FOI reference: FOI-2026-3668

You asked

For the purposes of this request, "temporary overseas working" means an employee who is ordinarily based in the UK being authorised to perform their normal duties remotely from another country. Please exclude official overseas postings, diplomatic postings and ordinary international business travel.

1) Does your department permit UK-based employees to work temporarily from locations outside the UK? If yes, please confirm whether employees are required to: 

a. Notify the department before working from outside the UK

b. Obtain formal approval before working from outside the UK

2) At the date of this request, has your department approved any arrangements allowing UK-based employees to work temporarily from another country at any point between 1 May and 30 September 2026? If yes, and where the information is centrally recorded and can be provided within the appropriate cost limit (please note: if providing this additional information impedes upon your ability to provide data for question 3, please prioritise question 3), please provide: 

a. The number of approved arrangements covering any part of this period. 

b. A list of the destination countries covered by those approved arrangements. 

If the number of approved arrangements or the destination countries are not centrally recorded, please confirm this. 

Please provide aggregated information only. I am not requesting employee names or any other personal information.

3) At the date of this request, please state whether each of the following controls/measures are in place for employees authorised to work temporarily overseas using departmental endpoints such as laptops, mobile phones or tablets. Please answer Yes, Partially, No, or Information not held for each control (where the answer is "Partially", please provide a brief, high-level explanation). 

  • Centralised mobile or unified endpoint management 

  • Full-disk encryption on department-managed endpoint devices 

  • Multi-factor authentication for access to departmental systems, applications or data from endpoint devices 

  • Conditional-access controls that restrict access where a device does not meet the department's security or compliance requirements 

  • Ongoing identity assessment used to support a Zero Trust access model 

  • Endpoint Detection and Response or Extended Detection and Response capabilities 

  • Automated deployment of operating-system and application security patches to endpoint devices 

  • Controls that restrict or adapt access according to the country or geographical location from which a user or device connects 

  • Data-loss-prevention controls designed to prevent sensitive departmental data from being copied, downloaded, transferred or otherwise removed from managed endpoint devices without authorisation 

  • The ability to remotely lock or erase a managed endpoint device 

  • Continuous or scheduled monitoring of endpoint-device compliance with departmental security policies. 

  • A requirement for employees working overseas to use a department-managed device rather than a personal device

I am requesting confirmation of whether these categories of control are in place. I am not requesting product names, software versions, configuration details, network architecture, security thresholds, vulnerabilities or other operational information that could compromise departmental security.

We said

Thank you for your request.  

In most instances where our staff are granted permission to work aboard, this is to undertake their official duties for the organisation, such as engagements with another statistical organisation, international development with Foreign, Commonwealth and Development Office (FCDO) and partner countries or representing the Office for National Statistics (ONS) internationally.

Staff are usually not permitted to work abroad while traveling for personal reasons.

We understand from your request that you are interested in instances of "temporary overseas working". The information provided in this response therefore does not relate to ordinary international business travel, and instead provides information relating to the very rare circumstances somebody may be permitted to work from abroad to undertake critical business operations under extenuating personal circumstances. 

Outside of these granted exceptions staff are prohibited from working outside the UK and there are technical controls in place so equipment cannot be used aboard. 

1a) Yes. International Remote Working is not permitted as standard within the ONS, but exceptions to this are considered for colleagues where there is a specific business requirement or within extenuating personal circumstances, for example, in situations where a family member has a critical illness. 

Appropriate governance is applied whereby colleagues are required to formally apply for such a consideration with approval required by Senior Management and an independent panel of experts who consider wider implications, such as: security, IT, Health and Safety, legal and payroll.

If the application is successful the independent panel agree the time period based on the personal circumstances contained within the application, with a maximum of four weeks permitted.

To mitigate security risks when working abroad, the panel may apply proportionate controls, including restricting access to higher-classification data where justified by risk assessment.

1b) Yes.

2a) There were 13 approved arrangements through this defined period. 

2b) The list of destination countries for this period are centrally recorded. The list of the destination countries are: 

  • United States of America

  • South Africa

  • Greece

  • Spain

  • Belgium

  • Germany  

  • Denmark 

  • France 

  • Hungary 

  • Cyprus

3) The information you have requested contains very specific details about the security controls for our devices. Knowledge of this specific information would allow a malicious actor to identify and exploit possible vulnerabilities. Disclosure of this information would therefore increase the risk of a targeted and successful attack on our systems. As such, disclosure would prejudice the prevention or detection of crime and the exemption found under s.31(1)(a) of the Freedom of Information Act 2000 (FOIA) is engaged.

This exemption is subject to a public interest test. We recognise that releasing this information would aid transparency and accountability of the ONS, particularly regarding the security of the data we hold. However, we see greater value in the inherent public interest in crime prevention. The ONS holds a large number of records containing sensitive personal information about business and individuals, and we take our duty to safeguard this information very seriously. There is a strong public interest in preventing the disclosure of any information that would increase the possibility of a successful attack, which has the potential to cause emotional and financial distress, and a loss of public trust in the ONS. The public interest test falls in favour of withholding this information.