ICO conducts performance review of FOI compliance in NHS Trusts

24/07/2025 | ICO

In a blog article, Warren Seddon, Director of Freedom of Information at the Information Commissioner's Office (ICO), marks the 20th anniversary of the Freedom of Information Act 2000 (FOIA) coming into force. In particular, the article focuses on the performance of NHS Trusts in relation to FOI compliance. 

Seddon highlighted that while most NHS trusts in England treat FOI compliance seriously, a small number show significant room for improvement, which has led the ICO to take intervening action.

The ICO regularly receives FOI complaints, particularly concerning timely responses and backlogs. To gain a better understanding of FOI compliance, the ICO examined a representative sample of 31 NHS trusts across England, varying in size and location. This involved reviewing casework data, analysing public information, and visiting eight trusts to gather staff experiences.

The findings showed that compliance with statutory deadlines varied greatly, from 10% to 100%, with an average of 82% across all sampled trusts. Smaller trusts (under 5,000 employees) performed best, with an average compliance rate of 92% and a backlog of 3 requests. Medium trusts (5,000-10,000 employees) averaged 83% compliance with 13 requests in backlog, while large trusts (over 10,000 employees) had an average compliance rate of 71% and a backlog of 86 requests. Despite these variations, only about 0.4% of FOI requests to NHS trusts resulted in an ICO complaint, suggesting overall good performance.

However, trusts identified challenges, including increased request volume and complexity without corresponding resource increases, the inability to prioritise FOI over patient care when frontline staff input is needed, and concerns about releasing information on IT systems, potentially increasing cyberattack vulnerability.

Based on its findings, the ICO encourages all NHS trusts to implement thorough FOI request handling processes that minimise impact on frontline staff, establish networks of contacts and FOI champions, raise awareness about FOI's operation, particularly concerning commercial information requests, and proactively publish commonly requested information. They also advise senior leaders to regularly review their organisation's FOI performance to enable early intervention.

The ICO has also issued enforcement notices to four trusts due to significant backlogs of FOI requests and lengthy wait times for responses. These include: 

Read Full Story
NHS

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 6,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.