Training

Subject access request staff training

Build general awareness of how to recognise a subject access request and help role-based staff understand the decisions, search considerations and further instruction relevant to handling one.

Training Course
CalmComplianceTraining course

Subject access request staff training

Version
v1
Updated
7 October 2026
Reviewed
7 October 2026
Audience
General staff in maintained and academy primary and secondary schools in England, plus staff with role-based responsibility for receiving, assessing, searching for, redacting, approving or disclosing subject access request information, including DPOs where the school is required to have one.
Jurisdiction
England

Estimated duration: 35 minutes

Learning outcomes

  • Recognise a subject access request from its substance, including verbal, written and social-media requests made to any part of the school, even when the requester does not use formal subject access terminology.
  • Explain why all staff need general recognition awareness and why staff involved in handling subject access requests need additional training appropriate to their roles.
  • Distinguish information that is personal information from information that does not relate to an identifiable living person, and identify when a record may relate to more than one person.
  • Recognise the need to search relevant school-held locations, including private devices or accounts where there is good reason to believe they hold the requester's information, and avoid intentional amendment or deletion to prevent disclosure.
  • Recognise the decision points for information about another person, including considering consent or reasonableness, withholding identifying information where disclosure is not justified, and providing as much requested information as possible through appropriate editing or redaction.
  • Identify when the supplied guidance is insufficient for a role-specific decision and prepare a focused discussion with the DPO or appropriate training provider about missing handling, approval or disclosure competence.

Lessons

  1. What counts as a subject access request?

    A subject access request is recognised from what the person is asking for, not from a particular label or format. A person may make the request verbally, in writing or through social media, and may send it to reception, a teacher, a pastoral team or another part of the school organisation. They do not need to use phrases such as “subject access request”, “right of access” or “Article 15”. If it is clear that the person is asking for their personal information, identify and handle it as a subject access request. Follow your school's local routing procedure if one exists.

    Apply the recognition test by noting the channel and recipient, ignoring the absence of formal wording, and focusing on whether the substance is a request for the person's personal information. This is an identification step, not a decision about what information will ultimately be disclosed.

    Recognising a subject access request Request received: A person has contacted the school or a part of its organisation. Channel: The request may be verbal, written or made through social media. Recipient: The request may be made to any part of the school organisation. Formal SAR wording present?: The requester does not need to use the phrases subject access request, right of access or article 15 of the UK GDPR. Clear request for personal information?: Decide whether it is clear that the person is asking for their personal information. Recognisable subject access request: The request should be identified and handled as a subject access request. Not identified by this diagram as a subject access request: The request is not shown by this diagram to be a subject access request because its substance is not clear. Request received leads to Channel. Channel leads to Recipient. Recipient leads to Formal SAR wording present?. Formal SAR wording present? leads to Clear request for personal information?. Clear request for personal information? leads to Recognisable subject access request. Clear request for personal information? leads to Not identified by this diagram as a subject access request.

    Hypothetical example: A parent sends a direct message to the school's social-media account saying, “Please send me every email and note you hold about me.” Although the message uses no formal term and is not sent to a named data protection contact, its substance is a request for the person's personal information. It should be recognised and routed under the applicable process.

    Practice

    Hypothetical situation: A pupil says to a member of staff, “Can I see all the information the school has about me?” The pupil says this during a conversation and does not put it in writing. What recognition feature matters most, and what should you do next?

    A likely mistake is to assume that only a written request sent to a data protection officer can be a subject access request. Correct this by listening for the substance and passing a possible request to the appropriate local contact or process. Do not promise a particular disclosure outcome; recognition and handling are separate stages.

  2. Awareness and role-based responsibility

    Every member of staff may receive a subject access request, so all staff need general awareness that helps them recognise one and pass it into the appropriate process. Staff who receive, assess, search for, redact, approve or disclose information need more detailed training suited to their decisions. General awareness does not automatically provide the knowledge needed for a role-specific decision. Where a school is required to have a data protection officer, the DPO is responsible for ensuring appropriate data protection training is provided.

    Use a role boundary: know what you can recognise or do from your training, and identify decisions requiring further instruction or authorisation. Before relying on a local procedure, look for its role descriptions, routing arrangements, search instructions, redaction guidance, approval responsibilities and escalation contacts. These details matter because the supplied general guidance does not create a complete school workflow or approval matrix.

    Hypothetical example: A receptionist has general awareness and recognises a request at the front desk. A records officer has additional instruction on locating relevant records. A person approving a response needs instruction on the school's decision and escalation arrangements. Each person has a different training need; recognition awareness alone should not be treated as approval or disclosure competence.

    Practice

    List your role in relation to subject access requests and one decision you may be expected to make. If the supplied guidance does not explain how to make that decision, write one focused question for the DPO or appropriate training provider.

    A likely mistake is to assume that general awareness training means a person can search, redact or approve a response. Correct this by separating recognition knowledge from role-specific handling knowledge and recording missing instruction for discussion with the DPO or appropriate training provider.

  3. Identify the information and people involved

    Before responding to a subject access request, the school should decide whether information is personal information and, if so, whom it relates to. Personal information is information relating to a living person who can be identified directly or indirectly. Context and the way information is held or used can affect whether it relates to a person. A record may relate to the requester alone or to the requester and another person.

    When reviewing a record, ask who is identifiable, what information relates to that person, and whether the record also contains information relating to someone else. This identification step should happen before a role-authorised disclosure decision and helps prevent a mixed-person record being treated as though it belongs entirely to one individual.

    Hypothetical example: A pastoral note states that a named pupil discussed an incident involving a named member of staff. The note may contain personal information relating to the pupil and information relating to the staff member. Flag it for consideration as a mixed-person record rather than assuming it concerns the requester only.

    Practice

    Hypothetical situation: A record contains the requester's name, a description of the requester's attendance and a comment identifying another pupil who was present. Which parts should be flagged before a disclosure decision is made?

    A likely mistake is to treat every record mentioning the requester as information about the requester alone. Correct this by checking whether another identifiable living person is also involved and considering the record's context and use.

  4. Search locations and preserve relevant information

    A subject access request concerns information held when the request is received, although routine use may mean information is later amended or deleted. Relevant school-controlled locations may include systems and records used in the school's work. The exact locations and search method must come from the school's applicable procedure or role-specific instruction; this course does not invent a universal search workflow.

    Staff should not normally hold information about pupils, parents, contacts or other staff on personal devices or private accounts. If there is good reason to think the requester's personal information is held in private email, on a device or in a private messaging application, the relevant staff member should be asked to search those locations as appropriate. Whether and how this happens must be confirmed through the school's policy or procedure because private locations raise security and control issues.

    Do not amend or delete requested information merely to prevent its disclosure. Routine changes or deletion that would have happened anyway may mean information supplied later differs from what was held at receipt, but intentional amendment or deletion to prevent disclosure is not acceptable and is identified in the supplied guidance as an offence under the Data Protection Act.

    Hypothetical example: A school has good reason to believe that a member of staff exchanged messages about the requester using a private messaging application. Raise the issue through the applicable school procedure so the relevant person can be asked to search the private location as appropriate. The staff member must not delete or edit messages simply because a subject access request has been received.

    Practice

    Hypothetical situation: A searcher checks the school's designated records and hears that a staff member may have relevant information in a private email account. What two issues should the searcher consider before taking action?

    A likely mistake is either to search every private device automatically or to assume private accounts can never be relevant. Correct this by applying the condition of good reason to believe the requester's information is there, then following the applicable local procedure. Do not tidy, edit or delete records to make disclosure easier where the intention is to prevent disclosure.

  5. Information about other people

    Information in a subject access request may relate to both the requester and another person. First identify the mixed-person information. Then consider whether the other person's consent has been obtained or whether disclosure without consent is reasonable. If disclosure is not justified, withhold information identifying that person while still providing as much requested information as possible.

    Editing or redacting may be appropriate to remove information identifying the other person while preserving the requester's information. This course does not set the school's approval threshold, redaction method or final disclosure authority. Consult the relevant local procedure or role-specific instruction so the authorised decision-maker and method are clear.

    Mixed-person information in a subject access request Record located: Information relevant to the request has been found. Relates to requester and another person?: Identify whether the information is personal information of more than one person. Continue applicable SAR assessment: The diagram has not identified information relating to another person. Consider consent or reasonableness: Consider whether the other person's consent has been obtained or whether disclosure without consent is reasonable. Disclosure justified?: Make the role-authorised decision about whether disclosure of the other person's information is justified. Withhold identifying information: Do not disclose the other person's identifying information when disclosure is not justified. Provide as much requested information as possible: Provide the requester's information without identifying the other person, including through editing or redaction where appropriate. Continue to role-authorised disclosure decision: The diagram does not replace the role-specific decision or approval process. Record located leads to Relates to requester and another person?. Relates to requester and another person? leads to Continue applicable SAR assessment. Relates to requester and another person? leads to Consider consent or reasonableness. Consider consent or reasonableness leads to Disclosure justified?. Disclosure justified? leads to Withhold identifying information. Withhold identifying information leads to Provide as much requested information as possible. Disclosure justified? leads to Continue to role-authorised disclosure decision.

    Hypothetical example: A requested email describes the requester's meeting with a named member of staff and includes the staff member's personal telephone number. If disclosure of the staff member's identifying information is not justified, the number and other identifying details should be withheld, while the requester's information should be provided as far as possible through an authorised edit or redaction.

    Practice

    Hypothetical situation: A record contains the requester's account of an incident and a second person's name and contact details. No consent from the second person has been obtained. What decision points should be considered, and what is the response principle if disclosure is not justified?

    A likely mistake is to assume that the presence of another person's information means the entire record must be withheld. Correct this by separating identifying information from the requester's information and considering whether the response can be edited or redacted to provide as much requested information as possible.

  6. Recognise handling gaps and prepare the provider discussion

    The supplied guidance supports recognition, role-based training, search considerations, preservation and proportionate handling of information about other people. It does not provide every instruction needed for a specific role, such as a school's routing rule, search checklist, redaction technique, approval matrix or disclosure authority. Recognising that boundary is part of safe role orientation.

    Prepare a focused discussion by recording your role; the decision or action expected; what the supplied guidance establishes; what instruction is missing; who should provide or approve it; and the question you need answered. Where a school is required to have a DPO, raise appropriate training needs with the DPO. Otherwise, use the school's designated data protection or training contact, where one exists.

    Hypothetical example: A member of staff is asked to approve a redacted response but has only completed general awareness training. Their gap log records: role—approver; decision—whether the proposed redaction is sufficient; established principle—provide as much requested information as possible while protecting unjustified third-party identifiers; missing instruction—local approval authority and redaction standard; question—“Which procedure and authorised person must I use before approving this response?”

    Practice

    Create a short gap log for one subject access request task relevant to your work. Include your role, the task, what this course establishes, the missing local or role-specific instruction, and the person or function you should approach.

    A likely mistake is to fill a gap by relying on assumption, informal practice or a colleague's unverified instruction. Correct this by documenting the gap and seeking role-specific instruction before making a decision that the course does not authorise or explain. This course is a starting point for appropriate training discussions, not a sign-off of competence.

Assessment

8 questions

Scope and limitations

  • This course provides general awareness and role orientation; it does not provide a complete school-specific subject access request workflow.
  • It does not replace role-specific instruction, DPO oversight or advice from the school's responsible organisation where those are needed.
  • It does not confer practical competence or sign off competence for receiving, searching, redacting, approving or disclosing SAR information.
  • Local routing, escalation, record-system, approval and refresher arrangements must be confirmed through the relevant school or responsible-organisation procedure.
CalmCompliance · v1Template for adaptation

Template details

Type
Training Course
Version
v1
Updated
7 October 2026
Reviewed
7 October 2026
Lessons
6 lessons
Estimated duration
35 minutes
Audience
General staff in maintained and academy primary and secondary schools in England, plus staff with role-based responsibility for receiving, assessing, searching for, redacting, approving or disclosing subject access request information, including DPOs where the school is required to have one.

Get this template

Free, editable Word document. We’ll email you a download link. No Calm account needed.

Edit in Word or Google Docs.

We record your email and the template you request. Read our privacy policy.

Subject access request staff training - CalmCompliance