Access to university record data logs

Question
Can I find out who has viewed, changed or downloaded my university record?

Short answer

There is no automatic legal right in England and Wales to be given a complete, ready-made “access log” showing every individual who has viewed, edited or downloaded your student record. However, you do have a data protection right to obtain a copy of your personal data and certain supplementary information, and in some circumstances that can include audit or log data that relates to you. What you can realistically obtain depends on what the university actually records in its systems and whether the log data counts as your personal data or someone else’s.

Your legal starting point: the right of access

Under the UK GDPR (Article 15) and the Data Protection Act 2018, you have the right of access, commonly called a subject access request or SAR. This entitles you to a copy of the personal data the university holds about you, plus supplementary information including the purposes of processing, the categories of data, the recipients or categories of recipient to whom your data has been or will be disclosed, and the source of the data where it did not come from you.

The right of access is a right to your personal data. It is not a general right to an activity or surveillance log about the university’s staff. That distinction is why you cannot simply demand “the name of everyone who looked at my file” as a freestanding entitlement.

When access and audit logs may be disclosable

Many university student information systems automatically record metadata such as when a record was viewed, amended or exported, and sometimes by whom. Whether you can obtain this through a SAR turns on whose personal data it is.

If a log entry records information about you, for example the date and time your record was changed, what field was amended, and the before and after values, that is your personal data and the university should consider disclosing it in response to a SAR. The ICO’s own guidance recognises that information logs can contain the data subject’s personal data, including dates, times and details of amendments made to records, and that this should be considered for disclosure.

The complication is the identity of the staff member who did the viewing or editing. That identifier is the personal data of the employee, not you. The university is entitled, and often obliged, to consider the rights of that third party. It may redact staff names or provide the information in a way that does not disclose an identifiable individual, unless it is reasonable to disclose without consent. So you may well be able to establish that a change was made, when, and what was changed, but not necessarily the name of the specific person who made it.

What you are unlikely to get

You are unlikely to obtain a full, itemised list of every person who has merely read or viewed your record. Read-only access is often not logged in the same way as amendments, and even where it is, the viewer’s identity is third-party data. Downloads and exports are more likely to leave a record, but again the identity of the person doing it is treated as their data, not yours.

Complaints and internal routes may be more effective

If your real concern is that someone has improperly accessed, altered or leaked your record, a SAR is not always the most effective tool, because of the redaction issues above. Consider these routes as well or instead.

1. Ask the university’s Data Protection Officer directly, in writing, whether an unauthorised access or amendment has occurred. Every university must have a DPO and publish contact details. Frame it as a concern about the integrity and security of your record rather than only as a request for logs.

2. If you believe there has been a personal data breach, or misuse of your data by a staff member, raise it as a data protection concern or complaint. The university must investigate, and can interrogate its own audit logs internally in a way you cannot.

3. Use the university’s internal complaints or student grievance procedure if the underlying issue is about the accuracy of your record or how it was handled.

Other data protection rights that may help

Alongside access, you have the right to rectification if your record is inaccurate, the right to restrict processing while a dispute about accuracy is resolved, and the right to erasure in limited circumstances. If your concern is that someone changed your record wrongly, the rectification right combined with a request for the university to investigate the change may achieve more than trying to extract log data.

How to make the request

1. Send a clear written request to the university’s DPO or data protection team. You can call it a subject access request. State your name, student or applicant number, and dates of study to help them locate your data.

2. Be specific about what you want. For example, ask for the personal data held about you including any audit, amendment or access log data that records changes made to your student record, together with the dates and details of those changes. Specificity helps and, where a controller processes a large amount of data, they can ask you to clarify the scope.

3. There is normally no fee. The university must respond without undue delay and within one month, extendable by up to two further months for complex or numerous requests, in which case they must tell you within the first month.

4. If they refuse or heavily redact, ask for their reasons and the exemptions relied on.

If you are not satisfied

If the university fails to respond properly, refuses without adequate justification, or you believe your data has been mishandled, you can complain to the Information Commissioner’s Office. It is usually best to complain to the university first and give it the chance to respond, as the ICO will generally expect you to have done so. In principle you can also enforce data rights through the courts, but that is rarely the sensible first step given cost and the availability of the ICO.

Key facts that would sharpen this answer

It would help to know what you are actually trying to find out and why. Whether you suspect someone altered a mark or record, whether you think your data was leaked, or whether you simply want transparency, will change the best approach. It would also help to know whether the university’s systems log the specific activity you are concerned about, which you can ask them directly, and whether any staff member’s identity is genuinely necessary for your purpose or whether confirmation that a change occurred, and its correction, would suffice.

Current sources checked

This answer draws on broad legal knowledge and checks current law, guidance and procedure against relevant sources.

What is the right of access? | ICOico.org.ukHow can we prepare for a subject access request (SAR)? | ICOico.org.ukInformation rights | ICOico.org.ukHow do we recognise a Part 3 subject access request (SAR) | ICOico.org.uk
Verify important information before relying on it.
Was this helpful?
0 people found this helpful

Ready to stop guessing?

The above is just an example answer. Sign up now to get personalised guidance and ask follow-up questions based on your own situation. Bring your legal issue, your contract, or your question. Lawyer Destroyer gives you clear, practical guidance so you can move forward with confidence.