The requests that arrive

Six rights,
and the two you will actually see.

In principle a school may receive any of the rights requests below. In practice small schools see two: a parent who wants to know what is held, usually during a dispute, and a family who has left and wants everything deleted. The others arrive occasionally and are mostly easier.

Right
How it arrives
What it means in practice
Access
"What do you hold about my child?"
A copy of the data, plus why you hold it and who sees it
Portability
"Give it to me in a usable form"
A machine-readable file, for data they gave you
Rectification
"This is wrong"
Correct it — usually the easiest request to satisfy
Erasure
"Delete everything"
Not absolute — other obligations can override it
Objection / restriction
"Stop using it for that"
Often about marketing or photographs rather than records
Withdraw consent
"Take her photo off the website"
Must be as easy as giving it was

A request does not have to say "GDPR" or "subject access request" to count. "Can you send me everything you have about Sofia?" in an email to a teacher is a request, and the clock starts when the school receives it, not when someone recognises what it is. That is the single most common way small schools get into difficulty, and the fix is to tell staff that any such message goes to one named person the same day.

Who may ask

The data is the child's.
Who exercises the right depends.

Personal data about a child belongs to the child; a parent usually exercises the right on their behalf, but not always and not for ever. Older children may be able to exercise their own rights, and where a child is mature enough the school may need to consider their views — the age and the test vary between countries, and this is one of the places where a school should know its local position rather than guess. Separated parents add a second question: whether the person asking holds parental responsibility, and whether disclosing to one parent reveals something about the other.

Two practical rules cover most cases. Verify identity proportionately — enough to be confident, not so much that you create an obstacle — and never by asking for more sensitive data than you already hold. And where a record contains information about someone else, a teacher's note about another student, a sibling's details, think about that person before disclosing; redaction is normal and expected.

The clock and the search

A month, typically,
and the search is the hard part.

GDPR generally requires a response within one month of receiving a request, extendable in limited circumstances, and free of charge in normal cases. The response itself is not usually the difficulty; the search is. A school that completed the inventory in the first article can go to a list of locations; a school that has not will spend the first week discovering where student data lives, which is exactly the wrong week to find out about the WhatsApp group.

Build the process once: a named owner, a log of requests with dates, a standard acknowledgement sent the same day, the location list from the inventory, and a template for the response. Acknowledge immediately even when the answer will take weeks — most complaints to regulators are prompted by silence rather than by the eventual answer.

📨Acknowledge on day zero
"Thank you — we have received your request and will respond by [date one month from today]. If we need anything from you to verify identity we will be in touch within two working days." One email, sent the same day, removes most of the pressure from the rest of the process.
Access and portability

A copy of the data,
plus the context around it.

An access request is not satisfied by a database dump. The person is entitled to a copy of their data and to know why you hold it, who you share it with, how long you keep it and where it came from — which is why a privacy notice written in advance saves work at exactly this moment, because much of that context can be pointed to rather than composed. Portability is narrower: a machine-readable copy of data they provided, which for a school is mostly enrolment and contact details rather than teacher assessments.

On SprintUp, an export of one account produces everything the platform holds about that person as a single readable document, which covers the platform's share of the request. Two caveats, both worth stating before you rely on it. It covers what is in SprintUp, not the spreadsheet on a teacher's laptop — the rest of your inventory is still yours to search. And, as the previous article sets out, the export is run by us rather than by your administrator, so raise it as soon as the request arrives rather than at the end of the month; the response window belongs to you, not to us, and we would rather be asked on day one.

Erasure

Not absolute,
and not the same as deletion.

"Delete everything" is the request that causes most confusion, because the right to erasure is not absolute and because a school genuinely cannot honour it in full. Records kept to comply with a legal obligation — financial records under accounting law being the clearest example — survive an erasure request, and that is a lawful outcome rather than a refusal. Where a school is inside compulsory education, further records may be required to be kept. The honest response says what will be erased, what will not, and why, rather than promising everything and quietly keeping some of it.

The design question is what "erased" should mean technically, and there is a real tension: strip a student from the database entirely and the school's own history breaks — a class roster with a hole in it, an attendance rate that no longer adds up, a grade distribution missing a student. SprintUp resolves it by keeping the account's place in the school's records while removing everything that identifies the person.

What
What happens on erasure
Why
Name, contact, identifying details
Removed
Nothing on the account identifies the person afterwards
Sign-in
Permanently disabled
The account can never be signed into again
Notifications and preferences
Removed outright
Personal to the individual; no reason to keep them
Grades, attendance, class history
Kept, de-identified
The school's records stay internally consistent
Invoices and payment records
Kept
Accounting law requires it; erasure does not override that
Reversibility
None
Erasure is permanent by design — that is the point of it

Two operational points follow. Deletion and erasure are different things and should be treated differently: on SprintUp an administrator deleting an account keeps it restorable, because schools make mistakes, while erasure is permanent and is run by us on request. And because erasure cannot be undone, the request should be confirmed with the person in writing before it is executed — a family that asks in anger during a dispute and changes its mind a week later is common, and there is no way back.

Before the first request

The rights request
checklist.

✅Nine items
Staff told that any "send me everything" message goes to one named person the same day · a log of requests with dates · a same-day acknowledgement template · identity verification that is proportionate · the location list from your inventory · a rule for redacting third parties · the vendor export raised on day one, not day twenty-five · an erasure response that states what will not be deleted and why · written confirmation before any irreversible erasure.

And the standing caveat for this cluster: none of it is legal advice. The rules on children's rights, parental responsibility and retention differ by jurisdiction, and a request that arrives alongside a dispute or a safeguarding matter is one to take advice on rather than to process routinely.

You've finished C7 — back to the cluster guide →← Back to A2