Six rights,
and the two you will actually see.
In principle a school may receive any of the rights requests below. In practice small schools see two: a parent who wants to know what is held, usually during a dispute, and a family who has left and wants everything deleted. The others arrive occasionally and are mostly easier.
A request does not have to say "GDPR" or "subject access request" to count. "Can you send me everything you have about Sofia?" in an email to a teacher is a request, and the clock starts when the school receives it, not when someone recognises what it is. That is the single most common way small schools get into difficulty, and the fix is to tell staff that any such message goes to one named person the same day.
The data is the child's.
Who exercises the right depends.
Personal data about a child belongs to the child; a parent usually exercises the right on their behalf, but not always and not for ever. Older children may be able to exercise their own rights, and where a child is mature enough the school may need to consider their views — the age and the test vary between countries, and this is one of the places where a school should know its local position rather than guess. Separated parents add a second question: whether the person asking holds parental responsibility, and whether disclosing to one parent reveals something about the other.
Two practical rules cover most cases. Verify identity proportionately — enough to be confident, not so much that you create an obstacle — and never by asking for more sensitive data than you already hold. And where a record contains information about someone else, a teacher's note about another student, a sibling's details, think about that person before disclosing; redaction is normal and expected.
A month, typically,
and the search is the hard part.
GDPR generally requires a response within one month of receiving a request, extendable in limited circumstances, and free of charge in normal cases. The response itself is not usually the difficulty; the search is. A school that completed the inventory in the first article can go to a list of locations; a school that has not will spend the first week discovering where student data lives, which is exactly the wrong week to find out about the WhatsApp group.
Build the process once: a named owner, a log of requests with dates, a standard acknowledgement sent the same day, the location list from the inventory, and a template for the response. Acknowledge immediately even when the answer will take weeks — most complaints to regulators are prompted by silence rather than by the eventual answer.
A copy of the data,
plus the context around it.
An access request is not satisfied by a database dump. The person is entitled to a copy of their data and to know why you hold it, who you share it with, how long you keep it and where it came from — which is why a privacy notice written in advance saves work at exactly this moment, because much of that context can be pointed to rather than composed. Portability is narrower: a machine-readable copy of data they provided, which for a school is mostly enrolment and contact details rather than teacher assessments.
On SprintUp, an export of one account produces everything the platform holds about that person as a single readable document, which covers the platform's share of the request. Two caveats, both worth stating before you rely on it. It covers what is in SprintUp, not the spreadsheet on a teacher's laptop — the rest of your inventory is still yours to search. And, as the previous article sets out, the export is run by us rather than by your administrator, so raise it as soon as the request arrives rather than at the end of the month; the response window belongs to you, not to us, and we would rather be asked on day one.
Not absolute,
and not the same as deletion.
"Delete everything" is the request that causes most confusion, because the right to erasure is not absolute and because a school genuinely cannot honour it in full. Records kept to comply with a legal obligation — financial records under accounting law being the clearest example — survive an erasure request, and that is a lawful outcome rather than a refusal. Where a school is inside compulsory education, further records may be required to be kept. The honest response says what will be erased, what will not, and why, rather than promising everything and quietly keeping some of it.
The design question is what "erased" should mean technically, and there is a real tension: strip a student from the database entirely and the school's own history breaks — a class roster with a hole in it, an attendance rate that no longer adds up, a grade distribution missing a student. SprintUp resolves it by keeping the account's place in the school's records while removing everything that identifies the person.
Two operational points follow. Deletion and erasure are different things and should be treated differently: on SprintUp an administrator deleting an account keeps it restorable, because schools make mistakes, while erasure is permanent and is run by us on request. And because erasure cannot be undone, the request should be confirmed with the person in writing before it is executed — a family that asks in anger during a dispute and changes its mind a week later is common, and there is no way back.
The rights request
checklist.
And the standing caveat for this cluster: none of it is legal advice. The rules on children's rights, parental responsibility and retention differ by jurisdiction, and a request that arrives alongside a dispute or a safeguarding matter is one to take advice on rather than to process routinely.