Annual data protection statement -

Published: 27 August 2026

The data in this report is for the period April 2025 to March 2026.

2025 to 2026 at a glance

1,359 

Freedom of information (FOI) and Environmental Impact Reports (EIR) requests.

91.2% 

FOI and EIR on time.

173 

Subject Access Requests (SARs) received.

88.5%

of SARs responded to were on time.

143 

incidents.

Information Commissioner's Officer (ICO) - reportable.

27 

data protection complaints closed.

 

More than 12,000

expired files deleted.

Strategic overview

Overall position

The council’s information governance position strengthened in 2025 to 2026 with:

  • core statutory performance remaining controlled
  • incident severity reduced
  • records, transparency and data protection officer (DPO) and information governance (IG) oversight continuing to mature

What the data tells us

Demand is increasing and is more complex than in previous years with:

  • Freedom of Information (FOI) and Environmental Impact Report (EIR) volumes rising by 10%
  • Subject Access Requests (SARs) increasingly involving multi-directorate records and third-party data
  • incident data showing preventable handling errors remain concentrated in higher-risk services

Assurance position

The available evidence does not point to systemic non-compliance. However, it does show that the council’s assurance position depends, increasingly, on the quality and consistency of service-level evidence. To remain confident and defensible, services need to:

  • record the reasons for decisions clearly
  • explain any exemptions or delays
  • take visible ownership of information risk

Strategic assurance

FOI and EIR timeliness remained above target. SAR responses were controlled within agreed parameters. Incidents reportable to the Information Commissioner's Office (ICO) reduced, and no sanctions have arisen to date. Regulatory and internal review outcomes provide assurance, while also identifying learning.

Strategic priorities for 2026 to 2027

The next phase should focus on:

  • evidencing FOI and EIR decisions
  • embedding Data (use and access) Act guidance
  • strengthening AI governance
  • building SAR capability for complex cases
  • reducing repeat incident themes
  • improving retention discipline

Where attention is needed

Higher-volume and higher-risk services need targeted support so controls are practical, consistently applied and embedded into everyday service management. This work is already underway at the time of this report.

Risks and continual improvement - 2026 to 2027 action plan

Govern AI before use

Risk

Unapproved tools may expose:

  • personal and confidential data
  • reuse council information
  • produce unreliable outputs

Action taken

Grok and DeepSeek have been blocked or restricted where assurance could not be demonstrated. This helps protect residents who trust us with their information or must share it with us.

Next steps

Maintain the approved-tools route, supplier and storage checks, lawful basis, human oversight and access controls.

Evidence

Approved-tools list, staff guidance and restrictions maintained and reviewed routinely.

Strengthen information rights decisions

Risk

Higher FOI and EIR volume, internal reviews and ICO notices show quality must keep pace with timeliness.

Action

Embed Data Use and Access Act (DUAA) guidance, improve search records, exemption and exception rationale, public interest and prejudice tests and requester explanations.

Next steps

Introduce a consistent FOI and EIR evidence standard and sample check higher-risk cases.

Evidence

Record searches, legislation applied, withholding rationale, public interest and prejudice test, advice and approval, and requester explanation.

Build Subject Access Request capability for complex cases

Risk

Complex Subject Access Requests (SARs) span multiple directorates and include third-party data, social care and SEND records, and significant redaction.

Action

Provide case clinics and training on scoping, ownership, searches, redaction, exemptions and coordinated sign-off.

Next steps

Target training and case clinics for complex, multi-directorate or high-redaction SARs.

Evidence

Earlier scoping, fewer avoidable delays and consistent audit trails.

Reduce repeat-incident themes

Risk

Repeat preventable errors persist, especially wrong-recipient email, attachments and redaction in high-volume sensitive services.

Action

Target service support, check-before-send controls, secure sharing, redaction QA and shared learning.

Next

Use incident trend data to target reminders, service support and controls in higher-risk areas.

Evidence

Trend monitoring by directorate and incident theme, with follow-up on repeat issues.

This local pattern reflects wider ICO trends, where many reported data security incidents continue to relate to non-cyber handling errors. This includes information sent to the wrong recipient.

2026 to 2027 deliverables

Key deliverables for 2026 to 2027 are:

  • Maintain restrictions on unassured AI tools
  • FOI and EIR evidence standards
  • SAR training and case clinics
  • incident prevention activity
  • retention
  • disposal and access-review checks

Security incidents (personal data breaches)

Overall pattern - more reporting, fewer reportable breaches

In 2025 to 2026, 143 security incidents were recorded through the formal process, an increase from 124 in 2024 to 2025. Reporting was uneven across the year, with lower volumes in quarters 1 and 2 before a marked increase in quarters 3 and 4.

Despite the higher overall volume, ICO-reportable incidents reduced from 6 to 3. This suggests that most incidents were contained below the threshold for regulatory reporting.

Incident type by month

A stacked bar chart displays monthly incident types from January to December. Incidents peak in January (20 total). March and October each have 16 breaches. Near misses appear in January, May, July, October, November, and December. Reportable breaches are only in January and February, while not-a-BFC breaches occur solely in October.

Security incidents breakdown by month

A 100% stacked bar chart displays monthly security incident percentages by category. People-related incidents (green) dominate, often over 80%. Community incidents (blue) peak in February and March, while Place (purple) and Resources (red) are less frequent. October is nearly all People-related incidents.

Main cause - practical handling errors

Wrong-recipient email accounted for 104 incidents. Further incidents were linked to:

  • redaction failures
  • use of BCC
  • incorrect attachments
  • wider checking errors

These incidents are largely preventable and point to the need for these continued practical controls:

  • check-before-send prompts
  • delayed send where appropriate
  • secure sharing routes
  • redaction quality assurance
  • targeted reminders for teams handling high volumes of sensitive personal information

Breakdown of incident types

Breakdown of incident types
Breakdown of incident types
Type of incident Quarter 1 Quarter 2 Quarter 3 Quarter 4 Total
Verbal disclosure of personal data 0 0 0 1 1
Unauthorised access (non-cyber) 5 0 0 0 5
Other 2 2 4 4 12
Incorrect disposal of paperwork 1 0 0 0 1
Failure to use bcc 0 2 0 2 4
Failure to redact 3 4 2 2 11
Data posted or faxed to incorrect recipient 0 0 1 1 2
Data of wrong data subject shown in client portal 1 1 0 1 3
Data emailed to incorrect recipient 33 21 16 33 103
Total 45 30 23 44 142

Targeted prevention - where support will have most impact

Incidents are concentrated in the People Directorate, accounting for 85% of the total. This is consistent with the volume and sensitivity of the information managed there.

From 2025 to 2026, the People Directorate reported 122 out of 143 incidents. Among these, 61 incidents involved vulnerable adults or children.

With email misdirection being the most common incident type, the focus for 2026 to 2027 is clear. We must:

  • provide targeted support in higher-volume services
  • improve attachment controls, redaction checks and secure sharing
  • promote shared learning across services

Incident type by directorate

The stacked column chart shows data incidents by directorate. "Data emailed to incorrect recipient" has 32 incidents (People) and a small segment for Resources (red). "Other" includes 3 People and 1 Place incident (purple). "Failure to redact" has 2 People incidents. "Failure to use bcc" has 1 People and 1 Place incident. "Data of wrong subject shown" has 1 People incident. "Data sent incorrectly" has 1 Communities incident (blue). "Verbal disclosure" has 1 People incident.

Total security incidents year on year

Pie chart showing incidents by year: 113 (2019/20), 83 (2020/21), 119 (2021/22), 145 (2022/23), 131 (2023/24), 120 (2024/25), and 140 (2025/26). The highest value is 145 in 2022/23 and the lowest is 83 in 2020/21.

Freedom of Information and Environmental Information Regulations

Demand for Freedom of Information (FOI) and Environmental Information Regulations (EIR) increased again in 2025 to 2026.

1,359 requests were received between 1 April 2025 and 31 March 2026. This is an increase from 1,235 in the previous annual statement period, which is a rise of 10%.

The quarterly breakdown of requests for 2025 to 2026 was:

  • quarter 1 - 313
  • quarter 2 - 353
  • quarter 3 - 323
  • quarter 4 - 370

This shows sustained demand rather than a short-term issue.

The Information Commissioner’s Office (ICO) has published 4 decision notices relating to Bracknell Forest Borough Council’s handling of FOI and EIR requests.

Overall, the notices provide a broadly positive assurance position:

  • in 3 cases, the commissioner did not require any steps to be taken
  • 2 FOI cases were not upheld in relation to whether further information was held
  • 1 EIR case supported the council’s reliance on the confidentiality of proceedings exception

Total number of FOI and EIR requests between 2025 and 2026

Stacked bar chart showing monthly totals from January to December across five categories: Communities, Multiple, People, Place and Resources. Activity remains fairly consistent throughout the year, with People contributing the largest share each month. Totals peak in February, March, August and October, and are lowest in December.

FOI and EIR requests by directorate and financial year

Clustered bar chart showing FOI/EIR request totals by directorate (People, Place, Communities, Resources, Cross Organisation and CXO) from 2019/20 to 2025/26. People consistently has the highest volume, while CXO has the lowest. Request numbers vary by year across all directorates.

Monthly FOI and EIR completion rates

Stacked column chart showing monthly completion rates by deadline status. Most requests are completed on time each month, ranging from 80 to 137. March has the highest number of on-time completions (137), while September has the highest number of late completions (20). Late completions remain low throughout the year compared with on-time completions.

Response times

Performance remained strong despite the higher volume.

1,227 responses were submitted on time, while 119 were late. This gives an annual on-time rate of 91.2%. This compares favorably with the previous annual statement, where 79% of responses were on time.

The average response time was 12.9 days overall, down from 16.6 days.

For on-time responses, the average was 11.6 days, slightly lower than the previous 11.7 days.

Late responses took an average of 26.9 days, compared to 34.7 days before.

Internal reviews increased significantly from 2025 to 2026, rising to 42 compared to 17 in the previous reporting period. This represents about 3.1% of all FOI and EIR requests.

Reviews were concentrated in:

  • Place - 15
  • Communities - 13
  • Planning - largest service-area cluster at 13 reviews

Most original responses that led to a review were issued on time. Specifically, 31 out of 42 met the statutory deadline. This suggests that the issue is more about decision quality, clarity of explanation, and exemption handling than just timeliness.

Exemptions

Funnel chart of exemption types. Information already reasonably accessible is the most common exemption, followed by personal information (52) and law enforcement (34). Cost limit exceeded (18) and commercial interests (17) are less common, while all other exemptions occur only a handful of times (four or fewer cases each).

Average response rates per directorate

Average response rates per directorate
Average response rates per directorate
Directorate No Yes
Communities 25.84 10.34
Multiple 29.80 13.39
People 20.88 12.29
Place 27.70 11.00
Resources 0 11.67

Demand continues to be driven mainly by individuals and commercial organisations.

Individuals made up about half of all requests. Commercial organisations were the next largest group, followed by requests from research and media. Directorate demand was focused on People, Communities, and Place.

The highest volume service areas were:

  • Contract Services
  • Planning
  • Education and Learning
  • Highways and Transport
  • Commissioning
  • Housing

Exemptions and refusals remain a notable assurance area. 237 cases were marked as having an exemption or refusal applied. The most common reasons were that the information:

  • was already reasonably accessible
  • involved personal information
  • related to law enforcement
  • exceeded cost limits
  • concerned commercial interests

12% (158 requests) of all requests came from:

  • 10 accounts
  • 5 individuals
  • 2 media organisations
  • 3 commercial organisations

Category source

Pie chart showing request sources. Individuals account for nearly half of all requests (672, 49%), followed by commercial organisations (317, 23%) and research purposes (189, 14%). Media accounts for 141 requests (10%), while charities represent 27 requests (2%). Other categories make up a very small proportion.

By requester

Bar chart showing requester categories from 2019/20 to 2025/26. Individuals are consistently the largest group and increase over time, followed by commercial organisations. Research requests rise significantly, while media requests remain relatively stable. Charity, authority, and MP/parliament requests remain low throughout the period.

Subject access requests

Subject access requests (SARs) demand remained consistently high throughout 2025 to 2026. A total of 173 requests were recorded across the year. Volumes were stable across all 4 quarters, showing sustained operational demand rather than a short-term spike.

The majority of requests continued to relate to People Directorate services, particularly children’s social care, SEND and adult social care. However, the year also saw a noticeable level of multi-directorate requests. This reflects the complexity of cases where records are held across several service areas.

Overall, control remained reasonable.

Of the SARs responded to, 88.5% were completed on time. Most completed SARs met the statutory deadline. Late cases were mainly concentrated in complex People or multi-directorate requests. This reinforces the need for:

  • early scoping
  • clear ownership
  • timely service-area responses
  • robust audit trails

Allocation by directorate by month

Stacked bar chart showing the number of cases assigned to each directorate by month. The People directorate accounts for most cases throughout the year, peaking at 18 in April, while other directorates contribute only small numbers each month. Total monthly counts are highest in April and October and lowest in February, June, and August.

Open request status (current year)

Double doughnut chart showing open request status by directorate. People accounts for the larger share of open requests, while Communities accounts for the remainder. Around 60% of open requests are in progress within the statutory timeframe, and around 40% are in progress past the statutory deadline.

SAR complexity and redaction

63% of completed SARs required partial or full redaction of third-party information. There were 72 cases closed as “Completed – 3rd party data redacted.” This shows the ongoing complexity of SARs, especially when records involve children’s services, adult social care, SEN, or multi-directorate information.

Of the SARs responded to, 88.5% were completed on time. The SARs recorded as late exceeded either the statutory deadline or an agreed extension period.

Statutory deadline met

Stacked bar chart of monthly statutory deadline outcomes. Most cases met the deadline (green) in every month, ranging from 7 to 15. The highest counts are in September and November (15), and the lowest is in March (7). Very few cases did not meet the deadline (red) across the year.

Average response time (in days) for requests completed per month

Horizontal bar chart showing average response time for requests completed each month. Response times range from 20 to 37 days, with the highest in January (37 days), September (36 days), and April (35 days), and the lowest in November (20 days) and December (22 days). Most months fall between 27 and 36 days.

Data protection complaints and third party requests

Between 1 April 2025 and 31 March 2026, 27 data protection complaints were received.

Out of 27 complaints:

  • 18 (67%) were resolved at Stage 1
  • 5 reached Stage 2
  • 2 were closed following ICO complaint activity
  • 2 were closed as not data protection complaints

No complaints remained open at the end of the period.

Related personal data breaches were identified in 7 cases (26%), while 15 complaints recorded no related breach.

Overall, the period shows a closed caseload with most matters resolved at Stage 1.

The main areas to monitor are the:

  • proportion of complaints linked to personal data breaches
  • length of time to provide Stage 1 responses in more complex cases

Complaints received year to date

Donut chart showing complaints received year to date by month. October has the highest number of complaints (7), followed by February (5). December has 3 complaints. January, July, September, and November each have 2 complaints. April, May, and June each have 1 complaint. The chart indicates complaints peaked in October and were generally low in the spring and early summer months.

Count of complaint status by complaint status

Treemap chart showing complaint outcomes by status. Most complaints were closed at Stage 1 (18 complaints), represented by the largest area. Closed at Stage 2 accounts for 5 complaints. Two smaller categories each contain 2 complaints: “Closed - not data protection complaint” and “ICO Complaint Closed.” The chart shows that the majority of complaints were resolved at Stage 1, with relatively few progressing to Stage 2 or other closure categories.

Key issues

44% of third-party requests were fully responded to, a reduction from 54% in 2024/25.

Where requests were declined:

  • 23% were because the council did not hold the information
  • 22% were because the third party used an incorrect lawful basis

38% of individual rights requests came from third-party legal teams, 11% from individuals and 24% from other enforcement agencies.

We have seen a sharp decline in requests from central government departments. This may partly be due to the work we have done with them over the last 12 months.

Third party by status

Bar chart showing FOI/EIR requests by directorate from 2019/20 to 2025/26. People has the highest volumes throughout, while CXO has the lowest.

Third party requests received by month

Horizontal bar chart showing the number of requests by month. Volumes range from 11 to 20 requests, peaking in September (20) and April (19), with January the lowest at 11. Most months record between 17 and 18 requests, indicating relatively consistent demand throughout the year.

Third party requests by type

Donut chart showing request types: 569 third-party information requests (92.2%) and 45 individual rights requests (7.3%). Third-party requests make up the vast majority of cases.