Last reviewed: Next review due:
Why complaints and safeguarding data matters
Complaints data from NHS trusts, councils, police forces, schools, and Multi-Academy Trusts can reveal systemic failures that individual cases do not. A single complaint about a hospital department may be anecdotal; a 40% year-on-year rise in complaints about the same department, combined with three referrals to the Parliamentary and Health Service Ombudsman, is a news story. Safeguarding data — the statistics on child protection referrals, care orders, and safeguarding enquiries under the Care Act 2014 — shows whether vulnerable people are being protected and whether institutions are improving or deteriorating.
Both types of data carry significant risks. Complaints data can identify specific incidents that, combined with other information, could identify the complainant or the subject of the complaint. Safeguarding data can, at insufficient levels of aggregation, identify the very people it is designed to protect — children and vulnerable adults who are often already at risk.
The approach for both is the same: request aggregate statistics, not individual records. Request category-level trends, not case-by-case detail. Apply statistical suppression thresholds before publishing. And interrogate your own data before publication to check whether it could identify anyone.
When complaints FOI requests are most useful
- 1Investigating a pattern of failures in an NHS trust or GP practice — complaints data shows volume and category trends.
- 2Examining whether a council's children's services are adequately protecting vulnerable young people.
- 3Assessing police complaints data to identify trends in misconduct allegations or forces with disproportionate complaint rates.
- 4Comparing how many complaints a school or MAT has received about a specific issue (e.g. exclusions, bullying policies).
- 5Cross-referencing complaints data with Ofsted or Care Quality Commission inspection outcomes.
- 6Establishing whether a public body is complying with its legal obligation to operate a complaints procedure.
- 7Identifying whether the rate of complaints upheld (vs dismissed) has changed significantly year on year.
Red flags — risks specific to safeguarding data
- Data disclosed at individual-case level rather than aggregate — do not publish it without statistical suppression.
- Small cell counts (fewer than 5) in any category — the combination of institution name + category + small number can identify a victim.
- Data that reveals the outcome of a specific named safeguarding review or serious case review.
- Any data combined with a named child, even indirectly — e.g. "the only safeguarding case at this school in this year".
- An authority that has disclosed data you suspect should have been withheld — do not publish first, verify ethics first.
- Requests about ongoing investigations or live criminal proceedings — s.31 law enforcement exemption is likely to apply and justified.
Complaints and safeguarding FOI checklist
- My request asks for aggregate statistics, not individual case records.
- I have specified that categories with fewer than five individuals should be suppressed or merged.
- I have checked what data is already publicly available (Ofsted reports, CQC ratings, PHSO annual reports) before filing.
- I have identified which exemptions are likely to be claimed (s.40 personal data, s.31 law enforcement, s.36 effective conduct) and prepared counter-arguments.
- My request relates to a time period that does not include any ongoing criminal investigation I am aware of.
- Before publishing, I will verify that no combination of published data and other publicly available information could identify a safeguarding victim.
- I have applied the statistical suppression threshold (fewer than 5 = suppress) before deciding what to publish.
- I have read the ethics guides on children and intrusion into grief before planning publication.
- If publishing names or details of complainants, I have their consent or can demonstrate overriding public interest.
- I have noted the 20 working day response deadline and set a reminder.
Copy-paste request template: complaints data
FOI Builder tool
Use our FOI Builder to generate a tailored complaints or safeguarding data request for your specific authority and purpose.
Open FOI BuilderCommon exemptions and how to respond
s.40 Personal Data (third parties)
The most common exemption for complaints and safeguarding data. Applies where disclosure would breach the data protection principles — principally because the information relates to identifiable individuals. Counter: confirm you are requesting only aggregate, anonymised statistics with suppression applied. Point out that aggregate data is not personal data if it cannot identify any individual. Request a redacted or suppressed version.
s.31 Law Enforcement
Used where disclosure could prejudice a criminal investigation or prosecution. Most often applied to police complaints data or safeguarding referrals where a criminal investigation is ongoing. Counter: request only completed cases; ask the authority to identify which specific case(s) are under active investigation and provide redacted data for the remainder.
s.41 Information Provided in Confidence
Sometimes claimed for complaint correspondence, particularly patient feedback in NHS contexts. Counter: you are not requesting the content of the complaint — you are requesting statistical data. Aggregate counts of complaints are not themselves provided in confidence.
s.36 Prejudice to Effective Conduct of Public Affairs
Requires a qualified person's reasonable opinion. Sometimes used by councils to protect sensitive internal safeguarding processes. Counter: general trends data about complaint volumes does not disclose deliberative processes or internal governance mechanisms. Ask for the qualified person's opinion in writing.
Common mistakes
- Requesting individual case files rather than aggregate statistics — this will always be refused under s.40.
- Publishing small-cell data that could identify a safeguarding victim even though the authority disclosed it.
- Assuming aggregate statistics are always safe to publish — cross-referencing risks and small populations can re-identify individuals.
- Conflating complaints data (formal complaints from service users) with safeguarding referrals — they are different datasets with different legal frameworks.
- Forgetting to request data in machine-readable format — a PDF table is hard to analyse and compare across years.
- Not exhausting the internal review process before complaining to the ICO — ICO requires internal review first.
- Publishing a story about an institution's complaint numbers without contextualising them against the volume of interactions or national benchmarks.
Related guides
Primary sources
- Freedom of Information Act 2000 (legislation.gov.uk)
- ICO guidance: personal data and FOI (s.40)
- ICO: Anonymisation: managing data protection risk (code of practice)
- ICO: FOI and journalism — guidance
- Parliamentary and Health Service Ombudsman (NHS complaints data)
- Local Government and Social Care Ombudsman (council complaints data)
- Working Together to Safeguard Children 2023 (statutory guidance)
- Care Act 2014 (safeguarding adults framework)