InfoGov

  • Welsh environmental watchdog hit by data breach

    Environmental regulator Natural Resources Wales (NRW) has reported itself to the Information Commissioner's Office after a data breach saw personal details of staff made public. NRW said those affected had worked for it between April 2013 and March 2018. A spreadsheet was inadvertently disclosed containing employee information that may have included diversity monitoring data, such as ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability or caring responsibilities. An NRW statement said: “As soon as we became aware of the issue, we took immediate steps to contain the incident and investigate the circumstances surrounding the disclosure. “This included removing the information from the website where it had been published, obtaining confirmation that...

  • Researchers warn of "agentic flooding" of public services with AI generated communications

    Researchers have identified a surge in AI generated requests and claims hitting public bodies across Europe and beyond including FOI requests, planning objections and compensation claims and warned that public authorities will soon run out of capacity to deal with the influx if they do not act quickly. Researchers Chris Schmitz of the Hertie School and Lewis Hammond and Alan Chan of the Centre for the Governance of AI have identified 84 cases across 11 countries in which public bodies or credible observers attribute surges in requests to public use of AI, including freedom of information requests, planning consultation responses and civil court claims. They warned that governments are likely to respond with fees and other barriers rather than by building capacity. The paper,...

  • Scottish Biometrics Commissioner urges ministers to replace 2011 CCTV strategy as consultation backs wider oversight remit

    Scottish Biometrics Commissioner Dr Brian Plastow has called on Scottish ministers to replace the 2011 National Strategy for Public Space CCTV in Scotland, that the framework predates the modern digital era and that the government's current review of his remit, alongside the opportunity to introduce a Scottish surveillance camera code of practice, represents a once in a generation chance to act. His comments, contained in an article in 1919 Magazine , were made shortly before the Scottish Government published an analysis of consultation responses showing most respondents want his oversight extended beyond the three policing bodies it currently covers. Plastow noted that the strategy has survived four first ministers, six cabinet secretaries for justice and seven ministers for community...

  • Adult Social Care files were not missing but had been “incorrectly catalogued”, council insists

    Southampton City Council has claimed that tens of thousands of adult social care files were not missing but had been “incorrectly catalogued”, after the Care Quality Commission (CQC) said the authority could not account for the location of large volumes of paper records. The council confirmed it had “no evidence” that the files were missing, adding that “significant work” is underway to review and digitise the records, and that around 2,000 files have now been scanned. In June this year, a Care Quality Commission (CQC) assessment of Southampton City Council identified significant information governance shortcomings. The assessment, published on 17 June 2026, identified failures across governance, safeguarding, and service delivery, with findings on information security and document...

  • Nearly three-quarters of staff use unapproved AI tools, NCSC warns in shadow AI advice

    The National Cyber Security Centre (NCSC) has published advice on the cyber security dangers of shadow AI, warning that employees who turn to unapproved AI tools for work tasks can expose sensitive data, remove it from organisational control and create new routes for attackers. In a blog published on 7 September, the NCSC warned that organisational policies and guidance have not kept pace with the rapid growth of AI use in workplaces, and that where cyber security policies cannot meet business needs, staff are likely to adopt new AI services before their employer has assessed them or provided approved alternatives. It cited Microsoft research findings that 71% of employees report using AI tools not approved by their employer, and said that the trend is likely to strengthen as AI...

  • ICO hits city council with enforcement notice over “systemic non-compliance” with Freedom of Information Act

    The Information Commissioner’s Office (ICO) has issued Derby City Council with an enforcement notice after evidence showed “widespread and persistent delays” in the local authority’s handling of freedom of information requests, with some outstanding requests dating back to 2022. The Commissioner became aware of concerns regarding the council's compliance with the Freedom of Information Act (FOIA) following information provided about the council's timeliness in responding to FOI requests and the scale of its outstanding caseload. The council provided information about its performance for FOI requests due between 1 January 2026 and 24 July 2026. Of those requests, 226 were completed on time, representing 29% of the total; 90 were completed outside the statutory timeframe, representing...

  • Mayor of London will have text messages and emails searched as part of procurement battle with data firm Palantir

    London Mayor Sadiq Khan will have his text messages and emails searched as part of an ongoing legal battle with data firm Palantir, it has been reported. Palantir is challenging in court the decision by the Mayor's Office for Policing and Crime (MOPAC) to block its £50m artificial intelligence contract with the Metropolitan Police, as Commissioner Sir Mark Rowley told the London Policing Board that the force must now scale back its technology-driven ambitions for 2026/27. A full hearing of the case is due to be held in January next year. According to ITV, at a preliminary hearing on Thursday, the High Court was told Sadiq Khan and more than a dozen other Mopac and Greater London Authority officials will be classed as “custodians”. This means their digital communications, including text...

  • Tribunal refuses application for certification that council was in contempt of court in Freedom of Information case

    The First-tier Tribunal has refused an application to certify that the London Borough of Haringey was in contempt of court after the council disclosed information 17 days after the deadline set by the Tribunal in a freedom of information case. Judge Armstrong-Holmes found that the council’s failure to comply with the ordered deadline for disclosure was a breach capable of constituting a contempt. However, the judge decided not to exercise her discretion to certify the matter and send it to the Upper Tribunal. The appeal concerned requests for information made under the Freedom of Information Act. A Tribunal decision issued in January 2025 resulted in a substituted decision notice requiring the disclosure of “appropriately unredacted” information. Haringey subsequently applied for...

  • Upper Tribunal breaks with Moss and recognises article 10 right to receive information in FOIA appeals

    The Upper Tribunal has held that First-tier and Upper Tribunals are not bound by precedent to automatically reject the limited right to receive information under article 10 (“Freedom of Expression”) of the European Convention on Human Rights (ECHR) recognised by the Grand Chamber in Magyar Helsinki Bizottság v Hungary departing from the 2020 decision in Moss v Information Commissioner ( that had led tribunals to dismiss such arguments for six years. In a case (Cruelty Free International v Information Commissioner and Home Office [2026] UKUT 328 (AAC)) brought by animal welfare campaign group Cruelty Free International (CFI), a three-judge panel of Lady Poole, Upper Tribunal Judge Citron and Upper Tribunal Judge Brewer found that CFI’s article 10 rights had been violated by the Home...

  • One in six people with a legal problem consult AI for advice: research

    What is thought to be the first large-scale look at the public use of AI chatbots has revealed that around a sixth of people who have faced a legal issue over the past year have used an AI chatbot for help, advice, or information. The study, conducted by charity JUSTICE and the Administrative Fairness Lab, surveyed 3,287 people across the UK and found almost half (1,428) had experienced a legal dispute in the last two years and, among them, 233 people used an AI chatbot to discuss the issue. The AI chatbots were predominantly used to seek assistance with common legal problems that largely fall outside the scope of legal aid, such as housing, employment, debt, consumer issues, and family law. The research, which included 77 participants sharing the transcripts of their AI legal queries,...

  • Former Council Chief Executive convicted of two charges connected to deletion of email

    A former chief executive of Mid and East Antrim Council, Anne Donaghy, has been convicted of two charges connected to deleting or attempting to delete an email to prevent disclosure under the Freedom of Information Act, the BBC has reported. The council said it acknowledged the verdict and would “carefully consider the outcome and any implications arising from it”. According to the BBC, the charges related to an email sent by Donaghy to the private email address of then-Democratic Unionist Party (DUP) leader Arlene Foster. District Judge Alana McSorley told the court that Donaghy had been under mounting political pressure at the time she told her PA to delete the email to Foster. The BBC said the judge outlined the prosecution's case that there was a perception that Donaghy was too...

  • FOI privilege ruling "erodes public interest test", says Scottish Commissioner as he seeks Supreme Court leave

    The Scottish Information Commissioner is seeking leave to appeal to the UK Supreme Court for the first time in the office's history, challenging a Court of Session ruling that overturned his order requiring the Scottish Government to disclose legally privileged communications about its decision to appeal an earlier FOI case. David Hamilton, the Commissioner, said the decision to seek leave had not been taken lightly but that the Inner House ruling of 26 March 2026 in The Scottish Ministers v The Scottish Information Commissioner (CSIH 15) ran contrary to the Scottish Parliament's clear intention behind the Freedom of Information (Scotland) Act 2002. He said the judgment placed significant risks on the public's right to access information and that it was therefore in the public interest...

  • ICO publishes explainer video on right to access care records after research claims finds that 89% of requesters were left with questions or concerns

    The Information Commissioner's Office has published a three-minute explainer video, My right to better records, setting out how people with care experience can make a subject access request for their personal care records, as part of its Better Records Together campaign. The launch follows ICO research which found that 89% of people who had accessed their care records were left with questions or concerns, 71% reported poor communication from their local authority and 69% said the process took longer than expected, with some waiting up to sixteen years. The video explains what a subject access request is, how to make one and what to expect once it has been submitted. The ICO is asking social care professionals and organisations supporting care-experienced people to use it as a resource...

  • NCSC publishes interim guidance on managing the cyber risks of agentic AI

    The National Cyber Security Centre has published interim practical advice on managing the cyber security risks of agentic AI, setting out seven safeguards for organisations deploying AI systems that can plan, use tools and take actions with significant autonomy. The guidance, published as a blog in the NCSC website on 20 August, is aimed at system designers and operators building environments in which AI agents operate with limited human intervention, and at those concerned about agents carrying out unintended actions because of the instructions they receive, the tools available to them or the systems they can access. The NCSC says it has been researching and experimenting in the area for some time and is working with partners on formal guidance that will build on and ultimately...

  • Solicitors Regulation Authority highlights concern over AI-generated inaccuracies and breaches of confidentiality

    The Solicitors Regulation Authority (SRA) has published a warning notice to remind the legal profession of their professional obligations when using artificial intelligence (AI). The warning notice comes as the regulator revealed it had received 42 reports related to the potential misuse of AI between July 2025 and July 2026. The SRA noted that while many law firms are using AI “safely and responsibly” to support tasks such as research, drafting, document review and administrative processes, recent cases had highlighted the importance of ensuring “appropriate human oversight”. It set out the following key concerns: AI-generated inaccuracies, or ‘hallucinations’ in legal research, advice, analysis and submissions to the court. Instances of confidential client information being entered...

  • Sensitive patient data routinely sent over unencrypted pager network, NHS Blood and Transplant admits

    The Information Commissioner's Office (ICO) has opened an enquiry after NHS Blood and Transplant (NHSBT) admitted to sending the sensitive medical data of transplant patients from across the UK over an unencrypted pager network. The organisation, which co-ordinates transplants across the country, said it had been sending urgent messages to inform hospitals about opportunities for transplants via pagers. However, following an investigation by the BBC, it learnt that when the system sent a message to a pager, the data was not encrypted. According to the BBC, the messages in question detailed the types of organs available, and the names, dates of birth, tissue-match scores, and immunosuppression risk factors of the people receiving the transplants. Pagers are small battery-operated radio...

  • ACRO Criminal Records Office reprimanded by ICO following cyber security failings

    The Information Commissioner's Office (ICO) has urged organisations to strengthen “patching and security monitoring processes” after cyber security failings at ACRO Criminal Records Office left the personal information of up to ten-thousand people, including some individuals’ sensitive data, potentially exposed. An ICO investigation found that between August 2022 and March 2023, a hacker gained unauthorised access to ACRO’s website and content management system (CMS). The attacker was then able to stage personal information to be stolen, although ACRO could not conclusively determine whether the information was removed from its systems, the ICO said. The investigation found that up to 10,920 people may have been affected. The ICO said: “The data potentially exposed included names, dates...

  • Bristol City Council must release audit report on diversity programme contracts after ICO rejects chilling effect arguments

    The Information Commissioner has ordered Bristol City Council to disclose an internal audit report into Stepping Up, a Community Interest Company, after finding that the council's reliance on section 36 of the Freedom of Information Act was based on a qualified person's opinion that was too generic to be reasonable. In a decision notice dated 20 May 2026 (IC-415528-V6Y5), the Commissioner found that neither limb of section 36(2)(b) was engaged and gave the council 30 calendar days to communicate the report to the complainant, redacting personal data (including the names and job titles of the key witnesses listed in the report) under section 40(2). Failure to comply may be certified to the High Court and dealt with as contempt of court under section 54. The request, made in June 2025,...

  • Court of Appeal upholds first successful "unfair processing" claim against a newspaper article in Dale Vince case

    The Court of Appeal has granted green energy entrepreneur Dale Vince summary judgment against Associated Newspapers for unfair processing of his personal data under the UK GDPR, in what is understood to be the first claim of its kind ever to succeed in the courts of England and Wales. In a unanimous judgment handed down on 15 July 2026 ([2026] EWCA Civ 899), Sir Geoffrey Vos, Master of the Rolls, sitting with Lord Justice Warby and Lady Justice Whipple, reversed the decision of Mr Justice Swift, who had struck out Mr Vince's claim as an abuse of process and entered summary judgment for the publisher. The Court of Appeal instead granted Mr Vince summary judgment for damages to be assessed. The claim arose from articles published in the Daily Mail and Mail+ on 8 and 9 June 2023 under the...

  • Cyber Essentials delivery partner IASME joins UK Cyber Security Council's professional registration regime

    The UK Cyber Security Council has appointed IASME as a Licensed Body, bringing the government's Cyber Essentials delivery partner into the framework through which the Council assesses and registers cyber security professionals against its chartered standards. The Council, the self-regulatory body for the UK cyber security profession established in 2021 by what was then the Department for Digital, Culture, Media and Sport, said the appointment supports its work to strengthen and professionalise the UK's cyber security sector. The Council was awarded its Royal Charter in 2022, giving it the power to license organisations to assess individuals and recommend them for professional registration - at Associate, Practitioner, Principal and Chartered levels - against the Council's Standard for...

InfoGov Masthead Newsletter 800