Manage GDPR requests
Use this when... a parent, student, tutor, employee, or other contact asks to access, correct, delete, export, restrict, or understand personal data held in TuitionFlow.
Before you start... follow your organisation data protection process. GDPR requests can carry legal deadlines and identity-check requirements. If you are not the data protection owner, record the request and escalate it promptly rather than trying to resolve it informally.
Use Compliance to track GDPR requests and their status.
Types of GDPR requests
Common requests include subject access, correction, deletion, restriction, portability, objection, and questions about how data is used. The first admin task is to classify the request and make sure the right owner sees it.
Do not promise deletion, export, or correction before identity, authority, retention requirements, and connected records have been checked. Tuition businesses may need to retain some records for finance, safeguarding, legal, or contractual reasons.
Step 1: Record the request
Open Compliance or the relevant person record and record the request date, requester, person the request concerns, request type, source, and owner. If the request arrived by message, keep the original message available but track the durable workflow in the GDPR area.
If a GDPR request arrives through Messages, move the workflow into Compliance for tracking.
Step 2: Verify identity and authority
Check that the requester is entitled to make the request. A parent may be authorised for a child, but that can depend on age, relationship, and organisational policy. A tutor or employee request should be handled according to staff data rules.
Step 3: Scope the affected data
Identify which records may be involved: family, parent, student, tutor, employee, invoices, payments, messages, lesson reports, assignments, consent, safeguarding, leads, forms, documents, and audit history. Some data may sit in integrations or exports as well as TuitionFlow.
Step 4: Complete and record the outcome
When the responsible owner completes the request, record the action taken, date completed, response route, and any data retained with a reason. Keep the record factual and avoid copying unnecessary personal data into the outcome note.
Common mistakes
Handling requests only in messages. Use the GDPR workflow so deadlines and ownership are visible.
Deleting records too quickly. Check retention, finance, safeguarding, and legal requirements first.
Ignoring linked systems. Integrations, exports, and documents may also contain relevant data.
Sharing data without identity checks. Verify the requester before providing personal information.
Troubleshooting
The request is unclear: acknowledge it according to your process and ask for clarification without delaying escalation.
Records span several people: separate the data subjects and avoid exposing one person's information to another without authority.
You cannot complete the request in TuitionFlow alone: record the external systems that need review and assign owners.
Deadline management
Set a review date or due date as soon as the request is received. If the request is complex, follow your organisation process for extensions or legal review. Do not let the request sit in an inbox without ownership.
Communicating with the requester
Keep communication clear and cautious. Confirm receipt according to your process, explain that the request is being reviewed, and avoid promising an outcome before identity and scope are confirmed. If the request is broad, ask for clarification where appropriate.
Corrections and deletion
If data is corrected, record what was changed and when. If deletion is requested, check whether records must be retained for invoices, safeguarding, contracts, complaints, tax, or audit. Where data cannot be deleted, record the reason and follow your organisation response process.
Final QA
Before closing the request, check that all relevant systems and exports have been considered. If a connected accounting, payment, calendar, or messaging tool contains related data, note whether it was reviewed or assigned separately.
Internal visibility
Keep GDPR request visibility narrow. Admins may need to know that a request exists, but they usually do not need to see all personal data gathered for the response. Share status and ownership without spreading the underlying data unnecessarily.
Response record
When the response is sent, record the completion date, response route, and owner. Do not paste full exported data back into the tracking note.
Next actions
After recording a GDPR request, assign it to the data protection owner, check identity and scope, and track the final response in the compliance record.


