Legal & Compliance
UK Information Commissioner’s Office (ICO) – Data Protection & FOI
- UK GDPR guidance and resources:https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/
- Freedom of Information guidance: https://ico.org.uk/for-organisations/eir-and-access-to-information/guide-to-freedom-of-information/
Why this matters:
The ICO regulates data protection and access to information law in the UK, setting expectations for subject access requests, FOI handling, exemptions, audit trails and lawful processing of personal data.
The National Archives (UK) – Legal Responsibilities
- Information management legal responsibilities:https://www.nationalarchives.gov.uk/information-management/
- Section 46 Code of Practice (FOI): https://www.nationalarchives.gov.uk/information-management/manage-information/planning/records-management-code/
Why this matters:
Explains the legal responsibilities of public authorities to create, keep and manage records to support accountability, transparency, audit, and compliance with FOI and other statutory duties.
National Records of Scotland (NRS) – PRSA Guidance
- Public Records (Scotland) Act overview:https://www.nrscotland.gov.uk/records-and-archives/public-records-scotland-act/
- Records Management Plan guidance: https://www.nrscotland.gov.uk/records-and-archives/records-management-plans/
Why this matters:
PRSA places a statutory duty on named Scottish public authorities to implement effective records management arrangements, recognising records as essential to protecting rights, supporting legal compliance, and evidencing decisions.
Scottish Information Commissioner – FOI (Scotland)
- Scottish Information Commissioner guidance:https://www.foi.scot/law-and-guidance
Why this matters:
The Commissioner oversees and enforces the Freedom of Information (Scotland) Act 2002, with guidance emphasising the link between good records management, knowing what information is held, and lawful disclosure.
Additional UK Records Management Resources
Key Legislation
- UK GDPR & Data Protection Act 2018:https://www.gov.uk/data-protection
- Freedom of Information Act 2000: https://www.legislation.gov.uk/ukpga/2000/36/contents
- Freedom of Information (Scotland) Act 2002: https://www.legislation.gov.uk/asp/2002/13/contents
Primary legislation underpinning data rights, access to information, and lawful records handling across the UK.
