is a data-processing rule, not an evidentiary privilege. Article 2 of the Rules on the Processing of Data obligates National Central Bureaus to respect the confidentiality of data they consult, transmit, or use. This binds member countries’ police agencies—except that a domestic court may still order disclosure if national law permits. The two concepts overlap visibly (both limit who sees what), but they rest on entirely different legal foundations. One is evidentiary; the other is administrative.

What information is protected under legal confidentiality?

Three categories receive explicit protection. First: Commission for the Control of Interpol’s Files submissions. Article 20 renders them confidential and excludes them from the INTERPOL Information System. Second: data in the INTERPOL Information System itself—Articles 1–4 of the Rules on the Processing of Data require confidentiality levels to be assigned, observed, and upgraded where necessary. Third: correspondence and archives. The Headquarters Agreement 2008, Articles 4–8, declares these inviolable.

For someone fighting extradition, this means your CCF application—legal arguments, evidence of political persecution, witness affidavits—remains shielded from the requesting state. The General Secretariat processes the application according to the confidentiality level assigned by your legal representatives (if submitted through your National Central Bureau) or by the CCF itself (if you submit directly). Article 4 obligates the General Secretariat to take “all necessary and appropriate measures to increase the confidentiality level attached to data” when risks demand it. In practice, this means encryption, restricted database queries, and segmented access by user role.

Why Is Legal Confidentiality Critical in International Police Cooperation?

Confidentiality underpins trust across 196 member countries. Interpol Operating Rule 13 codifies that confidentiality and security are “of paramount importance” to protect international police cooperation and applicants’ rights. Without these guarantees, National Central Bureaus would hoard intelligence rather than share it, sources would refuse to talk to police, and people would never dare submit evidence to the CCF if it could reach the very authorities pursuing them.

Interpol balances two competing interests. Confidentiality safeguards operational security—a tip from an intelligence agency, details of an active investigation, the identity of a cooperating witness. It also protects the person challenging a Red Notice. An applicant contesting a politically motivated notice must present evidence of persecution without that evidence being shared to the requesting regime before the CCF rules.

Real-world impact is measurable. Files, correspondence, and requests submitted to the CCF remain excluded from the INTERPOL Information System under Article 20(1) and (2). The requesting state cannot query the system and retrieve your submission. This prevents strategic disclosure: the prosecutor cannot adjust extradition arguments in real time based on your CCF filing.

What happens if confidential police information is disclosed?

Unauthorized disclosure carries legal, operational, and diplomatic consequences. Legally, breach of Article 20(3) or Article 2 of the Rules on the Processing of Data violates Interpol’s framework. The responsible individual or agency faces internal discipline, and the National Central Bureau may be censured. Operationally, disclosure unravels ongoing cases: sources disappear, investigations collapse, and CCF applicants lose fair process when evidence leaks to the requesting state before the Commission rules.

Diplomatically, silence follows. Rule 13 emphasizes that confidentiality protects international police cooperation itself. Repeated breaches by one National Central Bureau prompt other NCBs to restrict information sharing; Interpol’s General Secretariat may cut that NCB’s access to certain data channels.

In extradition cases, disclosure can destroy your right to a fair hearing. Suppose your CCF submission includes evidence of torture risk, and that evidence reaches the requesting state before the Commission rules. The prosecutor can preemptively provide diplomatic assurances or alter the extradition request to counter your evidence, undermining the entire CCF process. Courts in destination countries (Australia, Canada, others) may refuse extradition if confidentiality protections were breached—this violates natural justice. Your remedy then becomes a matter for judicial review, which is slower and more uncertain than a strong CCF confidentiality shield from the start.

How Does the INTERPOL Information System Protect Confidential Data?

The INTERPOL Information System operates under a three-tier responsibility framework. National Central Bureaus assign confidentiality levels to data they enter, observe the confidentiality of data they consult or transmit, and ensure compliance during external processing. The General Secretariat processes all data according to the level the submitting entity assigned and upgrades that level where disclosure risks warrant.

Article 2 of the Rules on the Processing of Data assigns NCBs the duty to assign confidentiality levels. This is mandatory, not discretionary. Each NCB must assess disclosure risks linked to the individual, the sources, and the Organization, then assign the appropriate level. Levels range from broadly accessible (for routine alerts) to highly restricted (for intelligence from sensitive sources or CCF submissions). Once assigned, the level governs who may access the data within Interpol’s network.

Article 3 requires the General Secretariat to process data according to the level assigned. If an NCB marks a Red Notice dossier as “confidential—authorized persons only,” the General Secretariat cannot downgrade it unilaterally. Article 4 goes further: the General Secretariat must take “all necessary and appropriate measures to increase the confidentiality level attached to data” to mitigate disclosure risks. In practice, this means restricting database queries, segmenting access by user role, encrypting transmissions, or even removing data from the main system entirely if risks escalate.

Who are considered authorized persons under Interpol rules?

Authorization under Interpol is not a one-size-fits-all designation. Article 1 of the Rules on the Processing of Data restricts access to authorized persons only, but the definition shifts based on the confidentiality level assigned to the data. For a routine Red Notice, authorized persons include any officer in a National Central Bureau with a legitimate operational need. For highly confidential intelligence, access narrows to a named subset of General Secretariat analysts and the submitting NCB’s senior officers.

INTERPOL member countries define their own authorization procedures within their National Central Bureaus. An Australian Federal Police officer authorized to access Red Notices relevant to Australian investigations cannot access confidential intelligence submitted by another member country without explicit permission from that country’s NCB. Every query gets logged: audit trails record who viewed what and when, giving the General Secretariat a way to detect unauthorized access.

This has teeth in extradition proceedings. A prosecutor seeking extradition from Australia cannot walk into Interpol’s databases themselves. They must work through the requesting state’s NCB, which submits the query on their behalf. If the data is marked confidential, the NCB must justify the request and secure approval before handing anything to the prosecutor—a step that can add weeks to time-sensitive cases.

How are confidentiality levels determined for police data?

Article 1 of the Rules on the Processing of Data anchors confidentiality levels to a straightforward risk assessment: would disclosure endanger the subject, expose sources, or harm Interpol itself?

The submitting National Central Bureau weighs three factors. First: risk to the subject. Would disclosure endanger their safety, compromise their rights, or invite retaliation? Second: risk to sources. Could disclosure identify informants, intelligence agencies, or cooperating authorities? Third: risk to the Organization—would disclosure undermine Interpol’s neutrality, expose operational methods, or breach diplomatic agreements?

Consider the difference between two Red Notices. One targets a suspected financial fraudster supported by public court records. Low risk all around: the subject is already known to law enforcement, sources are public, the Organization’s reputation is unaffected. That notice might be marked “law enforcement sensitive” but accessible to all National Central Bureaus. Now contrast a second notice based on testimony from a defector alleging that a foreign official embezzled state funds. High risk. Revealing the source could kill the defector. Premature disclosure could trigger diplomatic retaliation. That notice would be locked down as “confidential—restricted access.”

Levels shift as circumstances change. Article 4 permits and requires the General Secretariat to increase confidentiality when new risks emerge. If a CCF applicant reports that the requesting state has attempted to identify the applicant’s legal representatives, the General Secretariat may elevate the file’s confidentiality level to prevent further leaks.

What Are the Legal Obligations for Maintaining Confidentiality?

Article 20(3) of the Interpol Statute imposes a perpetual confidentiality obligation on all Commission members, Secretariat staff, and appointed experts. The duty does not expire when someone leaves office. A retired Commission member cannot later disclose case details. A former Secretariat officer cannot publish confidential files even decades after departure.

Article 112 and subsequent provisions extend this obligation to National Central Bureaus and any entity that consults, transmits, or processes data externally. When an NCB shares data with a domestic court or prosecutor—say, in support of an extradition request—the NCB must ensure the recipient maintains equivalent confidentiality protections. If domestic law falls short, the NCB must seek Interpol’s approval before sharing anything.

Breaches carry real consequences. Unauthorized disclosure can result in suspended access privileges, formal censure of the responsible National Central Bureau, and in serious cases, referral to the member country’s domestic authorities for prosecution under data protection or official secrets laws.

Do confidentiality obligations continue after employment ends?

Yes. Article 20(3) explicitly states the duty persists after individuals “cease to exercise their functions.” This applies to Commission members, Secretariat staff, and experts appointed to specific cases. A lawyer who served on the CCF in 2020 cannot publish case details in 2026, even if the case closed years earlier.

Two reasons anchor this rule. First: sources and subjects remain vulnerable indefinitely. Someone who cooperated in 2015 may face genuine danger in 2026 if their identity surfaces. Second: perpetual confidentiality preserves Interpol’s institutional credibility. If former staff could disclose historical files, applicants would stop trusting the system, and member countries would stop sharing sensitive intelligence.

For defence lawyers handling extradition cases, this means CCF case files stay protected regardless of who you know inside Interpol. Any attempt to obtain files through informal contacts or retired staff violates Article 20(3) and risks your own professional standing.

What is legal confidentiality - legal guidance

How Can Individuals Request Access to Confidential Files?

The Commission for the Control of Interpol’s Files handles access requests while keeping them secret. You can submit a request to access, correct, or delete data about yourself in the INTERPOL Information System. Here’s the critical part: your request itself stays confidential. Article 20(1) and (2) guarantee that applications under Chapter 4 “shall not be recorded in the INTERPOL Information System.” The requesting state’s NCB won’t learn you’ve filed unless the CCF’s decision changes your Red Notice status.

Deadlines are fixed and matter. Access requests must be decided within four months of admissibility. Correction or deletion requests get nine months. These timelines are binding on the CCF. Miss them and you have recourse through Interpol’s internal review mechanisms—a tool most applicants don’t know exists.

Confidentiality protections run throughout the process. Your submission, supporting documents, and CCF correspondence stay off the INTERPOL Information System. The CCF may ask you or the submitting NCB for more information, but it won’t disclose your arguments to the NCB unless necessary to let them respond. This one-way confidentiality prevents the requesting state from adjusting its extradition strategy based on your CCF filing.

The tension is real. You have a right to know what Interpol holds and to challenge its accuracy. Yet premature disclosure to the requesting state could undermine your ability to challenge an unjust Red Notice. INTERPOL Red Notice explained procedures navigate this: you receive status updates, but the requesting state only learns the outcome if the Notice is removed or changed.

What is the process for requesting confidential information from Interpol?

Start with a written request to the Commission for the Control of Interpol’s Files. Identify yourself, specify the data at issue, and explain why you want access, correction, or deletion. Include supporting evidence—court judgments showing dropped charges, documentation of persecution, whatever proves your case. The CCF screens for admissibility: Is the data in the INTERPOL Information System? Do you have standing?

Once the CCF deems you admissible, the clock starts. Four months for access. Nine months for correction or deletion. The CCF can ask you for clarifications or the NCB for a response. If the NCB’s reply contains confidential intelligence, you get a redacted version. You can reply to their arguments, and this exchange continues until the CCF has enough to decide.

The decision goes to you and the relevant National Central Bureau. If the CCF orders Red Notice deletion, the General Secretariat removes it within seven days. The NCB gets notified—but has no obligation to tell its domestic prosecutors. You may stay on national watchlists months after CCF deletion unless you push your defence team to notify domestic courts separately. This gap catches applicants off guard.

In extradition cases, timing becomes everything. Arrested in Australia on an extradition request? File a CCF application immediately. Australian courts have discretion to stay extradition proceedings while the CCF decides. The requesting state won’t know you’ve filed. If the CCF deletes the Red Notice, the extradition request can collapse before the requesting country even knows there was a problem.

⚠️ Time is critical — every day matters

Get a free case assessment

Our team specialises in cases with an international element. We review applicable treaties, assess risks, and prepare an action plan.

Free Consultation → 🔒 Confidential · Response within 24h · No obligation

What Legal Frameworks Govern Confidentiality in International Organizations?

Four primary frameworks establish and enforce confidentiality within Interpol’s operations. Article 20 of the Interpol Statute—adopted by all 196 member countries as binding treaty law—declares Commission files confidential, excludes CCF requests from the main INTERPOL Information System, and imposes a perpetual confidentiality duty on all members and staff. This is the legal bedrock.

The Interpol Operating Rules translate these protections into daily practice. Rule 13 marks confidentiality and security as “of paramount importance” to safeguard both international police cooperation and applicants’ rights. It cross-references Article 20 and specifies that all Commission correspondence, files, and decisions remain confidential unless the Commission explicitly decides otherwise in a particular case—which rarely happens.

Next is the Rules on the Processing of Data (RPD), Interpol’s comprehensive internal data protection regulation. Articles 1–4 define confidentiality levels and assign responsibility for setting and maintaining them; the General Secretariat can increase protection where necessary. Articles 112 onward extend these obligations to National Central Bureaus and third parties. Unlike national laws such as Australia’s Privacy Act, the RPD operates at the international level and takes precedence when conflicts arise.

Finally, the Headquarters Agreement 2008 adds diplomatic immunity. Articles 4–8 declare the Organization’s files, archives, and correspondence “inviolable”—beyond the reach of search, seizure, or court-ordered disclosure by France (the host country) or any member state’s law enforcement. This goes beyond confidentiality: a French court cannot legally access Interpol’s physical files, regardless of the reason.

Here’s where it gets complicated for individuals. Australia’s Privacy Act 1988 requires Australian government agencies to handle personal information transparently and securely. When the Australian Federal Police (Australia’s National Central Bureau) receives a Red Notice from Interpol, it must comply with both frameworks simultaneously. If someone in Australia requests their Interpol data under the Privacy Act, the AFP faces a genuine bind: disclose and risk violating Interpol confidentiality, or refuse and appear to obstruct transparency. In practice, Interpol confidentiality usually wins—disclosures arrive heavily redacted or are refused outright.

How does Interpol’s confidentiality framework compare to other international organizations?

Interpol’s approach is notably stricter than its peers. The United Nations protects confidentiality in Human Rights Council communications and treaty submissions, but these protections yield to Security Council resolutions or state consent—they’re procedural safeguards, not absolute shields. Interpol’s Article 20 is different: embedded in the Statute itself and reinforced by diplomatic inviolability, it cannot be overridden by unilateral state action.

Europol, the EU’s law enforcement agency, operates under Regulation (EU) 2016/794. It mandates confidentiality for operational data but allows EU judicial authorities to request disclosure under specific, legislated circumstances. Interpol is more defensive: the CCF’s files stay confidential even from courts unless Interpol itself authorizes release.

The International Criminal Court protects victims’ and witnesses’ identities under Rome Statute Article 68, yet this protection can be breached if the accused demonstrates a fair-trial need for disclosure. Interpol confidentiality works differently. The requesting state has no procedural right to access CCF files, even if it claims access is essential to defend its extradition case.

“The files of the Commission shall be confidential. Files, correspondence and requests submitted to the Commission … shall not be recorded in the INTERPOL Information System.” – Interpol Statute, Article 20(1) & (2)

What is legal confidentiality - legal process

Sources

Frequently Asked Questions

What is the difference between confidentiality and secrecy?

Confidentiality permits controlled access—authorized persons may view the data under defined conditions and with oversight. Secrecy is absolute: information stays behind a closed door, period. No one outside the inner circle sees it. Interpol uses confidentiality. National Central Bureaus, the General Secretariat, and CCF members access data according to their functions. State intelligence agencies, by contrast, often operate under secrecy regimes where even the fact that certain files exist is classified.

Can confidential information ever be disclosed legally?

Yes—if the entity holding the confidentiality obligation authorizes it. Within Interpol, the Commission for the Control of Interpol’s Files may decide disclosure serves a legitimate purpose: protecting an individual’s rights or correcting a manifest injustice. The General Secretariat can share data with authorized international bodies (the UN, regional organizations) under RPD Articles 112 and beyond, provided the recipient guarantees equivalent protection.In extradition cases, an Australian court cannot force Interpol to open CCF files. It can, however, request a procedural letter from Interpol confirming whether a Red Notice is active, suspended, or deleted. Such confirmation is administrative confirmation, not substantive disclosure—it respects the confidentiality framework.

Who enforces confidentiality obligations in international police cooperation?

Interpol’s Commission for the Control of Interpol’s Files polices the Organization itself. The CCF investigates breaches, censures National Central Bureaus or Secretariat staff, and recommends corrective measures to the General Assembly. Within member countries, domestic authorities take the lead. An officer in Australia’s NCB who discloses confidential Interpol data without permission faces disciplinary action under Australian public service rules and potential prosecution under the Crimes Act 1914 for unauthorized disclosure of official information.

What penalties exist for breaching legal confidentiality?

They escalate by severity. Within Interpol, breach of Article 20(3) or the RPD may result in suspended access privileges, formal censure, or (in serious cases) expulsion of a member country’s National Central Bureau from specific data channels. Domestically, an officer faces criminal prosecution under official secrets laws, potential dismissal, and civil liability if someone is harmed by the breach.In court, breach can make evidence inadmissible. If an Australian judge finds the requesting state obtained evidence by violating Interpol’s confidentiality protections, the court may exclude that evidence and refuse extradition on unfairness grounds.

How long must confidential information remain protected?

Perpetually. Article 20(3) of the Interpol Statute imposes a confidentiality obligation that never expires—it follows individuals after they leave office and covers all information obtained during their service. Interpol’s archives remain protected indefinitely unless the Commission for the Control of Interpol’s Files or the General Assembly votes to declassify. In practice, older files are reviewed periodically, and data on deceased individuals or cases closed decades ago may eventually be declassified for research, but only through formal approval and with sensitive details removed.

Planet