How Should Public Authorities Handle FOI Requests from Journalists?

Journalists play an essential role in scrutinising the actions of government and public authorities, and in informing the public about decisions and actions that affect their lives. To do this, they often turn to the Freedom of Information Act to obtain information that is not otherwise in the public domain. Yet research by the London School of Economics suggests that journalists’ experience of the FOI process, particularly when dealing with central government, can be characterised by delays, unresponsiveness and refusals on grounds that may be difficult to verify. 

From the perspective of information governance and FOI professionals, however, the picture can look rather different. They are often working under significant resource and workload pressures, while dealing with journalists who may be seeking information against tight publication deadlines or hoping to secure a newsworthy “scoop”. 

So how can public authorities and journalists navigate these competing pressures?
And what can FOI professionals do to handle journalists’ requests in a way that is both legally sound and constructive? 

We answer these questions in episode 9 of the Guardians of Data podcast. 
Ibrahim Hasan was joined by Martin Rosenbaum. Martin spent 16 years at the BBC as the organisation’s leading specialist in using FOI for journalism. Over that time, he broke major stories, trained reporters, and took cases all the way to tribunal hearings.
Martin is also the author of Freedom of Information: A Practical Guidebook 

Martin’s experience provides some practical lessons for anyone responsible for handling FOI requests from journalists. 

Don’t treat journalists differently 

The first principle is perhaps the most important. A journalist is simply another requester under FOI. 

As Martin explains, FOI gives journalists a legal right to seek information that might otherwise be difficult to obtain. That does not mean every request should be disclosed, but neither should the identity of the requester influence the application of the legislation. For an information governance professional, the task is to apply the law properly, regardless of whether the requester is a journalist, campaigner, researcher or member of the public. 

Good relationships can reduce the FOI burden 

It is tempting to see journalists and FOI officers as being on opposite sides.
Martin’s experience suggests that this is unnecessary. A constructive professional relationship and good communication can actually reducethe workload associated with FOI. 

Communicate early 

One of Martin’s strongest messages is the importance of communication. Journalists often work to publication deadlines. That does not change the statutory requirements of FOI, but it does make prompt communication particularly valuable. From a journalist’s perspective, being contacted on day 19 to clarify something that could have been resolved on day two or three can be extremely frustrating. 

If a request is unclear, contact the journalist as soon as possible. A quick telephone conversation can often establish what the journalist is actually looking for, whether the information is held and how records are organised. It can also prevent the authority spending time searching for information that will not answer the journalist’s question. 

It can also help establish whether information can simply be provided without the need for a formal FOI process. Martin recalls situations where discussions with FOI professionals saved both sides considerable time by identifying information that was not held, explaining terminology or suggesting a more productive approach. 

Don’t confuse sensitivity with exemption 

Some requests from journalists will concern controversial or embarrassing subjects. That is part of the nature of investigative journalism. The potential consequences of publication should not become an informal additional exemption. 

Martin’s own experience demonstrates the value of persistence within the FOI system. Information initially withheld can sometimes be disclosed following an internal review, an ICO investigation or an appeal to the tribunal. He believes that information can sometimes be withheld too broadly at an early stage, with more detailed consideration later resulting in additional disclosure. 

The two rules to remember 

Asked for his best advice, Martin offered two pieces: Think clearly about what you really want and talk to people. These apply to both sides of the FOI process. 

For journalists, a precise request is more likely to produce the information they actually need. For information governance professionals, early communication can make requests easier to understand, search and process. The result is not necessarily less FOI. It is better FOI: a process in which requests are dealt with properly, resources are used sensibly and information that should be in the public domain is made available. And ultimately, that is what FOI is there to achieve. 

Listen to the podcast 

Listen to the full episode 9, in which Martin also discusses his experiences using FOI to investigate government, his battles with other public authorities, taking cases to tribunal, the impact of AI on FOI and what he would like to see FOI change in the future. 

If you want more perspectives on this important topic be sure to check out our other podcast episodes. In Episode 3, Maurice Frankel, the Director of the Campaign for Freedom of Information explains the history of FOI and his views on current and future challenges to the legislation. in Episode 14 barrister, Saara Idelbi, gives advice on handling AI generated information requests. Finally, Episode 17 Ben Worthy discusses the research studies that he has conducted into FOI practice, to give us an insight into the effectiveness of FOI in achieving transparency. We also explore what FOI can (and can’t) achieve and where transparency in the UK might be heading next.

New Podcast: FOI and Transparency in Practice 

In the UK, Freedom of Information laws are now more than 20 years old. If you want to understand how they have impacted the way government operates, there are plenty of clues in the news headlines over the last few years: 

  • The Covid Inquiry gave us an extraordinary insight into how ministers and officials communicated during the pandemic, including the extensive use of WhatsApp. 
  • The Peter Mandleson affair raised questions about the vetting of ministers and civil servants, and more broadly, about what the public is entitled to know about the people exercising public power. 
  • And internationally, the release of the Epstein files demonstrated the enormous public interest in information held by powerful institutions and the political consequences when information is withheld or released. 

In the latest episode of the Guardians of Data podcast we are joined by Dr Ben Worthy, a Reader in Politics and Public Policy at Birkbeck College, University of London. Ben has written extensively on issues around Transparency and Freedom of Information including authoring the book “The Politics of FOI”. Ben discusses the research studies that he has conducted into FOI practice in various sectors, to give us an insight into the effectiveness of FOI in achieving transparency. We also explore what FOI can (and cant) achieve and where transparency in the UK might be heading next. 

Listen on your preferred platform via our podcast page, or download the episode directly.  

If you want more perspectives on this important topic be sure to check out our other podcast episodes. In Episode 3, Maurice Frankel, the Director of the Campaign for Freedom of Information explains the history of FOI and his views on current and future challenges to the legislation. In Episode 9 we talk to Martin Rosenbaum, an 
ex-BBC Journalist, who shares practical tips on dealing with FOI requests from journalists. Finally, in Episode 14 barrister, Saara Idelbi, gives advice on handling AI generated information requests. 

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Dr. Agnieszka Piotrowska talking about the profound ways that Generative AI is changing human relationships, Professor Kistie Ball talking about employee surveillance without losing trust and Ilyas Nagdee analysing the impact of predictive policing on human rights. 

Goodbye Information Commissioner’s Office; Hello Information Commission

The UK’s Information Commissioner and Information Commissioner’s Office will be replaced by the Information Commission on 30th September 2026. This change was made by the Data (Use and Access) Act 2025 (DUA Act) although not brought into force until last week. 

On 10th September 2026, The Data (Use and Access) Act 2025 (Commencement No. 9 and Transitional and Saving Provisions) Regulations 2026, SI 2026/1015 were passed, bringing the relevant provisions of the DUA Act in to force. These establish a body corporate, the Information Commission. This new body will be led by a chair, chief executive, and other non-executive and executive members with shared decision-making responsibilities. The chair of the Information Commission will retain the title of “Information Commissioner”. No decision has made as to who the new chair will be. 

The Information Commissioner’s Office is currently structured as a corporation sole, with all powers and responsibilities vested in one individual, the Information Commissioner. Paul Arnold, the current CEO is acting up in this position; the previous commissioner having resigned in controversial circumstances. This change to the structure of the ICO will not change the role of the regulator; all functions that currently rest with the Information Commissioner will continue to sit with the new Information Commission 

For those interested in the technical aspects, Section 117 of the DUA Act inserts new section 114A into the DPA 2018 establishing the Information Commission. 
Section 118 abolishes the Information Commissioner, omitting relevant sections of the DPA 2018. Schedule 14 inserts new Schedule 12A into the DPA 2018, setting out the governance structure of the new regulator. 

If you are looking to implement the changes made by the DUA Act to the UK data protection regime, consider our very popular half day workshop.  

The newly updated UK GDPR Handbook (2nd edition) includes all amendments introduced by the DUA Act, with colour-coded changes for easy navigation and links to relevant recitals, ICO guidance, and caselaw that help make sense of the reforms in context.
We have included relevant provisions of the amended DPA 2018 to support a deeper understanding of how the laws interact. 

New Podcast: Employee Surveillance Without Losing Trust 

Last year’s report by the Chartered Management Institute (CMI) suggests that use of workplace monitoring technology has increased substantially in recent years. 1 in 3 organisations now actively monitor their employees’digital activity.  

Employee monitoring is nothing new. In the past this would have involved CCTV and telephone monitoring as well as vehicle tracking. But new technologies, particularly AI, are taking it to another level. Employers can now collect much more detailed information about what their employees do, where they are and how they work. This information is increasingly being used, with AI and algorithms, to allocate tasks and assess employee performance. 

In July, the UK government launched a consultation on the use of workplace monitoring technologies including surveillance tools, algorithmic management systems and AI-enabled decision-making. The closing date to respond is 30th September 2026. The consultation seeks views on whether additional regulation is needed to improve transparency, worker engagement and accountability when employers monitor workers.  

But just because employers can monitor employees, does it mean they should?
Can surveillance really improve productivity? What happens to trust when employees know that every action can be measured? And as AI takes on more employee management functions, what are employers losing when human judgement and relationships are replaced by algorithms? 

We answer these questions in the latest episode of the Guardians of Data podcast.
The host, Ibrahim Hasan, is joined by Professor Kirstie Ball from the University of St Andrews. Kirstie is an internationally recognised expert on workplace surveillance and the author of “Electronic Monitoring and Surveillance in the Workplace”, a report  published by the European Union. She is also the co-director and founder of the Centre for Research into Information, Surveillance and Privacy and has been a consultant to the UK Information Commissioner’s Office. 

The focus of this podcast is not the law on workplace monitoring. It’s a conversation about what happens when surveillance changes the relationship between employers and employees. We talk about trust, dignity, autonomy and wellbeing as well as whether technology designed to improve performance can sometimes have the opposite effect. 

Listen on your preferred platform via our podcast page, or download the episode directly.

Please complete Kirsty’s Survey 

You are invited to complete this survey if you have used the ICO’s Data Protection and Worker Monitoring Guidance. The survey asks you whether you have noticed any changes in your and others’ understanding of electronic monitoring as a data protection issue, and if you have noticed any changes in compliance since using the guidance. It takes five minutes to complete. 

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for – with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Dr. Agnieszka Piotrowska talking about the profound ways that generative AI is changing human relationships, Caroline Wong explaining the impact of AI on Cybersecurity, Andrew Latham talking about the data protection risks in employment and Ilyas Nagdee analysing the impact of predictive policing on human rights.

Reform Will Repeal the UK GDPR

Today Reform UK, the right-wing party, will announce a set of ‘flagship policies’, including dropping the UK GDPR. Robert Jenrick, the party’s treasury spokesperson, will unveil a plan to replace the UK GDPR with a ‘light-touch style privacy law modelled on New Zealand’. The plans are part of a bid to slash ‘red tape’ for businesses. 

Ahead of his announcement, Jenrick said, ‘GDPR has strangled small businesses and tech firms alike in a web of unnecessary regulation.’ He added, ‘Ten years after the Brexit referendum we should not still be following ridiculous EU privacy laws that hurt British businesses.’ 

This announcement shows a lack of understanding about the nature of UK data protection law; which is common amongst politicians. The UK GDPR is not an ‘EU privacy law’; the clue is in the name. Following Brexit, the conservative government had a chance to make GDPR more ‘British’; they made (in the main) superficial changes including adding ‘UK’ to the title.  

We have been here before. Successive governments have proposed and then rowed back on data protection reforms. The most radical of these were in the Data Reform Bill. This was part of the Theresa May Government’s plans to ‘Replace the UK GDPR with a new, more proportionate, UK Framework of Citizen Data Rights.’ There was also the abandoned Data Protection and Digital Information Bill (two versions!). 
In the end they all concluded that, ‘It’s not broke, so let’s not fix it’. The most recent amendment to the UK came in the form of the Data (Use and Access) Act 2025 which many have described as ‘tinkering around the edges’. 

What Jenrick calls a ‘a web of unnecessary regulation’ includes the right of subject access which was used by Nigel Farage himself to discover the truth about his Coutts bank account being downgraded. 

Even if the UK GDPR is replaced it will not fully remove the ‘red tape’ for business especially the tech firms which Reform seems to be courting with these proposals.
The EU GDPR’s ‘extra territorial effect’ will still apply to many big companies as their business will involve ‘the offering of goods or services, to… data subjects in the [EU] or the monitoring of their behaviour as far as their behaviour takes place within the [EU].’(Article 3(2)). 

There is no report of Reform making any amendments to the Data Protection Act 2018, part 3 of which governs processing of personal data or law enforcement purposes.

This morning Data protection officers and privacy professionals may be asking ChatGPT about the New Zealand’s Privacy Act. And who can blame them as, despite the ‘Burnham Bounce’, there is still a good chance that Reform UK will form the next government. Here is a useful summary of the New Zealand legislation courtesy of the law firm Linklaters. 

Now is the time to remind yourself of the importance of data protection law. 
Listen to Episode 10 of the Guardians of Data Podcast. Our guest is Emma Martins who served as Data Protection Commissioner for the Bailiwick of Guernsey for over a decade. Emma is one of the most thoughtful voices in the world of privacy and information governance. In our conversation, she reminds us that data protection law is about far more than compliance checklists, privacy notices or subject access requests. At its core, it is about people, power, democracy and human dignity.

New Podcast: Analysing Human Relationships with AI Chatbots 

One of the most popular BBC comedies of late is Ann Droid. The main character, Sue (Sue Johnstone from Brookside and the Royle Family) is still grieving for her late husband when her son buys her a surprise to help her live independently: an Ann Droid Z58/100 humanoid care robot. Sue initially rejects her new companion but learns to live with it and eventually grows very fond of it, sharing her inner most thoughts and fears. The show is of course set in the future, but how long will it take for the central premise to become reality? 

In recent years, we’ve seen a remarkable shift in the way people use AI chatbots.
They are no longer simply tools for answering questions or writing emails.
Many people are entering into deep conversations with the likes of ChatGPT and Claude, often forming emotional and even romantic relationships with them.  

Last year’s controversy surrounding GPT-4o was a striking example: In April 2025, OpenAI rolled back an update to GPT-4o after users complained that the chatbot had become excessively flattering and agreeable. OpenAI described the behaviour as ”sycophantic” and acknowledged that the model could go beyond ordinary flattery, including validating doubts, fuelling anger, encouraging impulsive actions and reinforcing negative emotions. 

What was perhaps more surprising was that GPT-4’s eventual retirement prompted some users to describe a genuine sense of loss. At the same time, lawsuits alleging that AI chatbots have caused harm to vulnerable young people have raised serious questions about emotional dependency and the responsibilities of the companies developing these systems.  

So what is actually happening when we begin to form relationships with machines that can talk to us, remember us and appear to understand us? And what does it tell us about ourselves? In the latest episode of the Guardians of Data podcast, Ibrahim Hasan talks to psychologist, academic and award-winning filmmaker Dr. Agnieszka Piotrowska about the profound ways that generative AI is changing human relationships, drawing on the themes of her book  AI Intimacy and Psychoanalysis.  

We talk about why people form bonds with AI, the potential benefits for companionship, creativity and accessibility, and the risks surrounding privacy, emotional dependency, mental wellbeing and digital amnesia. We also explore the importance of boundaries, education and proportionate regulation as AI grows more personalised and embedded in everyday life. 

Listen on your preferred platform via our podcast page, or download the episode directly.

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’t designed for, with Phaselaw you collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Caroline Wong talking about the impact of AI on Cybersecurity, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, and Ilyas Nagdee analysing the impact of predictive policing in human rights. 

AI and Cybersecurity: Why Trust Is the New Battleground 

Artificial intelligence is reshaping cybersecurity. Recent examples of AI behaving in unexpected ways have added urgency to the debate about how these systems should be controlled and where responsibility lies. The first such case involved ChatGPT-maker OpenAI acknowledging that its model had hacked the Hugging Face website. Anthropic and Meta have also reported similar cases. 

In a recent episode of the Guardians of Data podcast, host Ibrahim Hasan spoke with Caroline Wong, cybersecurity expert and author of The AI Cybersecurity Handbook, about how AI is impacting cyber security; from accelerating attacks and strengthening defences to changing the skills cyber professionals need.  

Lowering the barrier for attackers 

AI is making sophisticated cyber hacking capability available to people with far less training. Tasks once requiring extensive manual effort can now be automated or guided by readily available tools. Caroline explained that someone with only “ten to one hundred hours” of experience may now conduct activities that previously demanded “a thousand or ten thousand hours” of expertise. 

Reconnaissance is a good example of this. Attackers can rapidly gather public information about an individual or organisation, including writing style, vocabulary, voice and professional relationships. A task that once took an hour may now take minutes. This brings privacy, data protection and cybersecurity closer together: organisations must consider what information is public, who can access it and how easily AI can turn scattered data into actionable intelligence. 

Social engineering becomes more convincing 

Social engineering targets human behaviour rather than a technical flaw. AI enables criminals to generate fluent, personalised messages in any language and adopt a credible persona; perhaps a senior executive, a worried relativeor a hurried delivery worker. Old advice about spotting poor grammar or suspicious graphics is no longer enough. Deepfake audio and video can imitate familiar people so convincingly that seeing or hearing is no longer believing. 

Modern scams exploit excitement, pressure and trust, and their quality makes occasional mistakes increasingly understandable. Caroline’s practical test for spotting deepfakes and scams is simple: Did I expect this message? Is it asking me to act, disclose information or transfer money? If anything feels unusual or urgent, verify the request through a separate channel. A call apparently from a relative, for example, should be checked by sending a message using trusted contact details; not by relying on the communication that triggered suspicion. As Caroline says, “You’ve got to pay attention to your nervous system, and you’ve got to learn how to pause.” 

Malware at machine speed 

AI is also changing malware. Traditional cyber defences often rely on signatures: recognisable technical characteristics used to identify and block malicious code.
But attackers can now create many variants quickly, including malware that changes inside a system. As Caroline puts it, “Rule-based detection can’t keep pace with
AI-generated novelty.” 

Defenders therefore need to focus increasingly on behaviour rather than appearance. The challenge is to identify what software is doing, such as unusual access or suspicious movement across a network, rather than relying on a fixed fingerprint that may disappear with the next iteration. 

AI gives defenders an advantage too 

The discussion with Caroline was not all doom and gloom. AI can help defenders not just attackers. It can accelerate repetitive security work, including third-party vendor risk assessments, customer due-diligence questionnaires and information gathering. Automating coordination and routine analysis can free security professionals to spend more time on judgement, governance and strategic risk management. 

However, Caroline cautioned against seeing AI as a product that can simply be purchased to make problems disappear. “AI is not a silver bullet,” she stressed. It remains error-prone, requires experimentation and does not remove the need for human communication or sound security basics. Budget disparities also remain: a small organisation cannot deploy the same resources as a multinational. Even AI usage itself carries ongoing token, operational and environmental costs that leaders must assess over time. 

The vulnerability-fixing gap 

The podcast also explored advanced AI systems capable of finding and exploiting software vulnerabilities far faster than humans. Caroline’s key concern is an emerging imbalance: discovery can be compressed from months or days into minutes, while remediation has not accelerated at the same rate. “We now have a significantly improved approach for finding vulnerabilities, but we don’t yet have an equally speedy approach for fixing vulnerabilities,” she warned. 

She was sceptical that banning powerful AI tools, such as Mythos, would provide a durable solution. Equivalent models are likely to emerge elsewhere and prohibition may concentrate access among a privileged few rather than eliminate the capability. The stronger response is therefore governance, controlled access, coordinated disclosure and investment in faster remediation. 

Trust, judgement and the future workforce 

Ultimately, trust is the new battleground. AI-generated voices, faces and “digital twins” complicate how people establish authenticity. Yet Caroline does not foresee cybersecurity becoming a fully automated discipline. Her five-year vision is a blended workplace in which humans communicate with both human and agentic AI colleagues. The crucial question will be where human oversight is required and at what level of abstraction. 

For professionals in cybersecurity, privacy and data protection, Caroline’s advice is to remain curious, learn quickly and gain hands-on experience with AI. Technical knowledge matters, but so do communication, judgement and the ability to work across organisational boundaries 

The enduring takeaway from this podcast is that AI will amplify capability, not abolish human responsibility. Organisations that combine useful automation with strong governance, verification and experienced judgement will be best placed to manage what comes next. As Caroline observed, “Judgment and opinion and experience are things that the machines cannot take away from us.” 

Listen to the full episode with Caroline Wong here.  

We have two workshops coming up (How to Increase Cyber Security in your Organisation and Cyber Security for DPOs) which are ideal for organisations who wish to upskill their employees about cyber security.

ICO Reprimand Issued to ACRO Criminal Records Office 

The Information Commissioner’s Office has issued a reprimand to ACRO Criminal Records Office (ACRO) after cyber security failings left the personal data of up to ten thousand people potentially exposed. 

The ICO’s investigation found that between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS). The attacker was able to stage personal data to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems. 

The investigation found that up to 10,920 people may have been affected.
The data potentially exposed included names, dates of birth, addresses, National Insurance numbers, passport and driving licence details, bank account information, biometric data, and highly sensitive criminal offence and special category information. Those affected included applicants for Police Certificates and International Child Protection Certificates, subject access request applicants, and third parties connected to those applications. 

The ICO found ACRO had engaged third-party providers to deliver certain security services, including patch management. However, ACRO did not ensure clear responsibility for identifying and monitoring critical CMS security updates, failed to maintain an effective patch management process, and did not adequately investigate security alerts that could have identified the hacker’s activity earlier. 

In deciding to issue a reprimand, the ICO considered a number of mitigating factors. Network segmentation prevented the hacker from moving beyond the compromised website environment into core systems, reducing the potential scale of harm.
The ICO additionally welcomed the remedial action taken by ACRO following the incident, including decommissioning the compromised infrastructure, migrating services elsewhere, implementing security monitoring, improving visibility of cyber threats and strengthening network segmentation. 

The Reprimand mentions infringements of Articles 32(1), 32(1)(b) and 32(1)(d) of the UK GDPR. However some commentators have questioned whether it should be for breaches of Part 3 of the Data Protection Act 2018 which applies to law enforcement processing (See Jon Baines post here.) 

With the rapid advance of AI, including emerging threats from AI agents, it is critical that organisations focus on cyber security. The ICO has highlighted the following action points for organisations to avoid similar breaches: 

Make accountability clear: Define who is responsible for identifying, assessing and implementing security updates across all systems and suppliers. 

Act on warning signs: Ensure security alerts are actively monitored, investigated and escalated so threats are identified before they become major incidents. 

Get the basics right: Effective patch management, vulnerability management and regular security testing remain some of the most important defences against cyber attacks. 

The ICO’s guidance on cyber security can be read here

For more on this topic, listen to Caroline Wong, an AI cyber security expert, speaking on the Guardians of Data podcast. 

We have two workshops coming up (How to Increase Cyber Security in your Organisation and Cyber Security for DPOs) which are ideal for organisations who wish to upskill their employees about cyber security.  

New Podcast: Handling AI Generated Information Requests

Many organisations are seeing a massive increase in AI generated Freedom of Information requests and GDPR Subject Access Requests (SARs). For example, Lincolnshire County Council received almost 2000 FOI requests in the last financial year; an increase of 18% compared to the previous year. No doubt the same is the case for SARs. 

AI has democratised and powered access to information. Large Language Models, like ChatGPT and Claude, can produce ‘perfectly written’ FOI requests and SARs at the touch of a button. But these are causing problems for over loaded information governance departments. Not only are more requests coming through; they are often longer, broader and difficult to interpret.  

In the latest episode of the Guardians of Data podcast we guide information governance practitioners to help them manage and lawfully respond to AI generated information requests. Our guest is Saara Idelbi from 39 Essex Chambers. Saara practises in administrative law, human rights, data protection and information rights. She is named by the Legal 500 as a ‘leading junior’ barrister. Saara is a recognised voice on AI and the law and is the co-founder of Advocatr, an AI legal training platform. 

Listen on your preferred platform via our podcast page, or download the episode directly, for practical guidance on how to handle AI generated information requests whilst respecting the key principles of information rights legislation: openness, transparency and accountability.  

This podcast is sponsored by Phaselaw – a purpose-built solution for document disclosures, like subject access requests and FOI requests. Instead of redacting PDFs one by one, or forcing litigation software to do a job it wasn’tdesigned for, with Phaselaw you get collection, review, and redaction in one workflow. Teams across the World are using it to cut response times from weeks to days. 

For Guardians of Data listeners, Phaselaw is offering a two-month free trial; run it on live requests, see what it does to your backlog, decide from there. No card, no commitment. 

Head to https://www.phase.law/guardians to claim your free trial.  

Previous episodes of the Guardians of Data podcast have featured Caroline Wong talking about the impact of AI on Cybersecurity, Jen Persson, a privacy campaigner, explaining the privacy implications of the Government’s new plans for children’s data, and Ilyas Nagdee analysing the impact of predictive policing in human rights.

Council Employee Given Suspended Sentence for Illegal Personal Data Access 

Rogue employees accessing personal data for their own gain, or just morbid curiosity, is a real issue for organisations, especially in the public sector, who hold vast databases of information about service users. 

In May, the medical director of Nottingham University Hospitals issued a public apology after staff inappropriately accessed the medical records of victims of the Nottingham attacks. Eleven employees were dismissed following initial investigations into the data breaches. In the same month, Aintree Hospital in Liverpool admitted that nearly fifty employees had pried into the medical records of victims of the Southport knife attack. 

Section 170 of the Data Protection Act 2018 makes it a criminal offence for a person to knowingly or recklessly obtain or disclose personal data without the consent of the controller. Over the years there have been a number of prosecutions under section 170 usually resulting in a fine. Most recently a teenage mechanic was fined £706 after he shared a football referee address and phone number online following a controversial penalty decision.  

Section 170 prosecutions would have a much greater deterrent effect if the sanctions included a custodial sentence. Successive Information Commissioners have argued for this but to no avail. This has led to some cases of unauthorised data access being prosecuted under section 1 of the Computer Misuse Act 1990 which carries tougher sentences including a maximum of 2 years imprisonment on indictment.  

In July the ICO announced that it had used Section 1 to successfully prosecute a council worker who accessed hundreds of personal records without lawful authority. Geoffrey Smith was a new employee at Herefordshire Council working in the Children and Young People directorate. His conduct was discovered after concerns were raised within the council about potential unauthorised access to a referral case, prompting an investigation into other records he had accessed. That investigation revealed that, over a four-day period, Smith unlawfully accessed approximately 490 records and downloaded 94 documents. The records related to his family members and families known to him and included children and adults. The records accessed involved highly sensitive material such as medical records, social worker reports and child and family assessments.  

On 27th May 2026, Smith pleaded guilty to an offence under Section 1 of the Computer Misuse Act 1990. He was sentenced to two months imprisonment suspended for 12 months, 120 hours unpaid work, £2000 costs plus a victim surcharge of £154.  

If a disgruntled or rogue employee commits a data protection offence, the employer may also be liable for the consequences. More on this in episode 13 of the Guardians of Data podcast where we discuss: 

  • what happens when employees are involved in personal data breaches; 
  • the legal and practical issues arising when employees misuse personal data; 
  • how employers should approach workplace investigations involving personal data; and 
  • how to respond effectively to employee Data Subject Access Requests. 

Our guest is Andrew Latham, a partner in the Public Law team at Capsticks, who specialises in data protection and privacy law.  

Click here to listen to Andrew.