Under the microscope: FOI & DP December ’25

What should we be publishing?

You’ll most likely, as an organisation, have a website, and some of you may have a FOI disclosure log and/or an open data site. But what must you be proactively publishing on any of those?

The publication of some information is mandatory due to

  • the obligation to have a Publication Scheme
  • the requirements in the FOI s45 Code of Practice (updated July 2018)
  • through the Environmental Information Regulations (EIRs)
  • from the Protection of Freedoms Act 2012 (for datasets)
  • for Local Government, the Local Government Transparency Code.

Whilst the FOI’s Publication Scheme only gives headings and leaves the actual information you publish up to you, other codes and legislation are more prescriptive.

EIRs: One of your obligations under the Environmental Information Regulations is to publish environmental information proactively by easily accessible electronic means. This includes policies, plans and procedures relating to the environment, reports on the state of the environment, and environmental impact studies. It also includes data taken from monitoring activities and risk assessments that affect or are likely to affect the environment

The Protection of Freedoms Act 2012: Datasets should be provided in an electronic format capable of re-use, with a licence for re-use, and newer versions regularly made available through publication.

FOI s45 Code of Practice – Those authorities with over 100 Full Time Equivalent (FTE) employees should publish details of their performance on handling FOI requests on a quarterly basis. For all public authorities covered by the FOI Act, pay, expenses and benefits of the senior staff at director level and equivalents should be published quarterly.

Local Government Transparency Code: The Ministry of Housing, Communities and Local Government (MHCLG) published a local government transparency code (‘the Code’) in 2015 that sets out the data that local authorities should be publishing, the frequency it should be published and how it should be published. It includes expenditure over £500, government procurement card transactions, procurement information, grants, organisation chart, senior salaries, the pay multiple, trade union facility time, local land assets, parking spaces, social housing asset value, fraud, the constitution.

It’s also worth reviewing your FOI requests every year to see if there are specific things you get asked for repeatedly. If so, consider publishing that data regularly so that future FOI requests can be answered under section 21 (accessible elsewhere) and section 22 (for future publication).

DP

Working out whether someone is using personal data in their business capacity or for personal reasons can sometimes be a grey area. In the judgement of Harrison v Cameron & ACL [2024] EWHC 1377 (KB) there were various considerations given as a result of recordings of threatening phone calls being shared amongst friends, family and colleagues.

The claimant, a property-investor (“Mr Harrison”), and the first defendant (“Mr Cameron”), a director of a landscaping company (“ACL”), fell into dispute over a landscaping contract. During telephone calls, unknown to Harrison, Cameron recorded two calls in which Harrison threatened him. Cameron then shared those recorded calls with a group of people — employees, friends, family and others (around 15 individuals).

Harrison made subject access requests requesting the identities of all individuals who had received the recordings. He requested this from both Cameron personally and from ACL.

  • Did Cameron’s recording and sharing of calls constituted “purely personal or household activity” — in which case GDPR might not apply.
  • Did Cameron personally qualify as a “data controller” (and so had obligations under GDPR), or was the company (ACL) the controller.
  • Was the claimant entitled under Article 15(1)(c) UK GDPR to receive the actual identities of the recipients (not just categories such as “friends/family/employees”).

The Court held that the recording and sharing was not a “purely personal or household activity”. Because the recordings related to a contract dispute and were made / distributed in the context of the business, the processing fell within the scope of GDPR / DPA 2018. Cameron was not treated as a data controller in his personal capacity. The Court found he acted as a company director / agent of ACL, and the company was the relevant data controller.

In principle, the Court accepted that a data subject has a right under Article 15(1)(c) to know the actual identities of all recipients of their personal data — not merely categories — unless providing them is impossible or manifestly excessive. However, the Court found that in this case the “rights of others” exemption was properly applied: given the claimant’s (Mr Harrison’s) prior threatening behaviour, and subsequent aggressive DSAR letters to numerous employees and acquaintances, disclosure of identities carried a real risk of intimidation or harassment.