Regulation 11: Personal data

When environmental information includes personal data and how data protection law interacts with the EIR(S).

Personal data#

Regulation 11 of the EIR(S) sets out when personal data can and cannot be disclosed in response to an environmental information request. Although this page is grouped with the regulation 10 exceptions for convenience, personal data is dealt with separately - it has its own regulation, its own tests, and its own relationship with data protection law.

In plain terms#

The authority is saying the information identifies, or could identify, a living person, and data protection law restricts what it can release. This comes up constantly - names on documents, contact details, professional roles, complainants’ identities, details about individuals affected by environmental decisions.

You ask a council for complaints about noise from a construction site. The complaints include the names, addresses, and personal accounts of the neighbours who complained. The council redacts the personal details of the complainants but releases the substance of the complaints and the council’s responses.

Regulation 11 covers two distinct situations:

Your own personal data - regulation 11(1). If the environmental information you’ve asked for is your own personal data, the EIR(S) do not apply. You should make a subject access request under Article 15 of the UK GDPR (or, where a law enforcement body processes the data, section 45 of the Data Protection Act 2018) instead. This is an absolute provision - there is no public interest test.

The reason is practical: if your personal data were disclosed under the EIR(S), it would go into the public domain. A subject access request gives you your data privately.

Someone else’s personal data - regulation 11(2). If the information includes a third party’s personal data, the authority must consider whether disclosure would be lawful under data protection law. There are three conditions, any one of which can trigger the exception:

  1. The first condition (regulation 11(3A)): disclosure would breach any of the data protection principles in Article 5(1) of the UK GDPR. This is effectively absolute - if disclosing the data would breach these principles, the authority must withhold it. No public interest test applies.

  2. The second condition: the data subject has exercised their right to object under Article 21 of the UK GDPR, and the public interest favours withholding. This is subject to the public interest test.

  3. The third condition (regulation 11(4A)): the data subject would not be entitled to the information if they made a subject access request (because a data protection exemption applies), and the public interest favours withholding. This is subject to the public interest test.

In practice, the first condition does most of the work. The key question is usually whether disclosure would be lawful - and specifically, whether there is a lawful basis under Article 6(1) of the UK GDPR. Regulation 11(7) of the EIR(S) allows authorities to use the legitimate interests basis in Article 6(1)(f) when deciding whether to disclose, even though public authorities are normally barred from using that basis.

The legitimate interests test#

The legitimate interests test involves three questions:

  1. Does the requester (or the public) have a legitimate interest in the personal data? Scrutiny of public bodies and accountability for environmental decisions are legitimate interests.
  2. Is disclosure necessary to achieve that interest? “Necessary” means reasonably necessary, not absolutely essential. Could the interest be met by other means that intrude less on the data subject’s privacy?
  3. Does the data subject’s right to privacy override the requester’s interest? This is a balancing exercise. The authority must weigh the benefits of disclosure against the potential harm to the individual.

How it’s used in practice#

The most common application is redaction - removing personal details while disclosing the rest of the document. Authorities should consider partial disclosure as a matter of course. Withholding an entire document because it contains some personal data is rarely justified if the personal details can be redacted.

Senior officials have lower privacy expectations for their professional activities. The Commissioner has consistently held that the names and professional roles of senior public officials should generally be disclosed. The more senior the person and the more public-facing their role, the weaker their claim to privacy in the professional context. But even senior officials retain privacy rights over their personal lives, and junior staff generally have stronger privacy expectations.

Names of public authority employees should be assessed case by case. Seniority matters, as does the context. An official’s name on an internal email may carry a different weight from their name on a decision letter sent to a member of the public.

Statistics and numbers can be personal data if they could identify individuals - particularly in small or geographically distinct communities in Scotland. The authority must assess whether there is a realistic prospect of identification.

How to challenge it#

Did they consider partial disclosure? The authority should redact personal details and release the rest, not withhold the entire document. If the refusal letter suggests the whole record was withheld, ask why redaction was not possible.

Is the person a senior official? Names and professional activities of senior public officials carry lower privacy expectations. If the authority withheld the name of a director, chief executive, or elected member acting in their official capacity, challenge whether their privacy interest genuinely overrides the public interest in accountability.

Is the information about professional or private life? Information about a person’s work for a public authority deserves less protection than information about their family, health, or private circumstances. Check which category the withheld data falls into.

See What to do if refused for the full process.

You can also use our interactive challenge tool for this exception to work through these questions step by step and draft a review request.

Good to know: Under regulation 11(6), the authority can use neither confirm nor deny (NCND) where confirming or denying whether personal data exists would itself involve making personal data available contrary to regulation 11. The FOISA equivalent is section 38 (personal information), and the two provisions work very similarly in practice. Regulation 11 applies only to living individuals - personal data of deceased people is not protected by regulation 11, though other exceptions can still apply to it. The UK Information Commissioner (ICO) enforces data protection law across the UK, including Scotland, while the Scottish Information Commissioner handles FOI and EIR(S) complaints.

Further reading#