FOI and GDPR: sharing personal data

FOI and GDPR meet when it comes to sharing personal data. The Freedom of Information Act 2000 (FOIA) is key legislation for transparency and accountability in the United Kingdom. Enacted with the aim of giving people greater access to information held by public authorities, it empowers them to request a wide range of information, including personal data, any organisation covered by the Act. In this article, we delve into the complex intersection of FOIA and personal data, exploring how the release of personal data works under FOIA in the light of other legislation – namely the Data Protection Act 2018.

________________________________________________________________________________________________

About the Author
Michael is an expert in governance and information governance, with many years’ experience developing and improving freedom of information systems and processes. He has worked in this field across the public sector including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five star rated Freedom of Information course.

________________________________________________________________________________________________

Understanding Freedom of Information

At its core, the FOIA is a legislative instrument designed to promote openness in government affairs. It gives anyone the right to request access to recorded information held by public authorities on request and (usually) free of charge. This information encompasses held by or on behalf of a public authority, including documents, emails, and yes, even personal data. The overarching goal is to enhance transparency, encourage public participation, and hold public bodies accountable for their actions.

FOIA applies to public authorities like local authorities, government departments, schools and universities, and others.

FOIA vs. Data Protection

While the FOIA champions the right to access information, it operates within a broader legal landscape that includes data protection laws, such as the General Data Protection Regulation (GDPR). These data protection laws are designed to safeguard individuals’ personal data, ensuring that it is processed and handled with care and respect for privacy.

This creates a delicate balancing act. On one hand, the FOIA asserts the right to access information, while on the other, data protection laws assert the right to protect personal data. This tension necessitates careful consideration and scrutiny when personal data is involved in FOIA requests.

Categories of Personal Data under FOIA

FOIA permits access to a wide array of information, including personal data. This term, as defined by the GDPR, means:

“anything that by itself or in combination with other data could lead to someone being identified”

You can learn more about the scope of personal data processing under the GDPR here. However, this definition of personal data is clearly more than name, or other obvious identifiers.

Examples of personal data that may be requested under FOIA includes

  • employment records of public officials,

  • records of expenses claimed by government employees

  • correspondence involving identifiable individuals.

Exemptions and Limitations

While FOIA is a powerful tool for transparency, it’s not without limitations. The legislation includes various exemptions that can prevent the disclosure of personal data. These exemptions are in place to strike a balance between the right to access information and the right to protect privacy and sensitive data.

For instance, personal data might be withheld if its disclosure would breach the data protection principles, such as the requirement to process data fairly and lawfully. Other grounds for withholding information include national security, legal privilege, and commercial interests.

Crucially there is a specific exemption to disclosing personal data under FOIA. Section 40 of the Act excludes disclosing information about the person making the freedom of information request (“the requestor”) because there is another way for them to do so: making a subject access request.

There is no specific exemption to disclosing the information of third parties to requestors. This means it can be done, but must be done in a way that is GDPR compliant. Section 40 of the FOI Act also covers the conditions by which third parties’ personal data may be shared.

You can read that section of the Act here. However, it is a little densely worded so: how does it work?

Sharing Personal Data Under GDPR

If a requestor makes a freedom of information request that may involve the release of personal data there are a number of factors to consider.

Firstly, might other exemptions apply?

For example, under FOIA there is an exemption to releasing information if it might compromise the health and safety of a person. You can also refuse to release information if it is reasonably available to the requestor by other means e.g. it is already in the public domain.

Secondly what is the minimum data that should be released here? We dealt with a FOIA request for a client that asked for the remuneration associated with specific roles. We recognised that the remuneration package an individual receives depends on a number of factors, such as seniority and experience. Some state benefits are administered through payroll and there may be expenses associated with supporting the person holding the post rather than the post itself.

Therefore we released generic information about the post such as the pay scales related to it and some of the generic benefits like training and pension contributions that would be available to all. This is reasonable because that is the kind of information the relevant public authority would put in the public domain when recruiting to the role anyway.

Data Minimisation and Anonymisation

Public authorities are encouraged to practice data minimization and anonymization when responding to FOIA requests that involve personal data. Data minimization involves limiting the amount of personal data shared to the minimum necessary for the purpose of the request. Anonymization, on the other hand, entails removing or altering identifying information to protect individuals’ identities.

These strategies strike a balance between transparency and privacy, allowing public authorities to fulfill their obligations under FOIA while safeguarding the interests of individuals whose data is being disclosed.

When Releasing Personal Data is Needed

Responding to requests that involve personal data under FOIA involves specific steps. Requests should be clear about the data that the requestor wants – although it doesn’t matter why they want it.

Requests should include the requester’s name and contact information, a clear description of the information sought, and any relevant details, such as timeframes or context.

Upon receiving a FOIA request, public authorities must process it promptly and effectively. They must identify whether the requested information contains personal data, apply any applicable exemptions, and determine if the information can be disclosed.

Timelines for responding to FOIA requests are set out in the legislation, ensuring that information is made available within a reasonable timeframe. This is usually 20 working days from receipt. Responsibilities for handling requests are typically designated to a designated FOIA officer within the organisation.

Complying with GDPR

Before releasing personal data to requestors there are a number of factors to consider. The primary duty public authority is to ensure that any release of personal data is lawful. NB the GDPR calls people whose data you are processing a “data subject”.

Privacy Principles

The GDPR rests on a small number of key privacy principles. The first one is that your data processing must be lawful, fair and transparent. That means if you are considering sharing personal data with a requestor it must be done:

  • on one of the lawful bases for data sharing set out in the GDPR

  • in a way that is fair to the person whose data may be shared

  • on the basis that the people affected know and understand what may happen with their personal information.

Lawful Routes for Data Sharing

There are a limited number of lawful routes for data sharing. You can read more about them in our content about GDPR here. Because you always need a lawful basis for sharing personal data, even in response to a freedom of information request, you must identify what it is before you proceed.

The main one you can rely on is consent. Consent is when people agree to their data being used – in this case shared – on the basis of a full understanding of what they are consenting to.

The other condition is if the people whose data has been asked for have put that information in the public domain. An example of this is people putting information about their professional activities on their LinkedIn profiles.

People’s GDPR Rights

People also have a number of rights to control how their data are used under the GDPR and one of those is the right to object. This applies to processing by public authorities so people can prevent their data being released in response to FOI requests. You cannot share personal data if people have exercised their right to object in most circumstances unless you can show there is a legitimate interest in providing the information that both:

  • overrides the grounds to the objection and

  • does not have a major impact on the privacy or other rights and freedoms of the person who objects

Sensitive Personal Data

Some classes of personal information such as health related data or criminal record data are considered sensitive and there are additional restrictions. In essence you can only lawfully share these types of personal information if either the people affected have given consent or they have themselves put the information in the public domain.

________________________________________________________________________________________________

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won’t use your data for anything else.

Sign Up Here:

________________________________________________________________________________________________

So What Do You Do?

IF you get a request for information that may involve the release of personal data then you must be able to say “yes” as the answer to these three questions:

  • can we explain to the people affected what has been requested and why we might need to share it?

  • can we seek consent or demonstrate the information is already in the public domain?

  • if any of the people affected object to the sharing of their data can you identify a clear legitimate interest that allows you to share the personal data without a negative affect on those individuals?

If the answer to any of these is “no” then you should issues a refusal notice. This will explain that you will not be sharing the information requested, and why.

Challenges and Appeals

If a requester is dissatisfied with the response to their FOIA request, they have the right to challenge the decision. Challenges can take the form of an internal review within the public authority. If necessary people can complain to the Information Commissioner’s Office (ICO).

The ICO plays a crucial role in upholding FOIA compliance and data protection. They investigate complaints and can issue decisions that impact the release of information.

You can find out how to handle internal reviews here.

If the ICO considers a complaint the worst case scenario is usually that they will direct you to release the information requested.

Public authorities are encouraged to follow best practices when processing FOIA requests that involve sharing personal data. This includes conducting thorough assessments, applying relevant exemptions judiciously, and implementing strong data protection measures. If you have done this and issued a refusal notice the ICO is not very likely to overturn your decision. However, it is your responsibility to show you have acted with care and your decisions were reasonable.

________________________________________________________________________________________________

Learn About the Freedom of Information

Gain the practical skills you need work with Freedom of Information and GDPR with these five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

 

Training testimonial

________________________________________________________________________________________________

Conclusion: Understanding FOI and GDPR

Sharing personal data under the Freedom of Information Act 2000 is a nuanced process. FOI and GDPR require a delicate balance between transparency and privacy. Understanding the legal framework, exemptions, and best practices is crucial for public authorities and individuals alike. Ultimately, FOIA serves as a vital tool for transparency in government while ensuring that individuals’ data protection rights are upheld and respected.