Guides & Tools
FOI annual report statistics: what regulators actually want
The statistical categories behind Canadian ATIP reports, Ontario IPC year-end filings, US FOIA annual reports, and UK monitored-body statistics — what each one means operationally, and how to make the report a query instead of a project.
Every access-to-information regime ends its year the same way: with an accounting. How many requests came in, how many went out, how long they took, what was withheld and under what authority. The categories are not a surprise — they are published, stable, and in Canada's case have barely changed shape since 1983 — yet in many offices the annual statistical report is still assembled in a multi-week reconstruction every spring. This guide sets out what the major regimes actually require, what the categories mean at the level of an individual case file, and what has to be true of your tracking during the year for the report to fall out of it at the end.
Canada: the TBS statistical report
Under paragraph 70(1)(d) of the Access to Information Act, the President of the Treasury Board collects statistics annually on the administration of the Act, and section 94 requires the head of every government institution to prepare an annual report to Parliament; the statistical report is filed with TBS and tabled with that annual report. The parallel structure exists under the Privacy Act. Reporting follows the fiscal year, April 1 to March 31, on standard forms (TBS/SCT 350-62 for access, 350-63 for privacy), and TBS publishes both a government-wide roll-up and the underlying datasets.
The access form's core sections are worth internalizing, because they dictate what your case data must capture:
- Volume: requests received during the period, requests outstanding from previous periods, requests completed, and requests carried over to the next period.
- Disposition of completed requests: all disclosed; disclosed in part; all exempted; all excluded; no records exist; request transferred; request abandoned; neither confirmed nor denied.
- Completion times: counts in bands (1–15 days, 16–30, 31–60, 61–120, 121–180, 181–365, more than 365), plus performance against legislated timelines and the principal reasons for lateness.
- Extensions: how many were taken under paragraph 9(1)(a) (interference with operations), 9(1)(b) (consultations), and 9(1)(c) (third-party notice), and for how long.
- Exemptions and exclusions: which sections of the Act were invoked, counted by request.
- Consultations: received from other institutions and organizations, and their completion times.
- Fees collected and waived, plus, in recent years, supplemental questions on capacity and informal requests.
Two features of the federal report catch teams out. Dispositions are mutually exclusive — each completed request gets exactly one — and the extension section counts extension events with their statutory paragraph and length, which cannot be reconstructed from a due-date column after the fact.
Ontario: the IPC year-end statistical report
Institutions covered by FIPPA and MFIPPA are required to file annual statistical reports with the Information and Privacy Commissioner of Ontario. The reporting year is the calendar year, submission is through the IPC's online statistics submission website, and the deadline is March 31 of the following year. The workbook distinguishes requests for personal information from requests for general records, and collects volumes received and completed, outcomes of completed requests, timeliness against the 30-day statutory clock, extended-time completions, and fee information; the request-source profile of who is asking (individuals, businesses, media, and so on) appears in the workbook as well. The IPC then publishes the results, naming institutions: its annual report sets out, per institution, the number and percentage of requests completed within 30 days, within a permissible extended time, and over time. In 2024, provincial institutions completed just over 78 per cent of requests within 30 days; the figure is public, comparable, and quoted — which is precisely why the underlying coding deserves care.
Bill 194 added a second annual filing: as of July 1, 2025, FIPPA institutions must report privacy-breach statistics to the IPC annually, covering breaches that met the real-risk-of-significant-harm threshold and were reported during the previous calendar year. Health custodians under PHIPA and service providers under Part X of CYFSA have filed analogous annual breach statistics for years, through the same submission site.
United States: the Annual FOIA Report
Every federal agency must file an Annual FOIA Report under 5 U.S.C. § 552(e), submitted to the Attorney General and published; the Department of Justice's Office of Information Policy prescribes the format in its Annual FOIA Report Handbook, and the government-wide data is aggregated on FOIA.gov. The required elements are the most granular of any regime discussed here: requests and appeals received, processed, and pending; dispositions, including full grants, partial grants, and full denials; the number of times each of the nine exemptions was applied; processing times by track (simple, complex, expedited) reported as medians, averages, and ranges; expedited-processing and fee-waiver requests and their outcomes; fees collected against total FOIA program costs; and staffing. Two elements have outsized operational consequences. The backlog is defined as requests or appeals pending beyond the statutory response period — twenty working days, or thirty with an unusual-circumstances extension — not merely pending. And agencies must publish the status of their ten oldest pending requests, appeals, and consultations, which turns the far end of the queue into a named, reportable liability. Since the FOIA Improvement Act of 2016, agencies must also publish the raw data behind the report in machine-readable form and report four key metrics quarterly.
United Kingdom: monitored bodies and the section 45 code
The UK is the outlier: the Freedom of Information Act 2000 imposes no general statistical-reporting duty. What exists instead is a two-tier arrangement. The Cabinet Office publishes accredited official statistics, quarterly and annually, for a set of monitored bodies — roughly forty central-government departments and agencies — covering volumes, timeliness, outcomes, exemptions relied on, and internal reviews. For the thousands of other authorities, the section 45 Code of Practice issued in July 2018 sets the expectation: public authorities with more than 100 full-time-equivalent employees should publish their own compliance statistics at least quarterly, including requests received, how many were answered in full, in part, or refused, and how many met the statutory deadline. The code is guidance rather than statute, but it is not toothless; the Information Commissioner's Office has issued practice recommendations to local authorities specifically for failing to publish these statistics, and uses published performance data when deciding which authorities to place under monitoring.
What the categories mean operationally
Across all four regimes, the same handful of concepts do the work, and the same ambiguities produce the errors.
What counts as "completed"
A request is completed in the period in which it was closed, regardless of when it arrived; the received and completed populations in any year are different sets of files. Completion means a final response has been issued — disclosure, refusal, a no-records response, a transfer, or a properly documented abandonment. Abandonment is the category most often stretched at year-end: a request is abandoned when the requester has failed to respond to a clarification or fee estimate after fair warning, not when the file has simply gone quiet on the institution's side. Coding dormant files as abandoned flatters the timeliness numbers this year and produces an audit problem next year.
How carried-over is computed
Carried over is arithmetic, not judgment: files open at the start of the period, plus files received, minus files completed, equals files carried out. Regulators reconcile this across years — the federal form explicitly reports requests "outstanding from previous reporting periods," and your carry-in must equal last year's carry-out. When it does not, the cause is nearly always one of three things: completion dates edited after a period closed, requests reopened without a new identifier, or transfers counted as completions in one year and as removals in another. Pick a convention, write it down, and apply it to every file.
Extension coding happens at extension time
Every regime that reports extensions wants them attributed: which statutory ground, taken when, for how long. That attribution exists at exactly one moment — when the extension notice is issued. A tracking system that stores only the current due date has destroyed the reportable fact; recovering it means re-reading correspondence file by file. The operational rule is that an extension is an event record (date, statutory ground, length, new due date), not an edit to a deadline field. The same logic applies to exemptions: the federal report counts sections invoked per request, and the US report counts exemption applications, so the citations need to be captured when the decision letter is written or the redactions are applied, not inferred later from the letter's prose.
Fees, consultations, and the long tail
Fee figures reconcile only if fees are a ledger — estimated, charged, collected, waived, refunded — rather than a single amount typed into a case note. Consultations received from other institutions are their own reportable population with their own timelines in the federal report, so they need case records of their own, not tags on someone else's file. And the US ten-oldest requirement is a reminder that every queue has a far end; a report that names your oldest files rewards knowing, all year, what they are.
The year-end scramble, and the alternative
The anti-pattern is familiar enough to have a season. Requests live in a spreadsheet with one row per file and a status column; extensions overwrite due dates; exemption citations live only in Word letters; fees live in email. Then the reporting deadline approaches, and the coordinator spends weeks re-deriving events from artifacts — opening decision letters to count exemptions, searching mailboxes to date responses, interviewing colleagues about why a 2024 file shows a 2025 close date. The output is a report that is late, unreconcilable against last year, and dependent on one person's memory. The failure is not effort; it is that facts were captured in prose and had to be converted back into data.
The alternative is structural, and none of it is exotic. Give every reportable fact a field that matches the report's own vocabulary: a disposition code list that mirrors the form you file, dates for received, clarified, extended, and closed, extension events with statutory ground and length, exemption tags applied at redaction time, and fee ledger entries. Close each month the way finance does — a short reconciliation of opened, closed, and carried figures while memories are fresh — so that errors are caught in weeks, not at year-end. Do that, and the annual statistical report stops being a project: it is a query over data that already exists, filtered to the reporting period, and the coordinator's March is spent checking the numbers rather than manufacturing them.
Last reviewed: August 2026.
Sources
- Access to information and privacy statistics — Treasury Board of Canada Secretariat, government-wide statistical reports and datasets (accessed August 2026).
- Form TBS/SCT 350-62, Statistical Report on the Access to Information Act — Treasury Board of Canada Secretariat (accessed August 2026).
- Annual statistical reporting FAQ and Annual statistical reporting — all sectors — Information and Privacy Commissioner of Ontario (accessed August 2026).
- OIP guidance, including the Department of Justice Handbook for Agency Annual FOIA Reports (handbook last updated September 2025) — US Department of Justice, Office of Information Policy; statutory basis at 5 U.S.C. § 552(e) (accessed August 2026).
- Freedom of Information statistics — UK Cabinet Office, quarterly and annual accredited statistics for monitored bodies (accessed August 2026).
- Section 45 Code of Practice: request handling — Information Commissioner's Office; code issued by the Cabinet Office, July 2018 (accessed August 2026).
Related reading on this site: how FOI request management software captures dispositions, extensions, exemption tags, and deadlines as structured data during the year; the FOI ROI calculator for what the year-end scramble actually costs; the Canada federal ATIP jurisdiction pack; or book a demo to see an annual statistical report produced as a report, not a reconstruction.