ICO accountability · FOI exemptions · Data protection
The Information Commissioner’s Office exists to uphold information rights. That role depends on public confidence: complaints must be assessed carefully, reasons must be understandable, and exemptions must not be experienced by complainants as a barrier to accountability. Where a data subject believes an investigation was too narrow, too opaque, or too dependent on future-publication exemptions, the core question is whether the process can be followed, tested and trusted.
Publication snapshot
- This article examines an ICO complaint involving Burnetts Solicitors as a public-confidence and investigation-quality case study.
- The central concern is whether complex data-protection complaints are investigated with enough depth, explanation and issue separation.
- FOI exemptions, including information intended for future publication, may be lawful in principle, but their use should still be explained clearly.
- The practical answer is structured review: complaint issue, evidence relied upon, principle engaged, finding made, reasons given and route to challenge.
The core point: transparency must be visible in the process
The ICO occupies a difficult position. It must handle large volumes of complaints, apply data-protection law, manage freedom-of-information requests, protect personal data, and explain decisions to people who may already feel that an organisation has failed to respect their rights.
The concern raised in the supplied draft is that an ICO complaint involving Burnetts Solicitors was, in the complainant’s view, investigated too narrowly and explained too thinly. The draft also raises concern about the ICO’s use of a Freedom of Information Act exemption for information intended for future publication.
The stronger public-interest argument is not that the ICO necessarily acted improperly. It is that a regulator’s reasoning must be sufficiently clear to let a complainant understand what was examined, what was not examined, what evidence mattered, what legal principles were applied, and why the outcome was reached.
The ICO’s role: regulator, complaint handler and information-rights body
The ICO is the UK’s information-rights regulator. Its work covers data protection, freedom of information, access to information, direct marketing and related areas. That makes transparency especially important. The body that promotes information rights must also show that its own complaint handling is intelligible and accountable.
In a data-protection complaint, the complainant may expect the ICO to consider the organisation’s processing, the evidence supplied, the relevant UK GDPR principles, and whether the controller’s explanation is adequate. The ICO does not act as the complainant’s solicitor, and it does not decide every civil dispute. But its conclusions should still make the reasoning path visible.
Complaint assessment
Assess whether a data-protection concern has been handled in a way consistent with the applicable information-rights framework.
Access to information
Apply freedom-of-information rules and exemptions while explaining why information is released, delayed or withheld.
Public confidence
Provide enough explanation for a complainant to understand the decision, even where the complaint is not upheld.
Process improvement
Use recurring complaint patterns to improve investigation quality, communication and published guidance.
The case study: Burnetts, complaint handling and disputed investigation depth
The supplied draft refers to a complaint about Burnetts Solicitors and says the complainant raised concerns about GDPR compliance, audit logs, SAR handling, conflicts of interest, data minimisation, purpose limitation and record-keeping.
The complainant’s position is that the ICO investigation did not engage sufficiently with those concerns. The draft also refers to a named ICO investigator and questions the investigator’s training and suitability. For publication, that point is better framed as a systems issue: did the ICO’s process explain the competence, scope and reasoning behind its investigation, rather than focusing on personal criticism of an individual officer?
A clean article should separate three questions: first, what Burnetts was alleged to have done; second, what the ICO actually considered; and third, whether the ICO’s reasoning was clear enough to command confidence.
Complaint issue
The complainant says the complaint raised data-protection concerns about SAR handling, audit trails and data-processing principles.
Investigation scope
The public-confidence question is whether the ICO identified and addressed each material issue, or narrowed the complaint too quickly.
Reasons given
The decision should make clear what evidence was reviewed, what principles were applied and why the complaint did or did not succeed.
FOI response
The later FOI response should explain any exemption relied upon, including why delayed disclosure was justified.
Investigation quality: what a reasoned assessment should show
A complainant may disagree with an outcome even after a fair investigation. Disagreement alone does not prove regulatory failure. The issue is whether the decision-maker has shown the work: the issue identified, the documents considered, the legal test applied and the reason for the conclusion.
The supplied draft raises concern that paper audit logs were accepted without enough scrutiny, that conflict points were not answered, that the distinction between different SARs became confused, and that the investigation did not engage with purpose limitation and data minimisation. Those are serious concerns, but they need to be tested against the actual ICO correspondence and any published decision or response.
The investigation-quality test
A regulatory complaint outcome is easier to trust when the reasoning can be reconstructed from the decision.
What issue was accepted for investigation?
What evidence was requested or reviewed?
What UK GDPR principle was engaged?
What explanation did the controller provide?
Why was the explanation accepted or rejected?
FOI exemptions: Section 22 and future publication
The draft says the ICO relied on Section 22 of the Freedom of Information Act 2000, which concerns information intended for future publication. The point requires precision. A future-publication exemption is not automatically improper. The real question is whether the information fell within the exemption and whether the public-interest balance was explained in a way that could be understood.
Where the requester seeks information about complaint handling, investigation quality or regulator performance, delayed disclosure may feel like the opposite of transparency. That does not mean the exemption is unlawful. It means the decision should explain why regular publication, timing, operational planning or other factors outweighed earlier disclosure.
What information was requested?
The request should be broken down by category: reports, internal communications, policies, complaint data or decision material.
What exemption was relied upon?
The response should identify the exemption clearly and explain how it applies to the requested information.
What public interest was weighed?
The requester should be able to see the balance between earlier disclosure and maintaining the exemption.
What remains available?
The response should identify any review, complaint, appeal or later publication route.
Data-protection principles: the complaint cannot be reduced to paperwork
The UK GDPR principles are not technical decoration. They are the framework through which controllers are expected to process personal data. The relevant principles in a complaint of this kind may include transparency, purpose limitation, data minimisation, accuracy, security and accountability.
That does not mean every complaint about audit logs or SAR handling proves a breach. It means a reasoned investigation should show whether the principle was considered, how the evidence was assessed and why the organisation’s practice did or did not raise a data-protection concern.
Transparency
Can the data subject understand what was processed, why and by whom?
Purpose limitation
Was the data used for specified and legitimate purposes, or was the purpose unclear?
Data minimisation
Was the data adequate, relevant and limited to what was necessary?
Security and accountability
Were records kept and protected in a way that allowed compliance to be demonstrated?
A practical reform test for ICO complaint handling
The reform argument does not depend on proving every allegation in this case study. It rests on a wider point: complaint handlers should make the investigation path clear enough for complainants to understand why their concern succeeded, failed or was treated as outside scope.
Clear issue framing
Tell the complainant which issues are being considered, and which are outside scope.
Evidence engagement
Show which documents or explanations were material to the conclusion.
Principle mapping
Connect the facts to the relevant UK GDPR principle or statutory rule.
FOI clarity
Explain exemptions and public-interest balancing in accessible terms.
Learning loop
Use difficult complaints to improve investigator training, communication and published guidance.
Source anchors
These anchors support the ICO, FOI and data-protection framework. They do not verify the Burnetts-specific allegations, the ICO case reference, the investigator-specific criticism, or any disputed complaint facts.
- ICO: what we do — official information on the ICO’s work and legislation it covers.
- ICO: guide to the data protection principles — official guidance on UK GDPR principles including transparency, purpose limitation, data minimisation, security and accountability.
- ICO: decision notices — official decision-notice search page for freedom-of-information and information-rights outcomes.
- ICO: make a complaint — the route for raising information-rights concerns with the ICO.
- Freedom of Information Act 2000, Section 22 — statutory provision concerning information intended for future publication.
Closing point
The concern raised by this case study is not simply that a complainant disagreed with the ICO. The deeper point is that complaint handling must be sufficiently transparent to command trust.
Where a complainant raises complex data-protection concerns, a regulator’s answer should not leave them guessing about scope, evidence, principle, reasoning or route. Where FOI exemptions are used, the decision should explain why delayed access is justified.
The Legal Lens point is simple: information rights are weakened when the process for enforcing them cannot itself be clearly understood.
ICO complaint, FOI response and evidence structure
Get a free written assessment before escalating an ICO or data-rights complaint
Legal Lens can help turn a complex complaint into a structured issue map. The assessment can separate data-protection principles, SAR issues, FOI exemptions, evidence gaps, complaint route, review route and the documents needed to make the next step clear.
Identify the ICO response, FOI refusal, review outcome or complaint decision under challenge.
Link each concern to the exact document, principle, request, exemption or answer relied upon.
Separate ICO complaint, internal review, FOI appeal, SAR issue, civil advice or regulator route.
Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors’ firm or data-protection consultancy. A preliminary assessment is not a substitute for regulated legal advice, specialist data-protection advice, tribunal advice or representation where that is needed.

