Legal & Compliance

UK Information Commissioner’s Office (ICO) – Data Protection & FOI 

Why this matters:
The ICO regulates data protection and access to information law in the UK, setting expectations for subject access requests, FOI handling, exemptions, audit trails and lawful processing of personal data. 

The National Archives (UK) – Legal Responsibilities 

Why this matters:
Explains the legal responsibilities of public authorities to create, keep and manage records to support accountability, transparency, audit, and compliance with FOI and other statutory duties. 

National Records of Scotland (NRS) – PRSA Guidance 

Why this matters:
PRSA places a statutory duty on named Scottish public authorities to implement effective records management arrangements, recognising records as essential to protecting rights, supporting legal compliance, and evidencing decisions. 

Scottish Information Commissioner – FOI (Scotland) 

Why this matters:
The Commissioner oversees and enforces the Freedom of Information (Scotland) Act 2002, with guidance emphasising the link between good records management, knowing what information is held, and lawful disclosure. 

Additional UK Records Management Resources 

Key Legislation 

Primary legislation underpinning data rights, access to information, and lawful records handling across the UK.