Skip to content

FOI & SAR register

For the helpdesk team

Schools and trusts receive several kinds of information-rights request:

  • FOI — Freedom of Information Act requests (general info about the trust).
  • EIR — Environmental Information Regulations (estates, sustainability, energy).
  • SAR — Subject Access Requests under UK GDPR Article 15 (personal data about the requester).

This register handles all three with a shared workflow and per-type statutory deadlines.

  • Request type — foi / sar / eir.
  • Reference — auto-assigned per workspace, e.g. FOI-2026-014.
  • Received on — date you logged the request.
  • Due by — auto-calculated from received_on + the type’s statutory window (FOI: 20 working days, SAR: one month, EIR: 20 working days). Override if the law allows extension (e.g. a complex SAR can be extended to 3 months).
  • Requester name + contact — who asked.
  • Subject — short summary.
  • Body — the full request text.
  • Status — open, acknowledged, information_gathered, clarification_needed, response_sent, refused, closed.
  • Handler — internal owner.
  • Outcome — final disposition. Granted in full, partial, refused (with exemption reason).

Sort: by status (open requests first), then by due_by. The clerk’s morning sweep starts at the top — anything past due_by is a regulatory breach.

Filter by type to pull just FOIs, just SARs, etc.

UK FOIA allows refusal under specific exemptions (Section 12, 14, 21-44). When you refuse, set status to refused and pick the exemption section. The system doesn’t enforce which sections are valid for which type — that’s a legal judgement, not a data validation.

  • Working days vs calendar days: FOI is working days. SAR is calendar (one month). EIR is working days. The auto-calculation handles this — don’t override due_by without re-checking.
  • A complex SAR can be extended to 3 months total under Article 12(3). Document the extension reason in the body.
  • Closed is the right state when the requester abandons or the request is otherwise resolved without a formal refusal. Refused is when you decline and apply an exemption. Response_sent marks that a substantive reply has been issued. Don’t mix them.