FOIL Privacy Balancing: Municipal E‑News Subscriber Names and Email Addresses Are Exempt Absent a Public Interest

Matter of Russell v Town of Mount Pleasant, N.Y., 2026 NY Slip Op 00966 (Ct App Feb. 19, 2026) (Rivera, J.)

I. Introduction

Matter of Russell v Town of Mount Pleasant, N.Y. presented a modern FOIL dispute at the intersection of open government, personal privacy, and cybersecurity. The petitioner, James C. Russell, sought under the Freedom of Information Law (FOIL) a list containing the names and corresponding email addresses of all subscribers to the Town of Mount Pleasant’s “E-news” alert system—a municipal one-way email notification service used to distribute Town announcements.

The Town denied disclosure, ultimately relying on FOIL’s privacy exemption on the ground that release would constitute an unwarranted invasion of personal privacy. Supreme Court ordered disclosure subject to non-use conditions similar to those imposed in Matter of Livson v Town of Greenburgh. The Appellate Division affirmed, characterizing the Town’s cybersecurity concerns as speculative. The Court of Appeals granted leave and reversed, holding the Town properly withheld the list.

The case’s central issue: When FOIL seeks a municipal email-subscriber list, how should courts balance subscriber privacy and cybersecurity risks against any public interest in disclosure?

Holding / Rule: Where FOIL’s enumerated privacy categories do not squarely apply, courts must apply the Matter of New York Times Co. v City of N.Y. Fire Dept. balancing test; here, municipal E-news subscriber names and email addresses implicate weighty privacy interests (including risk of unwanted contacts and credible cybersecurity harms), and where disclosure serves no public interest, the list is exempt as an unwarranted invasion of personal privacy under Public Officers Law § 87(2)(b) and § 89(2).

II. Summary of the Opinion

The Court of Appeals held that the Town met its burden to justify withholding. On the privacy side of the balance, the Court emphasized that email addresses coupled with names are commonly treated as personally identifying information and that disclosure exposes individuals to unwanted communications and heightened cybersecurity risks (notably spoofing/phishing leading to account compromise, identity theft, or malware). The Court credited the Town’s evidence: a consent survey in which 218 of 220 respondents refused consent, and an affidavit from the Town’s cybersecurity manager describing realistic threats and the loss of institutional security controls once the list leaves government custody.

On the public-interest side, the Court found essentially none: petitioner’s asserted goal—greater civic engagement—was deemed unlikely to be advanced and potentially undermined if residents fear subscribing. The Court also noted petitioner had alternative avenues (e.g., social media).

The Court concluded the Appellate Division misapplied the balancing test by (i) failing to meaningfully weigh privacy interests and (ii) applying an incorrect “more susceptible than ordinary” standard to cybersecurity risks. It reversed and dismissed the petition.

III. Analysis

A. Precedents Cited

1. FOIL’s presumption of access and narrow construction of exemptions

  • Matter of Gould v New York City Police Dept., 89 NY2d 267 (1996)
    Used to reaffirm FOIL’s broad disclosure duty, the presumption of access, the government’s burden in Article 78, and the principle that exemptions are narrowly construed; also cited for the impermissibility of “blanket exemptions.”
  • Matter of Beechwood Restorative Care Ctr. v Signor, 5 NY3d 435 (2005)
    Invoked for FOIL’s purpose to encourage public awareness, understanding, and participation in government—then used to show why the Court views “public interest” as tethered to governmental transparency, not private outreach objectives.
  • Matter of Data Tree, LLC v Romaine, 9 NY3d 454 (2007)
    Cited for the presumption of disclosure, agency burden, and the redaction principle (records containing private material may still require a redacted release). The Court’s inclusion underscores that it is not creating a categorical rule that all email-related material is exempt; rather, it is deciding that this specific record, in full, fails the balancing test.
  • Matter of Abdur-Rashid v New York City Police Dept., 31 NY3d 217 (2018)
    Cited for FOIL framework and, importantly, for the Court’s practice of consulting federal FOIA precedent when interpreting FOIL— a move the Court uses here to bolster that email addresses have recognized privacy weight under FOIA Exemption 6 analogs.
  • Matter of Town of Waterford v New York State Dept. of Envtl. Conservation, 18 NY3d 652 (2012)
    Reinforces narrow construction of exemptions and agency burden; it anchors the Court’s insistence that, even while exempting this list, the exemption remains a carefully justified deviation from the presumption of disclosure.
  • Matter of New York Civ. Liberties Union v Office of Ct. Admin., — NY3d —, 2025 NY Slip Op 05784 (2025) and Matter of Reclaim the Records v New York State Dept. of Health, — NY3d —, 2025 NY Slip Op 03102 (2025)
    These 2025 decisions are used as contemporary reinforcement of anti-blanket-withholding rules and “particularity and specificity” requirements. They help the Court frame the Town’s showing as specific (consent data + cybersecurity affidavit), rather than conclusory.

2. The privacy balancing test and its application

  • Matter of New York Times Co. v City of N.Y. Fire Dept., 4 NY3d 477 (2005)
    This is the controlling doctrinal tool: when the privacy request does not fit FOIL’s enumerated privacy examples, courts must “balance” privacy interests against the public interest in disclosure. The Court applies this test and finds the balance “squarely” favors nondisclosure.
  • Matter of Hanig v State of N.Y. Dept. of Motor Vehs., 79 NY2d 106 (1992)
    Cited for the proposition that FOIL’s privacy exemption was modeled on FOIA Exemption 6, legitimizing reliance on federal cases treating email addresses as private information.
  • Matter of Lesher v Hynes, 19 NY3d 57 (2012) and Matter of Fink v Lefkowitz, 47 NY2d 567 (1979)
    Both support the practice of using federal FOIA interpretation as persuasive authority where statutory structures align. They form the bridge to the federal district court decisions cited on email addresses as protected personal information.
  • New York Times Co. v Fed. Communications Commn., 457 F Supp 3d 266 (SD NY 2020) and Hall & Assoc. v U.S. Envtl. Protection Agency, 2020 WL 4673411 (DDC Aug. 12, 2020)
    The Court uses these to corroborate that privately held email addresses trigger cognizable privacy interests under FOIA Exemption 6, strengthening the Court’s conclusion that email + name is sensitive enough to weigh heavily on the privacy side of the balance.
  • Matter of Livson v Town of Greenburgh, 141 AD3d 658 (2d Dept 2016)
    This is the key “counterpoint” precedent: Livson ordered disclosure because the town failed to articulate any privacy interest. Russell distinguishes Livson implicitly by emphasizing that Mount Pleasant did articulate and substantiate privacy and cybersecurity harms, and that the public interest asserted here is negligible.

B. Legal Reasoning

1. Doctrinal framework: presumption of access; exemptions narrowly construed; agency bears burden

The Court begins from FOIL’s familiar architecture: disclosure is the rule, withholding is the exception, and the agency must justify the exemption. It reiterates that blanket denials are disfavored and that redaction may be required where partial disclosure is possible. This framing is important: it signals that the Court views the Town’s withholding not as a generalized retreat from FOIL, but as a record-specific application of the privacy exemption.

2. Why the enumerated privacy categories did not control—and why balancing did

Public Officers Law § 89(2)(b) lists examples of privacy invasions, but the Court emphasizes that the list is non-exhaustive and does not expressly cover the requested subscriber list (outside of a tax-purpose provision not applicable). Therefore, the Court turns to Matter of New York Times Co. v City of N.Y. Fire Dept. and applies the balancing test.

3. The privacy side: “weighty” interests in email + name confidentiality

The Court’s privacy analysis has two prongs that together deepen FOIL privacy doctrine for digital-era identifiers:

  • Unwanted contact / intrusion: The Court recognizes a strong interest in keeping contact information private to avoid unwanted communications. This is amplified by the context: individuals subscribed to receive Town communications, not to be contacted by third parties.
  • Cybersecurity risk as a privacy harm: The Court treats exposure to phishing/spoofing and related threats as a real, not speculative, privacy interest. It rejects the Appellate Division’s insistence that the Town show disclosure would make subscribers “more susceptible than they ordinarily would be.” Instead, the relevant question is whether the privacy interest in nondisclosure outweighs any public interest in disclosure.

Notably, the Court supports the “weight” of the privacy interest by (i) analogizing to statutes and rules treating email addresses as sensitive, (ii) crediting the consent survey (218/220 opposed disclosure), and (iii) citing federal FOIA treatment of email addresses under Exemption 6. The Court’s move here is doctrinally significant: it folds cyber-risk into the privacy calculus, treating modern threats as part of what “personal privacy” protects.

4. The public-interest side: disclosure must illuminate government, not merely facilitate private outreach

The Court sharply narrows the “public interest” asserted. Petitioner’s rationale—enhancing civic engagement—was not linked to exposing governmental operations, decision-making, spending, bias, or misconduct. The Court also finds the asserted benefit unlikely, reasoning disclosure may chill subscriptions, reduce uptake, and prompt unsubscribing—undermining access to government information rather than improving it. Additionally, the Court points to alternative channels available to petitioner, suggesting disclosure is not necessary to public discourse.

5. The Court’s critique of the Appellate Division: misapplication of the balancing test

The Court identifies two errors:

  • Failure to engage in balancing: The Appellate Division did not meaningfully discuss the privacy interests or explain how they were weighed.
  • Wrong metric for cyber-risk: By demanding proof that disclosure would increase risk beyond “ordinary” susceptibility, the Appellate Division effectively heightened the government’s burden beyond what the balancing test requires.

C. Impact

1. A practical rule for “subscriber lists” and municipal digital communications

The decision is likely to be cited as the leading New York authority that municipal subscriber lists (names + email addresses) can be categorically protected under the privacy exemption when the requester cannot articulate a meaningful public interest tied to government transparency and the agency supplies a concrete showing of privacy/cyber harms.

2. Cybersecurity enters FOIL privacy doctrine as a first-class consideration

The Court treats spoofing/phishing risk as more than conjecture; it is a foreseeable consequence of disseminating email identifiers. Future FOIL disputes involving digital identifiers (email, phone numbers, handles, device identifiers, login IDs) will likely cite Russell for the proposition that modern cybersecurity realities can materially strengthen the privacy side of the balance—especially where the record facilitates targeting.

3. Narrowing “public interest” for private-contact requests

The decision distinguishes between (a) disclosure that helps the public evaluate government conduct and (b) disclosure that primarily helps the requester contact private individuals. The Court’s analysis signals skepticism toward FOIL requests seeking lists of constituents absent a demonstrable connection to oversight of government operations.

4. Likely effects on municipalities and agencies

  • Agencies may be encouraged to maintain and document subscriber consent practices (as the Town did), and to present qualified IT/cyber affidavits when resisting disclosure.
  • Municipalities may revise sign-up interfaces and privacy notices to clarify whether subscriber information may be subject to disclosure, potentially influencing future balancing.
  • Agencies defending nondisclosure may rely less on “speculation” debates and more on demonstrating foreseeable misuse plus minimal public-interest value.

IV. Complex Concepts Simplified

  • FOIL (Freedom of Information Law): New York’s open-records law. Government records are presumed available unless an exemption applies.
  • CPLR Article 78 proceeding: The procedural vehicle used to challenge a government’s denial of access and to seek a court order compelling disclosure.
  • Unwarranted invasion of personal privacy (Public Officers Law § 87[2][b]): An exemption allowing agencies to withhold records when disclosure would improperly intrude on individual privacy. If the case does not fit a listed example in § 89(2)(b), courts apply a balancing test.
  • The balancing test (from Matter of New York Times Co. v City of N.Y. Fire Dept.): Courts weigh the privacy interest in nondisclosure against the public interest in disclosure. “Public interest” centers on shedding light on government activities.
  • PII (personally identifying information): Data that identifies or can help identify a person. The Court treats “name + email address” as PII.
  • Spoofing / phishing: Cyber techniques where an attacker impersonates a trusted sender to trick someone into revealing credentials or downloading malware. The Court accepted these as foreseeable risks heightened by public release of targeted email lists.
  • Constructive denial: When an agency fails to decide an administrative appeal within required timeframes, the law treats it as a denial that can be challenged in court.
  • FOIA Exemption 6 (federal analog): A federal privacy exemption similar to New York’s. The Court uses federal cases to support that email addresses carry privacy weight.

V. Conclusion

Matter of Russell v Town of Mount Pleasant, N.Y. establishes a clear, technology-attuned application of FOIL’s privacy exemption: subscriber names and email addresses for municipal alert systems may be withheld where privacy and cybersecurity risks are substantial and the requester cannot articulate a transparency-centered public interest in disclosure. The Court reaffirms FOIL’s presumption of openness while recognizing that, in the digital context, the release of contact identifiers can carry predictable downstream harms. The decision will likely shape future FOIL disputes involving digital contact lists by elevating cybersecurity realities within the “unwarranted invasion of personal privacy” balance and by cabining “public interest” to FOIL’s core purpose—illuminating government operations.