Subject access request identification, recording and classification procedure
- Version
- v1
- Updated
- 7 October 2026
- Reviewed
- 7 October 2026
1. Scope
This procedure applies to maintained and academy primary and secondary schools in England that process personal data and receive communications capable of containing subject access requests. It covers requests made verbally, in writing, through social media, to any part of the organisation or through another route. A requester does not have to use a prescribed form or channel.
2. Recognising a subject access request
Any employee who receives a communication must consider whether it is clear that the person is asking for their personal information. A request may be valid even if it does not use the phrases “subject access request”, “right of access” or “article 15 of the UK GDPR”.
A person may make a subject access request verbally or in writing, including through social media, and may send it to any part of the organisation. The request does not have to be directed to a specific person or contact point.
A request may still be a valid subject access request if it refers to other legislation, including the Freedom of Information Act 2000 or the Freedom of Information (Scotland) Act 2002.
3. Recording the request
Record each apparent subject access request, including requests made by telephone or in person. The record should include the requester’s identity, the date received, the scope of the request and any follow-up actions.
Use the recorded information to contact the requester if it is necessary to confirm identity or clarify the scope of the request. Each request must be identified and handled correctly.
4. Requests received through social media
A person may make a subject access request through any social media site where the school has a presence. Record the request and take reasonable and proportionate steps to identify and disclose the relevant information.
Social media is generally not a secure way to provide information. Ask the requester for alternative delivery details and use the alternative route for providing the information.
5. Requests labelled as freedom of information requests
If the requester is asking only for their own personal information but refers to freedom of information law, deal with the request as a subject access request in the normal way. The requester does not need to submit a new request.
Identity verification may be requested where necessary before the request is handled.
6. Mixed subject access and freedom of information requests
Where the school is a public authority and a request covers both the requester’s personal information and other information, treat it as two requests.
Handle the part concerning the requester’s personal information as a subject access request under the UK GDPR. Handle the remaining information as a freedom of information request under freedom of information law.
Consider each part under the correct legislation. Record the separation between the two parts and the legislation applied to each part.
7. Handling responsibility
Every employee must identify and handle a subject access request correctly when one is received. The request must be recorded and dealt with according to its classification, including any necessary identity or scope clarification and any required separation between subject access and freedom of information elements.
Sources
- How do we recognise a subject access request (SAR)? | ICOInformation Commissioner's Office (ICO)
