The Freedom of Information Act (FOIA) is often associated with government transparency, but for companies that regularly interact with federal agencies, it can present significant disclosure risks. Information submitted through permit applications, inspections, regulatory filings and routine communications with government officials may later become the subject of a FOIA request.
As advocacy groups, competitors and other third parties increasingly use FOIA to obtain information from federal agencies, companies should understand the tools available to protect sensitive business information from public disclosure. Proactive planning, consistent confidentiality practices and a strong understanding of FOIA’s protections can significantly reduce disclosure risk.
This Q&A from Bracewell’s environment, lands and resources team explains how companies can use FOIA Exemption 4 and other defensive FOIA strategies to safeguard confidential business information and respond effectively when a FOIA request targets agency records containing sensitive company data.
What Is Defensive FOIA?
Defensive FOIA refers to efforts by a company or other submitting party to prevent the federal government from disclosing information in response to a FOIA request. Unlike traditional FOIA requests, where a requester seeks information from an agency, defensive FOIA arises when a company has already provided information to the government and seeks to ensure that the information remains protected from public disclosure.
In some situations, companies may need to submit a response explaining why a FOIA exemption applies and why the information the company provided to the agency is not subject to disclosure. If the agency disagrees or the requester challenges the agency’s determination that an exemption applies, litigation may become necessary to prevent disclosure.
Why Is Defensive FOIA Becoming More Important?
Disclosure risks have increased significantly in recent years for two reasons:
- Companies are providing more information to government agencies than ever before. Permit applications, inspection materials, operational data, correspondence and other business records routinely make their way into agency files.
- Third-party requesters have become increasingly sophisticated in their use of FOIA. Advocacy groups, nongovernmental organizations and other stakeholders frequently use FOIA as a tool to gather information about regulated entities, often as a precursor to litigation, enforcement advocacy or public campaigns.
As a result, companies should assume that information submitted to a federal agency could eventually become the subject of a FOIA request.
What Is FOIA Exemption 4 and Why Is It Important?
Exemption 4 is the foundation of most defensive FOIA matters. The exemption protects:
“Trade secrets and commercial or financial information obtained from a person and privileged or confidential.”
5 U.S.C. § 552(b)(4)
For many companies, Exemption 4 serves as the primary mechanism for preventing disclosure of sensitive business information submitted to the government as part of permit applications, inspection-related submissions and other correspondence, such as:
- Operational and process information
- Commercial data
- Financial information
- Technical information
Because the applicability of Exemption 4 frequently determines whether confidential business information is protected or disclosed, companies should understand how courts interpret the exemption.
What Information Qualifies as Confidential Under FOIA Exemption 4?
Information qualifies as confidential under Exemption 4 when it is commercial or financial in nature and the submitter customarily and actually treats it as private. Several considerations are central to the Exemption 4 analysis:
- Whether the information is commercial or financial in nature
- Whether the information is customarily and actually treated as private
- Whether the information was provided to the government under an assurance of privacy
Of these factors, a company’s treatment of the information is often particularly important. Companies seeking protection should be able to demonstrate that they consistently treat the information as confidential in the ordinary course of business. Internal confidentiality practices can therefore play a significant role in determining whether information ultimately receives Exemption 4 protection.
How Has the Supreme Court’s Argus Leader Decision Changed FOIA Exemption 4?
The Supreme Court’s 2019 decision in Food Marketing Institute v. Argus Leader Media, (18-481) significantly reshaped the Exemption 4 analysis. Following the decision, courts no longer require a submitter to show that disclosure would cause competitive harm and instead focus on the plain meaning of “confidential” by examining whether the submitter customarily and actually treats information as private.
The case placed increased emphasis on a company’s own confidentiality practices. As a result, companies have greater ability to strengthen future Exemption 4 claims by establishing and consistently following internal procedures for protecting sensitive information.
Should Companies Seek Assurances of Confidentiality From Agencies?
In Argus Leader Media, the Supreme Court explained that “[a]t least where commercial or financial information is both customarily and actually treated as private by its owner and provided to the government under an assurance of privacy, the information is ‘confidential,’” but left open whether a government assurance of privacy is necessary for information to qualify under Exemption 4.
Lower court decisions have generally refrained from requiring an assurance of confidentiality, but companies that establish that an agency has provided an express or implied assurance will be positioned to more readily demonstrate that the information qualifies for exemption.
To that end, companies should seek to obtain an express assurance of confidentiality from an agency prior to submitting sensitive information. If the information has already been without an express assurance, companies should consider whether an agency provided an implied assurance. Some agencies routinely treat certain categories of information as confidential or maintain procedures for handling confidential information.
These practices can help support future arguments that information was submitted with an expectation of privacy. At the same time, companies should be aware of any agency statements indicating that certain information may be publicly disclosed. Such statements can complicate or foreclose future confidentiality arguments.
Understanding the agency’s treatment of submitted information before making a submission can be an important part of a comprehensive defensive FOIA strategy.
What Happens When a FOIA Request Targets Company Information?
When a FOIA request seeks information submitted by a company, agencies frequently notify the submitter (often referred to as a “submitter notice”) and provide an opportunity to explain why the information is subject to a FOIA exemption. This is often referred to as the “substantiation” process, through which the company explains why the information qualifies for an exemption. Because response deadlines can be short, companies should move quickly to identify:
- What information is at issue
- Whether the information is commercially sensitive
- Whether the company designated the information as confidential at the time of submission
- Who within the organization generated the information
- What measures have been taken to maintain confidentiality
- Whether the agency provided an express or implied assurance that the information would be treated as confidential
Companies are better able to substantiate confidentiality claims if they have documented and managed the information in accordance with clear confidentiality procedures, including at the time of submission.
What Are the Best Practices for Protecting Confidential Business Information From FOIA?
The most effective defensive FOIA strategies begin before information is submitted to the government. Key practices include:
- Understanding what information is already publicly available
- Clearly and consistently designating as confidential information that is not publicly available
- Seeking confidentiality assurances at the time of submission
- Restricting access to sensitive information within the organization
- Maintaining consistent confidentiality policies
- Preserving records that support confidentiality claims
- Entering into non-disclosure and/or confidentiality agreements prior to sharing confidential information with third parties
- Submitting confidential information to federal agencies only when necessary
Consistency is particularly important. Information that is treated as confidential in one context but freely shared in another will likely foreclose protection from disclosure.
How Can Agency Inspections Create FOIA Risks?
Inspections present a unique challenge because agency personnel often collect information that does not originate in a formal company submission. Inspection notes, photographs, observations and discussions may contain the company’s confidential information regarding operations, processes or business practices.
Companies should identify confidential information during inspections and assert information as such to ensure agency personnel understand they are handling sensitive information. Failure to do so increases the risk that confidential information becomes embedded in agency records without the agency’s awareness and without the appropriate designations. Draft inspection reports should also be reviewed, where possible, to identify confidential business information.
Who Should Be Involved When a FOIA Disclosure Dispute Arises?
One of the most important steps in any defensive FOIA matter is involving key personnel early. Companies should promptly assemble individuals who:
- Submitted the information
- Created the information
- Understand its commercial significance
- Manage access to the information
- Can explain how confidentiality has been maintained
Early coordination helps companies assess disclosure risks, determine whether outside counsel should be engaged and prepare timely responses to agency inquiries.
Key Takeaways
As the volume of information submitted to government agencies grows and third-party use of FOIA becomes increasingly sophisticated, companies face greater risks that sensitive business information could be disclosed.
The strongest defense begins long before a FOIA request arrives. Companies that consistently treat information as confidential, maintain effective designation practices, understand agency disclosure procedures and involve key personnel early are generally in the best position to protect sensitive information from public release.
By incorporating defensive FOIA principles into their broader regulatory and compliance strategies, companies can reduce disclosure risks and better protect sensitive and valuable business information.
