SARQuick reference

Subject Access Requests (SAR)

The right of access, commonly referred to as subject access, gives people the right to obtain a copy of their personal information from you, as well as other supplementary information. Requests can be made in any form, including verbally and through social media.

UK GDPR & Data Protection Act 2018

Time limits

One calendar month to respond. This can be extended by a further two months if the request is complex or you have received a number of requests from the same person. This can include other types of requests about their rights, such as a request for erasure.

Clarification & unclear requests

You can ask for further information to help you identify the personal information or the processing activity that the SAR relates to. You should only ask if it’s reasonably required. If you do ask for clarification, the time limit pauses on the day you request clarification and resumes on the day after you receive it.

ID requirements

You must be able to confirm the identity of the requester. You can request identification if necessary, but you should not request ID if it is not required — such as when a data subject makes a SAR in person to a member of your academy staff.

Exemptions

The ICO website has detailed guidance on how to apply the exemptions. We have also produced a separate guide on how to apply the most common exemptions to SARs received in the sector.

When and what to redact

Generally you will be looking to redact all third-party personal data from any disclosures. A presumption of reasonableness applies to teaching staff, social workers and medical staff. This means that you do not redact personal data belonging to these classes of individuals unless they are at a material risk of suffering serious harm. This should be judged for each third-party data subject individually. The presumption of reasonableness only applies to requests made for pupil data; however, you can apply the serious harm test to any requests you may receive for parental data or staff data.

Common mistakes

Common mistakes in redaction include not applying the presumption of reasonableness as discussed above, or ignoring the application of the serious harm test. Organisations may also choose to leave in initials or first names only, in the belief that this isn’t personal data because a general member of the public would not be able to identify the individual from these details. This is incorrect. As the SAR response is not being provided to a member of the public but to an individual associated with the school, the recipient may still be able to identify the individual using the first name or initials only. Trusts should also consider redacting more than just personal identifiers if the other data within the file inadvertently identifies the individual. For example, there could be a paragraph in safeguarding records which includes a statement made by Grandma. Whilst you may redact Grandma due to the parent making the request knowing who that is, if the statement is something that could only be provided by Grandma, you should redact the statement if it puts that individual at risk of serious harm.

Why this matters

Any missed redaction constitutes a data breach as per UK GDPR, which could result in regulatory action from the ICO and/or civil action by the affected data subjects.

Decision tree

Work through the questions below to see exactly what to redact for a pupil-data SAR — we’ll build your redaction checklist as you go.

Interactive guide · Pupil data

Question 1

Who is the data subject?

Start by identifying whose personal data the request relates to.

Redact with confidence

Eclipse surfaces likely personal data across your documents and keeps you in control of every redaction — so nothing gets missed.

Try Eclipse