Under the microscope: FOI & DP August #2 2026

Lynn Wyeth takes a look at some recent FOI and Data Protection issues, and what they mean for practitioners.

FOI

What should we advise?

Section 16 of FOIA requires public authorities to provide reasonable advice and assistance to those making, or wishing to make, information requests. When a public authority refuses a request because the cost of compliance exceeds the appropriate limit, it should explain to the requester how they could refine their request so that it would fall within that limit. In rare cases, it will be appropriate for the public authority to explain why the request cannot be meaningfully refined.

In recent decision notice IC-422771-P8J9, the public authority suggested that the complainant:

  • Narrow the timeframe of their request, for example to a specific term or academic year,
  • Limit the request to a particular individual or department, or
  • Focus on specific types of documents, for example formal reports or meeting minutes.

This was acceptable to the Information Commissioner’s Office as meeting the duty to provide reasonable advice and assistance.

A second decision notice, IC-513594-G4S4, allowed the following narrative as complying with Section 16:

“If you refine your request further, for example by requesting general information about the measures that are being taken regarding asylum seekers who commit VAWG offences and foreign national offenders, including those measures listed in the Action Plan that accompanies the Strategy on gov.uk, we may be able to comply with a future request. However, I cannot guarantee that this would be the case. I should also point out that a future request may still exceed the cost limit and it is possible that other exemptions in the Act might apply.”

These examples give public authorities a useful steer on what sort of suggestions can be made in order to comply with Section 16’s requirements.

DP

When does a data protection breach become a criminal offence?

Many data protection incidents are dealt with through training, disciplinary action or improvements to procedures. However, a small number cross the line into criminal behaviour. Recent prosecutions by the Information Commissioner’s Office (ICO) are a timely reminder that deliberately misusing personal data can have serious consequences, including criminal convictions, suspended prison sentences and confiscation of criminal assets.

One of the clearest examples came in July 2026 when a newly appointed Herefordshire Council employee unlawfully accessed around 490 records over a four-day period, downloading 94 highly sensitive documents relating to children, families and people known to him. The information included medical records, social work reports and child assessments. He pleaded guilty to an offence under the Computer Misuse Act 1990 and received a suspended prison sentence, unpaid work, costs and a victim surcharge.

Earlier this year, the ICO secured further convictions against Christopher Munro and William Chipoma following its long-running investigation into the unlawful sale of personal data within the claims management industry. Investigators found that both men deliberately obtained employment specifically to gain access to personal information, which they then sold for profit. Both received suspended prison sentences and community orders, with the ICO making it clear that it is also pursuing recovery of the financial benefit obtained through the Proceeds of Crime Act.

The ICO has also demonstrated that prosecution is not the end of the matter. In May and June 2026 it successfully obtained confiscation orders totalling more than £118,000 against two former RAC employees who had previously been convicted of unlawfully copying and selling almost 30,000 customer records. One individual was ordered to repay more than £85,000 and the other more than £33,000, in addition to their earlier criminal sentences.

Most organisations already tell staff not to misuse personal data, but these cases highlight several practical points that are worth reinforcing. Staff should never access records unless there is a genuine business need to do so. Looking up information about family members, friends, neighbours, celebrities or even your own record without authorisation can amount to unlawful access.

Organisations increasingly monitor system activity. Audit logs routinely record who accessed which records, when they did so and what actions they carried out. Many of the ICO’s prosecutions began after unusual access patterns were identified.

Staff should understand that criminal liability is personal. While an organisation may face regulatory action for poor security or governance, employees who deliberately misuse systems can themselves be investigated, prosecuted and ordered to repay any financial gains. Any such prosecution will show up on future DBS checks.