enjay Posted April 23 Posted April 23 Only a small number (1-2 per month) of SARs and/or FOI requests make it onto my radar, but based on the number of emails I receive from companies/consultancies offering advice or assistance with SARs and FOI requests, I wonder if we're actually receiving more, and staff are handling them directly without notifying me. I don't want to make more work for myself for the sake of it, but I do want to ensure we're handling these appropriately so I'm wondering if some improved staff training is needed. This training would be in case we're missing the requests, having accidental data breaches by staff who don't understand it properly, or have staff wasting time by manually redacting documents not using the redaction software we have. So, how many requests are you receiving? To avoid this thread getting derailed, I know these aren't IT things however I am also the school's GDPR lead (DPO is external, of course).
synaesthesia Posted April 23 Posted April 23 Averages 5 or 6 for us currently. A marked increase over the last year and many of the requests coming through now are AI generated/prompted, more than likely linked IMO. Great for people to have more control over their data - not so much for the people having to manage it.
pete Posted April 23 Posted April 23 *Opens the SARs folder for 2025-26* 13 SARs so far, across 5 schools. 2 rejected (person making the request didn't have authoritisation to do so on behalf of the data subject) 10 responded to (info provided with appropriate exemptions for data on other people) 1 in progress. FOIs: 30 or so but they're usually the same person/group making the same request of multiple schools and a lot of that is set at MAT-level. Detection: With regard to whether you're detecting them or they're being missed, put transport rules on the enquiries@ / admin@ shared mailboxes such that certain phrases trigger a CC to the dpo@ shared mailbox. Test it out so you're not pulling language from mail signatures though. If a SAR comes in and says "this is a subject access request for Bob" or "this is a SAR for Bob", our staff are good at notifying the appropriate people. If the sender hasn't used the magic phrase, they're not always great at spotting them. A number of FOIs (especially people using mailgun/mailchimp to bulk send them) end up in Junk/Quarantine and can get missed, but IMO that's on the sender to do a reasonable job of sending the email in a reliable manner: FOI from bob.bobblington@gmail will get delivered. FOI email that's got an "Unsubscribe from this mailing list?" link at the bottom - depends heavily on email content and may end up in spam.
enjay Posted April 23 Author Posted April 23 My numbers are roughly in line with those, in that case, allowing for us being a single academy not a MAT so possibly "escaping" some of the FOIAs. As for detection, I'm confident the ones which come in to office@ etc get to me, it's the requests (more likely SARs than FOIAs) which are going directly to year teams which might not. One example I can think of is a parent who wanted more detail on their child's behaviour points because the parent portal doesn't include everything - this made it to me because the admin who received it is relatively new and didn't know how to redact the document, but otherwise it might not have done.
psydii Posted April 23 Posted April 23 Similar numbers. There are of course potentially many more than this, but mostly they are just BAU school->parent communication - technically they could be SARs*, but nobody couches it in the legalize that gets it noticed and put on the SAR register. Only when the scope of the request (or where it was sent) raises a red flag or the language used makes it apparent the work needs to cross the desk of the DPO or SBM do we actually kick-off the formal SAR process. Our policy (and website) say that such requests need to be sent to a specific email address. This is monitored by the SBM, HT PA, and the DPO. Of course requests do arrive via generic email addresses, but these are monitored by the school office, who are well versed in forwarding emails to the correct location. Sometimes we just push a request back to the department that it should have gone to had it not been formally submitted to the DPO address to action, and the DPO just updates the register as it is completed. We get one or two really big ones every year, an the back and forth with the genAI that's writing them recently is frustrating. that said, we've had a couple of challenges to responses recently, and our process is sufficiently robust that our response to the challenge/query seems to have been found (by the genAI?) to be sufficient. *though one could argue they are actually Education Records requests.
enjay Posted April 23 Author Posted April 23 5 minutes ago, psydii said: Our policy (and website) say that such requests need to be sent to a specific email address. You can request that, but not insist on it. SARs can come via any medium, including verbally. 2
enjay Posted April 23 Author Posted April 23 8 minutes ago, psydii said: Only when the scope of the request (or where it was sent) raises a red flag or the language used makes it apparent the work needs to cross the desk of the DPO or SBM do we actually kick-off the formal SAR process. And that's becoming more common, as people ask ChatGPT to "write a letter of complaint to my school" rather than just write an email saying they're unhappy.
psydii Posted April 23 Posted April 23 4 minutes ago, enjay said: You can request that, but not insist on it. SARs can come via any medium, including verbally. Yup. But informal requests received aurally or verbally are basically standard school - home communications and are either covered by the Education records act or the *intent* of the right to access of the GDPR, so mostly never cross into the realms of a formally logged and managed SAR. If they are more formally presented, or exceed the rights under ERR then they are (at least) forwarded internally to the dpo address. The "unlogged" stuff does of course generate an audit trail of its own, with all calls and emails needing to be logged in the communication record, and of course their are the technical logs and the actual emails etc providing evidence. These only matter if something has gone badly wrong, or somebody is very grumpy.
synaesthesia Posted April 23 Posted April 23 Just please take care with that approach - if I recall correctly a precedent was set with someone who didn't handle a request in a timely manner and not handling it as an SAR because the request, although not formatted in the style or language of an SAR implied that it was one. Quite possible that our training told us that as a scare tactic though! (god I'm getting cynical). But as you say there's an audit trail regardless, so hopefully all covered - and that's the name of the game these days, covering your back as well as doing our actual jobs 1
TheHyperTechie Posted April 23 Posted April 23 All they need to specify is the need/want for their personal information = SAR Request It can be directed to any member of the org/school as well, you can't specify.
psydii Posted April 23 Posted April 23 Internally we have policies on response times which are shorter than those of an SAR. Also most "informal" request for data/info (but still technically, potential SARs) are actually by parents for data that is covered under The Education (Pupil Records) Regulation 2005 and that has a **SHORTER** deadline that those for an SAR. We'd been handling those for over a decade before GDPR came along, so only when a request falls outside of the scope of that does it get thrown over to the DPO to manage.
pete Posted April 23 Posted April 23 2 hours ago, psydii said: Internally we have policies on response times which are shorter than those of an SAR. Also most "informal" request for data/info (but still technically, potential SARs) are actually by parents for data that is covered under The Education (Pupil Records) Regulation 2005 and that has a **SHORTER** deadline that those for an SAR. We'd been handling those for over a decade before GDPR came along, so only when a request falls outside of the scope of that does it get thrown over to the DPO to manage. Academies can (https://ico.org.uk/for-the-public/schools/pupils-info/) reject that 15 school day timeframe and instead treat them as SARs. But they should to apply that across the board to all requests - not pick and choose. 15 school days is minimum 3 weeks. Maximum 9 weeks. If it's the start of a term, then the 30 days for a SAR gives you more wiggle room. 30 calendar days is 30 calendar days. If it's mid-December....
psydii Posted April 23 Posted April 23 Fair. But practically speaking as I said, mostly "can you give me the info you have about..." is for data in the education record and we acknowledge and process as such. If they need it urgently, they usually say so, and we adjust accordingly, and if the scope is wider than that... its thrown over to the DPO and it likely becomes an SAR. Of course if they cite the DPA that does steer it somewhat. The fun happens when an estranged parent cites the DPA, so its a SAR, but consent is then withheld.... but if they'd sumbitted under the ERR then they'd get it (because the ERR gives parents the right of access). Thankfully our senco is pretty good at navigating the politics of that sort of thing while keeping us out of the firing line.
Sylv3r Posted April 23 Posted April 23 As a trust of 48 schools, we probably on average have either one SAR or FOI a week. The week before a school holiday for some strange reason always seems to produce more.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now