By Jess Pembroke, Director of Information Law Services

As our new Prime minister talks about social care funding in recent weeks,[1] it’s incumbent upon him to look to end the scandal that is companies taking excessive profits from any of our public services.

“Care is costly in the UK, with 70 per cent of local authority budgets spent on funding care services. Yet our analysis shows that in just three UK regions, private care providers extracted more than £250 million in profit over three years. Over a third of these companies are owned by private equity firms, organisations registered in tax havens, or entities that fall into both those brackets.”[2]

What struck me most was not simply the story of social care funding itself. As somebody who works in information rights, beneath the headlines about public services, private providers, ownership structures and profits I can see a recurring issue: transparency is essential if public money, public services and public accountability are to be properly understood.

There will always be circumstances where genuinely sensitive commercial information requires protection. The law rightly recognises that. However, Freedom of Information Law is supposed to be more than a compliance obligation; it is a matter of public trust that we, the tax payers, can understand how public money has been spent and who has received it.

Freedom of Information exists because transparency strengthens democracy. It allows questions to be asked and decisions to be scrutinised. It provides a mechanism for understanding how public bodies operate. Yet transparency is often viewed as the problem.

As Data Protection Officers, FOI officers and information governance professionals, we have all heard the frustrations:

  • Supplier due diligence is slowing the project down
  • A Data Protection Impact Assessment is delaying progress
  • The privacy notice can be added later
  • An FOI request is a drain on resources
  • The compliance team is being difficult.

But when we look back at some of the most significant public scandals of recent decades, the lesson is usually the opposite.

The Post Office Horizon scandal which I wrote about here (link) demonstrated how concerns were raised for years. Freedom of Information Requests were refused. The evidence was there but a lack transparency and accountability allowed the problem to continue for far longer than it should have done.

The questions raised about social care funding and private profits follow a familiar pattern.

The same principle of transparency runs throughout UK GDPR. As organisations rely on larger and more complex supply chains. Personal data often passes through processors, cloud providers, software vendors and sub-processors. Yet many organisations struggle to provide a clear picture of where data goes and who ultimately has access to it. A privacy notice may refer to “trusted partners” and “service providers”, but does that genuinely help people understand what is happening to their information?

The more I reflected on this research into social care, ownership structures and public money, the more I realised that the questions asked by information rights professionals are very similar.

  • We ask who the supplier is
  • We ask who the sub-processors are
  • We ask who made the decision
  • We ask whether records exist
  • We ask whether information should be disclosed
  • We ask whether the public would understand what is happening.

Information governance professionals are not there to make everybody’s life more difficult. Instead, we have a valuable role in shining a light on what our organisation is doing and for who.

Perhaps, in time, a stronger culture of transparency across the public sector will not just expose the next scandal after it happens, but it will help prevent it from happening in the first place.

To learn more about transparency, join us on our Data Protection Essentials course. Designed for those who have limited prior understanding of basic Data Protection principles, this course is great for those somewhat new to handling personal data, or who are in need of a refresher. Worth 6 accredited hours from CPD UK, the next course dates are 15 & 17 September (9:30am-1pm). To book your place, use the link above or contact our Operations  Manager at info@naomikorn.com. Looking to learn more about Freedom of Information? Our intermediate half day CPD UK accredited course, Freedom of Information Act and Environmental Information Regulations, guides you step by step through handling requests, applying exemptions, managing refusals, and understanding appeals processes – giving you the tools to manage requests compliantly and confidently. The course next runs on 19 November (9:30am-1pm). To learn more or book your place, click the links above or get in touch by emailing info@naomikorn.com.


[1] Andy Burnham doesn’t rule out tax rises to fix social care – BBC News

[2] Ending extraction in the UK care system