Skip to main content

Manage GDPR requests

Manage GDPR requests

Use this when... a parent, student, tutor, employee, or other contact asks to access, correct, delete, export, restrict, or understand personal data held in TuitionFlow.

Before you start... follow your organisation data protection process. GDPR requests can carry legal deadlines and identity-check requirements. If you are not the data protection owner, record the request and escalate it promptly rather than trying to resolve it informally.

The TuitionFlow compliance dashboard showing GDPR, consent, documents, audit activity, and related compliance areas.

Use Compliance to track GDPR requests and their status.

Types of GDPR requests

Common requests include subject access, correction, deletion, restriction, portability, objection, and questions about how data is used. The first admin task is to classify the request and make sure the right owner sees it.

Do not promise deletion, export, or correction before identity, authority, retention requirements, and connected records have been checked. Tuition businesses may need to retain some records for finance, safeguarding, legal, or contractual reasons.

Step 1: Record the request

Open Compliance or the relevant person record and record the request date, requester, person the request concerns, request type, source, and owner. If the request arrived by message, keep the original message available but track the durable workflow in the GDPR area.

The TuitionFlow messages area where GDPR requests may arrive from parents, students, tutors, or staff.

If a GDPR request arrives through Messages, move the workflow into Compliance for tracking.

Step 2: Verify identity and authority

Check that the requester is entitled to make the request. A parent may be authorised for a child, but that can depend on age, relationship, and organisational policy. A tutor or employee request should be handled according to staff data rules.

Step 3: Scope the affected data

Identify which records may be involved: family, parent, student, tutor, employee, invoices, payments, messages, lesson reports, assignments, consent, safeguarding, leads, forms, documents, and audit history. Some data may sit in integrations or exports as well as TuitionFlow.

Step 4: Complete and record the outcome

When the responsible owner completes the request, record the action taken, date completed, response route, and any data retained with a reason. Keep the record factual and avoid copying unnecessary personal data into the outcome note.

Common mistakes

  • Handling requests only in messages. Use the GDPR workflow so deadlines and ownership are visible.

  • Deleting records too quickly. Check retention, finance, safeguarding, and legal requirements first.

  • Ignoring linked systems. Integrations, exports, and documents may also contain relevant data.

  • Sharing data without identity checks. Verify the requester before providing personal information.

Troubleshooting

The request is unclear: acknowledge it according to your process and ask for clarification without delaying escalation.

Records span several people: separate the data subjects and avoid exposing one person's information to another without authority.

You cannot complete the request in TuitionFlow alone: record the external systems that need review and assign owners.

Deadline management

Set a review date or due date as soon as the request is received. If the request is complex, follow your organisation process for extensions or legal review. Do not let the request sit in an inbox without ownership.

Communicating with the requester

Keep communication clear and cautious. Confirm receipt according to your process, explain that the request is being reviewed, and avoid promising an outcome before identity and scope are confirmed. If the request is broad, ask for clarification where appropriate.

Corrections and deletion

If data is corrected, record what was changed and when. If deletion is requested, check whether records must be retained for invoices, safeguarding, contracts, complaints, tax, or audit. Where data cannot be deleted, record the reason and follow your organisation response process.

Final QA

Before closing the request, check that all relevant systems and exports have been considered. If a connected accounting, payment, calendar, or messaging tool contains related data, note whether it was reviewed or assigned separately.

Internal visibility

Keep GDPR request visibility narrow. Admins may need to know that a request exists, but they usually do not need to see all personal data gathered for the response. Share status and ownership without spreading the underlying data unnecessarily.

Response record

When the response is sent, record the completion date, response route, and owner. Do not paste full exported data back into the tracking note.

Next actions

After recording a GDPR request, assign it to the data protection owner, check identity and scope, and track the final response in the compliance record.

Did this answer your question?