Introduction
We are committed to promoting transparency and openness to help build public trust in how we operate, and we will make information available where it is lawful, appropriate, and reasonable to do so.
Aim
The aim of this policy is to ensure we meet our obligations when receiving requests for information under the Freedom of Information Act (FOI) 2000, the Environmental Information Regulations (EIR) 2004, and the UK General Data Protection Regulation (UK GDPR).
Scope
This policy applies to all recorded information including official documents, drafts, emails, notes, and audio and video recordings, held by us or on our behalf.
Roles and Responsibilities
To ensure the effective management and compliance with our obligations, the following roles and responsibilities are defined:
Customer Information Service
The Customer Information Service acts as the operational hub to ensure that requests progress through the statutory process in a timely and consistent manner.
This includes:
- receiving, logging, and acknowledging all incoming information requests
- carrying out initial validation to confirm request type, scope, and statutory deadline
- coordinating and chasing service areas for timely provision of information
- maintaining the central case management system and audit trail
- issuing standard communications and updates to the requester throughout the process
- escalating delays or non-responses to managers where required
Information assurance team
The information assurance team provides corporate oversight, guidance, and assurance relating to information rights. Responsibilities include:
- being the policy owner
- being the first port of call for information rights support and advice
- supporting service areas in interpreting the request, considering the legislation, and applying good practice
- advising on the application of exemptions, exceptions, redaction, and decision making thresholds
- supporting colleagues who are undertaking internal reviews and responding to data protection complaints
- leading awareness, training, and education to ensure staff understand their obligations
- supporting risk assessments and escalation processes where necessary
- being the single point of contact for the information commissioner’s office
Legal Services
Legal Services will provide the following:
- support service areas, the Customer Information Service, customer relations team, and the information assurance team by providing legal advice in interpreting the legislation and statutory guidance
- advice on complex requests involving legal privilege, contractual disputes, litigation risk, or significant corporate impact
- support the assessment of public interest tests and high-risk exemptions and exceptions
- provide legal review where disclosure may affect ongoing legal proceedings or regulatory processes
- support the handling of FOI/EIR complaints to the ICO, appeals, and potential litigation
- ensure the council meets its legal obligations while protecting its legitimate interests
Service areas (information asset owners and decision makers)
Service area responsibilities include:
- identifying, retrieving, and supplying all relevant information within agreed deadlines
- ensuring the completeness and accuracy of the information provided
- highlighting any concerns or sensitivities, including potential exemptions
- responding to points relating to the information’s content and meaning
- owning the request and ensuring requests are dealt with in a timely manner and in line with our obligations
- ensuring that local record-keeping practices support compliance with statutory information rights
- ensuring proportionate and reasonable searches are carried out in response to a request
- taking ownership of all disclosure decisions, including the application of exemptions or exceptions, as the accountable decision makers for the information they hold
- undertaking internal reviews, where appropriate, whenever a requester expresses dissatisfaction with the outcom
- ensuring information that falls within scope of the ICO model publication scheme is proactively published or otherwise made available as a matter of routine
Requests for information
The type of request made will indicate what legislation the request falls under:
- Requests for copies of personal data, whether made directly by the individual concerned or by a third-party organisation, will be handled in accordance with the requirements of the UK GDPR.
- Requests for environmental information held by us will be dealt with under the EIR.
- Requests for information not subject to either UK GDPR or EIR will be regarded as a request for recorded information under FOI.
- Information subject to EIR and FOI that can be provided within a normal customer enquiry will be dealt with under the usual customer service procedures.
UK General Data Protection Regulation
Requests from Individuals
We will provide individuals with a copy of the personal data we hold about them (known as a subject access request), together with other supplementary information, unless there is a good reason for us not to.
Requests for personal data under UK GDPR can be made verbally or in writing, including via social media.
We will respond to third parties acting on behalf of the individual if we are satisfied that the third party making the request is entitled to act on behalf of the individual. It is the third party’s responsibility to provide evidence of their authority.
If a request is made by or on behalf of a child, we will make reasonable efforts to assess the child’s competence and where a child is deemed competent to exercise their rights independently, we will respond directly to them.
If we are unsure about an individual's identity, we will ask for information to verify it. The timescale for responding to a subject access request does not begin until we have received the requested information.
Where required, we will seek clarification or further information to help identify the personal data or the processing activity that the request relates to. The timescale for responding to the request is paused on the day that clarification is sought and resumes on the day the clarification is received. This is known as ‘stopping the clock’.
We do not usually charge a fee to comply with a subject access request. However, we may charge a ’reasonable fee’ for the administrative costs of complying with a request if it is manifestly unfounded or excessive, or if an individual requests further copies of their data.
We will make reasonable efforts to find and retrieve the requested information. However, we are not required to conduct searches that would be unreasonable or disproportionate to the importance of providing access to the information.
We will provide the information in a commonly used electronic format, unless you request otherwise.
Where an exemption applies, we may refuse to provide all or some of the requested information, depending on the circumstances.
If we refuse to comply with a request, we must inform the individual of:
- the reasons why
- the existence of other relevant data protection rights and how to exercise them
- how to complain to us if they believe their request has not been handled correctly
- their right to make a complaint to the information commissioners office or another supervisory authority
- their ability to seek to enforce this right through the courts
We will normally respond to a request within one month. We may extend the time to respond by a further two months if either:
- the request is complex
- we have received a number of requests from the same person
If an extension is applied, we will inform the individual within one month.
Requests from third parties
Requests for disclosure of personal data from anyone other than the individual it relates to (or their appointed representative) will be considered on a case-by-case basis. We will carefully consider the circumstances of the request and will only disclose personal data where there is lawful justification to do so.
Environmental information regulations
We will provide access to information about our activities that relate to or affect the environment, unless there is a good reason for us not providing it.
Requests for information under EIR can be made verbally or in writing, including via social media.
Disclosure of information should be the default.
A person requesting the information does not need to give a reason for wanting the information, however we must justify refusing them information.
We will:
- treat all requests for information equally
- treat any information we release under EIR as if it were being released to the world at large
- always respond in writing, regardless of whether the request was made verbally or in writing, reasonable adjustments for accessibility reasons will be considered
- tell the requester whether we hold any information
- make that information available, unless an exception applies
We will normally respond to a request within 20 working days. If we believe that the request complexity and volume would make it impractical to comply or reach a decision about whether to refuse the request, within 20 working days we may seek to extend the time for compliance from 20 to 40 working days.
We do not initially charge for making an EIR request, however we may charge an appropriate fee for complying with some requests for information.
We will supply a detailed breakdown and explanation of charges to the requester.
Freedom of information
We will provide access to information about our activities, unless there is a good reason for us not providing it. Disclosure of information should be the default.
Requests for information under FOI must be made in writing. This could be a letter or email. Requests can also be made via the web or using social media. We will not accept requests made verbally.
A request must include the requester’s real name and an address for correspondence. This need not be the person’s residential or work address – it can be any address at which the person can be contacted, including a postal address or email address.
To be valid, the request must describe the information requested. If we are unable to answer the request because it is unclear or ambiguous, we will contact the requester at the earliest opportunity to seek clarification. We will stop the clock whilst clarification is sought.
A person requesting the information does not need to give a reason for wanting the information, however, we must justify refusing them information.
We will:
- treat all requests for information equally
- treat any information we release under FOI as if it were being released to the world at large
- always respond in writing, and we will tell the requester whether we hold any information
- make that information available, unless an exemption applies
We will normally respond to a request within 20 working days of receipt. However, we may extend the 20 working day limit up to a ‘reasonable’ time if we need more time to determine whether or not the balance of the public interest lies in maintaining an exemption; or we need more time to consider whether it would be in the public interest to confirm or deny whether you hold the information.
We do not initially charge for making an FOI request, however, we may charge an appropriate fee for complying with some requests for information.
We will supply a detailed breakdown and explanation of charges to the requester.
Refusing a request
We will consider refusing a request for information if:
- it would cost too much or take too much staff time to deal with the request
- the request is vexatious, repeated, manifestly unfounded or excessive
- the request meets an exemption under FOI and/or EIR or UK GDPR
We may also refuse to confirm or deny whether we hold information where the law allows.
We may seek legal advice where appropriate before refusing a request.
We will ensure that our grounds for refusal are robust, and justification may be provided should the refusal be challenged.
A written refusal notice will be issued to the requester if we:
- refuse to say whether we hold information at all; or
- confirm that information is held but refuse to release it.
A refusal notice will include, where appropriate, a clear explanation of the exemption relied upon to withhold information from disclosure and explain the requesters' options to challenge that decision.
Complaints and review process
Internal reviews - FOI and EIR
We will carry out an internal review of a request in all cases where a requester:
- disagrees with our interpretation of their request
- believes we hold more information than we have disclosed
- believes we have withheld information without proper justification
- the timeframe for response has been exceeded
The internal review shall not be limited to the first decision. We will provide a new decision based on all available evidence that is relevant to the date of the request.
Where possible, the review shall be carried out by:
- someone within the relevant Service Area, who did not deal with the original request, and
- a more senior member of staff
We will conduct a review within 20 working days. In exceptional circumstances, this time limit can be extended to 40 working days.
We will advise requesters of their right to escalate their complaint to the Information Commissioner’s Office should they remain dissatisfied once the internal review process is completed.
We will fully comply with all requests from the Information Commissioner’s Office to investigate, or review, our handling of FOI and EIR requests.
Complaints about subject access requests
We will consider all complaints about the handling of subject access requests as corporate complaints in accordance with our complaints policy.
Training and awareness
We will provide mandatory annual training to all staff covering requests for information under FOI, EIR and UK GDPR.
Publication scheme
The Freedom of Information Act 2000 requires every public authority to adopt and maintain a publication scheme.
We are committed to proactively publishing information as part of our core transparency obligations.
We will adopt the model publication scheme for public authorities provided by the information commissioner’s office.
Re-use of public sector information
We support the re-use of our information to promote transparency and innovation.
Unless otherwise stated, our published information is available for re-use under the Open Government License v3.0.
If individuals or organisations wish to re-use information not clearly covered by a license, they should email customerinformationservices@lincolnshire.gov.uk with the details of the material and the intended re-use.
We aim to respond to requests for re-use within 20 working days.
We do not initially charge for permitting re-use, however, we may charge an appropriate fee to cover the costs of reproducing, providing and disseminating information.
We will supply a detailed breakdown and explanation of charges to the requester.
Further Information
For further information or guidance please contact IA@lincolnshire.gov.uk.
Review
This policy shall be reviewed annually.
Document control
- policy owner: Amy Jaines - information governance manager (DPO)
- published: 21 March 2023
- last reviewed: 23 April 2026
- version number: V2
- change history:
- 14 February 2024 - annual review, no change
- 23 March 2025 - V1.1 annual review, document control added
- 23 April 2026 - V2 - annual review:
- the title of the policy has been changed from 'Freedom of Information' to 'Access to information'
- scope has been expanded to explicitly include subject access requests (SARs)
- roles and responsibilities section has been expanded and clarified