Reading time 3 mins
Freedom Of Information (FOI) Toolkit
This Event Toolkit supports receipt, tracking and response to Freedom Of Information (FOI) requests across health and social care. It enables lawful, auditable decision‑making, protection of sensitive and patient data, timely responses within statutory timeframes and effective governance and escalation where exemptions, safeguarding or ICO review are involved.
Legislative Requirements
- Care Act 2014 — ensure disclosures under FOI promote wellbeing, dignity and respect for vulnerable adults; balance transparency with safeguarding obligations and lawful information sharing.
- Mental Capacity Act 2005 — when FOI requests engage information about people who may lack capacity, apply best‑interests reasoning and avoid disclosing personal data inappropriately via FOI routes.
- Freedom of Information Act 2000 (FOIA) — recognise FOI requests as a legal right to recorded information from public authorities (NHS bodies, local authorities, publicly funded providers). Providers must:
- Provide a clear route to submit FOI requests and publish a publication scheme.
- Confirm whether information is held and respond substantively within 20 working days (or record and justify any lawful extension).
- Apply exemptions lawfully, document reasoning and maintain records of decisions and response times.
- Provide internal review routes and cooperate with the Information Commissioner’s Office (ICO) when required.
- Data Protection Act 2018 / UK GDPR — FOI handling must not result in unlawful disclosure of personal data. Apply data minimisation and consider whether NHS subject access (DPA) routes rather than FOI are appropriate for personal data requests.
Regulatory Guidance
CQC (England)
- CQC does not publish FOI‑specific guidance but its regulations affect FOI practice: ensure FOI handling does not compromise Regulation 12 (safe care), Regulation 17 (good governance) or Regulation 18 (staffing and competence).
- Inspectors expect robust systems to manage statutory obligations, evidence of staff competence for FOI processing and clear governance oversight of disclosure decisions.
Care Inspectorate Scotland
- FOI is governed in Scotland by separate legislation (FOISA) but registered services must demonstrate governance and transparency without risking confidentiality or ongoing safeguarding processes.
Care Inspectorate Wales (CIW)
- CIW expects providers to be open and transparent and to handle FOI lawfully. Records of FOI activity and governance should be available for scrutiny.
Statutory Guidance
- Accountability — organisations are legally accountable for receipt, management and disclosure decisions under FOI; maintain auditable records.
- Duty of Candour — FOI should not be used to avoid candour obligations; factual information that must be shared under duty of candour should not be withheld improperly.
- Safeguarding — do not disclose information that would undermine safeguarding enquiries or the safety of individuals; apply exemptions and redaction where required.
- Reporting timelines — respond within 20 working days or document a lawful extension and reasons; retain records of timelines and communications.
Health care Guidance
- Department of Health & Social Care — expect FOI handling to align with broader transparency and accountability expectations; publication of FOI performance data is encouraged.
- Scottish Government — Scottish providers must comply with the Freedom of Information (Scotland) Act 2002 and integrate FOI practice with clinical governance while protecting confidential information.
- Welsh Health & Social Services — Welsh providers must align FOI handling with CIW expectations and Welsh transparency standards.
- NICE / other guidance — governance, risk management and quality frameworks should include FOI responsibilities and risk assessment where disclosure could affect care or safety.
Evidence Based Practice
- Maintain clear FOI policies aligned to FOIA, DPA 2018 and relevant national guidance.
- Assign trained FOI leads with information governance expertise and ensure staff competence for initial triage and redaction.
- Use structured decision records for exemption tests, public interest balancing and redaction rationale.
- Integrate FOI processes with safeguarding, clinical governance and PSIRF learning systems to treat disclosure failures as potential safety intelligence.
Clinical governance and Safety (NHS)
- Treat unlawful disclosure or FOI failures that impact care as patient safety incidents under PSIRF where appropriate; apply systems thinking to identify latent governance failures.
- Ensure FOI data and metrics feed into governance committees and board assurance to demonstrate oversight, timeliness and remedial action.
Using the Toolkit — Practical Steps
- Log the Request — capture requester contact, date received, request text, service(s) involved and whether request is for published information or new disclosure.
- Triage & Acknowledge — acknowledge promptly, confirm scope, clarify if needed and identify whether request includes personal data (DPA subject access) or third‑party information.
- Search & Collate — locate records, identify relevant teams (clinical, IG, legal), and preserve evidence of searches and holdings.
- Assess Exemptions & Risk — apply FOI exemptions, public interest tests and DPA considerations; consult IG/legal for high‑risk disclosures (safeguarding, commercial sensitivity, health data).
- Redact & Prepare Response — redact personal data where required, prepare substantive response and document reasons for withheld information and applied exemptions.
- Approve & Send — route for appropriate sign‑off (IG lead / senior manager) and issue response within 20 working days or record lawful extension.
- Offer Internal Review — advise requester of internal review rights and timescales; maintain records of review outcomes and any changes to original decision.
- Record & Learn — store the complete audit trail (decision logs, redactions, consultations), log complaints/ICO interactions and feed learning into training and governance.
- Protect Data — ensure secure transmission, lawful basis for any onward sharing and retention of FOI records in line with IG policy.
Templates & Data Fields (recommended)
- FOI reference, status and requester contact details
- Service/team involved, date received, due date for response and acknowledgement timestamp
- Full request text and any clarifications or scope changes
- Search log: holdings checked, searchers, dates and results
- Personal data flag (DPA route required?), third‑party data flag, safeguarding flag
- Applied exemptions, public interest test record and redaction rationale
- Draft response, approvals, sending date and method
- Internal review requests and outcomes, ICO contacts and case references
- Attachments: released documents (redacted/unredacted as appropriate), decision notes
- Access controls, sensitivity flag and retention metadata
Monitoring, Audit and Reporting
- Maintain an FOI register to track open requests, ageing, overdue items and internal review outcomes.
- Dashboards: requests by service, timeliness (within 20 working days), volumes, upheld/partly upheld/withheld statistics and ICO complaints.
- Audit completeness of decision records, exemption tests, redaction quality and evidence of senior oversight for high‑risk disclosures.
- Provide extracts for quality committees, board assurance and external scrutiny demonstrating compliance and learning.
Value Proposition
- Provides a single structured workflow to receive, triage, decide and evidence FOI decisions consistently and lawfully.
- Protects patient and staff confidentiality by integrating DPA checks and redaction controls into FOI workflows.
- Supports statutory compliance (FOIA/FOISA), reduces ICO risk and provides auditable evidence for inspections and tribunals.
- Feeds governance and learning systems to reduce repeat errors, improve timeliness and strengthen organisational transparency.
References
- Care Act 2014
- Mental Capacity Act 2005
- Freedom of Information Act 2000
- Freedom of Information (Scotland) Act 2002
- Data Protection Act 2018 / UK GDPR
- Department of Health & Social Care
- NHS England
- Scottish Government — Health & Social Care Directorate
- Health & Social Services Group (Wales)
- CQC — Health and Social Care Act 2008 (Regulated Activities) Regulations 2014
- CI Directorate Scotland — Health and Social Care Standards
- CIW — National Minimum Standards
- NICE guidance (governance, risk management)
- NHS information governance frameworks and PSIRF
- ICO guidance on Freedom of Information and data protection
Disclaimer
Radar Healthcare provides configuration templates and implementation guidance to support effective use of the platform. Any data protection, regulatory or FOI examples are for general guidance only and do not constitute legal, clinical or compliance advice. Radar Healthcare acts as a data processor under customer instruction. The customer, as data controller, remains responsible for assessing and managing legal and data protection risks, determining lawful processing, and ensuring compliance with applicable regulations.
