Section 38 - Personal information

Challenge a refusal under FOISA section 38 - the authority says the information is personal data

What this exemption means#

The authority is saying the information is exempt because it is personal data. Section 38 is one of the most commonly used exemptions and contains several different parts:

  • Section 38(1)(a) - the information is your own personal data. This is an absolute exemption, but you have a right to access your own data through a Subject Access Request (SAR) under data protection law instead.

  • Section 38(1)(b) - the information is the personal data of a third party (someone other than you). This is mostly an absolute exemption: in the usual case, the authority must show that disclosing it would breach the data protection principles (the “first condition”). Two rarer conditions - where the person has objected to processing under Article 21 of the UK GDPR, or where the data would be exempt from the person’s own subject access request - are instead subject to the public interest test.

  • Section 38(1)(c) - personal census information (rarely used).

  • Section 38(1)(d) - a deceased person’s health record (rarely used).

What the authority must show#

For section 38(1)(a) - your own personal data#

The authority must show the information is your personal data and issue a refusal notice under section 16 of FOISA. However, it should also advise you to make a Subject Access Request under the UK GDPR or DPA 2018 to access the same information privately.

For section 38(1)(b) - third party personal data#

The most common ground is that disclosure would breach the data protection principles in Article 5(1) of the UK GDPR - specifically, the requirement for lawful, fair, and transparent processing. The authority must show that:

  1. The information is personal data - it relates to an identifiable living individual
  2. Disclosure would breach a data protection principle - usually this means there is no lawful basis for disclosure under Article 6 of the UK GDPR, or that disclosure would be unfair

The key test is usually the legitimate interests condition (Article 6(1)(f) of the UK GDPR): does the requester have a legitimate interest in the personal data, is disclosure necessary to achieve that interest, and is the interest overridden by the rights and freedoms of the data subject?

If the authority instead relies on the second condition (an Article 21 objection) or the third condition (the data would be exempt from the person’s own subject access request), it must also carry out and explain a public interest test.

Things to check#

  • Is the information really personal data? Personal data is information relating to an identifiable living individual. If the individuals cannot realistically be identified from the information (even combined with other available data), it is not personal data and section 38 does not apply.

  • Could the information be anonymised or redacted? Authorities should consider whether they can disclose the information with personal details removed or redacted, rather than withholding the entire document. Redacting names and identifying details while releasing the substance of the information is often possible.

  • Is the person a public official acting in an official capacity? The names and roles of senior public officials carrying out their public duties generally have a weaker claim to privacy. Information about a senior official’s public life should generally be disclosed unless it also reveals details of their private life. The more senior the person, the less weight their privacy claim carries in relation to their public duties.

  • Are they over-redacting? Authorities sometimes redact far more than necessary. If only a name needs to be removed to protect someone’s privacy, the rest of the document should still be disclosed. Redactions should be the minimum necessary.

  • For section 38(1)(a) - did they tell you about Subject Access Requests? If the authority has withheld your own personal data under section 38(1)(a), you have a right to access it through a Subject Access Request (SAR) under the UK GDPR or DPA 2018. The authority should advise you of this. A SAR means the information is disclosed only to you, not into the public domain.

  • Is the information about someone’s private life or their public role? There is a significant distinction. Information about what a public official did in their official capacity is much more likely to be disclosable than information about their family, health, finances, or personal life.

  • Is the information especially sensitive data? Some types of personal data have extra protection. Special category data (Article 9 UK GDPR) covers health, race, religion, political opinions, sexual orientation, and trade union membership, among others. Criminal offence data has its own, separate protection under Article 10. It is very unlikely that either can be disclosed under FOISA.

Use the interactive tool#

Answer the questions below to check whether section 38 has been properly applied to your request.