This box is not visible in the printed version.
Request date: 24 July 2026
This version was printed or saved on: 26 August 2026
Online version: https://www.gamblingcommission.gov.uk/about-us/freedomofinformation/information-asset-register
For each information asset or system identified, please state, where held:
Please provide a list of all executive agencies, arm's-length bodies, advisory bodies, public bodies or other organisations sponsored by, accountable to, or reporting through the Attorney General's Office, together with a brief description of their responsibilities.
Please provide details of your Freedom of Information process, including:
Thank you for your request which has been processed under the Freedom of Information Act 2000 (FOIA).
You have requested information regarding the organisational structure and information management arrangements of the Gambling Commission. Specifically:
For each information asset or system identified, please state, where held:
Please provide a list of all executive agencies, arm's-length bodies, advisory bodies, public bodies or other organisations sponsored by, accountable to, or reporting through the Attorney General's Office, together with a brief description of their responsibilities.
Please provide details of your Freedom of Information process, including:
I respond to each question in turn below.
Question One
I confirm that the Commission does hold information falling with the scope of question one of your request. Section 21 of the FOIA provides that information is exempt from disclosure where it is reasonably accessible elsewhere. Information regarding the Commission’s organisational structure and departmental responsibilities can be found published on our website, here: Organisational Structure.
The Executive Team are also Information Asset Owners and are responsible for the information held by their area.
Question Two and Three
I confirm that the Commission does hold information falling within the scope of questions two and question three of your request.
This information is exempt under section 31 FOIA (law enforcement) which may apply where the exemption in section 30 FOIA (concerning investigations and legal proceedings) does not.
This exemption relates to (among others) information the disclosure of which would, or would be likely to, prejudice the prevention or detection of crime (s31(1)(a)) and the exercise by any public authority of its functions for any specified purposes (s31(1)(g)). Those specified purposes include ascertaining:
(a) whether any person has failed to comply with the law,
(b) whether any person is responsible for any conduct which is improper,
(c) whether circumstances which would justify regulatory action in pursuance of any enactment exist or may arise,
(d) a person’s fitness or competence in relation to the management of bodies corporate or in relation to any profession or other activity which he is, or seeks to become, authorised to carry on.
These purposes apply to the work of the Commission, which has statutory functions to regulate the gambling industry including issuing licences (both operating and personal licences) to individuals, reviewing compliance, and taking regulatory action in respect of breaches. These actions also include bringing prosecutions for gambling related offences.
The Commission has robust and effective processes and procedures in place which are utilised when completing our regulatory work. It could seriously impact the Commission’s investigative and regulatory processes if details of the information and systems we use to inform and carry out our regulatory activities became publicly known. This is clearly not in the public interest as it would impair the Commission’s ability to regulate effectively, including protecting the confidential nature of those investigation and prosecution activities.
There is also an increased risk of disruptive cyber-attacks where information is disclosed relating to specific IT infrastructure or security arrangements such as the Commission’s Information Asset Register (IAR) and supporting security information.
As such the Commission considers that disclosure of the information would be likely to prejudice the prevention or detection of crime and the performance of various other specific public functions pursuant to s31(1)(a) and (g).
Section 31 of FOIA is a qualified exemption and therefore the Commission has considered whether the public interest favours disclosing the information requested or whether the public interest favours maintaining the exemption and withholding the information.
The Commission is a public body with statutory functions to regulate the gambling industry which it does in the public interest. There is therefore a public interest in members of the public having confidence the Commission is being open and honest with the information it holds so that it can be held to account. We acknowledge that there is a legitimate public interest in promoting the accountability and transparency of the Commission.
We recognise the importance of ensuring there is sufficient information in the public domain, so stakeholders have an understanding of the Commission’s regulatory activity and daily operations. However, there is a strong public interest in protecting this information from unlawful access. The release of the level of detail within the IAR could be used by malicious actors in conjunction with other information in the public domain to facilitate an attack on Commission systems.
Disclosure of the detail within the IAR would be likely to put the Commission at a greater risk of ‘spear phishing’. Phishing is when attackers attempt to trick users into doing ‘the wrong thing’, such as clicking a link that will download malware, or direct them to a website with the purpose of infiltrating their device. The system name and accompanying detail within the IAR which is being withheld could allow an attacker to target specific user groups, asking them to undertake activities specific to their role and make their messages more plausible, realistic and persuasive.
Many Commission staff have social media and LinkedIn profiles where they have clearly articulated their role within the organisation. Combining this publicly available information with the systems listed within the IAR would make targeting a member of staff with a specific set of privileges a trivial task.
Further, the Commission already receives phishing/spam emails. Allowing malicious actors to perform more targeted attacks would be likely to have a significant negative effect on this existing risk.
Finally, releasing this information to the ‘world at large’ in response to a FOIA request would provide criminals with a quick and easy way of accessing useful intelligence of a list of Commission systems and their purpose.
Disclosure of the information requested would be damaging to the Commission as a regulatory body which serves to protect the wider public interest and outweighs the benefit in providing the specific information sought relating to roles and assets.
The Commission did consider whether it was possible and in the public interest to provide a selective release of the IAR. However, selective disclosure would still present the risks outlined above as it would be possible to infer details in relation to the redacted information.
The Commission is committed to the efficient management of records for the effective delivery of services, to document principal activities and decisions, and to maintain the corporate memory. In order to be of some assistance, information regarding our records management policy and retention schedule can be found on our website, here: Records Management Policy and Records Retention Schedule.
Question Four
I confirm that no information is held falling within the scope of this part of your request.
Question Five
The Information Management Team are responsible for managing FOIA requests. All FOIA requests are treated on a case-by-case basis. Searches may be coordinated centrally or by individual business areas depending on the request.
Further information in relation to how we manage FOIA requests can be found on our website, here: How we handle requests (opens in new tab).
If you are unhappy with the service you have received in relation to your Freedom of Information request you are entitled to an internal review of our decision. You should write to FOI Team, Gambling Commission, 4th floor, Victoria Square House, Victoria Square, Birmingham, B2 4BP or by reply to this email.
Please note, internal review requests should be made within 40 working days of the initial response. Requests made outside this timeframe will not be processed.
If you are not content with the outcome of our review, you may then apply directly to the Information Commissioner (ICO) for a decision. Generally, the ICO cannot make a decision unless you have already exhausted the review procedure provided by the Gambling Commission.
It should be noted that if you wish to raise a complaint with the ICO about the Commission’s handling of your request for information, then you are required to do so within six weeks of receiving your final response or last substantive contact with us.
The ICO can be contacted at: The Information Commissioner’s Office (opens in new tab), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
Information Management Team
Gambling Commission