Governing Freedom of Information in the UK
Tl;dr: the governance model of the ICO is changing and FOI isn’t well-represented in their new strategy. Here is how it could be made better.
Freedom of Information gives us the power to ask public authorities for information about their work. It has been used to uncover wrongdoing, scrutinise how public money is spent, and give communities the evidence they need to hold public bodies to account. Also, when public servants know that their decisions and records may be subject to public scrutiny, this can encourage better record-keeping and more accountable government in the first place.
Effective Freedom of Information systems require effective oversight. The UK’s Information Commissioner’s Office (ICO) has substantial legal powers, an experienced FOI team, and a well-established role in resolving complaints and improving public authority practice. However, there are longstanding questions about how FOI is governed within an organisation whose much larger responsibility is data protection.
The transition to the new Information Commission brings those questions into sharper focus. FOI plays a relatively small part in the proposed corporate strategy; specialist FOI expertise is not obvious within the new governance arrangements and the FOI function continues to depend on government funding at a time of increasing demand.
There are different ways these problems could be addressed. The new Information Commission can do more to give FOI strategic clarity, visibility and support within the combined regulator. Parliament can play a stronger role in scrutinising and supporting the FOI function, including how it is resourced. And, more fundamentally, FOI regulation could be separated from data protection altogether.
For an example of the last approach, we can already see this in the UK with the Scottish Information Commissioner (a dedicated regulator for the Scottish FOI system, appointed and funded via the Scottish Parliament). This arrangement does not need to be exactly replicated, but the new Information Commission needs to show how it can deliver the same kind of strategic clarity and agenda, and build a constructive relationship with Parliament on securing this important constitutional right.
If FOI remains within the new Information Commission, the challenge is to demonstrate how the combined model will deliver those conditions in practice.
What does effective FOI oversight need?
The existence of a legal right to information does not by itself guarantee effective access to information. FOI depends on an effective regulator.
Our 2022 Improving Oversight of Access to Information report looked at how information rights are regulated across Europe. It found that regulators need sufficient independence and resources to put their powers into practice, specialist knowledge of Access To Information law and practice, and good information about how the wider FOI system is working. This allows them not only to resolve individual complaints, but to identify where problems are occurring and intervene strategically.
The way a regulator is governed matters to its ability to do this. Its institutional purpose needs to be clear, expertise on Access To Information needs to inform its leadership and strategy, and its resources need to reflect the scale of the job it is expected to do. There also needs to be meaningful accountability for whether the regulator itself is delivering an effective FOI system.
These conditions are particularly important when FOI is one function within a much larger regulator. The Information Commission’s data protection responsibilities are substantially larger than its FOI role, with different funding arrangements, professional networks and regulatory priorities. Without deliberate arrangements to protect the strategic position of FOI, there is a risk that it becomes secondary within the priorities, governance and resources of the wider organisation.
This is the challenge facing the new Information Commission. It is not enough for the Commission simply to retain the ICO’s existing FOI responsibilities and powers. The new governance arrangements need to demonstrate how their FOI function will have the expertise and resources necessary for the regulator to use those powers effectively and improve the operation of the UK’s FOI system as a whole.
FOI within the new Information Commission
The new corporate strategy
FOI only plays a small part in the draft corporate strategy, and is not well-represented in the key strategic objectives.
There is a proposed objective for public authorities to be “transparent and provide public information openly and on time”. The suggested measurement framework also includes FOI compliance and complaints data, alongside qualitative evidence from FOI practitioners. Measuring the health of the wider FOI system is vital: our previous research demonstrates that regulators need to better understand more than just the complaints which eventually arrive with them.
However, considering the strategy more broadly, FOI is not well-represented. In particular, it is not always clear how the Commission’s wider strategic priorities and activities apply to its Access To Information responsibilities.
This may partly reflect the origins of the strategy itself. The Data (Use and Access) Act creates new requirements around the Commission’s strategy for data protection, while FOI legislation does not create an equivalent requirement for a dedicated FOI strategy. The ICO has previously operated with a distinct strategy for its FOI work; this should be revived.
FOI expertise within the new governance structure
The move from a single Commissioner to a Board creates new opportunities to bring a wider range of expertise into the organisation’s strategic governance. Seven non-executive members have now been appointed to the new Information Commission Board. They bring a range of experience; however, none of the members’ biographies identify specialist experience focused on information rights. FOI expertise is similarly not prominent in the published recruitment material for the new Chair.
It’s not necessarily the case that a seat on the Board needs to be reserved for an FOI specialist, but this does raise a practical question about how the Board will gather specialist Access To Information expertise and maintain strategic oversight of this part of the Commission’s responsibilities. Looking to Scotland, the Commissioner is appointed with a clear FOI remit and is expected to have experience with relevant legal/public sector matters.
Resources and independence
Funding is another longstanding issue for FOI within the ICO. Unlike much of the ICO’s data protection activity, which is funded through fees, its FOI responsibilities are supported through government grant funding. This creates an unusual relationship in which the resources available to enforce information rights against the government are ultimately determined through the government.
This has previously had practical consequences. In evidence to Parliament in 2021, the then Information Commissioner Elizabeth Denham linked resource constraints to the ICO’s ability to take enforcement action, noting that its FOI funding had fallen substantially over the preceding decade. Our comparative research subsequently identified the UK as an example where a regulator has extensive formal powers but their practical ability to deploy them could be constrained by resources.
It is important to recognise that the ICO’s performance on FOI has improved in recent years. However, we must not take this progress for granted – and the ICO is currently warning that at its current funding level increased pressure on the complaints system is increasing the size of the backlog and delays before cases are allocated. Giving evidence to the House of Commons Procedure Committee, Warren Seddon (Director of Freedom of Information and Transparency) – highlighted the increase in volume and impact on response times:
In the last 12 months, we saw our intake increase by 16% in Q1, 38% in Q2, and then 60% in Q3 and Q4. That is in a context where, historically, over two decades of the FOI Act, you see a 20% to 25% increase every five years. We have seen a massive surge in the number of complaints in the system. Although the evidence is not there to pull that apart in detail, I think AI is probably driving that.
[..]In terms of the impact on performance and how the system is working at the funding levels that we are seeing coming in right now, there is a real concern from our perspective about where we will end up. We are projecting at the moment that, by the end of this financial year, it will take about 16 months to allocate a case, which is not good from our perspective.
In a response to an FOI request, the ICO highlighted both the increase in workload and that they have been unable to secure an increase in budget to reflect this:
[D]espite bidding for more resource to recruit more staff at the last Comprehensive Spending Review (CSR), this was not successful. We continue to engage with government on this issue, but as a result, we currently anticipate allocation and wait times will continue to grow as approximately 400 excess cases a month are being added to our caseload.
Improvements to processes and technology may all help the regulator use its existing resources more effectively, but there is a limit to how far operational improvements can compensate for a sustained mismatch between workload and resources.
Responding to the Information Commission strategy
The current consultation on the Information Commission’s corporate strategy provides an immediate opportunity to strengthen the place of FOI within the new organisation.
The draft strategy includes an outcome focused on public authorities being transparent and providing information openly and on time, as well as proposals to use compliance, complaints and practitioner evidence to understand FOI performance.
However, it is less clear how these commitments connect to the wider strategy: how the Commission will use its regulatory powers and resources to achieve this FOI outcome, how progress will be scrutinised, and how the experience of people using FOI will inform its approach.
Proposals to strengthen the strategy:
- Explain how the corporate strategy applies to the Commission’s FOI work. The inclusion of an outcome on public authority transparency is welcome, but it is not always clear how the wider priorities in the strategy apply to the Commission’s Access To Information responsibilities. The final strategy should make clearer how the FOI outcome connects to regulatory priorities, activities, enforcement and resources.
- Commit to a dedicated FOI strategy. A more detailed Access To Information strategy sitting underneath the corporate strategy could explain how the Commission intends to approach casework, enforcement, systemic intervention, public authority compliance and the wider health of the FOI system.
- Measure the health of the FOI system from both sides. The proposed use of compliance, complaints and practitioner evidence is welcome. This should be complemented by evidence from requesters, alongside measures covering areas such as timeliness, disclosure, internal review and appeals. This would give the Commission a fuller picture of how FOI is working, beyond the cases that eventually reach it.
- Connect FOI ambitions to the resources required to deliver them. The Commission’s commitments on public authority transparency need to be supported by sufficient capacity within its FOI function. The final strategy should make clearer how the Commission will assess the resources required to meet its FOI responsibilities, particularly in the context of changing complaint volumes.
- Explain how FOI will be overseen within the new governance structure. With the move to a Board, the strategy could provide greater clarity about how specialist access-to-information expertise will inform decision-making and how the Board will scrutinise delivery of the Commission’s FOI responsibilities.
- Make engagement with FOI users and civil society more concrete. Continuing structured engagement with requesters, journalists, civil society and practitioners would give the Commission access to different perspectives on how the system is working in practice.
A stronger role for Parliament
Beyond the scope of the consultation, Parliament should play a greater role in supporting the independence and sustainability of FOI oversight.
Freedom of Information is a right created by Parliament, and the Information Commission is responsible for enforcing that right against public authorities, including the government itself. There is a reasonable argument that Parliament should have a stronger role in ensuring that the regulator has the resources it needs.
There are possible models (along the lines of the approach taken for the Electoral Commission) where a parliamentary committee rather than a government department is the sponsor. The ICO would submit an estimate for its FOI work to a parliamentary body, supported by independent audit and scrutiny, before the funding was approved through Parliament. This would help insulate decisions about FOI funding from the government whose compliance the ICO is responsible for regulating. It could also give Parliament a clearer role in scrutinising whether the ICO has the resources it needs, and how effectively those resources are being used.
There are precedents for this kind of arrangement. A number of independent constitutional and scrutiny bodies have funding arrangements involving parliamentary committees rather than conventional departmental sponsorship.
In Scotland, the Information Commission is funded through the Scottish Parliamentary Corporate Body and is subject to parliamentary scrutiny of both its resources and its performance. The Commissioner appears annually before the relevant parliamentary committee to discuss the office’s annual report and operational performance.
A separate FOI regulator?
One option for creating greater institutional clarity around FOI is to separate out the responsibilities for Access To Information and data protection.
The case for separation reflects the increasingly different scale and focus of the two functions. Data protection has developed into a much larger regulatory field, supported by an international profession and increasingly complex regulatory responsibilities. Within a combined regulator, there is a risk that the smaller FOI function has less influence over institutional strategy, leadership and resources.
A separate regulator would make responsibility for FOI explicit. It could provide a clear institutional purpose, specialist leadership and governance focused specifically on the effective operation of the FOI system. The Scottish Information Commissioner demonstrates some of the practical advantages of this clarity: there is an identifiable regulator with a specific FOI remit and a direct relationship with Parliament around its funding and performance.
Separation may not fix all issues automatically. Our comparative research found advantages to both specialist and combined oversight bodies. A larger combined regulator should, in theory, benefit from shared infrastructure, resources and greater institutional weight, while a separate regulator without sufficient resources or independence would not necessarily provide more effective oversight.
The important question is what institutional arrangements best deliver effective FOI regulation in practice. If responsibility for FOI remains within the Information Commission, the combined model needs to demonstrate how it will provide the strategic clarity, specialist expertise, resources and accountability that separation could provide more directly. Government and Parliament, in turn, need to ensure that the wider funding and governance arrangements make this possible.
Where next?
The creation of the Information Commission is an opportunity to strengthen the governance of FOI. There are actions that can be taken now within the new Commission, including giving FOI greater strategic clarity, making responsibility for it clearer within the new governance structure, and ensuring that its ambitions are matched by the resources needed to deliver them.
There is also a role for Parliament. Regardless of whether FOI continues to sit within a combined regulator or is ultimately separated from data protection, Parliament can play a stronger role in scrutinising the health of the FOI system and ensuring that its regulator has the independence and resources it needs. The government also has a responsibility to ensure that the wider regulatory and funding framework supports effective FOI oversight.
The Scottish Information Commissioner provides a useful example of how governance, funding and accountability can be aligned around a clear FOI purpose. If FOI is to remain within the new Information Commission, it should be clear how the combined model will provide the same kind of strategic clarity and focus, alongside a constructive relationship with Parliament that supports the effective protection of the right to information.
–
Photo by Maksym Kaharlytskyi on Unsplash