FOI / FOIA / ATIP
Freedom of information (FOI) is the umbrella term for laws that give the public an enforceable right to request records held by government. The name varies by country: the United States and the United Kingdom each have a Freedom of Information Act (FOIA); Canada's federal regime is known as ATIP — Access to Information and Privacy, under the Access to Information Act and the Privacy Act — while Canadian provinces use statutes such as FIPPA and FOIP; EU institutions answer document requests under Regulation 1049/2001, and each member state runs its own national access law. Whatever the label, the architecture is consistent: a written request, a statutory deadline, limited exemptions, and an independent oversight body.
Related:
FOI request management · Jurisdiction packs
Access request
An access request (also called an FOI, FOIA, ATIP, or public records request) is a written application asking a public body to disclose records it holds. Most statutes require the requester to describe the records in enough detail for an experienced employee to locate them, and start a response clock on receipt — 30 calendar days under Canada's federal Act, 20 working days under US FOIA and UK FOIA — with extensions available in defined circumstances. The body must search for responsive records, apply any exemptions, and issue a decision with reasons and review rights. In AccessPoint: each request runs through a full lifecycle with statutory deadlines computed from the jurisdiction's own rules.
Related:
FOI request management · FOI quick check
Deemed refusal (constructive denial)
A deemed refusal occurs when a public body fails to respond to an access request within the statutory time limit and the law treats the silence as a refusal of access. Under Canada's Access to Information Act, missing the 30-day deadline (or any validly extended deadline) is deemed a refusal under subsection 10(3), opening a complaint to the Information Commissioner — though the institution still owes a response. The US parallel is constructive denial: once FOIA's 20-working-day deadline passes, the requester is deemed to have exhausted administrative remedies and may go straight to court. In the UK, a late response can be complained about to the ICO. Deemed-refusal rates are a standard performance metric for access programs.
Related:
FOI request management · FOI quick check
Exemption vs. exclusion
An exemption is a provision inside an access law that permits or requires withholding information the Act otherwise covers — personal information, law-enforcement matters, advice to government, third-party business information. Exemptions can be mandatory or discretionary, and many turn on a harm (injury) test or a public interest test. An exclusion instead places records outside the Act entirely, so its process and oversight largely do not apply: Canada's federal Act excludes Cabinet confidences, and many statutes exclude court records or specific bodies. The practical difference matters — exempt records are still processed, severed, and reviewable, while excluded records fall outside the regime, leaving requesters with far narrower review rights.
Related:
FOI request management · Jurisdiction packs
Severing (redaction)
Severing is the practice of redacting only the exempt portions of a record and releasing the rest, rather than withholding whole documents. Most access laws make it a duty: Canada's federal Act requires disclosure of any part that can reasonably be severed, US FOIA requires release of 'reasonably segregable' non-exempt portions, and UK practice reaches the same result by applying exemptions to parts of a record. Good severing marks each redaction with the specific statutory exemption relied on, so the requester — and any commissioner or court reviewing the decision — can test each withholding on its own. In AccessPoint: reviewers redact documents with every redaction tagged to the exemption it relies on.
Related:
FOI request management
Duty to assist
The duty to assist obliges a public body to help requesters exercise their access rights rather than treat requests adversarially: making every reasonable effort to assist, clarifying ambiguous requests, responding accurately and completely, and providing records in the requested format where reasonable. Canada's federal Access to Information Act imposes it expressly (subsection 4(2.1)), as do provincial laws such as British Columbia's FIPPA; in the UK, section 16 of FOIA creates an equivalent duty to advise and assist, elaborated in the section 45 Code of Practice. US FOIA has no identically framed duty, but agencies designate FOIA Public Liaisons to assist requesters. Commissioners routinely measure institutions against this duty in delay and adequacy complaints.
Related:
FOI request management · FOI quick check
Transfer of request
A transfer of request moves an access request from the public body that received it to another body with a greater interest in the records — usually the body that created them or first obtained them. Statutes keep the window short: Canada's federal Act permits transfer within 15 days of receipt, and provincial laws are similar, with the statutory clock effectively continuing to run from the original receipt date. UK FOIA contains no transfer power; the section 45 Code of Practice instead expects the authority to tell the requester which authority holds the records so they can reapply. US agencies route records between agencies through referrals and consultations rather than formal transfer.
Related:
FOI request management
Fee estimate / deposit
A fee estimate is a public body's advance calculation of the charges a request will attract — search, preparation, copying — issued before processing continues; a deposit is a partial prepayment the body may require before doing the work. Practice varies widely: Canada's federal regime now charges only a $5 application fee, while Ontario requires an estimate when fees will exceed $25 and permits a 50% deposit when they exceed $100. US FOIA fees depend on requester category (commercial, media, educational, other), and UK FOIA lets authorities refuse requests whose cost exceeds the 'appropriate limit' rather than bill for staff time. Fee estimates typically pause the statutory clock and carry their own appeal rights.
Related:
FOI request management · FOI ROI calculator
Third-party notice
Third-party notice is the formal notification a public body must give an outside party — most often a business whose commercial or confidential information appears in responsive records — before disclosing information that may be exempt in that party's interest. The third party gets a defined period to argue against disclosure, and often a right to challenge the decision before release. Canada's federal Act gives affected third parties 20 days to make representations, with recourse to the Federal Court; provincial laws follow the same pattern. In the US, Executive Order 12600 requires submitter notice for confidential commercial information under FOIA. UK FOIA imposes no statutory duty, but the section 45 Code of Practice expects consultation with affected third parties.
Related:
FOI request management
Internal review vs. appeal to commissioner
Internal review and commissioner appeal are the two tiers of challenge open to a requester who disputes an access decision. An internal review asks the same public body to reconsider, usually through a more senior official uninvolved in the original decision; UK FOIA practice requires exhausting internal review before complaining to the Information Commissioner's Office. An appeal or complaint to a commissioner takes the dispute to the independent oversight body — Canada's Information Commissioner federally, provincial bodies such as Ontario's IPC, and the ICO in the UK. The US has no commissioner: FOIA uses an administrative appeal inside the agency, then federal court, with OGIS offering mediation. Appeal deadlines are short and jurisdiction-specific.
Related:
Complaint management · Jurisdiction packs
Public interest override
A public interest override is a statutory provision that requires or permits disclosure of otherwise exempt information because the public interest in release outweighs the interest the exemption protects. Forms differ by jurisdiction: UK FOIA builds a public interest test into every qualified exemption; Ontario's FIPPA (section 23) overrides listed exemptions where a compelling public interest clearly outweighs their purpose; British Columbia's FIPPA (section 25) goes further, mandating disclosure of information about significant risks to health, safety, or the environment even without a request. US federal FOIA has no general override, though the 'foreseeable harm' standard narrows discretionary withholding. The override is what keeps exemptions from operating as absolute secrecy rules.
Related:
FOI request management · Jurisdiction packs
Proactive disclosure / publication scheme
Proactive disclosure is the routine publication of government information without waiting for a request — expenses, contracts, grants, briefing-note titles, summaries of completed access requests. A publication scheme is the UK mechanism: FOIA sections 19–20 require every public authority to adopt and follow an ICO-approved scheme committing it to publish defined classes of information. Canada made proactive publication a statutory duty in 2019, adding Part 2 to the Access to Information Act for government institutions and ministers' offices; US federal agencies must post certain records — including records requested three or more times — in online FOIA reading rooms. Proactive disclosure reduces request volumes and is increasingly an obligation, not a courtesy.
Related:
Jurisdiction packs
Vexatious / frivolous requests
A vexatious or frivolous request is one that abuses the right of access — harassing staff, imposing grossly disproportionate burden, or re-litigating requests already answered — and that a public body may decline to process. The safeguards differ: under UK FOIA section 14 the authority may refuse a vexatious or repeated request itself, subject to ICO review; in Canada the bar is higher — federally an institution needs the Information Commissioner's approval to decline to act (section 6.1), British Columbia requires prior commissioner authorization, and in Ontario the head decides but the requester can appeal to the IPC. US FOIA has no vexatious-request provision. Everywhere the threshold is deliberately high: volume or annoyance alone does not qualify.
Related:
FOI request management
Working days vs. calendar days
Access statutes count response deadlines in either working days or calendar days, and the difference materially changes due dates. UK FOIA and US FOIA both allow 20 working days, excluding weekends and public holidays; Canada's federal Access to Information Act allows 30 calendar days, as do most Canadian provinces, with a deadline that lands on a weekend or holiday rolling to the next business day. GDPR access requests use a third convention entirely: one calendar month. Statutory holidays differ across jurisdictions — even between Canadian provinces — so miscounting is a common source of missed deadlines and deemed refusals. In AccessPoint: jurisdiction packs compute every due date using the statute's own deadlines and day-counting rules.
Related:
Jurisdiction packs · FOI request management
EIR (Environmental Information Regulations)
The Environmental Information Regulations 2004 (EIR) are the UK's parallel access regime for environmental information — records about air, water, land, emissions, energy, and the measures affecting them. Rooted in the Aarhus Convention via EU Directive 2003/4/EC, EIR requests differ from UK FOIA in ways practitioners must spot: requests can be verbal, not just written; the deadline is 20 working days, extendable to 40 for complex, voluminous requests; withholding relies on exceptions rather than exemptions, each subject to a public interest test with a presumption in favour of disclosure; and there is no section 12 cost-limit refusal — only 'manifestly unreasonable'. EIR also reach more bodies than FOIA: anyone carrying out functions of public administration, including privatised water companies.
Related:
uk foi · Jurisdiction packs
Glomar response / neither confirm nor deny (NCND)
A Glomar response — named for the Hughes Glomar Explorer, the CIA ship at issue in Phillippi v. CIA (1976) — refuses to confirm or deny that requested records exist, because acknowledging even their existence would reveal what an exemption protects. US agencies use it mainly for classified and personal-privacy matters. The device is not uniquely American: UK FOIA lets authorities exclude the duty to confirm or deny where exemptions provide for it — a 'neither confirm nor deny' (NCND) response — and Canada's federal Act permits the head of an institution to decline to indicate whether a record exists (subsection 10(2)), citing the exemption that would apply if it did. Commissioners and courts can review the refusal itself.
Related:
FOI request management
Fee waiver
A fee waiver relieves a requester of processing charges. Under US FOIA, fees must be waived or reduced where disclosure is in the public interest — likely to contribute significantly to public understanding of the operations or activities of government — and not primarily in the requester's commercial interest; separate requester categories (news media, educational, commercial) already determine which fees can be charged at all, and waiver denials are reviewed de novo by courts. Canadian statutes make waivers discretionary — Ontario's FIPPA allows one where payment would be unfair, weighing factors like financial hardship and public-health benefit — while UK FOIA rarely raises the question because authorities cannot charge for staff time on requests under the cost limit.
Related:
FOI request management · FOI ROI calculator
Expedited processing
Expedited processing moves an access request ahead of the normal first-in, first-out queue. US FOIA entitles a requester to it on showing 'compelling need': an imminent threat to someone's life or physical safety, or — for a person primarily engaged in disseminating information — urgency to inform the public about actual or alleged federal government activity. The agency must decide the expedite request, and notify the requester, within 10 days, and may add further qualifying categories by regulation; denials can be appealed and litigated. Most Commonwealth regimes have no statutory fast lane — every request carries the same clock — so prioritization there is a queue-management and backlog-triage practice rather than a legal status.
Related:
FOI request management · foi backlog recovery
Deliberative process / advice to government
Nearly every access law shields internal deliberations so officials can give free and frank advice. US FOIA does it through Exemption 5's deliberative process privilege, protecting predecisional, deliberative records — with a 25-year sunset added in 2016. Canada's federal Act exempts advice or recommendations developed for an institution or minister (section 21) — discretionary, limited to records under 20 years old — with provincial parallels such as Ontario FIPPA's section 13. UK FOIA divides the ground between section 35 (formulation of government policy) and section 36 (prejudice to the effective conduct of public affairs), both subject to the public interest test. The battle line: factual material and final decisions are disclosable; the deliberation itself may not be.
Related:
FOI request management · Jurisdiction packs
Cost limit / appropriate limit (UK FOIA section 12)
The cost limit — formally the 'appropriate limit' — lets a UK public authority refuse an FOI request when it reasonably estimates that finding the information would exceed a threshold set by the Appropriate Limit and Fees Regulations 2004: £600 for central government and £450 for all other public authorities, converted at a notional £25 per hour into 24 and 18 hours of staff time. Only locating, retrieving, and extracting the information count toward the estimate — not redaction or public-interest analysis — and related requests can be aggregated. The duty to advise and assist still applies: authorities should say what could be provided within the limit. EIR requests have no cost limit; the nearest ground is 'manifestly unreasonable'.
Related:
uk foi · FOI request management
Legal professional privilege / solicitor-client privilege
Legal professional privilege — solicitor-client privilege in Canada, attorney-client privilege in the US — protects confidential communications between lawyer and client for the purpose of legal advice, plus material prepared for litigation, and every major access regime lets government withhold it. UK FOIA's section 42 is a qualified exemption, so the public interest test applies, though tribunals give the privilege strong built-in weight. Canada's federal Act (section 23) makes it discretionary, and the Supreme Court of Canada treats solicitor-client privilege as quasi-constitutional, so any override is read narrowly. US FOIA folds the attorney-client and attorney work-product privileges into Exemption 5. A recurring processing question is waiver: advice circulated beyond those who needed it can lose protection.
Related:
FOI request management
Disclosure log
A disclosure log is a public list of information a body has already released under access law, often with the released documents attached. Australia makes it a statutory duty: section 11C of the federal FOI Act requires agencies to publish information released to FOI requesters on a website disclosure log within 10 working days, with carve-outs for personal and business information. US federal agencies must post frequently requested records — those requested three or more times — in online FOIA libraries, and Canada publishes summaries of completed access requests that anyone can use to order a re-release. UK authorities keep logs as good practice rather than obligation. A well-maintained log deflects duplicate requests and feeds proactive disclosure.
Related:
FOI request management · foi annual stats
Privacy impact assessment (PIA) vs. DPIA
A privacy impact assessment (PIA) is a structured analysis, completed before launch, of how a program or system will collect, use, disclose, and protect personal information — identifying privacy risks and their mitigations. A data protection impact assessment (DPIA) is the GDPR's mandatory equivalent: Article 35 requires one wherever processing is likely to result in a high risk to individuals, with prior consultation of the supervisory authority if high residual risk remains. In Canada, federal institutions owe PIAs under Treasury Board policy, and Ontario's Bill 194 makes them mandatory for public-sector entities; the UK GDPR carries the DPIA duty into UK law. In AccessPoint: PIAs run as screeners and questionnaires with section assignment, an embedded risk register, and regulator-ready summaries.
Related:
PIA software · ontario foi
Algorithmic impact assessment (AIA)
An algorithmic impact assessment (AIA) evaluates the risks of an automated or AI-assisted decision system before deployment, examining the decision's effect on individuals, data sources, transparency, human oversight, and recourse. The canonical example is Canada's federal AIA: a mandatory questionnaire under the Treasury Board Directive on Automated Decision-Making that scores a system into an impact level dictating the safeguards required. Ontario's Bill 194 brings AI-accountability duties to the province's public sector, and the EU AI Act requires deployers that are public bodies to complete a fundamental rights impact assessment (Article 27) before using a high-risk AI system. In AccessPoint: AIAs run alongside an AI systems register for responsible-AI oversight.
Related:
AI governance
Privacy breach
A privacy breach — in GDPR terms, a personal data breach — is the loss of, unauthorized access to, or unauthorized disclosure of personal information, whether through attack, error, or theft. What follows is jurisdiction-specific: GDPR requires notifying the supervisory authority within 72 hours where the breach risks individuals' rights and freedoms, and notifying affected individuals where that risk is high; Canada's PIPEDA requires reporting to the Privacy Commissioner and notifying individuals when a breach creates a real risk of significant harm, plus keeping records of every breach; US obligations run through state-by-state breach-notification laws. Public bodies typically owe additional reporting under their own sectoral privacy statutes, making a documented, repeatable response process essential.
Related:
Breach management · Security
Real risk of significant harm (RROSH)
Real risk of significant harm (RROSH) is the Canadian threshold that triggers mandatory breach reporting and notification. Under PIPEDA, 'significant harm' includes bodily harm, humiliation, damage to reputation or relationships, loss of employment or business opportunities, financial loss, identity theft, negative effects on credit records, and damage to or loss of property; whether a real risk exists turns on the sensitivity of the personal information and the probability it has been, is being, or will be misused. Alberta's PIPA pioneered the standard, and Québec's Law 25 applies a comparable 'risk of serious injury' test. It is roughly analogous to GDPR's 'high risk' trigger for notifying individuals. In AccessPoint: a structured RROSH assessment drives a live, statute-computed notification checklist.
Related:
Breach management
Records of processing activities (ROPA)
Records of processing activities (ROPA) are the internal register that GDPR Article 30 requires controllers and processors to maintain, documenting each processing activity: purposes, categories of data subjects and personal data, recipients, international transfers, retention periods, and security measures. Organizations under 250 employees are exempt only where processing is occasional, low-risk, and avoids special-category data — an exemption so narrow that most public bodies keep a full ROPA, which supervisory authorities may demand on request. Outside the EU and UK the concept appears as personal information banks under Canada's federal Privacy Act and as data inventories or data maps under US state privacy laws. A current ROPA is the usual starting point for DPIAs and breach response.
Related:
Jurisdiction packs
Subject access request (SAR / DSAR)
A subject access request (SAR) — also called a data subject access request (DSAR) — is an individual's request for their own personal data. In the UK, where the term SAR is standard, requests are made under UK GDPR Article 15 and the Data Protection Act 2018: one calendar month to respond (extendable by two for complex requests), free of charge in most cases, overseen by the ICO. The EU GDPR works the same way; Canada delivers the equivalent right through the federal Privacy Act and provincial statutes; US state privacy laws grant similar consumer access rights. A SAR differs from an FOI request in who may ask (the data subject versus anyone), what is disclosed (one person's data versus any records), fees, and deadlines — public bodies routinely re-route a request for one's own file to the privacy statute. In AccessPoint: subject access and GDPR requests run as configured request types with computed statutory deadlines, alongside FOI.
Related:
FOI request management · Jurisdiction packs
Privacy risk register
A privacy risk register is a living inventory of an organization's privacy risks, each entry recording the risk description, its source (often a PIA, audit, or breach), likelihood and impact ratings, an assigned owner, mitigations, and the residual risk after treatment. Registers typically follow the ISO 31000 risk-management vocabulary — identify, analyze, evaluate, treat, monitor. Unlike a one-off assessment, the register persists across programs, letting a privacy office verify that accepted risks stay acceptable and that mitigations actually land; regulators increasingly expect assessment findings to feed a maintained register rather than sit in a finished report. In AccessPoint: an ISO 31000 privacy risk register is built in, with risks flowing directly from assessments.
Related:
PIA software · Security
Consultation (inter-agency)
Consultation, in access-request processing, is the step of asking another government institution, another order of government, or an internal expert unit for its position before deciding on disclosure — typically because responsive records originated elsewhere, contain another body's confidences, or engage specialized exemptions such as international relations, law enforcement, or solicitor-client privilege. Consultations are a leading cause of delay: Canada's federal Act allows time extensions where consultations cannot reasonably be completed within the original 30 days, and in the US, FOIA consultations and referrals route records to the agency best placed to assess them. Well-run programs track each consultation with its own recipient, due date, and escalation path so the request clock is not silently lost.
Related:
FOI request management
Personal information bank (PIB)
A personal information bank (PIB) is Canada's federal description of a collection of personal information under a government institution's control, used or available for use for an administrative purpose — a decision-making process directly affecting an individual. Sections 10 and 11 of the Privacy Act require institutions to include such holdings in PIBs and require a published index — TBS's Info Source — describing each bank's class of individuals, purposes, and uses. PIBs are how people find out what files government keeps about them and where to direct a Privacy Act request. Standard banks describe holdings common across institutions, such as HR files; institution-specific banks describe program records. The closest GDPR analogue is the Article 30 ROPA.
Related:
Jurisdiction packs
Automated decision-making (ADM)
Automated decision-making (ADM) is a machine deciding, or shaping, a decision about a person. GDPR Article 22 gives individuals the right not to be subject to a decision based solely on automated processing — without meaningful human involvement — with legal or similarly significant effects, unless a contract, law, or explicit consent authorizes it, and even then with rights to human intervention and to contest. Canada's Treasury Board Directive on Automated Decision-Making governs federal systems making or assisting administrative decisions, requiring a public Algorithmic Impact Assessment whose impact level scales the safeguards — since 2023 including internal services such as hiring. In AccessPoint: Algorithmic Impact Assessments and an AI systems register support oversight under the TBS Directive.
Related:
AI governance
De-identification vs. anonymization vs. pseudonymization
Three techniques reduce how identifiable personal data is — with different legal consequences. Pseudonymization, defined in GDPR Article 4(5), replaces identifiers so data can no longer be attributed to a person without separate, safeguarded additional information; pseudonymized data is still personal data, and GDPR still applies. Anonymization aims at irreversibility: under GDPR Recital 26, data rendered anonymous falls outside the regulation entirely — a demanding standard given re-identification risk. De-identification is the North American term, defined operationally in US HIPAA through the Safe Harbor method (removing 18 listed identifiers) or expert determination; regulators caution that HIPAA-de-identified data can still be personal data under GDPR. Access practitioners meet the same spectrum when deciding whether 'anonymized' statistics could still identify someone.
Related:
PIA software
Privacy breach vs. security incident
A security incident is any event compromising or threatening the confidentiality, integrity, or availability of systems or information — malware, a lost laptop, misdirected email. A privacy breach is the subset involving personal information: GDPR's 'personal data breach' is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. The distinction drives obligations: incidents trigger internal response and sometimes cyber reporting; a privacy breach adds statutory duties — GDPR's 72-hour regulator report, Canada's real-risk-of-significant-harm assessment, US state notification laws. Every breach starts as an incident; triage should ask the personal-information question early. In AccessPoint: both run through one breach and incident management workflow, with a RROSH assessment driving a statute-computed notification checklist.
Related:
Breach management · rrosh
Responsive records
Responsive records are the records that fall within the scope of an access request as worded — the output of a reasonable search across the systems and custodians likely to hold them. Responsiveness is judged against the request's terms (subject, date range, record types, named offices), not against assumptions about what the requester really wants, and portions of a document outside scope may be marked not responsive. The concept anchors everything that follows: exemptions, severing, fees, and third-party notices apply only to responsive records. Disputes frequently turn on search adequacy — in US FOIA case law, whether the search was reasonably calculated to uncover all responsive records; before Canadian and UK commissioners, whether a reasonable search was conducted.
Related:
FOI request management
Records custodian
A records custodian is the person or unit with day-to-day control of records — the mailbox owner, the business unit keeping the case files, the administrator of a database — as distinct from the institution's overall legal responsibility for them. In access processing, custodians receive the search tasking, run the retrieval, and attest to what was searched and what was found; identifying the right custodians is the practical substance of a reasonable search. Many statutes use 'custody or control' as the test for whether records are subject to the Act at all: a record in a public body's custody, or under its control, is generally covered even when a contractor or a minister's office physically holds it.
Related:
FOI request management
Chain of custody
Chain of custody is the documented, unbroken record of who collected, handled, transferred, or altered a record and when — the evidentiary trail that lets a tribunal or court trust that what is produced is what was collected. Borrowed from criminal-evidence practice, it matters in access and privacy work whenever decisions may later be reviewed: commissioner investigations, judicial review of FOI decisions, breach investigations, and litigation holds. A defensible chain records each custody event with the actor, timestamp, action, and the record's identity — often a cryptographic hash — so any gap or alteration is detectable. Electronic case-management systems maintain it through immutable audit logs rather than paper transfer forms.
Related:
Security · FOI request management
Hash-chained audit trail
A hash-chained audit trail is an audit log in which each entry incorporates a cryptographic hash of the previous entry, linking the records into a chain: altering or deleting any historical entry changes its hash and breaks every link after it, making tampering evident. The technique — the same integrity mechanism that underlies blockchains, without the distributed consensus — turns an ordinary application log into tamper-evident evidence, which matters where access and privacy decisions must withstand commissioner review or court scrutiny years later. Verification is straightforward: recompute the hashes and confirm the chain is intact from the first entry to the last. In AccessPoint: case actions are written to a hash-chained audit ledger inside the customer's own tenant.
Related:
Security
Retention schedule / disposition
A retention schedule is the approved instrument stating how long each class of records must be kept and what happens afterward; disposition is that endpoint — destruction, transfer to an archives, or another authorized outcome. Retention interacts with access and privacy law in both directions. Records must survive long enough to honour access rights and litigation holds — destroying records to defeat an access request is an offence in several jurisdictions, including under Canada's federal Act — and an access request generally suspends disposition of responsive records until the request and any review conclude. Pulling the other way, privacy statutes and GDPR's storage-limitation principle prohibit keeping personal information longer than its purpose requires.
Related:
Security
Duty to document
The duty to document requires officials to create records of their decisions and deliberations in the first place — access rights mean little where nothing was written down. Most access laws govern only records that exist; commissioners across Canada investigate complaints yearly where requested records were never created, and Canada's information commissioners have jointly urged a legislated duty since 2016. British Columbia became the first Canadian jurisdiction to legislate one, amending its Information Management Act in 2017 to require documenting key government decisions. New Zealand's Public Records Act 2005 (section 17) requires every public office to create and maintain full and accurate records of its affairs. In the US the parallel obligation lives in the Federal Records Act, not FOIA.
Related:
FOI request management
Data residency & data sovereignty
Data residency is where data is physically stored and processed; data sovereignty is whose laws can reach it. The two diverge in cloud procurement: data stored in Canada by a US-controlled provider satisfies residency but remains exposed to US legal process such as the CLOUD Act, which can compel US companies to produce data under their control wherever it sits. Rules vary: British Columbia's FIPPA required in-Canada storage of public-sector personal information until 2021 amendments, EU personal data leaves only under GDPR adequacy or transfer safeguards, and government cloud frameworks classify what may leave the country. In AccessPoint: the platform deploys inside the customer's own Microsoft 365 and Azure tenant — no third-party cloud, no cross-border transfer.
Related:
Security