Stories from April, 2026

Freedom of Information Policy: Free Template

The Freedom of Information Act 2000 (FOIA) places clear obligations on public authorities to provide access to recorded information, and with those obligations comes the need for consistency, clarity, and control. This is where a well-designed Freedom of Information (FOI) policy becomes indispensable. Without one, organisations risk delays, inconsistency, and

Read more
Does it Matter if you Breach Timescales for SARs?

Subject Access Requests, or SARs, are the most commonly used GDOR right that people have. They can place a material burden on organisations and therefore it is not uncommon for deadlines or information to be missed. However, even missing the deadline is itself a breach of GDPR, regardless of whether

Read more
Freedom of Information Request Tracker

For any public authority or organisation subject to the Freedom of Information Act 2000, receiving a request can feel like a disruption to the "real" work. However, treating FOI requests as an afterthought is risky because of your statutory duties and the role FOI has in building openness and trust.

Read more
Data Retention: Why Organisations Might Keep Personal Data

Data retention and disposal are key elements of data flows. As part of this retention schedules and Records of Processing Activities (RoPAs) are essential tools for GDPR compliance. They set out how long personal data should be kept and when it should be deleted. In principle, this supports the storage

Read more
Staff Data and Freedom of Information

What Staff Data Can Be Disclosed Under the UK Freedom of Information Act? Many public sector organisations struggle when people make freedom of information requests  that involve information about staff and other workers. There is no automatic exemption for personal data about anyone other than the requestor under FOI. Therefore

Read more
Fairness is Not the Same as Nice

When it comes to the GDPR fairness is not the same as nice. The first data protection principle of the UK GDPR requires that personal data is processed lawfully, fairly, and transparently. These three elements are closely connected, but each carries its own weight. Of the three, fairness is often

Read more