Home · Solutions · Legal & compliance
Solution · Legal & complianceFour intake channels, eleven units, one register that closes with the answer
Information requests answered inside the statutory clock
Requests are registered from every channel, the deadline is computed, units are asked for named documents in Teams, and personal data is highlighted for a clerk to confirm before release.
Executive summary
Requests arrive on four channels, the clock starts on all of them, and the register is written afterwards.
We build a single intake for a duty that currently has four.
The collection round stops being elapsed time: units are asked on the day of intake, with documents named and a date attached.
the electronic document management system; a Microsoft SharePoint case library; the publication queue for the office's site
Business problem
Access to information
Anyone may ask a public body for information, and the body answers. It does not choose which requests to take, cannot ask why the information is wanted, and owes the same answer to a resident, a journalist, a law firm and a contractor's competitor. The duty cannot be prioritised away.
Requests do not arrive at one place. Some reach the published e‑mail address, some the electronic mailbox used for registered delivery, some the registry on paper, a few the form on the office's site. Each channel is opened by a different person, and each decides without a written test whether the item is a request. The clock starts either way; the register entry starts when somebody writes it.
The work then sits between the registry and the units. A request rarely maps onto one unit, so the clerk guesses which of eleven hold the documents, describes what is needed in their own words and chases. Those e‑mails carry no due date anyone else can see, so the last answer arrives with no time left for the release itself: reading every page, blacking out names, addresses and third-party details. The only later evidence that the reading happened is the redacted file, which proves what was removed and nothing about what was checked.
How it works today
This is the shape we find in most offices before anything is automated.
- PersonFour channels are opened by four people, each deciding on the spot whether an item is a request
- PersonThe request is entered in a register by hand, given a case reference, and its due date worked out on a calendar
- PersonThe clerk e‑mails two or three units describing what is needed, written from scratch each time
- WaitingUnits answer between other duties, and the last answer commonly arrives on the day the response is due
- PersonReturned documents are read page by page and personal data is blacked out in a PDF editor
- Risk of errorA unit that was never asked is discovered only if the requester writes again or appeals
- Risk of errorThe answer goes back on the channel it came in on; the register entry, and any refusal or extension, catch up later if at all
Why the current process costs more than it appears
The most expensive part of this process has no cost line.
- Coordination, not judgement, consumes the month. What may be released takes a lawyer minutes; finding which unit holds the file, asking in words it understands and chasing it takes days.
- Deadlines calculated by hand are the quietest risk in the building. A date on a calendar cannot be checked by anyone else and gives no warning before it passes.
- Equal treatment is asserted rather than evidenced. Two similar requests handled in two units produce two scopes, two redaction standards and two answers, and no record would show it.
- One unmasked identifier in a released document is a disclosure, not a defect the office can quietly correct, and the file that would explain it does not exist.
- Institutional memory is the real dependency. Which unit holds what, and what was withheld last time, sits with two long-serving clerks whose leave is visible in the response times.
Cost of inaction
Growth in this queue does not originate in the office. One decision published in the bulletin, one local dispute or one requester who writes every fortnight can hold volumes at a new level for a quarter, and nothing in the establishment plan moves to meet it.
What compounds is evidential rather than financial. An office that cannot show which units were asked, which pages were checked and how the date was calculated is not defending a decision; it is defending a recollection. That is a weak position in front of an appeal and a worse one in front of an auditor.
A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.
A city office of about 380 staff in eleven organisational units, with subordinate entities under the same duty; Microsoft 365 in daily use, correspondence in an electronic document management system, a legal unit of three.
140 requests for public information a month; roughly 55% by e‑mail, 25% through the electronic mailbox, 15% on paper and 5% on the office's own form; about a third need documents from more than one unit.
Registration by hand into a spreadsheet, deadlines on a calendar, collection by e‑mail, redaction in a PDF editor, a signed answer on the channel of origin. Refusals and extensions are drafted by the legal unit and filed wherever the drafter files them.
About 95 minutes per request across three desks, most of it in the collection round rather than in any decision, plus the cases needing a second round because the first ask was incomplete.
One queue and one register for every channel; the due date computed from the office's own rule table; a collection task per unit in Microsoft Teams naming documents and date; returned files highlighted for personal data and confirmed by a clerk; answer, documents and register entry produced in one step.
In the modelled case the collection round stops consuming elapsed time, the register is complete on the day of intake, and clerks spend their minutes confirming rather than assembling. The figures describe a model of this office, not a measurement of any office.
Proposed solution
We build a single intake for a duty that currently has four. Mail from the published address, items from the electronic mailbox, scans from the registry and web-form submissions land in one Orchestrator queue with their original document, timestamp and channel preserved. A project-specific extraction model proposes what is being asked for and which units are likely to hold it. A clerk confirms that proposal, and only then does a register entry exist, with a case reference and a due date computed from the office's own rule table.
Collection becomes a task rather than an e‑mail. Each named unit receives a card in its Microsoft Teams channel listing the documents, the date and the library to upload to. The card is a UiPath Action Center task, so it has an owner, a due date, a reminder nobody has to send, and an escalation to the head of unit before the deadline.
Redaction is assisted, never unattended. Returned documents pass through a Document Understanding model trained on the office's own material, which highlights candidate personal data page by page. The highlights arrive in Validation Station; a clerk confirms them, adds what was missed and drops what was flagged wrongly, and only a confirmed highlight reaches a released file. Answer, documents, register entry and, where the office's procedure requires publication, a package for the site are assembled from one case file and signed off in Microsoft Teams. Refusals and extensions run the identical path.
UiPath Document Understanding project-specific models and Validation Station; UiPath Orchestrator queues, time triggers, credential stores and audit; UiPath Action Center actionable notifications in Microsoft Teams; Microsoft Teams Approvals app with Microsoft Purview audit; Microsoft SharePoint libraries with versioning and retention labels
The four-channel intake and deduplication, the register and case reference logic, the deadline rule table and its triggers, the unit routing rules, the collection task and reminder flow, the redaction model and its confirmation step, and the answer and publication assembly
The electronic document management system through the API its supplier provides, or a monitored export folder where none is exposed; the publishing queue for material the office's procedure requires to be published. Where the office runs EZD RP, NASK states that the system offers an API
How the automated process works
- AutomationItems from the published mailbox, the electronic mailbox, the registry scanner and the web form enter one queue with channel, timestamp and original attached
- AutomationThe extraction model proposes the subject, the units likely to hold the documents and the reply channel; duplicates and follow-ups join an existing case
- PersonA clerk confirms or corrects the proposal in Microsoft Teams, and the register entry, case reference and due date are created from the rule table
- AutomationEach named unit gets a collection task in its Teams channel with the documents listed and the date needed; reminders and escalations run on the clock
- AutomationReturned files are checked against what was asked for, and the redaction model highlights candidate personal data page by page
- PersonA clerk confirms every highlight, and the head of unit signs the answer, refusal or extension in Microsoft Teams
- AutomationAnswer, documents and register entry are produced together and returned on the channel of origin; a Power BI view shows open cases and days remaining
Human-in-the-loop model
Automation handles
- Intake from every channel, deduplication, the register entry, the case reference and the deadline from the rule table
- Collection tasks to the named units, with reminders and escalation before the date
- Completeness checks against what was asked for, and the first pass of redaction as highlighted candidates
- Assembly of the answer, the released files, the register entry and the publication package
People decide
- Whether an item is an information request at all, and what it actually asks for
- What may be released, what must be withheld and on what ground
- Every redaction: nothing is removed until a named person confirms that highlight
- Whether a case ends in an answer, an extension or a refusal, and who signs it
Before and after
Systems and integrations
Every entry can be checked in vendor documentation. The evidence class is stated next to each one.
Inputs
- the office's published e‑mail address
- the electronic mailbox for registered delivery
- scans from the registry
- the office's own request form
Automation layer
- UiPath Orchestrator
- UiPath Robots
- UiPath Document Understanding
- UiPath Action Center
- UiPath Integration Service
Target systems
- the electronic document management system
- a Microsoft SharePoint case library
- the publication queue for the office's site
- Power BI
Human touchpoints: collection tasks in Microsoft Teams; redaction confirmation in Validation Station; sign-off in the Microsoft Teams Approvals app
Technologies used
project-specific models read the request and highlight personal data in returned documents; Validation Station carries confirmation
Aone queue for four channels, deadline triggers, retries, credential store and audit record
Acollection tasks and redaction confirmations completed where the units already work
Athe head of unit signs the answer, extension or refusal; the decision lands in the Microsoft Purview audit log
Awatches the published mailbox and files documents into the case library
Athe case file: request, documents, confirmed redactions, answer and trail, under retention labels
Aopen cases, days remaining and unit response times
AIllustrative economic model
The arithmetic is open, so it can be argued with.
Any secretary who keeps a register can produce better inputs than these within a week, and should. Ninety-five minutes covers three desks: the registry entry and the deadline, the coordination round, and the redaction and assembly of the answer. €22 an hour is a fully loaded cost of an administrative post. Nothing here was measured in an office, and the result is released capacity and met deadlines, never savings and never posts removed.
Run the numbers on your data
An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.
Business benefits
- The collection round stops being elapsed time: units are asked on the day of intake, with documents named and a date attached
- Deadlines are computed once from a rule table the legal unit owns, and every case carries its remaining days in one view
- Clerical capacity moves from assembling documents to confirming decisions, the only part of this process a person is needed for
- Equal treatment becomes demonstrable: the same scope questions, the same redaction standard and the same record for every requester
- The register is complete by construction, because answers, refusals and extensions are produced by one flow instead of three habits
The management view
- Deadline compliance stops depending on trust: the secretary sees which cases are near their date and who is holding each
- Capacity becomes visible: how many requests each unit serves, how long it takes, and where a second collection round was needed
- Every case carries its own evidence, so an appeal or an inspection is answered from the file rather than from recollection
- The process survives staff changes, because which unit holds what is written into routing rules
Board-level KPIs
Security and governance
Control is not an add-on.
- No decision here is made by a robot. Robots move documents, check completeness, compute dates and prepare drafts; a named official decides what is released and signs it
- Redaction is applied only to highlights a person has confirmed, and each confirmation is stored with a name and a time
- Robots hold their own accounts with the rights this process needs and no others, secrets stay in the credential store, and application access is scoped to a single mailbox
- Documents and evidence remain in the office's Microsoft 365 tenant under its retention labels, and the execution layer runs in the EU region of UiPath Automation Cloud
- The deadline table, the routing rules and the withholding grounds are versioned, and any change requires sign-off from the legal unit
Why now
Electronic delivery is no longer a pilot channel. A communication of the Ministry of Digital Affairs on 5 August 2026, reproduced by the designated operator's press service, reported more than 100 million items delivered through e-Doręczenia, over 50 million of them since the start of 2026, and 4.6 million addresses in the electronic address database. Requests now arrive on a channel that timestamps itself
The modelled €4,877 a month is capacity the office already spends, on coordination rather than decisions. It scales with the number of organisational units, the one variable an office cannot reduce
Human confirmation of an extraction result is a product feature rather than a development project, and the task arrives in Microsoft Teams, a channel the clerk already has open
Relevant executive roles
Owns deadline compliance across every unit and has no view of it until a date has passed
Gains a queue with dates instead of free-text requests in a mailbox
Gains per-page evidence that personal data was reviewed before release
One auditable integration in place of four channels and a spreadsheet
Common questions and objections
No, and the design makes that impossible. The model highlights candidate personal data and proposes which units to ask; nothing is removed and no answer leaves until a named official confirms and signs. The change is that the confirmation is recorded.
Variety is in the subject, not in the structure. Routing is built from your own closed cases, and where the rules are unsure the clerk is asked rather than guessed at; every correction improves the next case.
It stays. This flow puts a register, a computed deadline and a collection task on top of the correspondence that system already carries, and writes the case reference back where an interface exists.
When this is not the right solution
- Offices receiving a handful of requests a month, where a shared list and a disciplined registry stay cheaper
- Offices with no agreed statement of which unit holds which registers, since the routing rules have nothing to build on; that inventory comes first
- Requests from a person about their own personal data, which run under a different regime and a different clock; that flow uses Microsoft Purview eDiscovery, which this one deliberately does not
A question for the next management meeting
Does this office answer information requests to a rule that is written down and applied the same way to every requester, or to the judgement of whoever happens to open the channel that day?
Implementation approach
Delivery runs in stages, so it can be stopped at any point.
We deliver
- A read of one quarter of your register: channels, subjects and multi-unit share
- The intake and deduplication flow across all four channels, with original document and timestamp preserved
- The deadline rule table built with the legal unit, and the triggers, reminders and escalations that apply it
- The routing rules that turn a subject into named units, built from your structure and your closed cases
- The redaction model trained on your documents, with the confirmation step in Validation Station
- Answer, refusal, extension and publication assembly, the case library on Microsoft SharePoint and the deadline view
We need from you
- One quarter of closed cases with the documents released and the answers sent
- A named owner in the legal unit for the deadline rules and the withholding grounds
- A service account for the mailboxes, the case library and the document system
- Your organisational structure and a first list of which unit holds which registers
Stages
Register review
One quarter of cases read for channels, subjects, units and rework
Rules
Deadline table, routing rules, redaction categories and withholding grounds
Build
Intake, register, collection tasks, redaction model and assembly in your environment
Parallel run
Real requests handled both ways, with clerks comparing scope and dates
Go-live
Controlled start on one subject family, with supervision and daily review
Extension
Further subjects and subordinate entities, model tuning, rules handed over
Departmental. Effort is driven by the number of organisational units routed to, the state of the case history behind the rules, and how consistently personal data appears in the documents released.
The clock starts when the request arrives, not when someone decides it is a request.
Send us one quarter of your register: the channels requests came in on, how many needed more than one unit, and how many ended in an extension. We come back with the rule table your deadline calculation needs and a first read of what the collection round costs.
Take one quarter of your register apartThe neighbouring process usually has the same problem
Gaps in the bulletin are found by a resident, a journalist or an inspector, never by the office itself.
View solution Legal & complianceData-subject requests answered in days, not at the deadlineStop answering GDPR requests by hand on day twenty-eight of a thirty-day clock.
View solution Legal & complianceThe archive that knows what it may destroy and whenCases close, files do not: categories unchecked, transfer lists retyped, appraisal postponed another year.
View solutionIndustries we deliver this in most oftenPublic sector