A freedom of information request is a request for recorded information a public authority holds. The default is release. The work is deciding what cannot go out, taking it out of the documents, and being able to say why.
Most of that work is redaction. The request that looked like a search problem on day one is a review problem by day fifteen: names of junior staff, third-party personal data, a paragraph that would prejudice an investigation, a contract schedule that is a trade secret. Miss one occurrence and the exemption you claimed on page four is undone on page forty.
This guide covers the exemptions that actually drive redaction, where authorities get caught out, and a process that fits the twenty-working-day clock.
General guidance, not legal advice. The ICO's guidance on FOI exemptions is the authority for England, Wales and Northern Ireland. Scotland has a separate regime (FOISA) and a separate commissioner. Complex or high-profile releases are worth taking advice on.
The clock
Under the Freedom of Information Act 2000 you must respond promptly, and within twenty working days. The clock starts the first working day after the request is received. Weekends and bank holidays do not count.
Twenty working days is enough for a well-scoped request and not enough for a trawl that surfaces a few thousand pages. Redaction is usually the slow part. Authorities that discover the volume in week three have already lost the chance to clarify the request while there was still time.
If the request is for the requester's own personal data, it is not an FOI request at all — see below.
The exemption that does most of the redacting
Section 40 is the personal-data exemption, and it is the one that fills most redaction logs.
Section 40(1) covers the requester's own personal data. You do not release that under FOI. You treat that part as a subject access request under the UK GDPR / Data Protection Act 2018, and you do it within the SAR timescale, not as a second hoop the requester has to jump through. Mixed requests — some of it about them, some of it about the organisation — get split.
Section 40(2) covers everyone else. You withhold third-party personal data where releasing it would breach a data-protection principle, most often because there is no lawful basis for putting that person's information into the world. Section 40(2) is an absolute exemption, so there is no FOI public-interest test on top — but lawfulness under the UK GDPR can itself involve a balancing exercise.
Two working rules that save time:
- Senior officials, already public. Names of senior staff whose roles are on the website, and who are acting in that professional capacity, are often released. The ICO has said as much for years. Redacting every director by reflex looks like over-redaction and attracts complaints.
- Junior staff, private individuals, identifiable members of the public. These usually come out. So do home addresses, personal email accounts, staff numbers and anything that identifies a private person who happens to be in the file.
"The finance director" identifies someone if there is only one. Indirect identification is as much a problem here as it is in a subject access response.
The other exemptions that produce redactions
These are the ones that regularly take paragraphs, not just names, out of a release:
| Exemption | What it usually removes | Absolute or qualified |
|---|---|---|
| s40 personal data | Names, contact details, anything identifying a living individual | Absolute (with the GDPR analysis underneath) |
| s41 confidence | Information received from someone else, where disclosure would be an actionable breach of confidence | Absolute, but confidence itself has a public-interest defence |
| s31 / s30 law enforcement | Content that would prejudice an investigation, the prevention of crime, or a regulatory function | Qualified — public interest test |
| s43 commercial interests | Trade secrets, or information whose release would prejudice someone's commercial interests | Qualified |
| s42 legal professional privilege | Advice from lawyers, and material prepared for litigation | Qualified |
| s38 health and safety | Content whose release would endanger someone's physical or mental health or safety | Qualified |
Qualified means you can apply the exemption only if the public interest in withholding outweighs the public interest in release. "It would be embarrassing" is not an exemption. Neither is "we marked it confidential" for information the authority generated itself — s41 only covers information received from someone else.
Environmental information is usually an EIR request, not FOI (s39 points you there). The redaction job is similar; the exceptions are not identical. Do not run an EIR request through the FOI exemption list.
Where releases go wrong
Redaction that does not redact
Drawing a black rectangle over a PDF leaves the text in the file. Recipients extract it. This has happened to public authorities more than once, and it is avoidable. Use a tool that removes the content, then verify. See why drawing a black box isn't redaction.
Inconsistent application
A name removed from the covering letter and left in the attachment is not withheld. A commercial figure blacked out in the summary and visible in the spreadsheet is not withheld. Consistency has to hold across every file in the release, including annexes.
Over-redaction
Withholding a senior official's name, or a whole paragraph that is merely unflattering, produces more ICO casework than people expect. Requesters can see the shape of what was taken out. If the shape does not match a real exemption, they complain, and you spend the next two months on an internal review.
Metadata and filenames
investigation-Jones-draft-v3.pdf is a disclosure before anyone opens the file. So is an author field. Hidden rows, comments and previous revisions travel with Office documents that were "printed to PDF" without being cleaned. See what still leaks after you redact a PDF.
The requester's own data left in an FOI bundle
If part of the request is about them, that part is a SAR. Releasing it under FOI — or refusing it under FOI without handling it as a SAR — is the wrong statute.
A process that fits twenty working days
- Scope on day one. What is held, roughly how much, which exemptions are likely. If you need the requester to clarify, ask immediately. Clarification stops the clock; discovering the volume in week three does not.
- Build the withhold-list before marking pages. Named individuals (and whether they are senior / junior / public), commercial figures, investigation references. Working from a list is the only way consistency is achievable across a bundle.
- Mark, then apply, then sanitise. Marking in a PDF editor is not redaction. Apply the redactions so the content is gone, then remove hidden information.
- Keep a schedule of what was withheld and why. One line per exemption applied, with enough detail that an internal reviewer — or the ICO — can follow it in six months. "s40(2), junior staff names" is a reason. "redacted sensitive material" is not.
- Verify the output the way a requester will. Select the text, copy it, search the bundle for every name on the withhold-list. Read a sample as someone who already knows the organisation.
FOI is not a DSAR, and the difference matters
A subject access request is about one person. You hand them their data and take everyone else out. An FOI release is about the authority. The default is that the information goes out, and personal data is one of several reasons it might not.
That is why FOI redaction produces more blank paragraphs and fewer surviving names: you are not trying to preserve the requester's own story. It is also why over-redaction is the characteristic FOI failure, where over-disclosure is the characteristic SAR failure. The same tool can do the mechanical finding for both — where that line sits is set out on the SAR redaction service page. The judgement is a different job.