Work in progress: PublicAudit.uk is being built in my free time. Some features and data are still incomplete — thanks for your patience.
PublicAudit.uk paperclip mascotPublicAudit.uk

← Back to the Government Information Map

Non-ministerial department and regulatorFreedom of Information Act 2000

Competition and Markets Authority

Also known as CMA

Promotes competition and investigates anti-competitive practices and consumer-protection issues.

Contact this organisation

Link health

These addresses are checked automatically. This is an automated technical check that the address responds. It is not confirmation from the authority that the contact route is correct or still in use. Symbols are shown alongside the text so the status never relies on colour alone.

  • FOI email addressLink reachableChecked 8 September 2026
  • Official websiteLink reachableChecked 8 September 2026Automatically updated from https://www.gov.uk/cma
Contact status
Delivery accepted
Mapping status
Response Received
Contact route last checked
Check date not recorded
Details last checked
Check date not recorded
Mapping information last updated
2026-08-17

Contact route and mapping progress are separate things. A contact route status describes how the address or form was checked; mapping progress describes how far this project's own request to the organisation has got. Always confirm the route on the organisation's official website before sending a request.

What you may be able to request

Some information categories are based on the authority's published responsibilities and may not yet have been confirmed through an FOI response.

Likely areas of responsibility — not yet confirmed by Public Audit.

  • Spending and contracts
  • Board or committee minutes
  • Policies and internal guidance
  • Staffing and organisational structure
  • Complaints and performance figures

These are cautious suggestions based on what organisations of this kind usually do. They are not a statement that this organisation holds these records.

    Categories
    Policies and GuidanceResearch and ReportsInvestigations and EnforcementStatistics and PerformanceFinance and SpendingProcurement and ContractsInformation SystemsRegisters and Databases

    What the CMA disclosed

    Partially disclosedInformation Asset Register suppliedInternal FOI procedure suppliedSome information withheldInternal review available

    The Competition and Markets Authority disclosed a substantial redacted extract from its Information Asset Register and its internal Freedom of Information procedure. The disclosure identifies approximately 141 named information assets across nine organisational areas. However, the CMA withheld the complete register, system names, asset purposes, search capabilities and Information Asset Owner job titles under sections 31(1)(a) and 31(1)(g) of the Freedom of Information Act, citing cybersecurity and operational risks.

    FOI reference
    IAT/FOIA/1816
    Request submitted
    24 July 2026
    Response issued
    17 August 2026
    Response status
    Partially disclosed
    Named assets in the extract
    ≈141
    Organisational areas
    9
    FOI coordinating team
    Information Access Team / Information Governance Team
    Internal review deadline
    40 calendar days from the date of the response
    FOI email

    InformationGovernanceTeam@cma.gov.uk

    Internal review email

    internalreview@cma.gov.uk

    CMA target for reviews: 20 working days.

    Organisational areas in the disclosure

    These figures count the rows visible in the redacted extract supplied by the CMA. They are not necessarily the complete Information Asset Register.

    • Legal Service54 assets
    • Corporate Services34 assets
    • Strategy, Communications and Advocacy16 assets
    • Office for the Internal Market and Subsidy Advice Unit11 assets
    • Digital Markets Regulation8 assets
    • Consumer Protection6 assets
    • Data, Technology and Insights5 assets

      Plus two rows where the asset title was omitted from the extract

    • Competition Enforcement4 assets
    • Office of the Chief Economic Adviser3 assets

    Information assets

    Every row below is transcribed from the redacted register extract. The CMA disclosed the asset title, the responsible directorate and the retention or disposal rule. It withheld system names, asset purposes, asset owner job titles and search capability.

    Showing 25 of 141 matching assets (141 transcribed in total).

    Two further Data, Technology and Insights rows were visible in the extract but did not contain an asset title.

    Retention and disposal

    Different assets are kept for different lengths of time.

    • Destroy after 2 years

      Some website, blog, media and communications material, measured from the date the record was last modified or published.

    • Destroy after 6 years

      Many financial, payroll, commercial and procurement records, measured from the end of the financial year, the end of a contract or the date the record was last modified.

    • 6 years — destroy or review

      Freedom of Information, Environmental Information Regulations, data protection and information-governance records generally carry six-year retention or review periods.

    • Review after 10 years

      Consumer, intelligence, enforcement, subsidy-advice and digital-market records are commonly reviewed ten years after the record was last modified.

    • Review after 15 years

      Litigation files, information-law legal advice and counsel's opinions are commonly reviewed fifteen years after the record was last modified.

    “Destroy” and “Review” mean different things. A destroy rule sets the point at which a record is due for disposal. A review rule means the record is reassessed at that point and may be kept for longer. A retention period ending does not mean a record has automatically been deleted.

    How the CMA handles FOI requests

    1. 1Request received by the Information Access Team.
    2. 2Request allocated to the directorate or team believed to hold the information.
    3. 3The responsible team searches its records and drafts a response.
    4. 4The responsible team is expected to return the draft by day 15.
    5. 5Delays are escalated to senior information-governance management.
    6. 6The Information Access Team reviews the draft and applies redactions.
    7. 7Legal advice may be obtained from the Information Law Team or case lawyers.
    8. 8Senior sign-off is obtained.
    9. 9The response is issued.
    10. 10The request is closed on SharePoint.

    Who does what

    Information Access Team
    Daily administration, allocation of requests and issuing responses.
    Responsible directorate
    Searches records and drafts the response.
    Information Law Team
    Legal advice, internal reviews and complaints to the Information Commissioner.
    Head of Data Governance and Privacy
    Oversight and response sign-off.
    Legal Director of Governance, Compliance and Risk
    Internal-review and Information Commissioner sign-off.
    Litigation Unit
    Tribunal and court proceedings.
    Evidence: Confirmed by FOI IAT/FOIA/1816

    Where the CMA searches

    • SharePoint
    • Personal drives
    • Shared drives
    • Google Drive
    • Gmail
    • Outlook
    • Microsoft Teams chats
    • Teams recordings
    • Work mobile-phone recordings
    • Paper files
    • Off-site file stores
    • Sound and video recordings
    • Handwritten notes
    • Notepads
    • Post-it notes

    FOI applies to recorded information, not only formal reports. Relevant information may be held in emails, chats, recordings, paper files or handwritten notes.

    Internal handling revealed

    From the CMA's internal FOI procedure, version 3.0

    • The Press Office is notified about requests from journalists and campaign groups seeking publicity for their causes.
    • For higher-profile requests, the Press Office should be informed immediately.
    • The Press Office should receive the final draft response several days before it is issued.
    • The procedure says the requester's identity should not be shared with the Press Office as part of the normal notification.
    • The Executive Office and Press Office are notified when completed responses are issued.
    • The Chief Strategy and External Affairs Officer must be informed immediately about every data, technology and AI-related request, regardless of the requester.

    The procedure does not say that the Press Office decides what is disclosed. Decisions and sign-off sit with information-governance and legal roles.

    Cross-government coordination

    The internal procedure confirms that the Cabinet Office shares a spreadsheet of ‘Round Robin’ FOI requests submitted to more than one government department by the same requester. For many of these requests, the Cabinet Office may offer advice about how they should be handled and which exemptions should be applied to promote a consistent approach across government.
    CMA internal FOI procedure, disclosed under FOI IAT/FOIA/1816
    • The CMA checks whether a request appears on the Cabinet Office list.
    • The CMA notifies the Cabinet Office when it receives a listed request.
    • The CMA can notify the Cabinet Office about a new request it believes may be a Round Robin.
    • Cabinet Office advice is circulated to the responsible CMA team.

    PublicAudit note. Cross-government coordination may promote consistency, but each authority remains legally responsible for determining what information it holds, conducting adequate searches and applying exemptions to its particular circumstances.

    What the CMA withheld

    ✕ Withheld information

    • Complete Information Asset Register
    • Information Asset Owner job titles
    • System and database names
    • System and asset purposes
    • Maintaining business area details
    • Whether assets are electronically searchable
    • Whether authorised staff can search them

    Exemptions cited

    • Section 31(1)(a) Prevention or detection of crime

      A qualified exemption allowing information to be withheld where disclosure would be likely to prejudice the prevention or detection of crime.

    • Section 31(1)(g) Exercise of regulatory and enforcement functions

      A qualified exemption covering prejudice to the exercise of a public authority's regulatory or enforcement functions.

    • Section 40(2) Personal data of staff below Senior Civil Service level

      An exemption for third-party personal data where disclosure would breach data-protection principles.

    The CMA's position. The CMA argues that disclosing a comprehensive picture of its systems and information architecture could assist malicious actors, increase the risk of cyberattack and disrupt systems supporting its regulatory and enforcement work.

    PublicAudit assessment

    PublicAudit commentary — not part of the CMA's official response

    The CMA has provided a useful and substantial disclosure. The asset titles, responsible directorates and retention rules significantly improve public understanding of the information it holds.

    However, the application of sections 31(1)(a) and 31(1)(g) appears broad. The response does not clearly distinguish genuinely security-sensitive technical information from non-technical information such as an Information Asset Owner's job title, a general description of an asset's purpose or confirmation that authorised officials can search it.

    A job title, high-level purpose or basic searchable/non-searchable indicator does not necessarily reveal system architecture, access credentials, security controls or vulnerabilities. A more granular disclosure could potentially protect sensitive technical details while still improving public accountability.

    Internal review options

    You can ask the CMA to review this response. Send a request to internalreview@cma.gov.uk within 40 calendar days from the date of the response. Potential grounds:

    1. The prejudice claimed under section 31 is described generally rather than being linked to each category of withheld information.
    2. The CMA should conduct a granular assessment instead of withholding all requested details together.
    3. Information Asset Owner job titles may not expose technical architecture or security arrangements.
    4. General asset purposes could be disclosed without identifying software products, versions, configurations or vulnerabilities.
    5. A searchable/non-searchable indicator could potentially be disclosed without explaining how searches are conducted.
    6. The public-interest test should give greater weight to accountability for public information, regulatory power and records management.
    7. The CMA should disclose any reasonably separable non-sensitive information.
    Draft an internal review

    Source documents

    Data quality and limitations

    • The supplied register is a redacted extract and may not represent every CMA information asset.
    • Approximately 141 named assets were visible in the extract.
    • Two additional Data, Technology and Insights rows appeared without asset titles.
    • Repeated titles such as “Stakeholder engagement” may represent separate assets owned by different functions.
    • The CMA's original wording is preserved; only obvious spelling slips are tidied in display labels.
    • No system names, software platforms, asset owners or search capabilities are invented — the CMA withheld those details.

    Mapping progress

    1. 2026-07-24
      Mapping request sent
    2. 2026-08-17
      Response received

      FOI IAT/FOIA/1816 (17 August 2026) — partially disclosed. The CMA supplied a redacted Information Asset Register extract listing approximately 141 named assets across nine organisational areas, plus its internal FOI procedure (v3.0). System names, asset purposes, Information Asset Owner job titles and search capability were withheld under sections 31(1)(a) and 31(1)(g), with section 40(2) applied to junior staff personal data.

    Something look wrong?

    Contact details and responsibilities can change. If you spot outdated information, please let us know.

    Report incorrect information