Info Gov

Andrew Gallie shares some practical tips to help schools manage subject access requests effectively.

Subject access requests (SARs) continue to pose significant challenges for schools. They are often time-consuming, resource-intensive, and frequently linked to wider complaints or disputes.

The Data (Use and Access) Act 2025 (DUAA) received Royal Assent in July, although most of its provisions are not yet in force. It introduces several changes to UK data protection law, including putting some of the ICO’s existing SAR guidance on a statutory footing. This is a welcome development, many of the new SAR provisions are controller-friendly, and will help schools resist unreasonable or disproportionate requests. Some key examples are discussed below.

Managing SARs: key areas to consider

1. Searches

The obligation is to complete a reasonable and proportionate search for personal data (and this will be on a statutory footing once the relevant provisions of the DUAA start to apply). In practice, we often see searches extending far beyond what is legally required leading to unnecessary work. For example, if keyword searches reveal vast amounts of information, it may indicate that the search terms have been set too widely. Requesters sometimes attempt to dictate how the SAR should be handled by the school, for example, by specifying search terms or search locations. There is no legal obligation to use the criteria provided by the requester (or even, in some cases, to do key word searches at all), provided that the school has done enough to satisfy the "reasonable and proportionate" search threshold.

2. Safeguarding information

Requests made for pupil information can often be problematic, particularly where there is a safeguarding angle. Consider, for example, a request made by a parent for information following an allegation of bullying at school. Such requests will often engage multiple issues, such as whether it would be appropriate to seek the child's views on disclosure to their parents for older children, personal data about others such as other pupils and wider strategic considerations around managing the incident and any parental complaints. 

There is no blanket 'safeguarding' exemption, but there are exemptions that often allow information to be withheld for safeguarding reasons. In our experience, often the most effective approach is to begin by considering what degree of disclosure would be in the child’s best interests, and then identify any applicable exemptions to see if the preferred position can be supported.

3. Personal data rather than documents

A SAR gives the requester a right to their personal data, not to specific documents. It is lawful to extract the relevant data and present it in a schedule or table, rather than disclosing the documents themselves. Whilst providing originals may sometimes be appropriate if there are minimal redactions, it is often clearer to provide the data in an alternative format to avoid further queries if a lot of redactions will be required.

4. Extending the response timeframe

Schools must normally respond to a SAR within one month, but the period can be extended by a further two months if the request is complex (which can be particularly welcome if a request runs over a school holiday). In our experience, schools often underutilise the right to extend. The threshold for complexity is relatively low, and we are not aware of the ICO criticising a school for relying on the extension where it was justifiable to do so. 

5. Managing complaints

The DUAA will require schools to have a formal process for handling data protection complaints for the first time.

We often find that schools can get caught up in prolonged correspondence with a requester and having a clear complaints pathway provides requesters with clarity while giving schools a defined point at which escalation to the ICO is appropriate. This should help reduce the protracted correspondence we often see in relation to SAR complaints. 

Andrew Gallie is a partner at VWV.

Also in this section

Jul 13, 2026

Polite, one-off request can still be vexatious where motive is personal, First-tier Tribunal rules

The First-tier Tribunal (General Regulatory Chamber) has upheld the refusal of a freedom of information request to a special educational needs school as vexatious under section 14(1) of the Freedom of Information Act 2000, finding that a polite, factual and non-burdensome request could still amount to a misuse of the Act where its motive was the pursuit of a case against a named individual while…
Jul 13, 2026

Tribunal backs national security refusal of Home Protection Scheme statistics, citing mosaic disclosure risk

The First-tier Tribunal (General Regulatory Chamber) has upheld the Northern Ireland Office's refusal to disclose aggregate application and expenditure figures for its Home Protection Scheme, finding that even high-level statistical data could contribute to a "mosaic" of information capable of assisting terrorists in assessing the protection afforded to police officers and other public servants.
Jul 10, 2026

DWP holds Universal Credit migration code but extracting it would breach FOIA cost limit, tribunal rules

The First-tier Tribunal has overturned an Information Commissioner's finding that the Department for Work and Pensions held no further information about how claimants were selected for Universal Credit managed migration, but ruled that the requester will receive nothing more because the cost of extracting the material would exceed the limit under section 12 of the Freedom of Information Act 2000…
Jul 07, 2026

"Should have held" is not "held": tribunal upholds FCDO not-held response over Somaliland Crown service certificate

The First-tier Tribunal (General Regulatory Chamber) has dismissed an appeal against the Information Commissioner's finding that the Foreign, Commonwealth and Development Office did not hold a copy of a 1955 certificate awarded on behalf of Queen Elizabeth II to a member of the Haud Constabulary in colonial-era Somaliland, concluding on the balance of probabilities that no in-scope information…
Jul 07, 2026

Requester's claim that ICO confused him with his son fails to defeat section 14 vexatiousness finding

The First-tier Tribunal (General Regulatory Chamber) has upheld the Information Commissioner's reliance on section 14(1) of the Freedom of Information Act 2000 to refuse a request about a parish council's data protection registration, finding that the request formed part of a campaign of harassment against the council even though the appellant claimed the requesting history relied on belonged not…
Jul 07, 2026

Late compliance, apology and resource pressures save council from contempt certification over EIR decision notice

The First-tier Tribunal (General Regulatory Chamber) has refused to certify Guildford Borough Council to the Upper Tribunal for contempt over its admitted failure to comply with a substituted decision notice within the required 35 days, finding that the council's late and piecemeal response was capable of constituting contempt but that later compliance, an apology and an explanation grounded in…

InfoGov Masthead Newsletter 800