Mr. Ken Foxe / Right to Know & An Coimisiún na Meán (the Commission)
Ó Oifig an Choimisinéara Faisnéise
Cásuimhir: OIC-145751-L7Y1Y3
Foilsithe
Teanga: Níl leagan Gaeilge den mhír seo ar fáil.
Ó Oifig an Choimisinéara Faisnéise
Cásuimhir: OIC-145751-L7Y1Y3
Foilsithe
Teanga: Níl leagan Gaeilge den mhír seo ar fáil.
Whether the Commission was justified in refusing access to records of its communications with a number of social media platforms following the Dublin riots in November 2023 under sections 30(1)(a), 32(1)(a)(iii), 32(1)(c), 35(1)(a), 35(5), 36(1)(a), 36(1)(b) and 37(1) of the FOI Act
3 June 2026
In a request dated 27 November 2023, the applicant sought access to:
“Copies of any correspondence between the Commission and the following social media companies with regard to the riots that took place in Dublin and a stabbing incident involving a number of children and adults: Facebook, Instagram, X (Twitter), Tiktok, Snapchat. Copies of the notes or minutes of any meetings held between the Commission and the companies listed with regard to the above.”
In its decision dated 22 December 2023, the Commission identified 29 records as falling within the scope of the request. It granted partial access to 24 records and it refused access to 5 records. It relied on sections 30(1)(a), 32(1)(a)(iii), 32(1)(c), 35(1)(a), 35(5) and 37(1) of the FOI Act in refusing access in full or in part to the records concerned.
On 26 December 2023, the applicant wrote to the Commission and requested that the records be reissued with the names of staff members in the Commission restored. He argued that the staff names do not constitute personal information under section 37 of the FOI Act. In reply, the Commission said that the names of its staff were withheld under section 32(1)(a)(iii) of the Act. On 2 January 2024, the applicant sought an internal review of the Commission’s decision. On 22 January 2024, the Commission affirmed its original decision. It relied on sections 30(1)(a) and 32(1)(c) in relation to 19 additional records and it highlighted these changes on the schedule which it enclosed with its internal review decision. On 24 January 2024, the applicant applied to this Office for a review of the Commission’s decision.
During the course of the review, this Office provided the parties with an opportunity to make submissions. In its submissions, the Commission said it had relied on section 37 of the Act to refuse access to names, email addresses and contact details of staff in the social media companies and the European Commission. This Office updated the applicant and he confirmed that he was agreeable to omitting names, emails addresses and contact details of individuals other than staff members of the Commission from the scope of the review.
The records identified by the Commission contain communications with four social media companies. This Office notified each of these third-party companies of the review and provided them with an opportunity to make comments or observations. Three of the companies provided submissions. Records 2 to 7 and 25 contain communications with a social media company which the applicant did not include in his FOI request. This Office asked the Commission to confirm why it had included communications with that company. In reply, the Commission said it had received multiple requests on engagements with social media companies in the aftermath of the riots and some of the other request specified the company in question. It said this appears to have led to a mix up and the records of communications with that company were included in error. This Office notified the company in question that their records would not be considered in the review.
I have now completed my review in accordance with section 22(2) of the FOI Act. In carrying out my review, I have had regard to the submissions made by the various parties. I have also had regard to the contents of the record concerned. I have decided to conclude this review by way of a formal, binding decision.
While the Commission did not rely on section 36 of the FOI Act to refuse access to the records at issue, the social media companies argued in their submissions that their communications with the Commission and notes of their meetings with the Commission contain commercially sensitive information and are exempt under section 36(1)(a) and (b) of the FOI Act. I will therefore consider whether the records at issue are exempt under 36(1)(a) and (b) of the FOI Act in this review.
Accordingly, the scope of this review is concerned solely with whether the Commission was justified in refusing access in full or in part to records 1, 8 to 24 and 26 to 29 on the basis that the records or parts of records concerned are exempt from release under sections 30(1)(a), 32(1)(a)(iii), 32(1)(c), 35(1)(a), 35(5), 36(1)(a) and/or 36(1)(b) of the FOI Act.
Section 25(3) of the Act requires me to take all reasonable precautions in the performance of my functions to prevent the disclosure of information contained in an exempt record or that would cause the record to be exempt if it contained that information. Accordingly, I am limited in the extent to which I can describe the redacted portions of the records or the withheld records concerned.
The Records
While I am limited in the extent to which I can describe the records at issue, I can say that they concern communications between the Commission and the social media platforms following the Dublin riots in November 2023. The records fall into the following categories:
Administrative type emails between the Commission and the social media companies regarding the setting up of Teams meetings (1, 8, 9, 11, 12, 13, 14, 15, 17, 18, 19, 20, 21, 23, 24).
Substantive notes of the meetings themselves and follow up actions after the meetings (10, 16, 22).
Emails/WhatsApp messages between the Commission and the platform companies drawing their attention to the stabbing incident so that appropriate steps can be taken (26, 27, 28 and 29).
The Commission refused access in full to records 10, 16 and 22 which contain notes of the meetings and to record 27 which contains a WhatsApp message from one of the social media companies to the Commission. The Commission refused access to parts of the remaining records.
Section 32
As the Commission relied on sections 32(1)(a)(iii) and 32(1)(c) in relation to each of the records at issue, I will consider section 32 first. Section 32(1)(a)(iii) provides for the refusal of a request where the FOI body considers that access to the record concerned could reasonably be expected to prejudice or impair lawful methods, systems, plans, or procedures for ensuring the safety of the public and the safety or security of persons and property. Section 32(1)(c) provides for the refusal of a request where the FOI body considers
that access to the record concerned could reasonably be expected to facilitate the commission of an offence.
Where an FOI body relies on section 32(1)(a)(iii) it should identify the potential harm to the matters specified in the relevant sub-paragraph that might arise from disclosure and having identified that harm, consider the reasonableness of any expectation that the harm will occur. In doing this, the FOI Body should show how or why releasing the particular record could reasonably be expected to cause the harm which it has identified. In interpreting the words, “could reasonably be expected to ”, the Commissioner’s view is that the test is not concerned with the question of probabilities or possibilities. It is concerned with whether the decision maker’s decision is reasonable. Where an FOI body relies on section 32(1)(c) it should show how the release of the record could make the commission of an offence easier and consider the reasonableness of that occurring. It should also indicate the nature of the relevant offence(s) concerned. It should show the link between the particular record at issue and how its release could make the commission of the offence(s) easier.
The Commission said sections 32(1)(a)(iii) and 32(1)(c) were applied to all records in respect of withholding staff names. In relation to the Commissioners, it said their names were not redacted but their email addresses were. It said that in the specific circumstances of this case, where there are more extreme societal elements at play with a highly coordinated online presence, staff members could be targeted, subjected to harassment, online abuse, doxing or other potential threats. It said such harassment was directed at a member of the Commission in the aftermath of the incident. It provided this Office with examples of such abuse. The Commission said a few examples were threatening and also made reference to family members and the matter was reported to the Gardaí. It said that those involved in regulating online safety risk becoming victims of extreme targeting from these elements. It said that as its regulatory function is developing this will be increasingly pertinent, particularly as staff members deal with more sensitive and complex regulatory, investigative, and online safety matters.
The Commission said it relied on section 32(1)(a)(iii) to refuse access to links to Teams meetings it hosted. It said this information was redacted in case release would pose a risk to the security of its systems. It said this information is simply character strings and not content and release of this information would not serve transparency of information or the principles of FOI. Finally, the Commission said it relied on section 32(1)(a)(iii) to refuse access to record 27 as it referred to engagement with An Garda Síochána as part of a response mechanism for a crisis incident.
The Commission has provided this Office with over 120 examples of abuse, harassment and threats which were directed at a member of the Commission in the aftermath of the riots and it provided more recent examples of abuse. It includes threats of harm which are explicit or implicit in nature. I understand that making online threats constitutes a criminal offence under the Harassment, Harmful Communications and Related Offences Act 2020 and the Non-Fatal Offences against the Person Act 1997. Having regard to the information provided by the Commission, I accept that release of the names, email addresses and contact details of the staff members of the Commission who were involved in regulating online safety could reasonably be expected to make it easier for more extreme societal elements to send threats to those staff members. In the particular circumstances of this case, I find that that this information is exempt under section 32(1)(c) of the FOI Act.
The Commission also refused access to links to Teams meeting invites which it sent to the social media companies. I understand that old links cannot be used to access prior meetings or to view chat history. I do not accept, therefore, that release of these links to Teams meetings could reasonably be expected to impair systems for ensuring the safety of the public and the safety or security of persons and property and I find that they are not exempt under section 32(1)(a)(iii) of the Act.
The Commission said section 32(1)(iii) was also applied to record 27. Record 27 is a single line WhatsApp message which simply refers to contacting the gardai when the stabbing incident at issue was reported. It is not clear to me how the release of this message could reasonably be expected to give rise to any of the harms identified in sections 32(1)(a)(iii) or 32(1)(c), nor has the Commission adequately explained how the release of the record might give rise to such harms. I find that record 27 is not exempt under section 32(1)(a)(iii) or section 32(1)(c) of the Act.
Section 30(1)(a)
The Commission relied on section 30(1)(a) to refuse access in full or in part to records 8, 10, 15, 16, 18, 20, 22 and 24. Records 8, 15, 18, 20 and 24 contain meeting invites or invites to follow up meetings, records 10, 16 and 22 are notes of meetings. Section 30(1)(a) of the Act provides for the refusal of a request if the FOI body considers that access to the record concerned could reasonably be expected to prejudice the effectiveness of tests, examinations, investigations, inquiries or audits conducted by or on behalf of an FOI body or the procedures or methods employed for the conduct thereof. Section 30(1) is also subject to a public interest balancing test.
Section 30(1)(a) envisages two potential types of "prejudice " or harm. The decision maker must hold the view that the release of the record could reasonably be expected to prejudice the "effectiveness " of the tests, examinations, investigations, inquiries or audits, or prejudice the "procedures or methods employed for the conduct thereof ”. Where an FOI body relies on this provision, it should identify the potential harm in relation to the relevant function specified in paragraph (a) that might arise from disclosure. Having identified that harm, it should consider the reasonableness of any expectation that the harm will occur.
The FOI body should explain how and why, in its opinion, release of the record(s) could reasonably be expected to give rise to the harm envisaged. A claim for exemption under section 30(1)(a) must be made on its merits, in light of the contents of each particular record concerned and the relevant facts and circumstances of the case.
The Commission said that at the time the records at issue were created it was preparing for its regulatory role as Ireland’s Digital Services Coordinator (DSC) under the European legislative framework of the Digital Services Act (DSA) (the legislation subsequently came into effect from February 2024). It said each Member State’s designated DSC has responsibility for the application and enforcement of the DSA in that country. It said the compliance obligations within the legislative framework are:
to assess and mitigate risks of negative effects on public security
to inform law enforcement authorities of information that a criminal offence involving a threat to life or safety of a person is taking place or is likely to take place.
The Commission said it initiated engagement with the social media platforms in this regard on a non-statutory basis at the time. Its view is that disclosure of records relating to these engagements could reasonably have been expected to harm the integrity of such engagements overall at the time, and in future for similar such engagements. It argued that it could endanger the cooperation, openness and frankness of regulated entities in the event of major incidents or investigations. It said that such entities may not be willing to engage openly or provide information if they consider there is a risk that such information will enter into the public domain. It said it is important that as a matter of function, engagements between the supervisory function and platforms can remain confidential. It said this particular engagement was relevant to regulatory functions under the Digital Services Act but it also can envisage future similar engagements that may arise in relation to its statutory functions under the Terrorism Content Online Regulation and the Online Safety Code. It said notes of its meetings with the social media companies, details of agendas and reference to certain European Commission plans were all withheld under section 30(1)(a) of the Act.
An FOI Body relying on section 30(1)(a) should show how release of the record could reasonably be expected to cause the harm envisaged, i.e. it should show the link between granting access to the record concerned and the harm identified. It should do this by reference to the specific record being considered for release: what is it about the particular record or the particular information in the record which, if released, could reasonably be expected to cause the harm envisaged? An FOI body’s submissions to the Commissioner should be sufficiently detailed to demonstrate that link.
Record 8, 15, 18, 20 and 24 contain emails between the Commission and the platform companies which concern the setting up of Teams meetings or follow up meetings. Names and email addresses of attendees from the platform companies and European Commission have been redacted and this information falls outside the scope of the request. Names, emails addresses and contact details of staff have been redacted. I have found that this information is exempt under section 32(1)(c) of the Act. There is a small amount of remaining information which includes information in relation to agendas for the Teams meetings, links to Team meetings and the reason for attendance of staff of the European Commission. In my view, release of this type of high-level information could not reasonably be expected to endanger the cooperation, openness and frankness of regulated entities in the event of major incidents or investigations. I find therefore that the information withheld from these records is not exempt under section 30(1)(a) of the FOI Act.
Records 10, 16 and 22 contain the notes of the meetings between the Commission and the social media companies. These notes contain eight to ten bullet points which are a couple of lines long and which address the matters discussed and follow up actions. The information in the bullet points contains an overview of the platform’s response to the incident at issue. The information is very high level. Information about how social media companies manage content that violates their terms of service is in the public domain. It is in the public domain that platforms use AI, human moderation and user reporting mechanisms to manage this type of content. Due to the high level nature of the information and the fact that similar information is essentially publicly available, I am not satisfied that release of these notes would be likely to endanger the cooperation and openness of the social media companies in the event of similar investigations and I find that these records are not exempt under section 30(1)(a) of the FOI Act.
Section 35 – Information provided in Confidence
The Commission also relied on sections 35(1)(a) in refusing access in full or in part to records 8, 10, 15, 16, 20 and 22. Section 35(1) provides that an FOI body shall refuse to grant an FOI request if:
a) the record concerned contains information given to an FOI body in confidence and on the understanding that it would be treated by it as confidential and the body considers that its disclosure would be likely to prejudice the giving to the body of further similar information from the same person or other persons and it is of importance to the body that such further similar information as aforesaid should
continue to be given to the body, or
b) disclosure of the information concerned would constitute a breach of a duty of confidence provided >for by a provision of an agreement or enactment (other than a provision of an enactment specified in Schedule 3) or otherwise by law.”
Section 35(2) provides that subsection (1) shall not apply to a record which is prepared by a head or any other person (being a director or staff member of an FOI body or a service provider) in the course of the performance of his or her functions "unless disclosure of the information concerned would constitute a breach of a duty of confidence that is provided for by an agreement or statute or otherwise by law and is owed to a person other than an FOI body or head or a director, or member of staff of an FOI body or of such a service provider."
The Commission said that while it is not explicitly stated in the notes of communications with the social media companies, it is reasonable to expect that there would have been an expectation of confidentiality overall on such engagement, particularly in crises response situations. The Commission argued that it is reasonable to expect that breaking such confidentiality would prejudice the giving of such information to it in the future. The Commission said that it is of critical importance that such information is provided to it
where required in future in order for it to discharge its statutory remit.
As part of the review, this Office also sought submissions from each of the social media companies whose interests may be affected by release of the records at issue. A number of the companies have objected to the release of information given on the basis that they provided confidential information regarding internal policy decisions, actions taken by trust and safety teams and details of escalation protocols for urgent removal of problematic content on their sites. The third parties argued that such information is provided on the strict understanding that it would be treated as being confidential. They highlighted
concerns that certain records contain information relating to internal policy decisions and actions taken in response to the events in November 2023 and they consider that if that information was released it could aid bad actors in their attempts to circumvent safety controls and processes.
In the applicant’s response to the details provided of the material issues arising, the applicant expressed a number of general concerns about the social media companies. Among other things, he also said the Commission’s suggestion that release of these records "could endanger the cooperation, openness and frankness of regulated entities in the event of major incidents or investigations." is a frightening prospect that the Commission fears these companies will not even provide the basic assistance required in the event of widespread rioting in the State’s Capital. He said this is a matter for the companies involved
and the consciences of those who own them and work there and he argued that it does not seem a relevant factor to his FOI request and seems instead a great weakness in the State’s laws that such cooperation cannot be enforced on a legislative basis. In essence he argued that it is absolutely crucial that the public has a full understanding of what steps were taken by these companies to assist the Irish state in dealing with unprecedented levels of disorder. The applicant also asked that as much of his submissions as possible should be included in this decision. I do not consider it necessary to do so, in circumstances where much of his submissions contain his views in relation to the social media companies and their operations and practices, and do not directly engage with the question of the applicability or otherwise of the specific exemptions cited.
As the meeting invites and notes of the meeting were prepared by Commission staff in the course of the performance of their functions, I have considered whether section 35(2) serves to disapply section 35(1)(a) to those records. For section 35(2) to apply, disclosure of the records must constitute a breach of a duty of confidence that is provided for by agreement or statute or otherwise by law and is owed to the social media companies. The Commission has not argued, nor is it apparent to me, that the information was provided by the social media platforms pursuant to an agreement or statute. I note that the information was provided before the Digital Services Act came into effect. A duty of confidence provided for “otherwise by law ” is generally accepted to include a duty of confidence arising in equity. This Office accepts that breach of an equitable duty of confidence is comprehended by section 35(1)(b). In the Supreme Court decision in the case of Mahon v Post Publications Ltd [2007] 3 I.R. 338, Fennelly J. confirmed that the requirements for a successful action based on a breach of an equitable duty of confidence, at least in a commercial setting, are found in the judgment of Megarry J. in Coco v. A. N. Clark (Engineers) Ltd. [1969] R.P.C. 41, at 47:
“Three elements are normally required if, apart from contract, a case of breach of confidence is to succeed. First, the information itself ... must 'have the necessary quality of confidence about it'. Secondly, that information must have been imparted in circumstances importing an obligation of confidence. Thirdly, there must be an unauthorised use of that information to the detriment of the party communicating it."
Fennelly J. summarised or restated the requirements of what he called “the contours ” of the equitable doctrine of confidence as follows:
1. “the information must in fact be confidential or secret: it must ... ‘have the necessary quality of confidence about it’;
2. it must have been communicated by the possessor of the information in circumstances which impose an obligation of confidence or trust on the person receiving it;
3. it must be wrongfully communicated by the person receiving it or by another person who is aware of the obligation of confidence.” I have adopted this approach in considering whether disclosure of these records would constitute a breach of an equitable duty of confidence in this case. The records at issue comprise emails arranging Teams meeting and notes of the meetings between the Commission and the social media platforms. Record 8, 15 and 20 comprise administrative type emails sent from the Commission to the companies which concern the setting up of Teams meetings and asking companies to indicate a time slot which they can attend and emails from the companies indicating when they can attend. As outlined above names and contact details of staff are either outside scope or I have found to be exempt under section 32 of the FOI Act. I am not satisfied that the release of any remaining information which has been redacted from these emails would involve a breach of a duty of confidence owed to the platforms or any other third party. I do not accept that the information has the necessary quality of confidence about it. Records 10, 16 and 22 comprise notes of the meetings between the Commission and the platform companies. In their submissions to this Office, one of the companies stated that they acted quickly to provide substantive, highly sensitive and confidential information to the regulator on the very same day as the request. However, it is also clear from their submissions that while the social media companies have been provided with details of the records at issue they have not actually been provided with copies of the records. One of the social media companies said the Commission has informed it that the notes of their meeting is marked as an internal record and was not intended to be a formal meeting minute.
Therefore, while the companies may have provided substantive, highly sensitive information to the Commission, the notes in question were not intended to be formal minute meetings and they in fact consist of 8-10 bullet points which contain a high-level overview of the platform responses to the incident at issue. Having regard to the nature of the information at issue, I am not satisfied that it has the necessary quality of confidence about it to give rise to an equitable duty of confidence. As I have outlined above, the information is quite high level and Information about how social media companies manage content that violates their terms of service is already in the public domain. I find therefore that disclosure of the records would not constitute a breach of a duty of confidence owed to the social media companies. For this reason, I find that section 35(2) serves to disapply section 35(1) in respect of records 10, 16 and 22.
Finally, I note that in addition to relying on section 35(1)(a), the Commission has also sought to rely on section 35(5) of the Act in refusing access to records 8, 10, 15, 16, 20 and 22. When requesting focused submissions from the Commission, this Office noted that section 35(2) states that the exemption at 35(1) does not apply to certain records prepared by a member of staff of an FOI body and it asked whether the records were prepared by a member of staff in the course of the performance their functions. In reply, the Commission stated that the records were prepared by a member of staff, however it noted that section
35(5) provides that - in this section “record ” includes information conveyed in confidence in person, by telephone, electronically or in writing (including a written note taken of a phone message by a person authorised to receive such message). It seems to me that the Commission’s submission that section 35(5) applies notwithstanding section 35(2) are based on an incorrect interpretation of section 35(5). The explanatory memorandum to the FOI Bill explains the purpose and intent of section 35(5). In essence, it was introduced to put it beyond doubt that information could be regarded as having been given in confidence where that information is simply recorded in a record by a staff member as opposed to being
contained within correspondence received directly from the confider. In conclusion, I find that the Commission was not justified in refusing access to records 8, 10, 15, 16, 20 and 22 in full or in part on the basis of sections 35(1)(a) or (b) or 35(5) of the Act. Section 36(1)(a) As outlined above, in their submissions to this Office, the social media companies argued that their communications with the Commission and notes of their meetings with the Commission contain commercially sensitive information and are exempt under section 36(1)(a) and (b) of the FOI Act.
Section 36(1)(a) provides for the refusal of a request where the record sought contains trade secrets of a person other than the requester. This Office accepts that a trade secret is information used in the trade or business which, if disclosed to a competitor, would be liable to cause real (or significant) harm to the owner of the secret and that the owner must limit the dissemination of it or at least not encourage or permit wide-spread publication. Section 36(1)(b) provides for the refusal of a request where the record sought contains financial, commercial, scientific or technical or other information whose disclosure could reasonably be expected to result in a material financial loss or gain to the person to whom the information relates or could prejudice the competitive position of that person in the conduct of his or her profession or business or otherwise in his or her occupation.
One of the social media companies argued that given the nature of the information at issue, the records contain trade secrets and/or commercial, technical or other information of the type covered by sections 36(1)(a) and (b). It said that as the environment it operates in is competitive, it considers that the release of the information in the records could prejudice its competitive position in the market. It said this information is current and could be used by its competitors to either replicate its content regulation processes or to seek to improve/distinguish them from the company in question. It said it also has a real concern that disclosure of this information to the world-at-large could enable or entice persons with
malicious motives to abuse and/or seek to avoid content regulation processes. It considers that with knowledge of exact content moderation processes, persons with malicious motives can adapt the way they create posts and circumvent those moderation measures.
I accept that the environment in which social media platforms operate in is highly competitive. I also accept that the release of information into the public domain which could allow competitors to replicate content regulation processes could cause prejudice to the competitive position of the platform concerned. It may well be the case that the platforms provided the Commission with comprehensive explanations in relation to the actions they took in the aftermath of the riots. However as previously stated, the notes of the meetings with the platforms do not contain detailed information in relation to the
policies, protocols and processes that the platforms applied following the riots. Instead, the notes contain a high level overview of actions taken, much of which is publicly available information. I am not satisfied that the records contain the type of substantive, sensitive and confidential information which would qualify as a trade secret or could be used by competitors to gain an insight into the content regulation processes of the platforms. I find, therefore, that the records are not exempt from release on the basis of section 36(1)(a) or (b) of the FOI Act.
Having carried out a review under section 22(2) of the FOI Act, I hereby vary the Commission’s decision. I find that section 32(1)(c) applies to the names, email addresses and contact details of the staff members of the Commission which are contained in records. I find that the Commission was not justified in refusing access to any of the remaining records or parts of records on the basis of sections 30(1)(a), 35(1)(a), 35(1)(b), 35(5), 36(1)(a) or 36(1)(b) of the FOI Act.
Section 24 of the FOI Act sets out detailed provisions for an appeal to the High Court by a party to a review, or any other person affected by the decision. In summary, such an appeal, normally on a point of law, must be initiated by the applicant not later than eight weeks after notice of the decision was given, and by any other party not later than four weeks after notice of the decision was given.
Stephen Rafferty
Senior Investigator