The UK directors’ information request protocol is a cornerstone of effective board governance, ensuring directors receive the information necessary to fulfil their statutory duties while protecting the company’s interests. Balancing legal compliance and confidentiality is increasingly complex in today’s regulatory environment, especially when board dynamics are strained or sensitive data is involved. This guide offers practical, up-to-date steps for boards and company secretaries handling director information requests, with a focus on UK legal requirements, best practice, and real-world scenarios.
Understanding Directors’ Rights to Information
Under the Companies Act 2006, UK directors have a legal right to access company information needed to discharge their duties. This right extends to books, accounts, minutes, and other documents relevant to their functions. However, it is not an unlimited entitlement: requests must relate to the director’s responsibilities, and there are important carve-outs—such as legal privilege, data protection, and confidentiality agreements—that can restrict access.
Boards should establish a formal protocol to assess each request’s legitimacy and scope. This not only preserves boardroom discipline and trust, but also demonstrates that the company is acting consistently and in good faith toward all directors.
What Information Can Be Shared?
Director information requests are judged on their relevance and necessity. Legitimate requests often cover:
- Board minutes, agendas, and resolutions
- Management accounts, financial statements, and audit reports
- Key legal documents, major contracts, and regulatory submissions
- Strategic business plans, risk registers, and insurance documents
- Board correspondence and communications relevant to governance matters
Nonetheless, some information may be legitimately withheld or redacted. For example, solicitor-client privileged communications, sensitive employee data, and material related to ongoing disputes or whistleblowing investigations should be handled with particular caution. Boards are strongly advised to obtain legal and compliance guidance when considering the boundaries of disclosure and redaction. For further reference, see legal and compliance guidance.
Who Approves Director Information Requests?
To ensure clarity and reduce the risk of disputes, all director information requests should follow a defined approval route. Typically, the process involves:
- A written request from the director, clearly stating the purpose and the information sought
- Initial review by the company secretary or governance officer to confirm scope and legitimacy
- Consultation with legal counsel if privileged, contentious, or sensitive information is involved
- Final approval from the board chair or a designated board or governance committee, with conditions or limitations as appropriate
- Comprehensive documentation of the request, decision, and any rationale or restrictions in the board minute book
Codifying this process in a board protocol or terms of reference is best practice. This guards against ad hoc decision-making and supports future consistency. For companies seeking to enhance their governance frameworks, specialist corporate company secretarial services can assist with process design and implementation tailored to your organisation’s structure and sector.
Safeguarding Privilege and Confidentiality
Protecting legal privilege and maintaining confidentiality are vital, especially during periods of heightened scrutiny or boardroom tension. Directors should be briefed on the distinction between general company documents and those protected by legal privilege or subject to regulatory restrictions. For example, in a recent UK High Court case, a director’s demand for access to privileged material during a board dispute was rejected, with the court emphasising the need to balance transparency with the company’s right to protect its legal position.
When dealing with information requests:
- Clearly mark privileged or confidential documents and limit access to those with a genuine need to know
- Redact sensitive content rather than withholding entire documents where possible
- Record all disclosures, including rationale for redaction or refusal, to demonstrate compliance with statutory and fiduciary duties
- Keep protocols under regular review with legal advisers to ensure ongoing compliance with UK law
Failing to respect privilege could undermine the company’s legal position and expose directors to personal liability. Boards must also observe data protection rules when handling personal or confidential information in response to director requests.
Navigating Conflicts and Disputes: Practical Scenarios
Information requests often become most challenging when boardroom relationships are strained or when there is a risk of litigation. For example, if a director facing removal seeks access to documents relating to their own conduct, or in cases of internal whistleblowing or shareholder activism, the board must carefully assess whether fulfilling the request could prejudice the company or breach confidentiality.
Best practice in contentious scenarios includes:
- Seeking independent legal advice before granting or refusing access to contested information
- Recording the reasons for decisions in detail, ensuring transparency and accountability
- Escalating contentious decisions to the full board or an independent subcommittee if a material conflict of interest exists
- Applying the UK directors information request protocol consistently to all directors, regardless of circumstances
Several recent UK board disputes have highlighted the risk of ad hoc responses: inconsistent handling of requests can fuel litigation and regulator interest. Robust, documented protocols and independent oversight are essential to reduce legal and reputational risks.
Integrating Financial Governance and Risk Management
Director information requests frequently intersect with financial oversight, audit, and risk management. Requests for detailed financial or tax data should be considered in the context of the company’s risk appetite and statutory reporting duties. Using a structured tax risk register framework enables directors and finance teams to identify sensitive areas, mitigate disclosure risks, and ensure appropriate sign-off before sharing financial data.
Regular reviews of governance frameworks, involving audit and risk committees, help ensure that the UK directors information request protocol remains robust and responsive to regulatory change and evolving business risks. This continuous improvement approach is central to effective boardroom practice.
Conclusion
Implementing a structured, clear UK directors information request protocol is essential for any board aiming to balance transparency with the protection of privilege and commercial interests. By codifying processes, defining approval routes, and maintaining vigilance over sensitive disclosures, boards reinforce compliance and strengthen trust among directors. For tailored support, expert advisers can help boards adapt protocols to the unique needs of their business, sector, and risk profile—ensuring good governance and legal protection in a challenging regulatory landscape.

