Government data breaches now make the news weekly, and the public statements that follow them follow a script: sophisticated attack, contained quickly, no evidence of misuse. The records behind those sentences are often obtainable. The right request is not for the breach, it is for the response to the breach.
When a public body suffers a data breach, a paper trail begins almost immediately: incident reports, notifications to regulators, risk assessments, decisions on whether to tell affected people. Most of that trail is subject to freedom of information law even when the breach itself is being investigated, and requesting it changes the conversation from trusting a press release to reading the timeline. Here is how to do it properly.
Why request the response and not the breach
Asking a body for “all information about the breach” invites refusal. The incident itself is likely to be covered by exemptions: law enforcement investigations, national security, commercial interests of security contractors, personal data of staff or victims. A request framed around the response machinery is different, because the machinery is administrative record-keeping. Timelines, decision logs, notification assessments and post-incident reviews are the kinds of documents agencies create for their own governance, and governance documents are what FOI law was written to release.
A second reason is that the response is where accountability actually lives. Whether passwords were reset, how long notification took, who decided affected individuals did not need to be told, and what was changed afterwards are all questions about decisions, and decisions leave records. The breach is the attacker’s story. The response is the agency’s.
What to ask for, specifically
Vague requests get vague answers and long delays. Concrete categories get concrete documents:
The incident timeline: dates and times of detection, escalation, containment, and classification, with the log or report that records them.
Regulator notifications: the notification sent to the information commissioner or data protection authority, including the date it was filed and the basis for the severity assessment.
The notification decision: any assessment, memo or risk analysis on whether and how to inform affected individuals, including the reasoning if the decision was not to inform.
External assistance: contracts, engagement letters or task orders for forensic or legal firms involved in the response, with dates and scopes. Costs may be separately requestable.
The post-incident review: any lessons-learned report, board briefing, or remediation plan produced after containment.
Correspondence with suppliers: where a third-party processor was involved, the breach notices exchanged under the contract.
Framing matters as much as content. Ask for recorded information, not explanations: FOI law releases documents, not answers to open-ended questions like “why did this take so long”. Request “copies of the notifications and the date each was sent”, not “an explanation of your response”.
The exemptions to expect, and how to narrow around them
Four exemptions do most of the work in these refusals. Law enforcement, where an investigation is live, protects material that could prejudice it. You cannot argue an investigation away, but you can argue that a timeline of dates already disclosed to a regulator is not prejudicial. Personal information protects named individuals; offer to accept redacted copies, which the authority must provide unless the redaction renders the document meaningless. Commercial interests of security contractors protects things like pricing and vulnerability details; the fact that a firm was engaged and when is rarely commercially sensitive. And prejudice to the conduct of public affairs is the catch-all, which the tribunal case law narrows: there must be a real and specific likelihood of harm, not a general nervousness.
The pattern that works is segmentation. Accept that the investigation file stays closed for now, and get the surrounding documentation: the regulator notification, the notification decision, the review. Six months later, re-request the investigation material; many authorities will release more once a case is closed, and a second request that follows a first is harder to fob off with boilerplate.
Practical sequence
File quickly. Internal review reports are drafted while memory is fresh, but more importantly, some bodies have document-deletion or archiving practices that shorten the life of incident material. A request filed within weeks of the breach covers documents that a request filed two years later may not.
Ask for the information handling log as well as the documents: every FOI authority keeps a record of how it processed your request, and if the handling goes wrong, that log is itself requestable evidence.
Use the internal review step when refusal letters are template language. A large share of first refusals on breach-response requests are partially overturned on review, because the review officer actually reads the documents against the exemption claimed. Beyond that, the information commissioner’s office takes complaints, and the complainant does not need a lawyer to file.
One structural note: several high-profile breach response documents in recent years were released not because an authority chose transparency but because a requester kept the file open through review and re-request. Persistence is not a tactic of last resort here, it is the tactic.
The boundary of what you will get
Be realistic about the ceiling. You are unlikely to obtain attacker details, exploit specifics, or unredacted personal data of victims, and you should not want the latter. What you can realistically obtain is the clock: when the body knew, who it told, how long affected people waited, and what changed afterwards. That clock, read against the press release, is the whole story. Where the gap is wide, the documents make the point without a word of commentary from you.