A former council chief executive has been convicted after an email was deleted to prevent it being disclosed under freedom of information laws. Former Mid and East Antrim Borough Council chief executive Anne Donaghy was convicted at Ballymena Magistrates’ Court of two charges relating to the deletion of an email sent to the then First Minister of Northern Ireland, Arlene Foster. She was fined £750 on each count. Ms Donaghy maintains her innocence and has indicated that she intends to appeal.
While most businesses are not subject to Freedom of Information laws, UK data protection law contains a strikingly similar criminal offence covering information sought through a subject access request. That provision potentially applies to private companies and their employees as well as public bodies.
What happened in the Anne Donaghy case?
The case arose from events surrounding post-Brexit arrangements at Larne Port in 2021. Donaghy had written to the Cabinet Office about concerns relating to the Northern Ireland Protocol and security at the port. The correspondence was subsequently forwarded to a number of politicians from the province’s governing Democratic Unionist Party, including an email sent to then First Minister Arlene Foster’s personal email address.
On 26 April 2021, the council received a freedom of information request seeking emails concerning the Northern Ireland Protocol. Three days later, Donaghy instructed her personal assistant to delete the email to Foster. When told that a copy had already been supplied to the council’s FOI team, her response became part of the evidence considered by the judge.
District Judge Alana McSorley concluded that there was a live FOI request at the time and that the deletion was intended to prevent disclosure of information to which the applicant would have been entitled.
Why can deleting an email become a criminal offence?
Section 77 of the Freedom of Information Act 2000 applies where a request has been made to a public authority and the requester would have been entitled to receive the information.
It makes it an offence to alter, deface, block, erase, destroy or conceal a record with the intention of preventing its disclosure. The provision can apply both to the public authority and to individuals employed by, holding office in or acting under the direction of the authority.
The offence does not depend on someone falsifying an FOI response or constructing an elaborate cover-up. An individual employee can commit it through what might otherwise appear to be an ordinary records-management action, such as deleting an email, provided the necessary intention to prevent disclosure is present.
There is also an important limitation. Deleting information is not automatically an offence. Organisations are entitled, and frequently required, to delete information as part of legitimate retention and disposal programmes. The criminal element arises where information is deleted, concealed or altered with the intention of preventing disclosure following a relevant request.
What about subject access requests?
This is where the case becomes relevant to almost every organisation processing personal data. Section 173 of the Data Protection Act 2018 creates a closely related offence where an individual has exercised a data subject access right.
Where someone would have been entitled to receive information, it is an offence for the controller or someone employed by, acting as an officer of, or subject to the direction of the controller to:
- alter, deface, block, erase, destroy or conceal that information; with
- the intention of preventing disclosure of all or part of it.
The provision expressly covers the UK GDPR right of access under Article 15, alongside certain other access rights. Unlike the FOI offence, which is principally relevant to public authorities covered by the Freedom of Information Act, the Data Protection Act offence can apply to private-sector organisations and their staff.
An employee who deliberately deletes an embarrassing email because they know it falls within an employee’s SAR could therefore be facing something considerably more serious than an internal disciplinary issue.
Section 173 is a criminal offence. On summary conviction it can result in a fine, and the offence is also listed as a recordable offence under the Data Protection Act.
What happens if someone deletes an email after a SAR arrives?
A SAR generally concerns personal information held by the organisation when the request is received. Normal business activity may mean that information is subsequently updated or deleted while the organisation is dealing with the request.
The critical distinction is whether that deletion would have happened anyway. The ICO states that organisations should not amend or delete information following receipt of a SAR if they would not otherwise have done so. Doing so with the intention of preventing disclosure can constitute an offence under the Data Protection Act.
Section 173 itself provides two important defences. A person may have a defence if they can prove that the alteration or deletion would have occurred even without the request, or that they reasonably believed the requester was not entitled to receive the information.
That makes a documented retention schedule particularly important. Suppose an organisation automatically deletes a particular class of system logs after 90 days and that established process happens to run while a SAR is being processed. That is very different from a manager receiving notification of a SAR and manually deleting a particular email because they do not want the requester to see it.
From a compliance perspective, however, continuing routine deletion once potentially relevant information has been identified creates unnecessary risk. A preservation or legal-hold process is generally much safer.
What if the employee deletes the information before the SAR?
Section 173 requires a request to have been made. The specific criminal offence therefore does not generally turn an earlier, unrelated deletion into a crime simply because somebody later submits a SAR.
Routine deletion may in fact be required under the UK GDPR’s storage limitation principle. Organisations should not retain personal information indefinitely in case somebody eventually asks for it. The ICO expects organisations to establish appropriate retention periods and erase or anonymise information when it is no longer required.
This creates an important balance for compliance teams.
Good data governance requires organisations to delete information when they no longer have a reason to retain it. Once an FOI request, SAR, regulatory investigation, litigation hold or other preservation requirement intervenes, relevant deletion processes may need to be suspended. The solution is a defensible retention system, rather than keeping everything forever.
Could deleting data also amount to a personal data breach?
Potentially, yes. Under the UK GDPR, a personal data breach includes a breach of security leading to the accidental or unlawful destruction, loss or alteration of personal data. It covers availability and integrity as well as unauthorised disclosure. The ICO specifically recognises that both accidental and deliberate actions can produce a personal data breach.
An employee who deletes personal information without authorisation could therefore trigger two separate compliance questions:
Was the deletion itself an unlawful security incident that needs to be assessed under the organisation’s breach-management procedure?
And, if a SAR had already been received, was the deletion carried out with the intention of preventing disclosure, potentially engaging section 173?
Why organisations need an information preservation process
The Donaghy case illustrates a weakness in many organisations’ FOI and SAR procedures. Policies often concentrate on who receives a request, how long the organisation has to respond and which exemptions might apply.
They devote much less attention to what staff are permitted to do with the underlying information once the request arrives. A robust process should ensure that relevant custodians are quickly informed when a request requires information to be preserved. Automated deletion settings may need to be suspended, and staff should be told expressly not to delete, edit or move potentially responsive information without approval.
This should extend beyond the corporate inbox. Depending on the circumstances, relevant information may exist in Teams, Slack, WhatsApp, shared drives, archived mailboxes and even personal devices or private accounts used for work. The ICO confirms that personal information stored by staff on private devices can fall within the scope of a SAR where they are holding it on the controller’s behalf.
Public authorities face similar issues under FOI. The ICO has warned that official information can remain subject to FOI even where it is held in private email accounts and that deliberately treating such information as outside the authority’s control could potentially amount to concealment.
A wider question of judgement
The case also raises broader questions about the judgement expected of senior leaders responsible for public bodies and sensitive information.
Donaghy had already been suspended by Mid and East Antrim Borough Council in 2021 pending an investigation into separate bullying and harassment allegations. She strongly contested those allegations and subsequently brought legal proceedings against the council, claiming victimisation on grounds including sex, disability, religion and political belief. Those matters should not be conflated with the FOI prosecution and do not establish wrongdoing on her part.
The present conviction, however, concerns conduct on which a court has now reached a finding. The judge concluded that Donaghy intended to prevent information from being disclosed and found that concern over a perception that she was too close to DUP politicians formed part of her motivation for deleting the email. Donaghy maintains her innocence and intends to appeal the convictions.
For compliance professionals, there is a wider leadership lesson here. Senior executives are often the people under the greatest pressure when correspondence becomes politically, commercially or reputationally uncomfortable. They are also the people whose decisions set the tone for everyone else.
An uncomfortable email is precisely the point at which normal governance procedures matter most. Once an FOI request, subject access request, investigation or litigation hold has arisen, the appropriate response is to preserve the record, escalate the issue and take advice on whether it must be disclosed. Attempting to make the underlying problem disappear by making the record disappear can transform a reputational problem into a legal one.
What should compliance teams do?
Organisations should review their procedures with the criminal offences in mind. In practice, this means making sure staff can recognise an FOI request or SAR, immediately escalating it to the appropriate team, preserving potentially relevant information and documenting any legitimate deletion that continues during the response period.
Particular attention should be paid to senior managers and HR teams. Employment disputes frequently generate SARs, and the emails most likely to become contentious are often held by managers who may have little understanding of the criminal provisions governing deletion.
Training is therefore important. Employees do not need to become experts in section 173 of the Data Protection Act. They do need to understand a simple instruction: once you know information may fall within an access request, do not delete or alter it simply because you would rather it was not disclosed. Escalate it instead.
VinciWorks’ UK data protection training includes courses covering subject access requests, individual rights, personal data breaches and practical GDPR compliance.