Introduction to Handling a Child Subject Access Request
When a parent asks for a copy of their child’s personal data, the request can seem straightforward. However, for many organisations, particularly those in health, education, or social care, this is one of the most complex challenges in data protection. A child Subject Access Request (SAR) requires a careful balancing act between a parent's desire for information and a child’s own right to privacy and protection.
This area is often misunderstood. It is not governed by a single rule, but by the interaction of three distinct legal concepts: the UK General Data Protection Regulation (UK GDPR), statutory exemptions in the Data Protection Act 2018, and the common law duty of confidentiality. Misinterpreting how these fit together can lead to incorrect disclosures or refusals.
This guide provides a clear, risk-based framework for handling these requests. It will help you navigate your obligations, protect the welfare of the child, and make accountable, well-documented decisions. We will move beyond legal jargon to offer practical steps for your organisation.
The Starting Point: A Child’s Right of Access Under UK GDPR
Under UK GDPR, the right of access to personal data belongs to the individual. This principle applies equally to children. A child has the right to request a copy of the information an organisation holds about them. The key question when a parent makes a request is whether they are the appropriate person to exercise this right on the child’s behalf.
The answer depends on the child’s level of understanding, often referred to as their competence. There is no specific age in the UK GDPR when a child is automatically deemed competent. Instead, you must make a judgement based on the individual child. The Information Commissioner’s Office (ICO) suggests that children are generally considered mature enough to understand their rights from around the age of 12 or 13, but this is a guideline, not a strict rule.
If a child is considered competent, they should typically be the one to exercise their right of access. A parent can only act on their behalf with the child’s explicit consent. If the child is not competent to understand their rights, a parent or guardian with parental responsibility can make a request on their behalf. You must assess this on a case-by-case basis.
Confidentiality vs Data Protection: Two Separate Duties
A common point of confusion is the difference between the duty of confidentiality and data protection obligations. While they are related, they are not the same. Understanding this distinction is crucial for making the right decision when responding to a child Subject Access Request.
The UK GDPR Right of Access
This is a statutory right granted by data protection law. It gives individuals a right to obtain a copy of their personal data from an organisation. Any refusal to provide this data must be justified by a specific, named exemption within the Data Protection Act 2018. It is a legal obligation focused on transparency and individual control over personal information.
The Common Law Duty of Confidentiality
This duty arises from the relationship between an individual and a professional, such as a doctor, therapist, or social worker. It is based on the trust that sensitive information shared within that relationship will not be disclosed without permission. This duty exists independently of the UK GDPR. For example, a doctor’s duty to protect patient confidentiality is a long-standing ethical and legal principle.
Think of it like this: a child’s school record contains their personal data, which is covered by the UK GDPR. However, a private conversation a child has with a school counsellor, where they share sensitive feelings, is also protected by a duty of confidence. When responding to a SAR, you must consider both aspects.
When Can You Legally Withhold Information?
Refusing to disclose information in response to a SAR is not a decision to be taken lightly. You cannot withhold data simply because it is sensitive or because a child shared it with an expectation of privacy. You must rely on a specific legal justification.
Statutory Exemptions in the Data Protection Act 2018
The Data Protection Act 2018 contains specific exemptions that allow or require you to withhold personal data in certain circumstances. For a child Subject Access Request, the most relevant exemptions often relate to:
- Serious Harm: You can withhold health, education, or social work data if disclosing it would be likely to cause serious harm to the physical or mental health of the child or another person.
- Social Work Data: Information related to social care functions can be withheld if its disclosure would be likely to prejudice the carrying out of those functions.
These decisions require careful, professional judgement. You must document your reasoning, explaining exactly why you believe the exemption applies. You can find official information on these rules in the ICO's guidance on the right of access.
Protecting Third-Party Data
A child’s records often contain information about other people, such as siblings, parents, or teachers. This is the personal data of a third party. You must not disclose third-party data unless you have that person’s consent, or it is reasonable to disclose it without their consent. In most cases, this will mean redacting (blacking out) names and other identifying information of third parties.
A Step-by-Step Guide to Responding to a Child SAR
A structured approach ensures you meet your legal obligations while protecting the child. This process builds upon the standard process for handling a Subject Access Request, with additional considerations for children's data.
- Verify the Requester: Confirm the identity of the person making the request and their parental responsibility for the child.
- Assess the Child’s Competence: Make a reasonable judgement about whether the child can understand their data protection rights. Document your assessment. If the child is competent, you may need their permission to proceed.
- Locate and Collate All Data: Conduct a thorough search for all personal data relating to the child across your organisation’s systems, including emails, notes, and database records.
- Review the Information Carefully: This is the most critical stage. Scrutinise every piece of data. Identify any information that may be covered by an exemption (like serious harm) and any data that identifies third parties.
- Document Every Decision: For any information you decide to withhold or redact, record which exemption you are applying and why. This documentation is essential for accountability.
- Consider the Duty of Confidentiality: Separately, assess whether any disclosure would breach a duty of confidence owed to the child. This might apply to notes from counselling sessions, for example.
- Prepare and Send the Response: Compile the disclosable information. Write a clear covering letter that explains you have provided the child's personal data, and briefly state that some information has been withheld where a legal exemption applies. You are not required to specify which exemption applies to each redaction. Deliver the response securely within the one-month time limit.
Myth vs Fact: Children’s Data and Confidentiality
Myth: “A child told me something ‘in confidence’, so I can automatically refuse a parent's SAR under UK GDPR.”
Fact: This confuses two separate legal concepts. An expectation of confidentiality does not create a UK GDPR exemption. To withhold the information, you must determine if a specific statutory exemption from the Data Protection Act 2018 applies (e.g., disclosure would likely cause serious harm) or if disclosure would unlawfully breach the common law duty of confidentiality. Your decision must be based on one of these formal legal grounds, not just an informal promise.
Frequently Asked Questions (FAQ)
What if the child’s parents are separated?
Unless a court order says otherwise, both parents with parental responsibility have an equal right to make a SAR. You should handle each request independently, applying the same checks for competence, exemptions, and third-party data for both.
Is there a set age when a child is competent?
No. The UK GDPR and the ICO avoid a strict age limit. You must assess each child’s capacity to understand what a SAR is and the implications of releasing their data. This will vary depending on the child’s age, maturity, and circumstances.
What does ‘serious harm’ mean in practice?
Serious harm is a high threshold. It means more than just distress or upset. According to the ICO's guidance on children's information, it must be a significant and weighty risk to the physical or mental health of the child or another person. This judgement should ideally be made by, or with input from, a relevant professional, like a clinician or social worker.
Do I have to explain why I have redacted information?
You should inform the requester that some information has been removed in line with data protection law. However, you do not have to detail the specific exemption for each piece of redacted text, as doing so could reveal the very information you are trying to protect.
A Balanced and Accountable Approach
Handling a child Subject Access Request correctly is not about creating barriers for parents. It is about fulfilling your legal duties in a way that prioritises the safety, privacy, and well-being of the child. The law requires a careful balancing of rights, not a simple tick-box exercise.
By separating the concepts of access rights, confidentiality, and statutory exemptions, you can make clear and defensible decisions. Always document your reasoning thoroughly, as this forms the basis of your accountability under UK GDPR. Being transparent from the outset by designing clear and effective privacy notices for both children and parents is also fundamental. For high-risk processing involving children's sensitive data, conducting a Data Protection Impact Assessment is a crucial step in managing these risks proactively.
If you are facing a complex request and need expert guidance, our data protection consultancy services can provide the specialist support you need to ensure compliance and safeguard the individuals you serve.