Lynn Wyeth takes a look at some recent FOI and Data Protection issues, and what they mean for practitioners.
FOI
Public authorities must properly justify FOI cost refusals… even for neither confirming nor denying
The Information Commissioner’s Office (ICO) has issued a decision notice (IC-459750-S2Z6) reminding public authorities that they must have solid evidence before refusing Freedom of Information (FOI) requests on cost grounds. This one is slightly unusual though as it relates to section 12(2) – refusing to confirm or deny on cost grounds.
The case involved a request to the Department for Work and Pensions (DWP) about whether it had carried out any legal reviews into whether the non-payment of Universal Credit to some people who die during an assessment period is compatible with the European Convention on Human Rights.
The DWP refused to even confirm whether it held the information, relying on section 12(2) of the FOIA. It argued that simply establishing whether the information existed would exceed the statutory cost limit.
The ICO agreed that the DWP could combine the different parts of the request because they all related to the same subject. However, it found that the department had failed to demonstrate that confirming or denying whether it held the information would genuinely exceed the cost limit.
The Commissioner criticised the DWP’s estimate for including activities that cannot legally be counted towards the FOI cost limit, such as management sign-off, checking estimates and preparing summaries. For section 12(2) the only thing you can count is locating the information.
The ICO also found that the searches carried out were far too broad, using generic search terms that produced hundreds of potentially irrelevant documents rather than focusing on the specific issue being requested.
The ICO ordered the DWP to issue a fresh response without relying on section 12(2).
Key learning points for FOI practitioners:
- Cost estimates must only include the activities permitted by the FOIA Fees Regulations. In the case of 12(2) – locating the information
- Estimates should be based on realistic, targeted searches supported by evidence.
- Broad or poorly chosen search terms may undermine a section 12 refusal.
- The ICO expects experienced public authorities to provide robust and well-evidenced cost estimates when relying on section 12.
DP
When too much personal data is shared: a reminder about data minimisation
The Information Commissioner’s Office (ICO) has issued a reprimand to Staines Health Group after it sent 23 years of a patient’s medical records directly to an insurance company, despite only five years of records being requested and those records first being intended for the patient to review.
The patient, who had been diagnosed with a terminal illness, believed that the excessive disclosure affected the value of their insurance claim.
The ICO found that the problem was not simply an individual mistake. It identified several organisational failings, including:
- No written procedure for staff handling insurance requests.
- Staff relying on old training rather than documented guidance.
- No regular refresher training.
- No effective quality assurance or checking process before records were disclosed.
Following the incident, the GP practice introduced written procedures, additional staff training, a sign-off process and carried out a full review of what had gone wrong. The ICO therefore decided that a reprimand, rather than a financial penalty, was the appropriate regulatory response.
The key lesson
One of the fundamental principles of the UK GDPR is data minimisation. Organisations should only disclose personal data that is adequate, relevant and limited to what is necessary for the purpose.
In practice this means asking simple questions before sending information:
- Has the recipient only asked for specific information?
- Am I sending more than is actually required?
- Has somebody checked the disclosure before it leaves the organisation?
- Does the individual need to see the information first?
Practical tips
To reduce the risk of excessive disclosure, organisations should:
- Have clear written procedures for routine disclosures.
- Train staff regularly, not just when they join.
- Introduce a second-person check for sensitive disclosures where possible.
- Use disclosure checklists.
- Review attachments carefully before sending.
- Remember that “more information” is rarely “better information”.
The Staines Health Group case is a useful reminder that data breaches are not always about cyber-attacks or sending information to the wrong recipient. Sometimes the breach is simply sending too much information to the right person and that can still have significant consequences for the individual concerned.
