1,359
Freedom of information (FOI) and Environmental Impact Reports (EIR) requests.
The data in this report is for the period April 2025 to March 2026.
1,359
Freedom of information (FOI) and Environmental Impact Reports (EIR) requests.
91.2%
FOI and EIR on time.
173
Subject Access Requests (SARs) received.
88.5%
of SARs responded to were on time.
143
incidents.
3
Information Commissioner's Officer (ICO) - reportable.
27
data protection complaints closed.
More than 12,000
expired files deleted.
The council’s information governance position strengthened in 2025 to 2026 with:
Demand is increasing and is more complex than in previous years with:
The available evidence does not point to systemic non-compliance. However, it does show that the council’s assurance position depends, increasingly, on the quality and consistency of service-level evidence. To remain confident and defensible, services need to:
FOI and EIR timeliness remained above target. SAR responses were controlled within agreed parameters. Incidents reportable to the Information Commissioner's Office (ICO) reduced, and no sanctions have arisen to date. Regulatory and internal review outcomes provide assurance, while also identifying learning.
The next phase should focus on:
Higher-volume and higher-risk services need targeted support so controls are practical, consistently applied and embedded into everyday service management. This work is already underway at the time of this report.
Unapproved tools may expose:
Grok and DeepSeek have been blocked or restricted where assurance could not be demonstrated. This helps protect residents who trust us with their information or must share it with us.
Maintain the approved-tools route, supplier and storage checks, lawful basis, human oversight and access controls.
Approved-tools list, staff guidance and restrictions maintained and reviewed routinely.
Higher FOI and EIR volume, internal reviews and ICO notices show quality must keep pace with timeliness.
Embed Data Use and Access Act (DUAA) guidance, improve search records, exemption and exception rationale, public interest and prejudice tests and requester explanations.
Introduce a consistent FOI and EIR evidence standard and sample check higher-risk cases.
Record searches, legislation applied, withholding rationale, public interest and prejudice test, advice and approval, and requester explanation.
Complex Subject Access Requests (SARs) span multiple directorates and include third-party data, social care and SEND records, and significant redaction.
Provide case clinics and training on scoping, ownership, searches, redaction, exemptions and coordinated sign-off.
Target training and case clinics for complex, multi-directorate or high-redaction SARs.
Earlier scoping, fewer avoidable delays and consistent audit trails.
Repeat preventable errors persist, especially wrong-recipient email, attachments and redaction in high-volume sensitive services.
Target service support, check-before-send controls, secure sharing, redaction QA and shared learning.
Use incident trend data to target reminders, service support and controls in higher-risk areas.
Trend monitoring by directorate and incident theme, with follow-up on repeat issues.
This local pattern reflects wider ICO trends, where many reported data security incidents continue to relate to non-cyber handling errors. This includes information sent to the wrong recipient.
Key deliverables for 2026 to 2027 are:
In 2025 to 2026, 143 security incidents were recorded through the formal process, an increase from 124 in 2024 to 2025. Reporting was uneven across the year, with lower volumes in quarters 1 and 2 before a marked increase in quarters 3 and 4.
Despite the higher overall volume, ICO-reportable incidents reduced from 6 to 3. This suggests that most incidents were contained below the threshold for regulatory reporting.
Wrong-recipient email accounted for 104 incidents. Further incidents were linked to:
These incidents are largely preventable and point to the need for these continued practical controls:
| Type of incident | Quarter 1 | Quarter 2 | Quarter 3 | Quarter 4 | Total |
|---|---|---|---|---|---|
| Verbal disclosure of personal data | 0 | 0 | 0 | 1 | 1 |
| Unauthorised access (non-cyber) | 5 | 0 | 0 | 0 | 5 |
| Other | 2 | 2 | 4 | 4 | 12 |
| Incorrect disposal of paperwork | 1 | 0 | 0 | 0 | 1 |
| Failure to use bcc | 0 | 2 | 0 | 2 | 4 |
| Failure to redact | 3 | 4 | 2 | 2 | 11 |
| Data posted or faxed to incorrect recipient | 0 | 0 | 1 | 1 | 2 |
| Data of wrong data subject shown in client portal | 1 | 1 | 0 | 1 | 3 |
| Data emailed to incorrect recipient | 33 | 21 | 16 | 33 | 103 |
| Total | 45 | 30 | 23 | 44 | 142 |
Incidents are concentrated in the People Directorate, accounting for 85% of the total. This is consistent with the volume and sensitivity of the information managed there.
From 2025 to 2026, the People Directorate reported 122 out of 143 incidents. Among these, 61 incidents involved vulnerable adults or children.
With email misdirection being the most common incident type, the focus for 2026 to 2027 is clear. We must:
Demand for Freedom of Information (FOI) and Environmental Information Regulations (EIR) increased again in 2025 to 2026.
1,359 requests were received between 1 April 2025 and 31 March 2026. This is an increase from 1,235 in the previous annual statement period, which is a rise of 10%.
The quarterly breakdown of requests for 2025 to 2026 was:
This shows sustained demand rather than a short-term issue.
The Information Commissioner’s Office (ICO) has published 4 decision notices relating to Bracknell Forest Borough Council’s handling of FOI and EIR requests.
Overall, the notices provide a broadly positive assurance position:
Performance remained strong despite the higher volume.
1,227 responses were submitted on time, while 119 were late. This gives an annual on-time rate of 91.2%. This compares favorably with the previous annual statement, where 79% of responses were on time.
The average response time was 12.9 days overall, down from 16.6 days.
For on-time responses, the average was 11.6 days, slightly lower than the previous 11.7 days.
Late responses took an average of 26.9 days, compared to 34.7 days before.
Internal reviews increased significantly from 2025 to 2026, rising to 42 compared to 17 in the previous reporting period. This represents about 3.1% of all FOI and EIR requests.
Reviews were concentrated in:
Most original responses that led to a review were issued on time. Specifically, 31 out of 42 met the statutory deadline. This suggests that the issue is more about decision quality, clarity of explanation, and exemption handling than just timeliness.
| Directorate | No | Yes |
|---|---|---|
| Communities | 25.84 | 10.34 |
| Multiple | 29.80 | 13.39 |
| People | 20.88 | 12.29 |
| Place | 27.70 | 11.00 |
| Resources | 0 | 11.67 |
Demand continues to be driven mainly by individuals and commercial organisations.
Individuals made up about half of all requests. Commercial organisations were the next largest group, followed by requests from research and media. Directorate demand was focused on People, Communities, and Place.
The highest volume service areas were:
Exemptions and refusals remain a notable assurance area. 237 cases were marked as having an exemption or refusal applied. The most common reasons were that the information:
12% (158 requests) of all requests came from:
Subject access requests (SARs) demand remained consistently high throughout 2025 to 2026. A total of 173 requests were recorded across the year. Volumes were stable across all 4 quarters, showing sustained operational demand rather than a short-term spike.
The majority of requests continued to relate to People Directorate services, particularly children’s social care, SEND and adult social care. However, the year also saw a noticeable level of multi-directorate requests. This reflects the complexity of cases where records are held across several service areas.
Overall, control remained reasonable.
Of the SARs responded to, 88.5% were completed on time. Most completed SARs met the statutory deadline. Late cases were mainly concentrated in complex People or multi-directorate requests. This reinforces the need for:
63% of completed SARs required partial or full redaction of third-party information. There were 72 cases closed as “Completed – 3rd party data redacted.” This shows the ongoing complexity of SARs, especially when records involve children’s services, adult social care, SEN, or multi-directorate information.
Of the SARs responded to, 88.5% were completed on time. The SARs recorded as late exceeded either the statutory deadline or an agreed extension period.
Between 1 April 2025 and 31 March 2026, 27 data protection complaints were received.
Out of 27 complaints:
No complaints remained open at the end of the period.
Related personal data breaches were identified in 7 cases (26%), while 15 complaints recorded no related breach.
Overall, the period shows a closed caseload with most matters resolved at Stage 1.
The main areas to monitor are the:
44% of third-party requests were fully responded to, a reduction from 54% in 2024/25.
Where requests were declined:
38% of individual rights requests came from third-party legal teams, 11% from individuals and 24% from other enforcement agencies.
We have seen a sharp decline in requests from central government departments. This may partly be due to the work we have done with them over the last 12 months.
You can find out more about data protection and your rights from the ICO.