Skip to main content

Freedom of Information (FOI) and Environmental Information Regulation (EIR) Policy

Policy details

Policy number
OTpol006
Version number
1
Issue date
1 June 2026
Approved by
Trust Board
Responsible Director
Chair
Policy author
Darren Bassett
Review body
Organisational Steering Group
Review by date
31 December 2026

1. Summary

This policy sets out how Online NHS Trust receives, logs, assesses, and responds to requests for information under the Freedom of Information Act 2000 (FOIA) and the Environmental Information Regulations 2004 (EIR). It explains who the policy applies to, the roles and responsibilities for handling requests, and the end-to-end process for confirming validity, locating and collating recorded information, applying FOIA exemptions/EIR exceptions where appropriate, and issuing responses within the required timescales

2. Equality impact statement

The author of this policy has undertaken an equality impact assessment (EHIA) and has concluded that there is no negative impact on any of the protected characteristic groups. The completed EHIA form can be found at the end of this policy.

3. Introduction

The FOI Act 2000 (FOIA) and EIR 2004 provide rights of access to information held by NHS Online, aligned with NHS England guidance.

The Online NHS Trust is committed to openness and accountability and recognises the public's right to access recorded information we hold. The Freedom of Information Act 2000 (FOIA) and the Environmental Information Regulations 2004 (EIR) provide the legal framework for this access and set out the duties placed on public authorities, including NHS organisations, to respond to requests in a timely and appropriate way.

This policy explains how the Trust will manage FOI and EIR requests from receipt through to response, including how requests are logged and triaged, how responsibilities are assigned across teams, how we identify information held, and how we apply relevant exemptions (FOIA) or exceptions (EIR) where disclosure is not required.

4. Objectives

The aim of this policy is to:

  • ensure compliance with FOIA and EIR timelines, transparency, and public access to information
  • ensure accurate classification and lawful routing of requests
  • strengthen governance and accountability by defining clear responsibilities
  • Maintain robust records for compliance and audit

5. Scope

This policy applies to all Trust activities and to all staff working for or on behalf of the Trust. This includes people on differing employment terms, who for the purposes of this policy we refer to as 'staff' and are listed below:

  • All salaried employees, including those seconded into the Trust;
  • All workers;
  • All office holders;
  • All prospective employees, workers and office holders – who are part-way through recruitment;
  • All contractors and sub-contractors;
  • All sub-committee, and advisory group members (who may not be directly employed or engaged by the organisation); and
  • All agency workers.

6. Training requirements

All staff involved in FOI/ EIR handling will be required to undertake awareness training. This will be recorded and monitored via the NHS Online HR system.

As an FOI or EIR request can be made to any individual working at Trust, and need not specifically state that it is an FOI or EIR request, all staff need to be made aware of the requirement to follow this policy.

7. Definitions

For the purposes of this policy:

Freedom of Information (FOI) is the Freedom of Information Act 2000. It covers all recorded information held by or on behalf of a public authority (emails, documents, data, etc.) unless exempt.

Environmental Information Regulations (EIR) is the Environmental Information Regulations 2004. It covers information held by or on behalf of a public authority specifically about the environment, defined very broadly (e.g., land use, emissions, energy, environmental policies, biodiversity, etc.).

Working day is any day excluding Saturdays, Sundays or public holidays (England and Wales).

8. Duties and responsibilities

FOI and EIR responsibilities by role
RoleResponsibility
Programme Director
  • Provide oversight and accountability for compliance
Chairman and Non-Executive Directors
  • Ensure the processes and procedures are in place to meet statutory obligations
Corporate governance team
  • Respond in the first instance to FOI/ EIR requests
  • Log requests, undertake quality assurance and draft responses
  • Maintain a record of all requests received
Information Governance lead
  • Review draft responses (including heavy/ high risk responses).
  • Provide approval for full or partial exemptions for responses that are not exemption heavy and/ or high risk.
  • Escalate exemption heavy/ high risk responses to the DPO for DPO sign off.
Data Protection Officer (DPO)
  • Provide sign off for exemption heavy and/ or high risk responses
All Staff
  • Retrieve and collate all relevant recorded information required to respond to requests
  • Identify FOIA and EIR requests and send these on to the Trust Secretary

9. Policy details

9.1 Freedom of Information Act and Environmental Information Regulations

The Freedom of Information Act 2000 provides a right of access to a wide range of information held by public authorities, including the NHS.

The Environmental Information Regulations 2004 provide a right of access to information relating to the environment, which is held by public authorities, including the NHS.

9.2 Personal information

If individuals want to request their own personal information, this is not a Freedom of Information (FOI) request.

There is a different way to make a request if individuals want information that an organisation holds about them. This is via the Trust's Data Subject Rights Request process.

Where an authorised third party makes a subject rights request on behalf of a patient, for example a parent, solicitor, someone with an appropriate power of attorney, these should also be referred to the Trust's Data Subject Rights Request process.

9.3 Our duty to individuals

The Freedom of Information (FOI) Act 2000 and the Environmental Information Regulations (EIR) 2004 requires the Online NHS Trust to:

  • confirm whether or not the Trust holds the information that has been requested; and
  • provide information to individuals which is held by the Trust.

unless an exemption/ exception applies.

The Trust is required to respond within the deadlines set out in the legislation and provide reasonable advice and assistance to the requester in relation to their request.

9.4 Before individuals request information from the Trust

Please check whether the information sought is already available. We publish information on our website, and you may find the answer to the question is already there. Our publication scheme explains what information we currently release or expect to release.

If an individual requests information from the Trust that is already published, refer the individual to the published source.

If a request has already been made then the "information accessible by other means" exemption (section 21) will need to be applied.

9.5 Who can request information?

Anyone, anywhere in the world, can make a FOI or EIR request to the Online NHS Trust.

9.6 What can they request?

An individual can seek any recorded information that they think the Online NHS Trust may hold, or that another organisation may hold on behalf of the Trust. If the information is their own personal data, then they should make a subject access request under the UK General Data Protection Regulation (UK GDPR), and not an FOI request. Information on how to make a subject access request is available on the Trust's website.

An individual does not have to know whether the information they request is covered by the EIR or the FOI Act. When they make a request, we will decide which law applies.

9.7 How do individuals request information?

We request that FOI requests are emailed to the Online NHS Trust at this email address: onlinetrust.FOIrequests@nhs.net. However, legally, a requester does not have to use the email route designated by the Trust.

Whilst we request the above route is used, FOI requests can be made to anyone working for the organisation, including via social media accounts. FOIA requests cannot be made verbally. Any individual at the Trust receiving an FOI request should forward them to onlinetrust.FOIrequests@nhs.net at the earliest opportunity. It is important to do this promptly.

We request that EIR requests are emailed to the Online NHS Trust at this email address: onlinetrust.EIRrequests@nhs.net. However, legally, a requester does not have to use the email route designated by the Trust.

Requests can be made to anyone working for the organisation, including via social media accounts. EIR requests can also be made verbally. Any individual at the Trust receiving an EIR request should forward them to onlinetrust.EIRrequests@nhs.net at the earliest opportunity. It is important to do this promptly.

FOI and EIR requests can be made with telephone support for people unable to write requests.

Requesters are asked to write "FOI" or "EIR" in the subject line of any FOI/ EIR request, although it is not mandatory to do so.

9.8 What information must individuals include in their request?

The FOI Act requires certain information to be supplied before the Trust can respond to a request:

  • The individual's real name – we do not have to respond to requests submitted under a pseudonym.
  • The individual's address (this could be their email addresses) where they wish the response to be sent.
  • A description of the information the individual wishes to obtain.

EIR requests require the following to be supplied before the Trust can respond to a request:

  • The individual's address (this could be their email addresses) where they wish the response to be sent.
  • A description of the information the individual wishes to obtain.

Whilst it is not mandatory, it is preferable for requestors to describe the format the individual wishes to obtain information in.

9.9 What the individual does not need to do

They do not need to:

  • explicitly mention the FOI Act or EIR, although it may be helpful
  • know whether the information is covered by the FOI Act or the EIR
  • say why they want the information
  • specify particular documents that contain the information they are seeking; they have a right to information, however it is recorded.

9.10 What happens when a request is received?

We have a legal obligation to reply to an FOI or EIR request within 20 working days of receipt. This can be extended in some circumstances.

The Trusts corporate governance team will respond in the first instance. If any other colleague receives an FOI or EIR request, this should be forwarded onto the Trust Secretary.

We will do one of the following:

  • Supply the requester with the information requested.
  • Inform the requester that we don't hold the information and, if we are able, advise them who does.
  • Neither confirm nor deny that we hold the information, citing one or more of the exemptions from the FOI Act or exceptions under EIR where relevant
  • Inform the requester that we hold the information requested but refuse to provide all or part of it and explain why, citing one or more of the exemptions from the FOI Act or exceptions under EIR where relevant.
  • Inform the requester that we need to extend the 20-working day deadline either to allow us to consider the Public Interest Test for FOI requests or if the complexity and volume of the information requested means that it is impracticable to respond for EIR requests.

9.11 Immediate actions

Upon receipt:

  • Acknowledge the request within 3 working days
  • Log the request into the tracking system, including:
    • Unique reference number
    • Date received
    • Deadline (20 working days)
    • Request summary
    • Requester contact details

9.12 Validity Check

Immediately confirm whether the request meets the FOI/ EIR criteria (see Section 8.8):

  • Is the requester identifiable?
  • Is the information described sufficiently?
  • Is the information requested recorded?

If the request is for personal data, redirect it to a Subject Access Request process.

9.13 Initial Assessment & Triage

Check:

  • Does the organisation hold the information, or does another organisation hold it on our behalf? This may be another NHS organisation, for example.
  • Is it already published? If yes, direct the requester to the source.
  • Has the request already been made? If yes, then the "information accessible by other means" exemption (section 21) will need to be applied.
  • Should it be processed under FOIA or EIR?.

Following NHS Trust FOI/ EIR SOP best practices:

  • Check previous responses to establish if the information has already been released and/ or if this is a vexatious request.
  • Check planned future publication so that the response can reference information that will be published.
  • Assess whether the request triggers full or partial exemptions.

Document early concerns for public interest test if required.

9.14 Allocation to Relevant Teams

Assign each part of the request to appropriate departments:

  • Include only the relevant questions, not requester identity
  • Set internal response deadlines (e.g., 10 working days) to allow time for collation, review, and sign-off.

9.15 Collation of Information

Departments must:

  • Retrieve recorded information only (not generating new data).
  • Ensure accuracy and completeness.
  • Flag any risks, data quality issues, or exemption considerations.

If the cost to produce a response would be greater than £450, then the request can be rejected on the grounds of excessive cost. Staff time is costed at a flat rate of £25 per hour, regardless of grade.

If the time spent locating, retrieving and extracting information would be over 18 hours, the request can be rejected on the grounds of excessive time taken.

Legal advice may be sought to confirm any exemptions applied.

The corporate governance team performs quality assurance before drafting the final response.

9.16 Drafting the Response

The corporate governance team will prepare the response including:

  • Confirmation of whether the information is held
  • The information itself, unless restricted by exemption
  • Explanation of any exemptions applied, with public interest test if needed
  • Notice of the right to request an internal review.

Where full/ partial exemptions apply, approval should be sought from Information Governance leads.

9.17 Approval & Sign-Off

Before issuing:

  • Information Governance Lead reviews all responses.
  • Information Governance Lead identifies any responses that are cases for exemption or deemed high risk.
  • Exemption-heavy or high-risk responses will require Data Protection Officer (DPO) sign-off, and may require additional consultation before publication, where appropriate (e.g. External Comms, Trust Secretary, legal counsel).

9.18 Issuing the Response

Responses must be issued within 20 working days unless the deadline for response has been extended in accordance with the legislation.

The response should be via the method requested (i.e. email/ letter). However, this is only required where it is reasonably practical to do so. Please include a link to the publication log if the response is also published.

9.19 Internal Review Handling

If a requester is dissatisfied:

  • They may request an internal review.
  • This review should be conducted by someone not involved in the original decision.
  • The aim is to complete this within 20 working days.

9.20 Record Keeping & Audit

The corporate governance team will maintain comprehensive records, including:

  • Initial request
  • All internal correspondence
  • Exemption assessments
  • Final response
  • Review outcomes

The NHS Publication Scheme and Records Management code expectations include maintaining FOI-related information responsibly and transparently.

9.21 What can individuals do if they are unhappy with the response they receive or the way their request was handled?

Individuals can ask us for an internal review of their FOI or EIR request. When they write to us requesting an internal review, we will acknowledge their request and tell them how long the review will take. We aim to complete internal reviews within 20 working days, although cases that are complex may take longer. Where internal reviews go over 20 working days, we will write to the requestor to explain there has been a delay and keep them informed of progress.

If, after an internal review, they are still not satisfied, they can then complain to the Information Commissioner, and we will advise them of the process for doing this. For details of how to do this visit the ICO website: https://ico.org.uk/about-the-ico/our-information/request-information-from-us/.

Full details of how to ask the Trust for an internal review and details of how to complain further to the Information Commissioner will be included in our initial response to their request.

Details of how to complain further to the Information Commissioner will also be included in our response to their internal review request.

9.22 Calculating response times

The 20-day response period begins on the first working day after receipt. A request is considered received on the day it arrives in the organisation, even if it is not logged.

If a request is received after close of business (5pm on any working day), or on a non-working day, it is treated as being received the following working day.

The day of receipt is Day 0. The deadline for responding starts from the following working day (Day 1). The deadline for responding falls at the end of the 20th working day.

If clarification is required, the clock is stopped. This happens when the requestor is contacted for additional information, for example to clarify their request.

The clock restarts when sufficient clarification is received.

For EIR requests it is possible to allow an extension to 40 days for a response. This is allowed when the request is complex or voluminous. The Information Governance Lead will determine if this applies.

In the event of any extension, the requestor needs to be notified within 20 days and the Trust must provide reasons for the extension. A new deadline must be provided, with a maximum extension of an additional 20 days.

10. Implementation

This policy is implemented via communication to staff and integration into IG processes.

11. Dissemination and communication

The policy will be published on the internal staff intranet.

12. Monitoring and audit

Monitoring criteria and methods for FOI and EIR compliance
Monitoring criterionMonitoring methodHow often?Who will lead the monitoring?Where will it be reported?Who will be responsible for ensuring that actions identified from monitoring results are followed up?
Compliance with statutory compliance response timescale: % of requests completed within 20 working days; Number of late responsesFOI case management systemMonthlyTrust SecretaryAudit & Risk CommitteeProgramme Director
Internal FOI performance: Number of internal reviews; Themes and repeated issuesFOI case management systemMonthlyTrust SecretaryAudit & Risk CommitteeProgramme Director

13. References