Guide · Information Rights

What to do if an information request is refused

How to audit a refusal, identify the correct review route and escalate a SAR, FOI or EIR dispute without mixing the legal frameworks.

Start with the refusal notice or response.

Identify what was refused, under which legal regime, the provision relied on, and the reasons actually given. Do not substitute your own explanation for one the organisation never provided.

The next route depends on the regime.

For FOI and EIR, an internal review is commonly the next step before an ICO complaint. For a SAR or other data-rights complaint, first raise the issue with the organisation/controller and then consider the ICO route. Court or tribunal appeal rights can arise at later stages.

Challenge the reasoning, not only the outcome.

A useful challenge identifies the request, the withheld category, the exemption/exception, the missing reasoning, any factual error, and the remedy requested. If the response does not answer a material issue, record that separately.

Keep the escalation chronology.

Record request date, acknowledgement, clarification, extension, response, internal review and regulator dates. Information-rights disputes are easier to audit when every stage is separated.

Give the regulator the smallest complete file.

When escalating, attach the original request, acknowledgement if material, substantive response/refusal, internal review request and review outcome. Then list the live issues in a few numbered paragraphs. The regulator should not have to infer why you disagree from a long email chain.

Useful formulation.

“I challenge the refusal on three grounds: (1) the authority applied the wrong regime; (2) it has not shown that the exemption is engaged; and (3) the public-interest analysis does not address the factors set out below.”

Do not miss the review deadline while arguing informally.

FOI and Scottish FOI review processes have timing expectations and some statutory deadlines. EIR internal review is statutory. If the authority has given you a review route, submit a clear review request rather than allowing repeated informal emails to consume the period.

Challenge the decisive proposition.

They say…Useful response
“We do not hold any more information.”Identify why you believe further records may exist and ask what reasonable searches/systems were checked.
“Third-party data prevents disclosure.”Ask whether your personal data can be provided with third-party material redacted or otherwise protected.
“Section/regulation X applies.”Ask how the legal test applies to the specific information and, where relevant, how the public interest was balanced.
“The request is too broad.”Ask what clarification is genuinely required; offer a precise date/category narrowing if it still meets your objective.
“It is commercially sensitive.”Commercial sensitivity is not itself the whole FOI test; examine the actual exemption/prejudice/public-interest reasoning.

A refusal should tell you more than “we cannot disclose this”.

For FOI/EIR, identify the exemption or exception, the facts said to engage it and any public-interest reasoning. For a SAR, identify whether information is withheld because of an exemption, third-party rights, lack of identity information, scope/clarification, manifestly unfounded or excessive requests, or because the organisation says the data is not held. Each needs a different response.

First identify which legal regime produced the refusal.

Request typeFirst challenge route
SAR / personal-data rightComplain to the organisation about the data-protection handling; ICO if unresolved
FOI in England, Wales or Northern Ireland public authority under FOIAAsk for internal review where available/expected, then ICO
EIR 2004Request the statutory internal review, then ICO
FOISA / Scottish EIRsAsk the Scottish authority for review, then Scottish Information Commissioner