The competing demands of Freedom of Information and Data Protection legislation in the UK present challenges for all public bodies involved in collecting, holding and disclosing personal information. Understanding the interface between Freedom of Information laws (including the Environmental Information Regulations 2004) and the General Data Protection Regulation is essential for all those involved with information management in the public sector.
This session, which is designed for people who already work with FOI issues, explains the key principles underlying the differences between FOI and data protection laws, including when personal data should and should not be released in response to subject access requests and FOI/EIR requests. Delegates who do not have an existing understanding of the basics of FOI law are recommended to attend FOI Level 1 before attending this session.
The session includes:
- knowing whether an information request should be dealt with under the GDPR/DPA 2018, or under FOI (or EIR) law (or under both sets of regimes)
- recognising and determining what is personal data
- the interpretation and practical application of the personal data exemptions (in s 40, FOI Act) and EIR exceptions (in Regulation 13, EIR))
- the legal principles governing such public access
- disclosing information about public authorities’ staff to the public
- analysing the practical implications of key decisions of the Commissioner (in future, the Information Commission), the First-Tier and Upper Tribunals, and the higher courts
This session enables delegates to understand how to manage requests for personal data, and to achieve best practice within their organisation.
It takes into account relevant changes arising from the Data (Use and Access) Act 2025.
“Very interesting day. It's given me a lot more confidence about applying s40, because I now understand the principles it's based on.”