Navigating the delicate balance: FOI versus data security – 8 key recommendations

As several recent high-profile cases have demonstrated, organisations can sometimes find themselves in a difficult situation where the principles of the Freedom of Information Act (FOIA) seem to conflict with those of data security.

While the FOIA gives members of the public the right to access government and publicly-held information, safeguarding sensitive data remains a crucial obligation. With the responsibility of upholding both transparency and security, it’s essential organisations understand and navigate this delicate balance thoughtfully.

In this post, we highlight some of the challenges and recommend how best to navigate them.

The power of transparency versus the non-negotiable priority of data security

Transparency is central to FOI legislation – members of the public have the right to know how government bodies and public institutions operate, fostering trust and accountability. 

However, transparency doesn’t have to mean complete exposure. The challenge lies in revealing information that enhances public understanding while safeguarding sensitive data.

That’s because, in an age where cyber threats are a daily reality, data security is a key concern for organisations of all sizes. With a responsibility to protect their sensitive information, organisations must defend against breaches, cyber attacks, and privacy infringements. A single data breach can, after all, lead to financial losses, legal repercussions, and reputational damage.

These two priorities can sometimes seem to be at odds with each other, as seen in the following high-profile incidents.

The clash: transparency vs security

Some recent examples have shown us exactly what’s at stake when the right balance between FOI and data security hasn’t been achieved:

PSNI data breach puts lives in danger

On August 8th 2023, the Police Service of Northern Ireland (PSNI) accidentally published the names and professional details of every single officer and civilian employee in the force, which compromised their data and jeopardised their safety.

The individuals whose data was leaked now face a unique terror threat from the New IRA, which demonstrated its intent to kill police officers as recently as February. 

The breach occurred when the police force uploaded the wrong Excel spreadsheet to a Freedom of Information website and revealed details many officers had kept secret, even from relatives and close friends.

The website had requested details of the force’s staffing levels by rank and grade, under Freedom of Information (FOI) laws, but the FOI officer responsible evidently failed to notice the file also contained a number of of data-rich tabs underneath, detailing more than 10,000 current and past employees, from the chief constable down to trainees.

This means current and past employees of the PSNI are now fearful for the safety of both themselves and their families.

Victims of crime and witnesses had their data breached by Norfolk and Suffolk police forces

On August 15th 2023, Norfolk and Suffolk police forces admitted that 1,230 people, including victims of crime and witnesses, had their data breached due to a ‘technical issue’ when responding to a FOI request.

They said the information was attached to 18 responses to FOI requests for crime statistics issued by the forces between April 2021 and March 2022.

According to the forces, the leaked data contained descriptions of offences including sexual and domestic assaults, and it included personal identifiable information on victims, witnesses and suspects relating to a range of offences including sexual offences, domestic incidents, assaults, hate crimes and thefts.

This directly conflicts with the right under law of victims of sexual offences to have lifelong anonymity.

A matter of government concern 

According to the Guardian, a leading author of the UK Freedom of Information Act has called for a parliamentary review into the system after these serious data breaches by police forces in response to FOI requests.

The call by Lord Clark of Windermere, who as Chancellor of the Duchy of Lancaster drafted the Blair government’s FOI proposals, said a serious re-examination was needed to look at whether the correct balance was being struck between the need for confidentiality and openness.

“I think there really does need to be a serious re-examination of the situation,” he said. “I would set up a parliamentary committee with a general view of examining FOI over the past 25 years, [and] the balance between confidentiality and openness.”

Finding an equilibrium between FOI and data security 

Balancing the right to access information against the need to protect sensitive data requires a strategic approach. 

A freedom of Information request does exempt disclosure of personal data if releasing it would be contrary to the UK General Data Protection Regulation (the UK GDPR) or the Data Protection Act 2018 (the DPA2018) – but unfortunately, slip-ups can still occur that can lead to damaging consequences.

Here are eight recommendations on how you can navigate this terrain:

1) Understand data sensitivity

Begin by classifying data into categories of sensitivity. Not all information is equally vulnerable, and this understanding helps prioritise protection efforts.

2) Foster transparency by design

Develop a proactive transparency approach by classifying your data and making externally classified information readily available to the public to mitigate the need for FOI requests. This reduces the risk of inadvertently releasing sensitive data.

3) Implement robust data protection measures

Protect your sensitive data through access controls, employee training regular audits (all of which are essential), but also make sure you encrypt sensitive data to protect it further.

4) Ensure compliance with FOI laws

Familiarise yourself with FOI laws and exemptions. Not all information is subject to disclosure, and understanding these nuances is crucial.

5) Conduct a risk assessment

Conduct thorough risk assessments before releasing information under FOI. Evaluate potential harm versus public interest and take precautions accordingly.

6) Implement an approval process for releasing information 

Even with clear policies, mistakes can still happen, like in the examples outlined above. This is why implementing an approval process for releasing information under FOI requests is vital, so other trusted team members can help catch any errors or spot potential issues with releasing certain information.

7) Utilise redaction and anonymisation

When releasing documents, use redaction and anonymisation techniques to protect sensitive details while fulfilling transparency requirements.

8) Adopt clear communication

Communicate your commitment to both transparency and data security to stakeholders. Openly discuss challenges and solutions to foster understanding. 

The path forward

It’s important to embrace a holistic approach that encompasses both transparency and data security, so creating policies, procedures, and protocols that address this duality will be key.

As the ICO says, ‘you should consider any information you release under the Act as if it were being released to the world at large’. By proactively seeking to provide information that is both informative and safe, organisations can showcase their commitment to public interest while demonstrating a responsible approach to data management. 

If you want to find out more about how to meet your data security responsibilities while ensuring you meet the requirements of the FOIA, get in touch with the Securious team using the contact form below.