Section 38: Personal information
When the information requested is personal data, and disclosure would breach data protection principles.
Personal information#
Section 38 of FOISA is the most commonly used exemption in Scottish FOI. It covers four different situations involving personal data, and they work in very different ways. If you have been refused under section 38, the first thing to check is which subsection the authority has cited - the rules depend entirely on which one.
In plain terms#
If the authority cites section 38(1)(a), it’s saying: you’ve asked for your own personal data. FOI isn’t the right route - use a subject access request instead.
If the authority cites section 38(1)(b), it’s saying: the information identifies someone else, and releasing it would breach data protection law.
Sections 38(1)(c) and (d) cover personal census information and deceased persons’ health records. These are rarely encountered.
You ask a council for records of complaints made about a named social worker. The council refuses under section 38(1)(b), saying that disclosing the details would breach the data protection principles because the social worker would not reasonably expect their personal information to be released in response to an FOI request.
The legal detail#
Section 38(1) contains four separate exemptions:
Section 38(1)(a) - the information is the requester’s own personal data. This is absolute. The authority is likely to treat your request as a subject access request under Article 15 of the UK GDPR or section 45 of the Data Protection Act 2018, and must still issue a formal refusal notice under FOISA.
Section 38(1)(b) - the information is someone else’s personal data, and one of three conditions is met. This is mostly absolute, with two specific exceptions (see below).
Section 38(1)(c) - personal census information. Absolute.
Section 38(1)(d) - a deceased person’s health record. Absolute.
For section 38(1)(b), there are three conditions under which someone else’s personal data is exempt:
First condition: disclosure would breach any of the data protection principles in Article 5(1) of the UK GDPR. In practice, the question is almost always whether disclosure would be lawful, fair, and transparent. This is absolute - no public interest test.
Second condition: the person has exercised their right to object to processing under Article 21 of the UK GDPR, and the public interest favours withholding. This is subject to the public interest test.
Third condition: the person would not be entitled to receive the data if they made a subject access request, and the public interest favours withholding. This is also subject to the public interest test.
The first condition is overwhelmingly the one that matters in practice. The test it uses comes from data protection law: is there a legitimate interest in disclosure, is disclosure necessary to achieve that interest, and do the data subject’s rights and freedoms override it?
Absolute or qualified?#
Mostly absolute. Section 38(1)(a), (c), and (d) are all absolute. The first condition under section 38(1)(b) is also absolute.
The second and third conditions under section 38(1)(b) are qualified - subject to the public interest test. These apply when a data subject has objected to processing, or when the data wouldn’t be released under a subject access request. In both cases, even if the condition is met, the authority must still consider whether the public interest in disclosure outweighs the interest in withholding.
See What can they refuse? for more on how the public interest test works for qualified exemptions.
How it’s used in practice#
Your own data - section 38(1)(a)#
If you’ve asked for information about yourself, the authority is likely to redirect your request to the subject access route. A subject access request gives you stronger rights - the information is disclosed only to you, not to the world. If the authority applies section 38(1)(a), it must still send you a formal refusal notice and should tell you how to make a subject access request. The Information Commissioner (ICO) handles complaints about subject access requests, not the Scottish Information Commissioner.
Someone else’s data - section 38(1)(b)#
This is where most refusals happen. The central question is whether disclosure would be fair to the person the data is about. Fairness depends on what that person would reasonably expect.
Seniority matters. Senior officials acting in a public capacity have reduced privacy expectations for their professional activities. A council chief executive’s decisions about a major contract are part of public life. The Commissioner has regularly found that disclosing the names and professional actions of senior staff is fair. The more senior the person, the harder it is to argue that disclosure of their professional conduct would be unfair.
Junior staff are different. A junior member of staff who processed a routine application has greater privacy expectations. Their name and role are less relevant to public accountability. Disclosing their personal details could expose them to unwanted contact or pressure.
Special categories get extra protection. Data about someone’s health, ethnicity, political opinions, trade union membership, sexual orientation, or criminal record is subject to much stricter rules. It is very unlikely that such data could be disclosed under FOI.
Redaction is the usual answer. Authorities should consider whether they can release the information with personal identifiers removed. If the substance of the information matters but the individual’s identity does not, redaction lets both interests be served. If the authority has refused entirely without considering partial disclosure, that is worth challenging.
Census information and health records - sections 38(1)(c) and (d)#
Personal census information is protected for 100 years. A deceased person’s health record held under the Access to Health Records Act 1990 is similarly protected for 100 years. These are rarely the subject of FOI requests.
How to challenge it#
If the refusal is under section 38(1)(a), ask the authority to treat your request as a subject access request. You have a right to your own data under data protection law.
If the refusal is under section 38(1)(b), check the following:
Is the person a senior official acting in a public role? If so, argue that their reasonable expectations of privacy are lower for professional activities. The public interest in accountability for public functions outweighs individual privacy in those circumstances. The Commissioner has ordered disclosure of information about senior officials’ professional decisions in many cases.
Did the authority consider redaction? Ask whether they could release the information with names and identifying details removed. If the information is about a process, decision, or policy rather than an individual, partial disclosure with redacted names is often the right answer.
Is the information genuinely personal data at all? Personal data means information that identifies a living individual, directly or indirectly. Aggregated statistics, anonymised data, or information about organisations (rather than people) is not personal data and section 38 does not apply to it.
Has the authority explained whose data is involved and why disclosure would be unfair? A refusal that simply says “this is personal data” without explaining the fairness assessment is inadequate. The authority should identify the type of data, who it relates to, and what harm disclosure would cause.
See What to do if refused for the full process.
You can also use our interactive challenge tool for this exemption to work through these questions step by step and draft a review request.
Good to know: Sections 38(1)(a) and (b) have no fixed time limit, but they only apply to the personal data of living individuals. Once a person has died, their information is no longer “personal data” under data protection law, and section 38(1)(b) falls away. Sections 38(1)(c) and (d) generally cannot apply to information more than 100 years old. The authority can neither confirm nor deny whether it holds information under section 38 where revealing whether the information exists or is held would be contrary to the public interest - for example, where revealing that the authority holds a complaint about a named person would disclose personal data.
Further reading#
- Section 38 of FOISA — the legislation on legislation.gov.uk
- SIC guidance on section 38 — Scottish Information Commissioner’s guidance
- What can they refuse? - overview of all the exemptions
- What to do if refused - how to request a review and appeal
- Health, safety and the environment - sometimes applied alongside personal information
- Confidentiality - protects information shared in confidence, a different test from personal data