Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·GRI · Disclosure guides

GRI Confidentiality Constraints and Legal Prohibitions: When an Omission Is Defensible

A requirement-level test for evidence, legal review, alternatives and precise Content Index explanations

Who this is for A 9-minute read for reporting teams working through Preparing the GRI Content Index, and for reviewers testing whether the evidence behind it holds.

Short answer

The answer, before the reasoning

A legal-prohibition or confidentiality omission is defensible only when it applies to a specific GRI disclosure or requirement, the restriction is described specifically, and the organisation has tested whether the requirement can still be met through aggregation, anonymisation, ranges, time lag or a narrower non-identifying explanation. Under GRI 1, “legal prohibitions” applies when law forbids collecting the information or reporting it publicly.

“Confidentiality constraints” applies where law does not prohibit reporting but the organisation considers the information confidential and cannot report it publicly. Generic phrases such as “commercially sensitive”, “legally restricted” or “confidential” are not sufficient explanations.

Working edition · 1 August 2026

Rule

GRI-IDX-004

<p>GRI Confidentiality Constraints and Legal Prohibitions: When an Omission Is Defensible A requirement-level test for evidence, legal review, alternatives and precise Content Index explanations</p>

In practice

Type

Type Tier Audience — Current context
Technical guide / decision log Tier 4 · Expert Note Reporting teams, legal counsel, data owners, reviewers and assurance practitioners — GRI 1 Requirement 6 and GRI 2/3 omission restrictions checked to 1 August 2026

Why this is a high-risk judgement

The two reasons can protect legitimate interests, rights and legal obligations. They can also be misused to hide poor performance, unresolved grievances, adverse impacts or uncomfortable governance information. That is why the decision should be narrower than the topic and supported by a review trail.

The question is not whether the topic is sensitive. The question is whether the exact required information cannot lawfully or responsibly be collected or reported publicly, and whether an alternative presentation can satisfy the information need without creating the prohibited or confidential exposure.

The four-part GRI test

1. Identify the exact disclosure or requirement that cannot be met. Do not omit an entire Topic Standard when only one sub-requirement is affected.

2. Choose one permitted reason for omission and apply the GRI definition. Legal prohibition and confidentiality constraint are not interchangeable.

3. Provide the required specific explanation in the GRI Content Index.

4. Report all remaining information that can be disclosed, and ensure the omission is not being used where GRI 1 does not permit reasons for omission.

In practice

Legal prohibition, confidentiality and commercial sensitivity

Situation GRI classification Evidence expected — What not to do
Law forbids collecting the required information. Legal prohibitions Specific legal provision, jurisdiction, prohibited collection act, affected requirement and counsel confirmation. — Do not collect the data merely to satisfy reporting if collection itself is unlawful.
Law permits collection but forbids public reporting. Legal prohibitions Specific publication restriction, scope, duration and affected information. — Do not cite “privacy law” generically where aggregated disclosure is lawful.
Law does not prohibit reporting, but public disclosure would breach a specific confidentiality constraint. Confidentiality constraints Nature of the constraint, protected party/information, factual basis, alternatives tested and authorised decision. — Do not equate an internal preference or reputational concern with inability to report publicly.
Information is commercially sensitive but a range or aggregation is feasible. Usually no full omission; report the defensible alternative or identify any residual missing requirement. Competitive-harm analysis, aggregation test and review of whether the requirement is still met. — Do not use “commercially sensitive” as a complete Content Index explanation.
Information is unavailable, poor quality or incomplete. Information unavailable / incomplete, not confidentiality. Missing part, reason, steps and expected timeframe. — Do not relabel a data gap as confidentiality.
The policy, committee or process does not exist. Report that it does not exist; this is not automatically not applicable or confidential. Owner confirmation and any development plan. — Do not hide absence behind an omission reason.

Where reasons for omission are not permitted

GRI 1 does not permit reasons for omission for GRI 2-1 through GRI 2-5 or for GRI 3-1 and GRI 3-2. An organisation reporting in accordance must report those disclosures. Legal and confidentiality review must therefore focus on how to provide the required information without unlawful detail, or whether the organisation can support an in-accordance statement at all.

Figure 1. The defensible omission test separates a specific legal prohibition or confidentiality constraint from ordinary sensitivity or discomfort.

Rule

IMPLEMENTATION PRACTICE

<p>GRI 1 requires a specific explanation but does not prescribe an internal legal memo format. The evidence threshold below is London Reporting Academy implementation guidance for a defensible, reviewable decision.</p>

In practice

Evidence threshold: an LRA review model

Evidence component Legal prohibition Confidentiality constraint
Authority Exact law, regulation, order or binding public-law restriction. Contractual, privacy, safety, security, fiduciary or other specific confidentiality basis.
Affected act Collection, internal processing or public reporting that is prohibited. Public disclosure that would expose protected information or breach a concrete obligation.
Affected requirement Exact GRI disclosure and sub-requirement. Exact GRI disclosure and sub-requirement.
Scope and duration Jurisdiction, entities, data subjects, dates and any expiry or review condition. Parties, information class, geography, duration and conditions for release.
Alternatives tested Aggregation, anonymisation, non-identifying narrative, ranges and delayed publication. The same alternatives plus consent, redaction and separation of public/restricted evidence.
Decision and approval Counsel view, reporting owner recommendation and authorised approval. Information owner, legal/privacy/security review and authorised approval.
Residual disclosure All information that remains lawful to report. All information that remains possible without breaching the constraint.

In practice

Alternatives to a complete omission

Alternative When useful Control question
Aggregation Entity, country, product or case-level detail is sensitive but totals remain meaningful. Does aggregation still meet the required scope and avoid concealing significant variation?
Ranges or bands A precise amount creates competitive or identification risk. Does the requirement allow a range, and is the band narrow enough to be useful?
Anonymisation or redaction Individuals or counterparties could be identified. Has re-identification risk been tested, including small populations and linked datasets?
Time lag A current negotiation or market-sensitive event is temporary. Is delayed disclosure legally and technically acceptable, and when will the position be reviewed?
Qualitative narrative Quantitative detail is restricted but the nature, process and impacts can be explained. Does narrative genuinely satisfy the requirement or only provide additional voluntary context?
Public summary plus restricted evidence Assurance or internal review needs access to records that cannot be published. Is the public requirement still met, and are restricted-access controls documented?

Readiness

Legal-review checklist

  • The reviewer has the exact current GRI requirement, not only the disclosure title.
  • The legal or confidentiality basis is identified precisely, including jurisdiction and affected act.
  • The restriction applies to the information GRI requests, rather than to a more detailed dataset that GRI does not require.
  • Aggregation, anonymisation, ranges, time lag and non-identifying narrative have been tested.
  • The risk to affected people, complainants, workers or rights-holders is considered, not only commercial harm to the organisation.
  • The omission does not cover information for which GRI 1 prohibits reasons for omission.
  • The explanation can be published without itself revealing the protected information.
  • The decision has an owner, approver, review date and trigger for reassessment.
  • The assurance provider or technical reviewer can access sufficient restricted evidence where appropriate and lawful.

In practice

Decision log template

Field Record
Decision ID Unique omission decision and reporting period.
GRI reference Standard, disclosure and exact requirement.
Information affected Specific data or narrative that cannot be reported.
Proposed reason Legal prohibitions or confidentiality constraints.
Specific basis Law/constraint, jurisdiction, scope and duration.
Alternatives tested Aggregation, range, anonymisation, time lag, narrative and other options.
Residual disclosure Information that will still be reported and exact location.
Risk assessment Risk of disclosure, risk of omission and stakeholder consequences.
Review and approval Legal/privacy/security owner, reporting owner and final approver.
Content Index wording Requirement-level reason and explanation.
Review trigger Change in law, expiry of constraint, new consent, improved aggregation or next reporting cycle.

Hypothetical case: grievance information

A hypothetical infrastructure company is asked to report information about grievances connected to a material community-impact topic. Several open cases involve a very small community, and detailed case outcomes would identify complainants and expose them to retaliation risk. The company first tests aggregation across locations and a high-level description of the process, categories and remediation progress. It reports those elements. For one numerical breakdown that would still enable identification, it records a confidentiality constraint at the exact requirement level, explains the re-identification and safety constraint, retains restricted evidence for legal and assurance review, and sets a review trigger when the cases close.

In practice

Weak versus stronger omission wording

Weak wording Why weak Stronger illustrative pattern
Omitted for confidentiality. No requirement, constraint or scope is identified. GRI [x-y-z] [requirement] - confidentiality constraints. The organisation has not reported [specific information] because [specific protected interest/constraint]. Aggregated information covering [scope] is reported at [location].
Data cannot be disclosed for legal reasons. Does not identify the law or whether collection or publication is prohibited. GRI [x-y-z] [requirement] - legal prohibitions. [Jurisdiction/instrument] prohibits [collection/public reporting] of [information] for [scope].
Commercially sensitive. Sensitivity may be manageable through aggregation or range reporting. The organisation tested [alternatives]. [Alternative] is reported; only [residual item] remains omitted because [specific constraint].
Information is confidential and unavailable. Combines two different permitted reasons and obscures the real problem. Use one reason for each missing requirement and provide the explanation required for that reason.

Common mistakes

Using one confidentiality statement for an entire Topic Standard or report section.

Citing a non-disclosure agreement without checking whether the GRI requirement can be met at an aggregated level.

Treating reputational damage from poor performance as a confidentiality constraint.

Using legal prohibition where the law actually permits aggregated reporting.

Failing to distinguish a temporary negotiation from a permanent public-disclosure restriction.

Providing detailed legal advice in the public Content Index instead of a precise but safe explanation.

Leaving the omission in place every year without a review trigger.

Using confidentiality frequently, despite GRI guidance that confidentiality and unavailable-information reasons should be exceptional.

Myth

Management can label any commercially sensitive information confidential and omit it from an in-accordance report.

Reality

The organisation must identify the exact affected requirement, describe the specific constraint and test whether a less revealing presentation can still meet the requirement. The reason is not a licence to suppress unfavourable information.

Readiness

Final defensibility checklist

  • Exact requirement identified.
  • Permitted reason selected correctly.
  • Specific legal or confidentiality basis documented.
  • Scope and duration defined.
  • Alternatives tested and recorded.
  • Residual information reported.
  • Stakeholder and rights-holder risks considered.
  • Approvals and restricted evidence retained.
  • Content Index explanation is precise and safe.
  • Review trigger and owner assigned.

Self-check

  1. What exact act is prohibited or constrained: collection, processing or public disclosure?
  2. Could aggregation or anonymisation satisfy the same GRI requirement?
  3. Would the organisation still omit the information if the result were favourable?
  4. When and by whom will the decision be reconsidered?

In practice

Related standards and next learning steps

Relation Reference Why it matters
Direct GRI 1 Requirement 6 Defines permitted reasons and required explanations.
Publication GRI 1 Requirement 7 Requires reasons for omission in the GRI Content Index.
Restriction GRI 2 introduction and GRI 3 introduction Identifies disclosures for which reasons for omission are not permitted.
Comparison Partial GRI Disclosures Explains requirement-level gaps and incomplete information.
Evidence GRI Evidence Pack Retains legal analysis, decision logs, alternatives and approvals.

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · GRI

GRI Standards Certified Training

A full reporting cycle with a mentor: impact inventory, threshold, Topic Standard selection, Content Index and assurance readiness.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See course formats
/en/knowledge-hub/disclosure-guides/gri/gri-content-index/gri-confidentiality-constraints-and-legal-prohibitions-when-an-omissio/