Guides & Tools

FOI annual report statistics: what regulators actually want

The statistical categories behind Canadian ATIP reports, Ontario IPC year-end filings, US FOIA annual reports, and UK monitored-body statistics — what each one means operationally, and how to make the report a query instead of a project.

Every access-to-information regime ends its year the same way: with an accounting. How many requests came in, how many went out, how long they took, what was withheld and under what authority. The categories are not a surprise — they are published, stable, and in Canada's case have barely changed shape since 1983 — yet in many offices the annual statistical report is still assembled in a multi-week reconstruction every spring. This guide sets out what the major regimes actually require, what the categories mean at the level of an individual case file, and what has to be true of your tracking during the year for the report to fall out of it at the end.

Canada: the TBS statistical report

Under paragraph 70(1)(d) of the Access to Information Act, the President of the Treasury Board collects statistics annually on the administration of the Act, and section 94 requires the head of every government institution to prepare an annual report to Parliament; the statistical report is filed with TBS and tabled with that annual report. The parallel structure exists under the Privacy Act. Reporting follows the fiscal year, April 1 to March 31, on standard forms (TBS/SCT 350-62 for access, 350-63 for privacy), and TBS publishes both a government-wide roll-up and the underlying datasets.

The access form's core sections are worth internalizing, because they dictate what your case data must capture:

  • Volume: requests received during the period, requests outstanding from previous periods, requests completed, and requests carried over to the next period.
  • Disposition of completed requests: all disclosed; disclosed in part; all exempted; all excluded; no records exist; request transferred; request abandoned; neither confirmed nor denied.
  • Completion times: counts in bands (1–15 days, 16–30, 31–60, 61–120, 121–180, 181–365, more than 365), plus performance against legislated timelines and the principal reasons for lateness.
  • Extensions: how many were taken under paragraph 9(1)(a) (interference with operations), 9(1)(b) (consultations), and 9(1)(c) (third-party notice), and for how long.
  • Exemptions and exclusions: which sections of the Act were invoked, counted by request.
  • Consultations: received from other institutions and organizations, and their completion times.
  • Fees collected and waived, plus, in recent years, supplemental questions on capacity and informal requests.

Two features of the federal report catch teams out. Dispositions are mutually exclusive — each completed request gets exactly one — and the extension section counts extension events with their statutory paragraph and length, which cannot be reconstructed from a due-date column after the fact.

Ontario: the IPC year-end statistical report

Institutions covered by FIPPA and MFIPPA are required to file annual statistical reports with the Information and Privacy Commissioner of Ontario. The reporting year is the calendar year, submission is through the IPC's online statistics submission website, and the deadline is March 31 of the following year. The workbook distinguishes requests for personal information from requests for general records, and collects volumes received and completed, outcomes of completed requests, timeliness against the 30-day statutory clock, extended-time completions, and fee information; the request-source profile of who is asking (individuals, businesses, media, and so on) appears in the workbook as well. The IPC then publishes the results, naming institutions: its annual report sets out, per institution, the number and percentage of requests completed within 30 days, within a permissible extended time, and over time. In 2024, provincial institutions completed just over 78 per cent of requests within 30 days; the figure is public, comparable, and quoted — which is precisely why the underlying coding deserves care.

Bill 194 added a second annual filing: as of July 1, 2025, FIPPA institutions must report privacy-breach statistics to the IPC annually, covering breaches that met the real-risk-of-significant-harm threshold and were reported during the previous calendar year. Health custodians under PHIPA and service providers under Part X of CYFSA have filed analogous annual breach statistics for years, through the same submission site.

United States: the Annual FOIA Report

Every federal agency must file an Annual FOIA Report under 5 U.S.C. § 552(e), submitted to the Attorney General and published; the Department of Justice's Office of Information Policy prescribes the format in its Annual FOIA Report Handbook, and the government-wide data is aggregated on FOIA.gov. The required elements are the most granular of any regime discussed here: requests and appeals received, processed, and pending; dispositions, including full grants, partial grants, and full denials; the number of times each of the nine exemptions was applied; processing times by track (simple, complex, expedited) reported as medians, averages, and ranges; expedited-processing and fee-waiver requests and their outcomes; fees collected against total FOIA program costs; and staffing. Two elements have outsized operational consequences. The backlog is defined as requests or appeals pending beyond the statutory response period — twenty working days, or thirty with an unusual-circumstances extension — not merely pending. And agencies must publish the status of their ten oldest pending requests, appeals, and consultations, which turns the far end of the queue into a named, reportable liability. Since the FOIA Improvement Act of 2016, agencies must also publish the raw data behind the report in machine-readable form and report four key metrics quarterly.

United Kingdom: monitored bodies and the section 45 code

The UK is the outlier: the Freedom of Information Act 2000 imposes no general statistical-reporting duty. What exists instead is a two-tier arrangement. The Cabinet Office publishes accredited official statistics, quarterly and annually, for a set of monitored bodies — roughly forty central-government departments and agencies — covering volumes, timeliness, outcomes, exemptions relied on, and internal reviews. For the thousands of other authorities, the section 45 Code of Practice issued in July 2018 sets the expectation: public authorities with more than 100 full-time-equivalent employees should publish their own compliance statistics at least quarterly, including requests received, how many were answered in full, in part, or refused, and how many met the statutory deadline. The code is guidance rather than statute, but it is not toothless; the Information Commissioner's Office has issued practice recommendations to local authorities specifically for failing to publish these statistics, and uses published performance data when deciding which authorities to place under monitoring.

What the categories mean operationally

Across all four regimes, the same handful of concepts do the work, and the same ambiguities produce the errors.

What counts as "completed"

A request is completed in the period in which it was closed, regardless of when it arrived; the received and completed populations in any year are different sets of files. Completion means a final response has been issued — disclosure, refusal, a no-records response, a transfer, or a properly documented abandonment. Abandonment is the category most often stretched at year-end: a request is abandoned when the requester has failed to respond to a clarification or fee estimate after fair warning, not when the file has simply gone quiet on the institution's side. Coding dormant files as abandoned flatters the timeliness numbers this year and produces an audit problem next year.

How carried-over is computed

Carried over is arithmetic, not judgment: files open at the start of the period, plus files received, minus files completed, equals files carried out. Regulators reconcile this across years — the federal form explicitly reports requests "outstanding from previous reporting periods," and your carry-in must equal last year's carry-out. When it does not, the cause is nearly always one of three things: completion dates edited after a period closed, requests reopened without a new identifier, or transfers counted as completions in one year and as removals in another. Pick a convention, write it down, and apply it to every file.

Extension coding happens at extension time

Every regime that reports extensions wants them attributed: which statutory ground, taken when, for how long. That attribution exists at exactly one moment — when the extension notice is issued. A tracking system that stores only the current due date has destroyed the reportable fact; recovering it means re-reading correspondence file by file. The operational rule is that an extension is an event record (date, statutory ground, length, new due date), not an edit to a deadline field. The same logic applies to exemptions: the federal report counts sections invoked per request, and the US report counts exemption applications, so the citations need to be captured when the decision letter is written or the redactions are applied, not inferred later from the letter's prose.

Fees, consultations, and the long tail

Fee figures reconcile only if fees are a ledger — estimated, charged, collected, waived, refunded — rather than a single amount typed into a case note. Consultations received from other institutions are their own reportable population with their own timelines in the federal report, so they need case records of their own, not tags on someone else's file. And the US ten-oldest requirement is a reminder that every queue has a far end; a report that names your oldest files rewards knowing, all year, what they are.

The year-end scramble, and the alternative

The anti-pattern is familiar enough to have a season. Requests live in a spreadsheet with one row per file and a status column; extensions overwrite due dates; exemption citations live only in Word letters; fees live in email. Then the reporting deadline approaches, and the coordinator spends weeks re-deriving events from artifacts — opening decision letters to count exemptions, searching mailboxes to date responses, interviewing colleagues about why a 2024 file shows a 2025 close date. The output is a report that is late, unreconcilable against last year, and dependent on one person's memory. The failure is not effort; it is that facts were captured in prose and had to be converted back into data.

The alternative is structural, and none of it is exotic. Give every reportable fact a field that matches the report's own vocabulary: a disposition code list that mirrors the form you file, dates for received, clarified, extended, and closed, extension events with statutory ground and length, exemption tags applied at redaction time, and fee ledger entries. Close each month the way finance does — a short reconciliation of opened, closed, and carried figures while memories are fresh — so that errors are caught in weeks, not at year-end. Do that, and the annual statistical report stops being a project: it is a query over data that already exists, filtered to the reporting period, and the coordinator's March is spent checking the numbers rather than manufacturing them.

Last reviewed: August 2026.

Sources

Related reading on this site: how FOI request management software captures dispositions, extensions, exemption tags, and deadlines as structured data during the year; the FOI ROI calculator for what the year-end scramble actually costs; the Canada federal ATIP jurisdiction pack; or book a demo to see an annual statistical report produced as a report, not a reconstruction.

FOI Statistics Questions

What statistics must Canadian federal institutions report each year?

Every institution subject to the Access to Information Act and the Privacy Act files an annual statistical report with the Treasury Board of Canada Secretariat covering the fiscal year (April 1 to March 31). The standard form captures requests received, outstanding from prior periods, completed, and carried over; the disposition of completed requests (all disclosed, disclosed in part, all exempted, all excluded, no records exist, transferred, abandoned); completion times in bands; performance against legislated timelines; extensions taken under paragraphs 9(1)(a), (b), and (c) and their lengths; the exemptions and exclusions cited; consultations received; and fees. The statistical report is tabled with each institution's annual report to Parliament, and TBS publishes a government-wide roll-up.

When are Ontario FOI statistics due to the IPC?

Institutions covered by FIPPA and MFIPPA report on a calendar year (January 1 to December 31) and submit through the IPC's online statistics submission website, with reports due by March 31 of the following year. The IPC publishes compliance results in its annual report, including each institution's 30-day compliance rate. Since Bill 194 took effect on July 1, 2025, FIPPA institutions also file annual privacy-breach statistics with the IPC.

What is a backlogged request in a US FOIA annual report?

In the Annual FOIA Report that 5 U.S.C. 552(e) requires each federal agency to file, a request or appeal is backlogged when it is pending beyond the statutory response period, generally twenty working days, or thirty with an unusual-circumstances extension. Backlog is reported as of the end of the fiscal year and is distinct from simple volume: an agency can process more requests than it receives and still carry a backlog. Agencies must also report the status of their ten oldest pending requests, appeals, and consultations.

Do UK public authorities have to publish FOI statistics?

Most UK public authorities have no statutory duty to file FOI statistics with anyone. The Cabinet Office publishes accredited quarterly and annual statistics covering only a set of monitored central-government bodies, roughly forty departments and agencies. For everyone else, the section 45 Code of Practice (2018) says public authorities with more than 100 full-time-equivalent staff should publish their own compliance statistics at least quarterly, including requests received, outcomes, and timeliness, and the ICO has issued practice recommendations to authorities that fail to do so.

How should carried-over requests be calculated?

Carried over means open at the end of the reporting period: requests on hand at the start of the period, plus requests received during it, minus requests completed during it. Regulators reconcile these figures year over year, so this year's opening balance must equal last year's closing balance. Discrepancies usually trace to inconsistent completion dating, requests reopened after closure, or transfers and abandonments coded differently in different years.

See AccessPoint in action. 30 minutes, on your jurisdiction's rules, with the person who built it.

© 2026 Realizer Services Inc. About Privacy Terms