Subject access requests (DSARs) at universities: a practical guide with templates
Students ask for their exam scripts and examiner comments. Employees in a dispute ask for every email that mentions them. Former research participants ask what was kept. This guide explains what Article 15 GDPR requires of a university, how the one-month deadline works, how to check identity proportionately, how to deal with exam material, emails, third-party data and research data, how to get data out of vendor systems, and when a request can be refused. Free Word templates for the main letters and a request log are included.
The short version
- Article 15 GDPR gives a right to confirmation, a copy of the personal data, and information about the processing. No form, wording or reason is required.
- Answer within one month of receipt. Extend by up to two months only where necessary, and say so within the first month (Article 12(3)).
- Check identity proportionately. University login or a reply from a known email address is often enough; a passport copy usually is not.
- Exam answers and examiner comments are the student's personal data (CJEU, Nowak). Exam questions are not.
- Redact other people's data rather than refusing (Article 15(4)). Search vendor systems too: processors must assist (Article 28(3)(e)).
- Research exemptions exist only where national law provides them under Article 89(2), and they vary by country.
- Download the free DSAR response templates (Word): acknowledgement, identity request, extension notice, response cover letter and request log.
Contents
- What Article 15 covers
- Recognising a request
- The one-month deadline and extensions
- Identity checks
- Student requests: exam scripts and examiner comments
- Staff requests, emails and third-party data
- Research data and national exemptions
- Searching vendor systems
- Manifestly unfounded or excessive requests
- A workable process
- The templates
- Sources
- About this page
1. What Article 15 covers
Article 15(1) GDPR gives the data subject the right to obtain confirmation of whether their personal data are being processed and, if so, access to the data and the following information [1]:
- the purposes of the processing;
- the categories of personal data;
- the recipients or categories of recipients, in particular in third countries;
- where possible, the envisaged storage period, or the criteria used to determine it;
- the rights to rectification, erasure, restriction and objection;
- the right to complain to a supervisory authority;
- where the data were not collected from the person, any available information on the source;
- the existence of automated decision-making, including profiling, and at least in those cases meaningful information about the logic involved and its consequences.
Article 15(2) adds information on safeguards for third-country transfers, and Article 15(3) requires a copy of the personal data. Further copies may carry a reasonable fee; electronic requests get an electronic answer in a commonly used form unless the person asks otherwise [1].
Two judgments of the Court of Justice shape the "copy". In F.F. (C-487/21, 4 May 2023), the Court held that the copy must be "a faithful and intelligible reproduction" of all the data, which can mean copies of extracts from documents, entire documents or database extracts where that is essential for the person to exercise their rights effectively, taking account of the rights and freedoms of others [4]. In FT (C-307/22, 26 October 2023), it held that the first copy must be provided free of charge even where the request is made for a reason unrelated to checking the lawfulness of processing [5].
The EDPB's Guidelines 01/2022 on the right of access (version 2.1, adopted 17 April 2023) are the main EU reference. They say the data subject does not need to give reasons, and that the right of access is distinct from rights of access to public documents [2]. That distinction matters in countries with strong freedom of information laws, such as Sweden: a request can be both, and each regime must be applied on its own terms.
The supporting information under Article 15(1) can draw on your record of processing activities and privacy notices, tailored to the person, as the EDPB notes [2]. A well-kept ROPA makes this part quick.
2. Recognising a request
The GDPR sets no formal requirements. According to the EDPB, it is enough for the person to say they want to know what personal data the controller processes about them; they do not have to mention Article 15 or the GDPR [2]. The controller should offer user-friendly channels, but the person may instead use an official contact point of the controller, and the controller is not obliged to act on requests sent to random or apparently incorrect addresses [2].
Validemic's analysis In a university, requests arrive at the student service desk, at HR, in a complaint to a head of department, or at the end of a long email to a supervisor. Train front-line staff to forward anything that looks like a request to the privacy team the same day, and publish one address for requests. A form can help but must never be a precondition.
3. The one-month deadline and extensions
Article 12(3) requires information on action taken "without undue delay and in any event within one month of receipt of the request" [1]. The EDPB explains how to count [2]:
- The period starts when the request reaches the controller through one of its official channels, even if the responsible person has not yet seen it.
- A request received on 5 March must be answered by 5 April at the latest. A request received on 31 August must be answered by 30 September, because there is no 31 September.
- If the last day falls on a weekend or public holiday, the controller has until the next working day.
- If the controller promptly asks for information needed to confirm identity, or asks the person to specify a request where Recital 63 allows this, the clock may be suspended until the answer arrives.
The period can be extended by two further months "where necessary, taking into account the complexity and number of the requests". The person must be told within the first month, with the reasons [1]. The EDPB stresses that the extension is an exception that should not be overused [2]. The EDPB also recommends confirming receipt in writing, stating the dates the period runs from and to [2]. The acknowledgement template does this.
Large requests. Recital 63 allows a controller that processes a large quantity of information about the person to ask them to specify the information or processing activities the request relates to [1]. The EDPB is clear that this must not be used to narrow the request: if the person confirms they want everything, they get everything, and when asking, the controller should explain the relevant processing so the person can choose [2]. Its example of an employee's general request (login data, building access, canteen, payroll, performance reviews) maps closely onto a university staff request.
4. Identity checks
Article 12(6) allows a controller with "reasonable doubts" about identity to request additional information necessary to confirm it [1]. Recital 64 says the controller should use all reasonable measures to verify identity, and should not retain data only to be able to answer future requests [1]. The EDPB's guidance is specific [2]:
- It is disproportionate to require a copy of an identity document where the person is already authenticated by the controller.
- Using a copy of an identity document creates a security risk and should be considered inappropriate unless necessary, suitable and in line with national law. Requesting ID card copies should generally not be considered an appropriate way of authentication.
- Alternatives include authentication the controller already uses, such as confirmation links or codes sent by email or text message.
- If a copy is genuinely needed, the person may redact information not needed to confirm identity, such as the photo or document number, unless national law requires a full copy.
Validemic's analysis Universities have an advantage: most requesters are current or former students or staff with an institutional account. A request from a university email address, or submitted through a single sign-on form, usually needs no further check. Former students can often be verified against data already held (student number, programme, years of study). Reserve document checks for unclear cases, and do not keep the copies after verification.
A request can also be made through a third party, such as a lawyer or other proxy, and the EDPB accepts that the authorisation to act may need verification [2]. Validemic's analysis Ask for evidence of authority, and do not treat a parent as acting for an adult student without the student's authorisation.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
5. Student requests: exam scripts and examiner comments
The leading case is Nowak (C-434/16, 20 December 2017). A trainee accountant asked for access to his exam script. The Court of Justice held that "the written answers submitted by a candidate at a professional examination and any comments made by an examiner with respect to those answers constitute personal data" [3]. It added that the rights of access and rectification do not extend to the exam questions, which are not as such the candidate's personal data (paragraph 58), and that rectification cannot be used to "correct" wrong answers after the event, because errors in answers show the candidate's level of knowledge rather than inaccuracy in the data [3].
Nowak was decided under the 1995 Data Protection Directive, but the definition of personal data is materially the same in the GDPR, and the EDPB relies on the judgment in its access guidelines. The EDPB also notes the Court's point that the data protection right of access applies regardless of whether a separate access regime exists, such as one in an examination procedure [2].
National variation. Member States can restrict Article 15 only through laws that meet Article 23 GDPR. Check your national law for exam-specific rules. Outside the EU, the UK provides a clear example of an exemption: under paragraph 25 of Schedule 2 to the Data Protection Act 2018, the access provisions do not apply to "information recorded by candidates during an exam", and exam marks requested before results are announced follow modified time limits [7].
In practice, a student request typically touches:
| Data | Typical location | Points to watch |
|---|---|---|
| Exam answers, marks, examiner comments | Assessment platform, learning platform, paper archive | Personal data under Nowak. Questions and model answers are not. Comments by second markers are included. |
| Study records, transcripts | Student information system | Usually straightforward. |
| Plagiarism and AI-detection reports | Text-matching vendor, case files | Similarity reports may contain other students' text: redact. Include scores and flags. |
| Proctoring recordings and flags | Proctoring vendor | Check vendor retention: data may be deleted before you ask. Include flags and reviewer notes. |
| Misconduct, complaint and appeal files | Case management, email | Witness statements: Article 15(4) balancing. |
| Learning analytics and risk scores | Analytics platform | Article 15(1)(h) information if automated decisions with significant effects are made. |
| Emails about the student | Staff mailboxes | See section 6. |
6. Staff requests, emails and third-party data
Staff requests are often linked to grievances, disciplinary cases or dismissal. That does not change the obligation. The EDPB says a request should not be regarded as excessive because the person intends to use the data to file further claims against the controller, without prejudice to national law that meets Article 23 [2]. Some national procedural rules on disclosure in litigation may apply alongside.
Emails. The EDPB says the personal data concerning the requester should not be interpreted overly restrictively and may include communication history involving incoming and outgoing messages [2]. The ICO makes the complementary point that being the recipient of an email does not mean the whole content of the email is the person's personal information [6]. Provide the requester's personal data, in context where needed to make it intelligible (as F.F. requires), and redact what is only about others.
Other people's data. Article 15(4) says the right to obtain a copy "shall not adversely affect the rights and freedoms of others" [1]. The EDPB says the controller must be able to demonstrate the adverse effect in the concrete situation, and that applying Article 15(4) should lead to leaving out or rendering illegible the affected parts, not to refusing the request altogether [2]. Colleagues' names in their professional role are often not a reason to redact; personal opinions about a third party, health details of a colleague or a confidential complainant's identity may be. Decide case by case and record the reasoning in the request log.
Searching. The EDPB expects a search of all IT systems and non-IT filing systems using criteria that match how data is structured, such as name, staff number or user name [2]. It also warns that search functions should not themselves compromise the privacy of others, for example the controller's employees. The ICO adds that you need not use expensive technical measures to recover properly deleted data, but should search archives and backups with the same effort you would for your own purposes, and that staff may need to search private devices or accounts where university business was done on them [6]. The assessment reflects the situation when the request was received: data already deleted under a retention policy cannot be provided, but there must be measures so that data are not erased while the request is being dealt with [2].
7. Research data and national exemptions
Research participants have the right of access like anyone else. The GDPR itself contains no general research exemption from Article 15. Article 89(2) instead allows Union or Member State law to provide derogations from Articles 15, 16, 18 and 21 for scientific or historical research or statistics, subject to the safeguards in Article 89(1), but only "in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes" and where the derogations are necessary [1]. Article 89(3) allows similar derogations for archiving in the public interest.
Whether and how a derogation exists therefore depends on the country. Two examples:
- Germany. Section 27(2) of the Federal Data Protection Act (BDSG) limits the rights in Articles 15, 16, 18 and 21 to the extent they are likely to render impossible or seriously impair the research purposes, and says the Article 15 right does not apply where the data are necessary for scientific research and providing information would involve disproportionate effort [8]. Note that the BDSG applies to public bodies of the federal states (Länder) only where data protection is not governed by state law, so a public university will usually need to check its state's data protection act as well.
- The Netherlands. Article 44 of the GDPR Implementation Act (UAVG) allows institutions or services for scientific research or statistics to set aside Articles 15, 16 and 18 where the necessary safeguards ensure the data are used only for research or statistical purposes [9].
Validemic's analysis Treat a research exemption as narrow. It must exist in your national law, its conditions must be met in the specific project, and the safeguards must be in place. Pseudonymised research data are still personal data, and a participant who can be re-identified through the key held by the research team can usually be answered. Where an exemption is used, record the legal provision and the reasons, and tell the participant. Our guide on GDPR and AI tools in research covers research safeguards more broadly.
8. Searching vendor systems
The university remains the controller for data its vendors process on its behalf. Article 28(3)(e) requires the processing contract to oblige the processor to assist the controller, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise data subject rights [1]. The EDPB says the search "naturally has to be extended" to data processed by the processor, and that controllers and processors should build in functions that make retrieval possible [2].
In practice:
- Know which vendors hold what. Use the recipients column of your ROPA to list candidate systems for a student or staff request.
- Check the DPA before you need it. Does it set a response time for assistance, and is assistance included in the price? Our DPA checker looks for the Article 28(3)(e) clause.
- Prefer self-service exports. Many platforms let administrators export a user's data. Test this during procurement, not during the first request.
- Watch vendor retention. Proctoring, chat and AI tools may keep data only briefly, or for much longer than the university expects. Both affect the answer.
- Include subprocessors. Data held by a subprocessor is still within the scope of the request.
Our vendor assessment guide includes data subject rights assistance in its checklist.
9. Manifestly unfounded or excessive requests
Article 12(5) allows a controller to charge a reasonable fee or refuse to act where a request is "manifestly unfounded or excessive, in particular because of their repetitive character", and puts the burden of demonstrating this on the controller [1]. The EDPB reads both terms narrowly [2]:
- Manifestly unfounded means the requirements of Article 15 are clearly and obviously not met on an objective approach. There is "only very limited scope" for this ground.
- Excessive mainly concerns repetitive requests, judged against reasonable intervals and how often the data change. The effort required cannot on its own make a request excessive.
- Not grounds for refusal: no reasons given, the controller considers the request meaningless, impolite language, or an intention to use the data for further claims against the controller.
- Possible grounds: offering to withdraw the request in return for a benefit, or requests made with the sole intent of causing disruption, for example as part of a campaign of weekly requests.
If you refuse in whole or in part, Article 12(4) requires you to tell the person, without delay and at the latest within one month, the reasons and the possibility of complaining to a supervisory authority and seeking a judicial remedy [1]. Document the facts behind the decision, as the EDPB recommends [2]. The response cover letter template includes this wording.
10. A workable process
- Log the request on the day it arrives, with the date of receipt and the deadline.
- Acknowledge it, stating the response period (template A).
- Verify identity only if there are reasonable doubts, proportionately (template B).
- Clarify scope only for large data sets, explaining what the university holds.
- Search central systems, the relevant faculty and department, mailboxes of named staff, paper files and vendor systems. Ask vendors for exports early.
- Review for third-party data, legal privilege and applicable national exemptions. Record each redaction decision.
- Extend only where necessary, before the first month ends (template C).
- Respond with the data and the Article 15(1) and (2) information in an intelligible form (template D).
- Close the log entry and keep the file for your retention period for request records.
Validemic's analysis If extensions are common, the EDPB's view is that procedures need improving [2]. The usual causes in universities are unclear ownership between central services and faculties, and not knowing which vendors hold data. Both are fixable before the next request.
11. The templates
The DSAR response templates are a Word document containing:
- A. Acknowledgement of receipt, with the response period.
- B. Request for information to confirm identity, proportionate and with the clock rule explained.
- C. Extension notice under Article 12(3), with reasons.
- D. Response cover letter with the Article 15(1) and (2) information, a redaction note and the complaint wording required for refusals.
- E. A request log table and a search checklist for typical university systems.
The templates follow Articles 12 and 15 GDPR and the EDPB Guidelines 01/2022 as read on 7 October 2026. National law can add rules, for example on exams, research or public sector records. They are not legal advice.
Sources
- Regulation (EU) 2016/679 (GDPR), Articles 12, 15, 23, 28 and 89 and Recitals 63 and 64, Official Journal text (retrieved 7 October 2026).
- EDPB Guidelines 01/2022 on data subject rights: right of access, version 2.1, adopted 17 April 2023 (retrieved 7 October 2026).
- Court of Justice, Case C-434/16, Nowak v Data Protection Commissioner, judgment of 20 December 2017 (retrieved 7 October 2026).
- Court of Justice, Case C-487/21, F.F. v Österreichische Datenschutzbehörde, judgment of 4 May 2023 (retrieved 7 October 2026).
- Court of Justice, Case C-307/22, FT v DW, judgment of 26 October 2023 (retrieved 7 October 2026).
- ICO: How do we find and retrieve the relevant information? (UK guidance, retrieved 7 October 2026).
- UK Data Protection Act 2018, Schedule 2, Part 4, paragraph 25 (retrieved 7 October 2026).
- Germany: Federal Data Protection Act (BDSG), Section 27, official English translation (retrieved 7 October 2026).
- Netherlands: Uitvoeringswet Algemene verordening gegevensbescherming (UAVG), Article 44 (retrieved 7 October 2026).
About this page
Sources checked on 7 October 2026. The GDPR and the judgments were read in their official EU versions, the EDPB guidelines in the adopted version 2.1, and national laws on their official government sites. The UK material is included as an example of national variation; the UK is outside the EU and applies the UK GDPR. Statements labelled as Validemic's analysis are our interpretation. This page is not legal advice. If you spot an error or know of a national rule we should mention, please contact us and we will correct it.
Frequently asked questions
How long does a university have to answer a subject access request?
Without undue delay and at the latest within one month of receipt (Article 12(3) GDPR). The EDPB's example: a request received on 5 March must be answered by 5 April. The period can be extended by two further months where necessary because of complexity or the number of requests, but the requester must be told within the first month, with reasons.
Do students have the right to see their exam scripts?
Under EU law the answers a candidate writes and the examiner's comments on them are the candidate's personal data, as the Court of Justice held in Nowak (C-434/16), so the right of access applies to them. The exam questions themselves are not the candidate's personal data. National law can restrict access within the limits of Article 23 GDPR, and some countries do; the UK, for example, exempts exam scripts.
Can we ask for a copy of a passport before answering?
Only if you have reasonable doubts about identity (Article 12(6)) and the check is proportionate. The EDPB says a copy of an identity document should generally not be considered an appropriate way to authenticate, and that it is disproportionate where the person is already authenticated, for example through the university's own login.
Does a DSAR give access to every email that mentions the person?
It gives access to the requester's personal data, which can include emails they sent, received or are discussed in. It does not automatically cover the whole content of every email; information about other people may need to be redacted under Article 15(4). The EDPB says this should lead to redaction, not to refusing the request altogether.
Do we have to search systems run by our vendors?
Yes. The university is the controller and remains responsible. Processors must assist the controller in responding to data subject requests under Article 28(3)(e), and the EDPB says the search naturally has to include data processed by the processor.
Can a request be refused because the person is in a dispute with the university?
No, not for that reason alone. The EDPB says a request should not be regarded as excessive because no reasons are given or because the person intends to use the data for further claims against the controller, subject to national law that meets Article 23 GDPR. Refusal is possible only for manifestly unfounded or excessive requests, and the university bears the burden of demonstrating that.
Can we charge a fee?
Not for the first copy. The Court of Justice confirmed in FT (C-307/22) that the first copy must be free, even where the request is made for reasons other than checking the lawfulness of processing. A reasonable fee is possible for further copies (Article 15(3)) or for manifestly unfounded or excessive requests (Article 12(5)).