The most common data requests that a Multi-Academy Trust will receive are:
- Subject Access Requests (SAR): requests for a specific data subject’s personal data pursuant to Article 15 UK GDPR.
- Freedom of Information (FOI): requests for information held by a public authority pursuant to s.1 Freedom of Information Act 2000. Such requests may include requests for personal information or other types of information.
Trusts may also receive a request for information under Regulation 5 of The Education (Pupil Information) (England) Regulations 2005. Please note that this regulation does not apply to academies; however, such a request should be considered as a subject access request in line with UK GDPR / Data Protection Act 2018.
What does the legislation say?
The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
- the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing;
- the right to lodge a complaint with the Commission;
- where the personal data are not collected from the data subject, any available information as to their source;
- the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
(1) Any person making a request for information to a public authority is entitled—
(a) to be informed in writing by the public authority whether it holds information of the description specified in the request, and
(b) if that is the case, to have that information communicated to him.
Redacting a SAR
When determining what to redact within a SAR, you will need to consider who is making the request. You are legally obliged to disclose an individual’s personal data to them when they request it. The request may come from a data subject themselves or, in the case of a minor or SEN pupil, from a parent. If the data subject does not have capacity to make their own decisions, then a parent or legal guardian may make the request on their behalf. Generally, an average-intelligence 13-year-old is considered to have capacity, but decisions should be made on a case-by-case basis. You could also get such a request on behalf of a data subject (of any age and capacity) from a solicitor or other legal representative.
Requests made on behalf of an individual should be considered to have come from the data subject themselves. So, if a request comes from a solicitor or a parent on behalf of a pupil, you treat this as if it has come from the pupil themselves. This is very important when determining the redactions of third-party data as set out in Schedule 2, Part 3, paragraph 16 & 17 Data Protection Act 2018. This exemption to the right of access will apply to the vast majority of responses you provide to pupils or parents, as well as elements of responses to staff requests. At its core, the purpose of this exemption is to protect the personal data of other individuals who might happen to be contained in the same document or data set as the data subject to whom the request relates.
Looking at this practically, you will want to be redacting the personal data of anyone who is not the individual making the request, unless those other individuals have provided consent for their data to be released — which is often impractical to obtain. Safeguarding records, for example, will contain references to multiple pupils, teaching staff and potentially other data subjects such as health workers. If you don’t have consent, you must consider whether it’s reasonable to disclose the information about them anyway.
You must take into account all the relevant circumstances, including:
- the type of information that you would disclose;
- any duty of confidentiality owed to the third party;
- any steps you have taken to try to get the third party’s consent;
- whether the third party is capable of giving consent; and
- any stated refusal of consent by the third party.
This is a non-exhaustive list, and ultimately it’s your decision whether to disclose the information to the requester. You must make the disclosure if it’s reasonable to do so without the third party’s consent. Deciding whether it’s reasonable to make the disclosure anyway is not straightforward. It’s more likely to be reasonable for you to disclose the information if:
- the requester has previously received the third-party information;
- the requester already knows the information; or
- the information is generally available to the public.
Third-party information about a member of staff (acting in the course of their duties), whom the person making the request knows well through their previous dealings, is more likely to be disclosed than information relating to an anonymous person.
On the face of it, you may consider that leaving in third-party pupil information is permitted as the requester may already know the information. For example, if an incident occurred between two pupils during lunchtime, academy staff may have already informed the parents of both pupils of the incident and who was involved. If a subsequent request is received for the academy’s log of the incident, it could be reasonable to leave in the third-party pupil data. Conversely, a request for all data held by an academy on behalf of Pupil A will contain references to other pupils, where it would be necessary to redact the third-party pupil data (which can include initials if the recipient is aware of the individual to whom the initials belong).
You can also save administrative time here by choosing not to redact a parent’s information from a request for pupil data, as doing so would not be a data breach (because you are disclosing that parent’s data to them).
Education data, health data and social care data are subject to an assumption of reasonableness for health workers, social workers and education workers, as detailed in Schedule 2, Part 3, paragraph 17 DPA 2018. This means that you do not need to redact the personal data of current or former staff from your responses (subject to the serious harm test below). The same principle applies to the personal data of health professionals contributing to a health record in their capacity as a health professional who has been involved in the diagnosis, care or treatment of the data subject.
The serious harm test for education data (Schedule 3, Part 5, paragraph 21)
What is it? This exemption is designed to protect individuals from suffering serious harm due to their involvement in a pupil’s education. The exemption allows an organisation to withhold the data in response to a request, and also puts the organisation under no obligation to confirm if it even holds the data.
How do I apply it? The “serious harm test” is met with respect to education data if disclosure would be likely to cause serious harm to the physical or mental health of the data subject or another individual.
Organisations should not use this exemption in a blanket fashion. The “serious harm test” should be considered for each individual data subject that you are considering for redaction. This exemption can apply to teacher data, social worker data, health worker data or any other third-party data subject who may be in the data set or document.
There are instances where you may need to redact pupil data which puts them at risk of suffering from child abuse, staff data held in a confidential reference, or a plethora of other exemptions. These further exemptions are not considered in this guide; however, further information can be found in our SAR Exemptions guide.
Taking everything above into account, the decision tool below shows what personal data should be redacted from a data source depending on who the request concerns:
Interactive guide · Pupil data
Who is the data subject?
Start by identifying whose personal data the request relates to.
Redacting an FOI request
Generally, when redacting data in response to an FOI request, you will be looking to redact all personal data — even that of the individual making the request (should you hold it). This is due to s.40(2) FOI, which covers the personal data of third parties (anyone other than the requester) where complying with the request would breach any of the principles in the UK GDPR. This exemption can only apply to information about people who are living; you cannot use it to protect information about people who have died. A similar provision at s.40(1) confirms that you should treat any request made by an individual for their own personal data as a subject access request. You should apply this to any part of the request that is for the requester’s own personal data. They should not be required to make a second, separate subject access request for these parts of their request.
Remember that job titles may also identify individuals in your response. If a position is held by only one individual who can also be identified via the academy website, this will constitute personal data.
There are, however, situations where you should not redact personal data included within the response to the FOI. Before considering if you can disclose, you must first decide if you can confirm or deny holding the requested third-party personal data. The ICO website contains detailed information regarding whether you can confirm or deny holding the data.
If you have decided that you can confirm holding the information, you must go on to consider if section 40(2) applies. There are cases when doing so can — in itself — disclose exempt information or harm the interest an exemption protects. In these circumstances, you don’t have to say whether or not you hold the information. You can issue a “neither confirm nor deny” response. This is also known as an NCND response. You don’t have to confirm or deny holding the requested personal information when:
- it is the requester’s personal data and you’re handling the request under FOIA; or
- it is a third party’s personal data; and
- confirming or denying would contravene the data protection principles; or
- confirming or denying would contravene a valid objection to processing; or
- confirming or denying would itself be exempt from the right of access under data protection legislation.
The aim of giving an NCND response is to leave the question of whether or not you hold the information entirely open. This is to ensure that no inferences can be drawn from the fact that you hold or do not hold the information.
This means you can give an NCND response when you do not in fact hold the requested information. In these cases, you can consider the consequences of confirming or denying by reference to hypothetical information you might hold, without first establishing if you do actually hold it.
For example, if you are dealing with a request for information about someone’s disciplinary records, giving an NCND response could be appropriate. This is because confirming or denying whether or not you hold such records risks revealing if that person is, or is not, subject to a disciplinary process.
As far as redaction is concerned, you will need to consider whether the request is for a legitimate interest — e.g. are you, or the third party seeking access to the information, pursuing a legitimate interest? If you cannot identify a legitimate interest in disclosure of the requested information, the first part of the legitimate interest assessment is not met. This means that disclosure would contravene principle (a), as the legitimate interest lawful basis for processing would not apply.
If there is a legitimate interest, you should consider whether the disclosure of the personal information is necessary to meet those interests. Necessary means more than desirable but less than indispensable. It involves considering alternative measures which can meet the relevant legitimate interests and therefore make disclosure of the requested information unnecessary.
If you can justify that the disclosure of the third-party personal data is necessary, you should undertake the balancing test. The balancing test involves considering whether the legitimate interests served by the disclosure outweigh “the interests or fundamental rights and freedoms of the data subject which require the protection of personal data”. When conducting the balancing test, you should consider:
- the potential harm or distress that disclosure would cause;
- the extent to which the information is already in the public domain;
- the extent to which the information is already known to some people;
- whether the individual has expressed concern or objected to the disclosure; and
- the data subject’s reasonable expectations of privacy.
These factors are often interlinked. For example, what other information is available in the public domain may have a bearing on the consequences of disclosure or on the person’s reasonable expectations. You will also need to remember that a disclosure made in response to an FOI is considered as given “to the world”, and that the recipient is within their rights to share your response publicly if they want to.
If you can still justify disclosing the personal data, you may be able to disclose the information.
SAR vs FOI at a glance
Related guides
- SARSubject Access RequestsWhat a SAR is, how long you have to respond, and how to handle third-party data and redactions correctly.
- FOIFreedom of Information RequestsHow FOI requests work, the 20 working-day limit and £450 cost cap, and when personal data can or cannot be disclosed.
- SARSAR ExemptionsThe most common exemptions to the right of access, when each applies, and the exact wording to use in your SAR correspondence.