# Freedom of Information and open records: what becomes public and when
A city planner emails a colleague: "This developer's traffic study is garbage, but let's not say that in writing." Eighteen months later, a local journalist files a records request, and that email lands in a folder titled "Responsive Documents," printed out, redacted in parts, and posted to the city's website. The planner never imagined that sentence would be read by anyone outside the office. That is the lesson: in the public sector, almost anything you write on a government system can become public record, and you should draft accordingly.
This lesson traces how a Freedom of Information Act (FOIA) request actually moves through an agency, so you understand what gets captured, what gets withheld, and how long the clock runs.
FOIA (Freedom of Information Act, US federal law, enacted 1966, most recently amended by the FOIA Improvement Act of 2016) gives any person the right to request records from federal executive branch agencies. No reason required. The requester doesn't need to be a US citizen or explain why they want the documents.
Each US state has its own equivalent, commonly called "open records" or "sunshine" laws (examples: California's Public Records Act, Texas Public Information Act, New York's Freedom of Information Law). Rules on fees, timelines, and exemptions vary by state, so a compliance officer working across jurisdictions cannot assume federal FOIA timelines apply locally.
In the EU, the comparable framework is Regulation (EC) No 1049/2001, governing public access to European Parliament, Council, and Commission documents, alongside member-state laws (for example, the UK's Freedom of Information Act 2000, which survived Brexit as domestic law). The EU adds a second layer: the GDPR (General Data Protection Regulation), which restricts releasing personal data even when a document is otherwise disclosable. A FOIA-style release in Europe often requires redacting names, emails, and identifying details that US disclosure would leave visible.
Oversight bodies differ too. In the US, the Department of Justice's Office of Information Policy issues federal FOIA guidance, and disputes go to federal court. In the UK, the Information Commissioner's Office (ICO) enforces both FOI and data protection law and can order agencies to release records.
1. Intake. A request arrives, often by email or an online portal, asking for records "related to" a topic, a date range, or a named official. Under federal FOIA, agencies must respond within 20 business days (extendable by 10 more for "unusual circumstances"), though real-world backlogs routinely stretch this to months. The FOIA.gov portal tracks average processing times by agency; some agencies report multi-year backlogs for complex requests, per the Justice Department's own annual reports.
2. Search. Records officers identify likely custodians: staff whose files, inboxes, and shared drives might contain responsive material. This is where scope matters enormously. A request for "all communications regarding the downtown rezoning project" can sweep in emails, text messages on government-issued phones, Slack or Teams messages, meeting notes, and draft memos, not just final reports. Courts have repeatedly held that format doesn't matter: if it's a government record, capturing agency business, it's usually in scope regardless of the app used to create it.
3. Review for exemptions. Not everything found gets released. US federal FOIA has nine exemptions, the most commonly invoked include:
Agencies apply exemptions line by line, not document by document, which is why released files often arrive with black bars over specific sentences rather than being withheld entirely.
4. Redaction and release. Approved portions go out, typically as PDFs. Requesters can appeal a denial administratively, and then in court.
5. Litigation risk. If an agency withholds too much or too slowly, the requester can sue. Nonprofit newsrooms and watchdog groups (MuckRock, the Reporters Committee for Freedom of the Press) routinely litigate FOIA denials, and their track record shapes how conservatively agencies redact going forward.
Three practical habits follow directly from this process:
Assume discoverability by default. Any record created on a government email account, government phone, or government-funded contractor system is presumptively subject to request. Personal Gmail used for government business doesn't fully escape this either; courts have held that using a private account to conduct public business doesn't exempt those records if they relate to agency action (this became a high-profile issue in several state and federal cases over the past decade).
Separate analysis from editorializing. Write "traffic study shows X deficiency; recommend requesting revised data" rather than commentary about the study's authors or motives. The deliberative process exemption protects the analytical back-and-forth, not sarcasm or personal attacks, and sarcasm reads very differently printed out of context two years later.
Know your agency's retention schedule. Records retention schedules (governed in the US by the National Archives and Records Administration, NARA, for federal agencies, and by state archives for state/local government) dictate how long you must keep, versus when you may lawfully destroy, records. You cannot delete something specifically to dodge a pending request; that's spoliation and carries legal consequences. But routine, policy-compliant deletion before any request exists is generally lawful.
Vérification des acquis
1. What is the key practical lesson from the city planner's email becoming a public record?
2. Why can't a compliance officer working across multiple US states simply apply federal FOIA timelines and rules to a state-level records request?
3. In the EU context, why does GDPR add complexity to an otherwise disclosable document under Regulation (EC) No 1049/2001?
4. Select ALL correct answers about how FOIA (US federal law) works.
Sélectionnez toutes les réponses correctes.
5. Select ALL correct answers about the general concept of open records/freedom of information laws across jurisdictions.
Sélectionnez toutes les réponses correctes.
FOIA doesn't operate in isolation. A few overlaps matter for cross-functional teams:
For international teams, remember that a US-style request has no direct EU equivalent in scope; EU access-to-documents rules apply narrowly to formal institutional documents, while GDPR access requests (a different mechanism entirely, letting individuals see their own personal data) are frequently confused with FOI requests by non-specialists. Know which regime someone is actually invoking before you respond.
🎬 [VIDEO: "How the Freedom of Information Act Works" - https://www.youtube.com/results?search_query=how+freedom+of+information+act+works - a primer on FOIA mechanics, exemptions, and the request-to-release timeline, useful for building a mental model before handling a real request]