For Individuals Only

This website is designed for individual consumers to understand their rights and track their own SAR and FOI requests.

It is not intended for commercial use by organisations, companies, or professionals managing requests on behalf of others.

Back

Key Definitions

Glossary of legal terms in plain English

Based on definitions from the Information Commissioner's Office (ICO) and UK legislation. These terms are explained simply to help you understand your rights. New terms from the Data (Use and Access) Act 2025 are marked DUAA.

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
A
Absolute exemption
An exemption under FOIA that does not require a public interest test. If the information falls under an absolute exemption, the public authority can refuse to disclose it without balancing public interest. Examples include security bodies (Section 23) and personal data where disclosure would breach data protection law (Section 40).
Accountability principle
A principle requiring organisations to be responsible for their own compliance with data protection law and to be able to demonstrate that compliance. This means they must have appropriate policies, procedures, and records in place.
Adequacy decision
A decision by the European Commission that a country outside the EU provides an adequate level of data protection, allowing personal data to flow freely from the EU to that country without additional safeguards.
Administrative fine
A financial penalty imposed by the Information Commissioner's Office (ICO) on an organisation for serious breaches of data protection law. Fines can be up to £17.5 million or 4% of annual global turnover, whichever is higher.
Anonymisation
The process of irreversibly removing all information from a dataset that could identify an individual. Once data is genuinely anonymised, it is no longer considered 'personal data' and falls outside the scope of the UK GDPR.
Appropriate policy document
A short document required under the DPA 2018 when processing special category data. It outlines the organisation's compliance measures and retention policies for such data.
Article 15
The article of the UK GDPR that gives individuals the right of access to their personal data – commonly known as the right to make a Subject Access Request (SAR).
Automated decision-making DUAA
A decision made solely by automated means (without human involvement) that produces legal effects or significantly affects an individual. Under the DUAA 2025, rules are relaxed for non-sensitive data – ADM is now prohibited only where decisions are based in whole or in part on special category data. Safeguards include the right to human intervention and to contest the decision.
B
Biometric data
Personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics of an individual. This includes facial images, fingerprints, and iris scans that allow or confirm unique identification. Under UK GDPR, biometric data is classified as special category data.
Breach (personal data breach)
A security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Organisations must report certain breaches to the ICO within 72 hours.
Broad consent DUAA
A new concept under the DUAA 2025 allowing researchers to rely on broader consent for areas of scientific research, subject to ethical standards, rather than needing specific consent for each research activity.
C
Child
For data protection purposes, a child is anyone under 18 years old. Under the UK GDPR, children have the same rights as adults but deserve special protection regarding their personal data. The Age Appropriate Design Code (Children's Code) sets standards for online services likely to be accessed by children.
Competent authority
A public authority with law enforcement functions to which Part 3 of the DPA 2018 applies. This includes police forces, prosecuting authorities, and other organisations with statutory law enforcement powers.
Consent
A freely given, specific, informed and unambiguous indication of agreement to the processing of personal data. It must be given by a clear affirmative action (such as ticking a box or signing a statement). Consent can be withdrawn at any time.
Controller (data controller)
The person or organisation that determines the purposes and means of processing personal data. They decide why and how personal data is processed. This could be a company, public authority, charity, or sole trader.
See also: Processor
Criminal data
Personal data relating to criminal convictions, offences, or related security measures. This type of data has additional protections and can generally only be processed by official authorities unless specific conditions are met.
D
Data harm
The harm a person experiences caused by misuse, loss, or improper sharing of their personal data, whether deliberate or accidental. Harm can be physical (fraud, identity theft) or emotional (damage to reputation, distress).
Data portability
The right under Article 20 UK GDPR to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller. This right applies only when processing is based on consent or contract and carried out by automated means.
Data protection by design and default
A legal obligation requiring organisations to implement appropriate technical and organisational measures to integrate data protection into their processing activities from the design stage and ensure that, by default, only personal data necessary for each purpose is processed.
Data sharing agreement / ISA
A document that sets out the common rules and arrangements for sharing personal data between organisations. It helps ensure all parties understand their roles and comply with data protection law.
Data subject
The identified or identifiable living individual to whom personal data relates. In plain terms: you, me, and anyone whose data is being processed.
DPA 2018
The Data Protection Act 2018 – the UK law that sits alongside the UK GDPR and sets out the framework for data protection in the UK. It covers areas where the UK GDPR allows for national derogations, as well as separate regimes for law enforcement and intelligence services processing.
DPIA (Data Protection Impact Assessment)
A process to help organisations identify and minimise data protection risks of a project. A DPIA is required for processing that is likely to result in a high risk to individuals.
DPO (Data Protection Officer)
An individual appointed by an organisation to oversee data protection strategy and compliance. DPOs are required for public authorities and organisations that carry out large-scale systematic monitoring or large-scale processing of special category data.
DUAA 2025 NEW
The Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025. It introduces the most significant UK data protection reform since the UK GDPR, amending the UK GDPR, DPA 2018, and PECR. Key changes include new rules for scientific research, automated decision-making, recognised legitimate interests, and SAR procedures including "stop the clock".
E
EIR (Environmental Information Regulations)
The Environmental Information Regulations 2004 give the public rights to access environmental information held by public authorities. This includes information on air, water, land, emissions, and measures affecting the environment.
Enforcement notice
A legal notice issued by the ICO requiring an organisation to take specific action to comply with information rights law. Failure to comply with an enforcement notice can lead to court proceedings.
Erasure (right to)
The right under Article 17 UK GDPR to have personal data erased without undue delay. Also known as the 'right to be forgotten'. This right applies in certain circumstances, such as when the data is no longer necessary or consent is withdrawn.
See also: GDPR
Excessive request
A request (such as a SAR) that is manifestly unfounded or excessive. Organisations may charge a reasonable fee or refuse to act on such requests, but they must justify this decision.
Exemptions
Provisions in the UK GDPR, DPA 2018, or FOIA that allow organisations to refuse or restrict some rights and obligations in certain circumstances. Exemptions must be applied on a case-by-case basis and cannot be applied as a blanket rule.
Explicit consent
A higher standard of consent required for processing special category data. It must be an express written statement (such as a signed form or email) clearly confirming agreement.
F
Filing system
Any structured set of personal data accessible according to specific criteria, whether centralised, decentralised, or dispersed. This includes both paper and electronic records.
FOIA (Freedom of Information Act 2000)
The UK law that gives the public a right to access recorded information held by public authorities in England, Wales and Northern Ireland. Scotland has separate legislation (FOISA).
G
GDPR (General Data Protection Regulation)
The EU regulation that sets the framework for data protection. Since the UK left the EU, this has been incorporated into UK law as the 'UK GDPR', which sits alongside the DPA 2018.
Genetic data
Personal data relating to inherited or acquired genetic characteristics that give unique information about an individual's physiology or health, including from analysis of a biological sample. Classified as special category data.
H
Health data
Personal data relating to an individual's physical or mental health, including healthcare services provided. This is classified as special category data requiring additional protection.
High risk processing
Processing of personal data that is likely to pose a high risk to individuals' interests. This includes large-scale use of special category data, systematic monitoring of public areas, or automated decision-making with significant effects. A DPIA is required in such cases.
I
ICO (Information Commissioner's Office)
The UK's independent regulator for data protection and information rights. The ICO enforces the UK GDPR, DPA 2018, FOIA, and EIR, and has powers to investigate, issue enforcement notices, and impose fines. Under the DUAA 2025, the ICO has enhanced investigatory powers.
Identifiable individual
An individual who can be identified directly or indirectly from information, including by reference to a name, identifier, location data, or factors specific to physical, genetic, mental, economic, cultural, or social identity.
Internal review
A process where a public authority reviews its own decision to refuse an FOI or EIR request. While not a statutory requirement under FOIA, it is considered good practice and must be completed within 20-40 working days. For SARs, organisations may voluntarily offer internal reviews but are not legally required to do so.
International transfer
The transfer of personal data from the UK to organisations in other countries. Such transfers are restricted under UK GDPR unless the destination ensures adequate protection or appropriate safeguards are in place. The DUAA 2025 introduces a new framework for international data transfers.
J
Joint controllers
Two or more controllers that jointly determine the purposes and means of processing personal data. They must arrange between them who will provide information to data subjects and handle rights requests.
L
Law enforcement purposes
The purposes of preventing, investigating, detecting, or prosecuting criminal offences, or executing criminal penalties. Part 3 of the DPA 2018 sets out a separate regime for processing for these purposes.
Legal professional privilege
A legal principle protecting confidential communications between a lawyer and client. Under FOIA, information covered by legal professional privilege is absolutely exempt from disclosure. The DUAA 2025 confirms this exemption for SARs.
M
Manifestly unfounded
A request that clearly has no serious purpose or value. Organisations can refuse to comply with manifestly unfounded requests or charge a reasonable fee, but they must justify this decision.
Motivated intruder test
A test used to assess whether anonymised data is truly anonymous. It considers whether a determined person with reasonable resources and capabilities could re-identify individuals from the data.
Mandatory complaints procedure DUAA
From 19 June 2026, all data controllers must have a formal, accessible complaints procedure for alleged UK GDPR infringements. Complainants must use this procedure before going to the ICO. Requirements include acknowledging receipt within 30 days and responding without undue delay.
N
Neither confirm nor deny (NCND)
A response under FOIA where a public authority refuses to confirm or deny whether it holds the requested information. This may be used where confirming the existence of information would itself reveal exempt information.
O
Object (right to)
The right under Article 21 UK GDPR to object to processing based on legitimate interests or public task. The controller must stop processing unless it demonstrates compelling legitimate grounds that override the individual's interests. There is an absolute right to object to direct marketing.
P
PECR (Privacy and Electronic Communications Regulations)
Regulations that sit alongside data protection law, covering electronic marketing, cookies, and communications privacy. The DUAA 2025 reforms PECR, including reduced consent for low-privacy-risk cookies and extending soft opt-in to charities.
Personal data
Any information relating to an identified or identifiable living individual. This includes names, addresses, email addresses, IP addresses, CCTV footage, HR records, opinions about a person, and indications of intentions towards them.
Prejudice
A term used in exemptions meaning compromising or undermining a purpose or function. For an exemption based on prejudice to apply, the organisation must show that disclosure would cause actual, real, and substantial prejudice, not just trivial consequences.
Privacy information
The information organisations must provide to individuals about the collection and use of their data. Under Articles 13 and 14 UK GDPR, this includes the purposes of processing, lawful basis, retention periods, and rights.
Processing
Any operation performed on personal data, whether automated or not. This includes collecting, recording, organising, storing, adapting, using, disclosing, and deleting data. In plain terms: anything you do with personal data.
Processor
A person or organisation that processes personal data on behalf of a controller. Processors do not decide why or how data is processed – they follow the controller's instructions. A contract (data processing agreement) must govern the relationship.
See also: Controller
Profiling
Any form of automated processing of personal data to evaluate personal aspects about an individual, particularly to analyse or predict performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
Pseudonymisation
Processing personal data so it can no longer be attributed to a specific individual without using additional information, which must be kept separately and securely. Unlike anonymisation, pseudonymised data remains personal data and is subject to UK GDPR.
See also: Anonymisation
Public interest test
A balancing exercise required for qualified exemptions under FOIA. The public authority must weigh the public interest in disclosure against the public interest in maintaining the exemption, and explain their reasoning.
Publication scheme
A requirement for public authorities under FOIA to publish certain information proactively, showing what information they routinely make available.
Purpose limitation DUAA
Under the DUAA 2025, new "safe harbours" are introduced where further processing is automatically treated as compatible with the original purpose, including for research, archiving, and public interest objectives.
Q
Qualified exemption
An exemption under FOIA that requires a public interest test. The public authority must weigh the public interest in disclosure against the public interest in maintaining the exemption before deciding whether to withhold information.
R
Reasonable and proportionate searches DUAA
Under the DUAA 2025, controllers only need to conduct reasonable and proportionate searches when responding to SARs. This codifies existing case law and clarifies that controllers are not required to conduct exhaustive or disproportionate searches.
Recognised legitimate interests DUAA
A new lawful basis introduced by the DUAA 2025 for purposes including crime prevention, safeguarding, emergencies, and national security. Unlike the standard legitimate interests basis, no balancing test is required – only necessity needs to be demonstrated.
Rectification (right to)
The right under Article 16 UK GDPR to have inaccurate personal data corrected without undue delay, and to have incomplete data completed.
Redaction
The process of removing sensitive or exempt information from a document before disclosure. Redaction must be irreversible, and organisations should indicate where information has been removed and which exemption applies.
Refusal notice
A written notice under Section 17 FOIA that must be issued when a public authority refuses a request. It must state which exemption applies, explain why, provide public interest reasoning (for qualified exemptions), and inform the requester of their right to complain.
Restriction of processing
The right under Article 18 UK GDPR to limit processing of personal data in certain circumstances, such as when accuracy is contested or processing is unlawful. When restricted, data may generally only be stored.
S
Scientific research DUAA
Under the DUAA 2025, the definition of "scientific research" is broadened to include commercial research activities, giving researchers greater consistency and certainty. Researchers can now rely on "broad consent" for areas of scientific research, subject to ethical standards.
Section 17
The section of FOIA that requires public authorities to issue a refusal notice when refusing a request. It sets out what must be included in the notice.
Section 12 (cost limit)
The section of FOIA allowing public authorities to refuse requests where the cost of compliance exceeds the appropriate limit (£600 for central government, £450 for other authorities).
Section 14 (vexatious requests)
The section of FOIA allowing public authorities to refuse vexatious or repeated requests. The threshold for vexatious is high – the request must cause unjustified distress or be obsessive.
Sensitive processing
A term used in Part 3 of the DPA 2018 for law enforcement processing of data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or sex life/orientation.
Soft opt-in DUAA
Under the DUAA 2025, the soft opt-in for direct marketing is extended to charities, allowing qualifying charities to send certain electronic marketing without explicit consent, subject to conditions.
Special category data
Under the UK GDPR, this is personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, or data concerning sex life or sexual orientation. This type of data needs greater protection.
Stopping the clock DUAA
Under the DUAA 2025, the deadline for SAR responses pauses from the day clarification is requested until the day after clarification is received. This applies only where clarification is genuinely required to identify or locate the information requested.
Subject Access Request (SAR)
A request made by an individual to a controller for access to their personal data under Article 15 UK GDPR. The individual has the right to know whether their data is being processed, receive a copy, and obtain supplementary information. Under the DUAA 2025, controllers now have the power to "stop the clock" when seeking clarification.
See also: Article 15
T
Tribunal (First-tier Tribunal)
The independent judicial body that hears appeals against ICO decision notices under FOIA, EIR, and data protection law. Appeals usually must be made within 28 days.
U
UK GDPR
The UK version of the EU General Data Protection Regulation, incorporated into UK law after Brexit. It sits alongside the DPA 2018 and sets out the core framework for data protection in the UK. The DUAA 2025 amends the UK GDPR.
V
Vexatious request
Under Section 14 FOIA, a request that is obsessive, harassing, or causes unjustified distress. The threshold is high – legitimate scrutiny, even if critical, does not automatically make a request vexatious.
W
Working day
For FOI purposes, Monday to Friday excluding bank holidays, weekends, and public holidays. The 20 working day deadline for FOI responses is calculated using working days.
Sources:

Last reviewed: March 2026. Includes new definitions from the Data (Use and Access) Act 2025. These definitions are for guidance only and do not constitute legal advice.

Back to Resources Hub