The Eye of Accountability

Exposed: How ICO’s Secrecy Undermines Trust in GDPR Investigations – What You Need to Know!

ICO accountability · FOI exemptions · Data protection

The Information Commissioner’s Office exists to uphold information rights. That role depends on public confidence: complaints must be assessed carefully, reasons must be understandable, and exemptions must not be experienced by complainants as a barrier to accountability. Where a data subject believes an investigation was too narrow, too opaque, or too dependent on future-publication exemptions, the core question is whether the process can be followed, tested and trusted.

Category
Regulatory accountability
Jurisdiction
England & Wales
Reading time
c. 9 minutes
Last reviewed
1 June 2026
By-line
Legal Lens

Publication snapshot

  • This article examines an ICO complaint involving Burnetts Solicitors as a public-confidence and investigation-quality case study.
  • The central concern is whether complex data-protection complaints are investigated with enough depth, explanation and issue separation.
  • FOI exemptions, including information intended for future publication, may be lawful in principle, but their use should still be explained clearly.
  • The practical answer is structured review: complaint issue, evidence relied upon, principle engaged, finding made, reasons given and route to challenge.
Reader note: this article is public-interest commentary and practical legal education. References to Burnetts Solicitors, the ICO, an ICO investigator, alleged superficial investigation, alleged conflict handling, alleged poor record-keeping, alleged weak reasoning, alleged misuse of FOI exemptions or alleged regulatory failure are allegations and analysis unless established by a competent court, tribunal, regulator, ombudsman, inquiry, audit report, formal admission or primary document.

The core point: transparency must be visible in the process

The ICO occupies a difficult position. It must handle large volumes of complaints, apply data-protection law, manage freedom-of-information requests, protect personal data, and explain decisions to people who may already feel that an organisation has failed to respect their rights.

The concern raised in the supplied draft is that an ICO complaint involving Burnetts Solicitors was, in the complainant’s view, investigated too narrowly and explained too thinly. The draft also raises concern about the ICO’s use of a Freedom of Information Act exemption for information intended for future publication.

The stronger public-interest argument is not that the ICO necessarily acted improperly. It is that a regulator’s reasoning must be sufficiently clear to let a complainant understand what was examined, what was not examined, what evidence mattered, what legal principles were applied, and why the outcome was reached.

The ICO’s role: regulator, complaint handler and information-rights body

The ICO is the UK’s information-rights regulator. Its work covers data protection, freedom of information, access to information, direct marketing and related areas. That makes transparency especially important. The body that promotes information rights must also show that its own complaint handling is intelligible and accountable.

In a data-protection complaint, the complainant may expect the ICO to consider the organisation’s processing, the evidence supplied, the relevant UK GDPR principles, and whether the controller’s explanation is adequate. The ICO does not act as the complainant’s solicitor, and it does not decide every civil dispute. But its conclusions should still make the reasoning path visible.

Data protection

Complaint assessment

Assess whether a data-protection concern has been handled in a way consistent with the applicable information-rights framework.

FOI

Access to information

Apply freedom-of-information rules and exemptions while explaining why information is released, delayed or withheld.

Reasons

Public confidence

Provide enough explanation for a complainant to understand the decision, even where the complaint is not upheld.

Learning

Process improvement

Use recurring complaint patterns to improve investigation quality, communication and published guidance.

The case study: Burnetts, complaint handling and disputed investigation depth

The supplied draft refers to a complaint about Burnetts Solicitors and says the complainant raised concerns about GDPR compliance, audit logs, SAR handling, conflicts of interest, data minimisation, purpose limitation and record-keeping.

The complainant’s position is that the ICO investigation did not engage sufficiently with those concerns. The draft also refers to a named ICO investigator and questions the investigator’s training and suitability. For publication, that point is better framed as a systems issue: did the ICO’s process explain the competence, scope and reasoning behind its investigation, rather than focusing on personal criticism of an individual officer?

A clean article should separate three questions: first, what Burnetts was alleged to have done; second, what the ICO actually considered; and third, whether the ICO’s reasoning was clear enough to command confidence.

1

Complaint issue

The complainant says the complaint raised data-protection concerns about SAR handling, audit trails and data-processing principles.

2

Investigation scope

The public-confidence question is whether the ICO identified and addressed each material issue, or narrowed the complaint too quickly.

3

Reasons given

The decision should make clear what evidence was reviewed, what principles were applied and why the complaint did or did not succeed.

4

FOI response

The later FOI response should explain any exemption relied upon, including why delayed disclosure was justified.

Investigation quality: what a reasoned assessment should show

A complainant may disagree with an outcome even after a fair investigation. Disagreement alone does not prove regulatory failure. The issue is whether the decision-maker has shown the work: the issue identified, the documents considered, the legal test applied and the reason for the conclusion.

The supplied draft raises concern that paper audit logs were accepted without enough scrutiny, that conflict points were not answered, that the distinction between different SARs became confused, and that the investigation did not engage with purpose limitation and data minimisation. Those are serious concerns, but they need to be tested against the actual ICO correspondence and any published decision or response.

The investigation-quality test

A regulatory complaint outcome is easier to trust when the reasoning can be reconstructed from the decision.

A

What issue was accepted for investigation?

B

What evidence was requested or reviewed?

C

What UK GDPR principle was engaged?

D

What explanation did the controller provide?

E

Why was the explanation accepted or rejected?

FOI exemptions: Section 22 and future publication

The draft says the ICO relied on Section 22 of the Freedom of Information Act 2000, which concerns information intended for future publication. The point requires precision. A future-publication exemption is not automatically improper. The real question is whether the information fell within the exemption and whether the public-interest balance was explained in a way that could be understood.

Where the requester seeks information about complaint handling, investigation quality or regulator performance, delayed disclosure may feel like the opposite of transparency. That does not mean the exemption is unlawful. It means the decision should explain why regular publication, timing, operational planning or other factors outweighed earlier disclosure.

What information was requested?

The request should be broken down by category: reports, internal communications, policies, complaint data or decision material.

What exemption was relied upon?

The response should identify the exemption clearly and explain how it applies to the requested information.

What public interest was weighed?

The requester should be able to see the balance between earlier disclosure and maintaining the exemption.

What remains available?

The response should identify any review, complaint, appeal or later publication route.

Data-protection principles: the complaint cannot be reduced to paperwork

The UK GDPR principles are not technical decoration. They are the framework through which controllers are expected to process personal data. The relevant principles in a complaint of this kind may include transparency, purpose limitation, data minimisation, accuracy, security and accountability.

That does not mean every complaint about audit logs or SAR handling proves a breach. It means a reasoned investigation should show whether the principle was considered, how the evidence was assessed and why the organisation’s practice did or did not raise a data-protection concern.

1

Transparency

Can the data subject understand what was processed, why and by whom?

2

Purpose limitation

Was the data used for specified and legitimate purposes, or was the purpose unclear?

3

Data minimisation

Was the data adequate, relevant and limited to what was necessary?

4

Security and accountability

Were records kept and protected in a way that allowed compliance to be demonstrated?

A practical reform test for ICO complaint handling

The reform argument does not depend on proving every allegation in this case study. It rests on a wider point: complaint handlers should make the investigation path clear enough for complainants to understand why their concern succeeded, failed or was treated as outside scope.

1

Clear issue framing

Tell the complainant which issues are being considered, and which are outside scope.

2

Evidence engagement

Show which documents or explanations were material to the conclusion.

3

Principle mapping

Connect the facts to the relevant UK GDPR principle or statutory rule.

4

FOI clarity

Explain exemptions and public-interest balancing in accessible terms.

5

Learning loop

Use difficult complaints to improve investigator training, communication and published guidance.

Source anchors

These anchors support the ICO, FOI and data-protection framework. They do not verify the Burnetts-specific allegations, the ICO case reference, the investigator-specific criticism, or any disputed complaint facts.

Closing point

The concern raised by this case study is not simply that a complainant disagreed with the ICO. The deeper point is that complaint handling must be sufficiently transparent to command trust.

Where a complainant raises complex data-protection concerns, a regulator’s answer should not leave them guessing about scope, evidence, principle, reasoning or route. Where FOI exemptions are used, the decision should explain why delayed access is justified.

The Legal Lens point is simple: information rights are weakened when the process for enforcing them cannot itself be clearly understood.

ICO complaint, FOI response and evidence structure

Legal Lens can help turn a complex complaint into a structured issue map. The assessment can separate data-protection principles, SAR issues, FOI exemptions, evidence gaps, complaint route, review route and the documents needed to make the next step clear.

Issue map Evidence schedule FOI route Complaint review
01 What was decided?

Identify the ICO response, FOI refusal, review outcome or complaint decision under challenge.

02 What was missed?

Link each concern to the exact document, principle, request, exemption or answer relied upon.

03 Which route fits?

Separate ICO complaint, internal review, FOI appeal, SAR issue, civil advice or regulator route.

Independent Legal Lens consultancy. Legal Lens is not a regulated solicitors’ firm or data-protection consultancy. A preliminary assessment is not a substitute for regulated legal advice, specialist data-protection advice, tribunal advice or representation where that is needed.

This article is general legal information and public-interest commentary. It is not legal advice, data-protection advice or a finding that the ICO, Burnetts Solicitors, any investigator, solicitor, firm, controller, regulator or public body acted unlawfully or improperly.

Leave a Reply

Your email address will not be published. Required fields are marked *

Skip to toolbar