top of page

      ⭐ THE MASTER INTRODUCTION FOR                                            PARENTS

(Read this BEFORE sending any letters)

This guide explains:

  • why the letters exist,

  • how the process works,

  • what each letter does,

  • when to send each letter,

  • who to send them to,

  • how long replies take,

  • what to expect,

  • what to do if the school refuses,

  • what to do if they try to punish your child,

  • where you stand legally,

  • and whether letters can be sent together.

This is written in plain English, for real parents, with no jargon.

⭐ THE TRUTH PARENTS NEED TO KNOW FIRST

Schools and trusts have introduced:

  • phone bans,

  • confiscation policies,

  • biometric systems,

  • digital behaviour platforms,

  • identity systems,

  • external data processors,

  • automated communication apps,

  • behaviour scoring systems,

  • retention systems,

without giving parents proper legal information or lawful consent forms.

Most parents think these are “just school rules.”

They are not.

They are legal agreements, data‑processing activities, and contract‑based systems — and parents were never properly included.

Your child’s phone is personal property. Your child’s biometric data is sensitive personal data. Your child’s behaviour logs are digital records. Your child’s identity profile is contract‑linked data.

Schools cannot:

  • confiscate personal property without lawful authority,

  • process biometric data without explicit consent,

  • process behaviour data without informed consent,

  • enforce policies that were never agreed to,

  • penalise parents for asserting rights,

  • penalise children for a parent’s legal position.

This is why the 8‑letter process exists.

It is not aggressive. It is not confrontational. It is not anti‑school. It is simply parents asserting their rights under:

  • Consumer Rights Act 2015

  • Data Protection Act 2018

  • UK GDPR

  • Human Rights Act 1998 (Article 8)

  • Children Act 1989

  • Contract law principles

  • Property law principles

  • Unfair Terms Regulations

These are public laws, government‑published, non‑political, and fully allowed for parents to use.

⭐ THE 8‑LETTER PROCESS — SIMPLE STORY FOR PARENTS

Letter 1 — You object.

You tell the school:

  • I do not accept the phone ban as lawful.

  • I do not accept confiscation.

  • I do not accept biometric or digital processing without consent.

  • Show me the legal authority.

If they refuse, ignore you, or send policy instead of law…

Letter 2 — You escalate to the trust.

You ask the trust:

  • Who approved these systems?

  • Who approved biometrics?

  • Who approved confiscation?

  • Where is the legal authority?

  • Where is the parental consent?

If they refuse or ignore you…

Letter 3 — You assert the law.

You state:

  • consent was not informed,

  • consent was not freely given,

  • consent was not specific,

  • therefore enforcement is unlawful.

If they still push…

Letter 4 — You demand evidence (SAR).

This forces them to reveal:

  • every system used,

  • every behaviour log,

  • every biometric record,

  • every external processor,

  • every retention period.

If they escalate…

Letter 5 — You remove their power (Deletion Demand).

This legally forces deletion of:

  • identity data,

  • behaviour logs,

  • biometric data,

  • phone‑related incidents.

Once deleted, they cannot enforce anything digitally.

If they still push…

Letter 6 — You block all processing (Consent Withdrawal).

Processing must stop immediately.

If they still push…

Letter 7 — You expose everything (Plain‑English Request).

This forces them to rewrite:

  • policies,

  • contracts,

  • system descriptions,

in plain English.

If they STILL push…

Letter 8 — You unite parents (Collective Action).

This shuts the policy down.

Schools cannot fight organised parents.

⭐ WHEN TO SEND EACH LETTER (VERY CLEAR)

Letter 1 — Send immediately.

This starts the process.

Letter 2 — Send ONLY if Letter 1 is ignored or refused.

Letter 3 — Send ONLY if Letter 2 is ignored or refused.

Letter 4 (SAR) — You have TWO options:

Option A — Send SAR at the correct escalation point (after Letter 3).

This is the standard path.

Option B — Send SAR at the same time as Letter 1.

Parents CAN do this if they want to know:

  • which vendors have their child’s data,

  • which systems are used,

  • what biometric data exists,

  • what behaviour logs exist,

  • what external processors exist.

This is allowed.

Letter 5 (Deletion Demand) — You have TWO options:

Option A — Send after SAR reply.

This is the standard path.

Option B — Send at the same time as SAR.

Parents CAN do this if they want to:

  • force deletion early,

  • block digital enforcement immediately,

  • remove behaviour logs,

  • remove biometric data,

  • remove identity tokens.

This is allowed.

Letter 6 — Send if they still push after deletion or SAR.

Letter 7 — Send if they still push after consent withdrawal.

Letter 8 — Send if they STILL push after everything.

⭐ CAN PARENTS SEND MULTIPLE LETTERS AT ONCE?

✔ YES — SAR + Deletion Demand can be sent together.

This is common and effective.

✔ YES — SAR + Consent Withdrawal can be sent together.

This blocks all processing immediately.

✔ YES — Letter 1 + SAR can be sent together.

This gives parents early access to data.

❌ NO — Do NOT send all 8 letters at once.

It removes the escalation power.

⭐ HOW LONG THEY HAVE TO REPLY (EXPANDED)

Letter 1 & Letter 3 (School)

5–10 working days Schools usually reply quickly because these letters challenge their authority.

Letter 2 (Trust)

10–20 working days Trusts take longer because they need legal input.

Letter 4 (SAR)

30 days — legally required They cannot delay. They cannot refuse. They cannot ignore. They must provide:

  • all data,

  • all systems,

  • all vendors,

  • all processors,

  • all retention periods.

Letter 5 (Deletion Demand)

Within 30 days They must delete:

  • identity data,

  • behaviour logs,

  • biometric data,

  • external processor copies.

Letter 6 (Consent Withdrawal)

Processing must stop immediately. Confirmation usually within 10–20 days.

Letter 7 (Plain‑English Request)

20–30 days They must rewrite policies clearly.

Letter 8 (Collective Action)

Within 10 days Schools respond fast when multiple parents act together.

⭐ WHO TO SEND LETTERS TO (EMAIL IS BEST)

Email is legally valid.

It is:

  • timestamped,

  • traceable,

  • easy to escalate,

  • easy to prove.

Letter 1

Headteacher Deputy Head School Admin Office Behaviour Lead (optional)

Letter 2

Trust CEO Trust Governance Team Trust Data Protection Officer Trust Complaints Email

Letter 3

Headteacher Trust Governance Team Trust Data Protection Officer

Letter 4 (SAR)

Trust Data Protection Officer School Data Protection Officer

Letter 5 (Deletion Demand)

Trust Data Protection Officer School Data Protection Officer

Letter 6 (Consent Withdrawal)

Headteacher Trust Governance Team Trust Data Protection Officer

Letter 7 (Plain‑English Request)

Trust Governance Team Trust Legal/Compliance Team

Letter 8 (Collective Action)

Headteacher Trust CEO Trust Governance Team Trust Data Protection Officer

⭐ WHAT IF THEY TRY TO PUNISH THE PARENT OR CHILD?

They cannot. Legally. At all.

Punishing a child because a parent asserted legal rights is victimisation, which is unlawful under:

  • Equality Act 2010

  • Human Rights Act 1998 (Article 8)

  • Children Act 1989

  • Education Act principles

  • Safeguarding rules

Punishing a parent for asserting legal rights is also unlawful.

If they try:

  • the punishment becomes invalid,

  • the behaviour record becomes invalid,

  • the sanction becomes invalid,

  • the policy becomes unenforceable,

  • the trust becomes legally exposed.

You then escalate to:

  • Trust complaint

  • Governor complaint

  • Local authority

  • ICO (if data involved)

  • DfE

  • Ofsted (if safeguarding breached)

Schools almost NEVER escalate once parents reach Letter 4.

⭐ WHERE THE PARENT STANDS LEGALLY

Parents stand on:

  • Consumer Rights Act 2015

  • Data Protection Act 2018

  • UK GDPR

  • Human Rights Act 1998

  • Children Act 1989

  • Contract law principles

  • Property law principles

  • Unfair Terms Regulations

Schools stand on:

  • internal policy

  • trust rules

  • behaviour frameworks

Internal policy cannot override statutory law.

Parents are legally protected. Children are legally protected. Schools cannot retaliate.


⭐ NOW WE BEGIN THE LETTERS


 

⭐ LETTER 1 — PARENT OBJECTION LETTER (PHONE BAN + BIOMETRICS + SYSTEMS)

To: Headteacher and Chair of Governors / Trust Board

Subject: Formal objection to phone ban, biometric use, and digital behaviour systems

Dear [Headteacher / Chair],

I am writing to formally object to the school’s mobile phone ban, the confiscation of my child’s personal device, and any use of biometric or digital behaviour systems applied to my child without my informed consent. This letter is to put you on notice that I do not accept the legal validity of these practices as currently implemented.

Under the Consumer Rights Act 2015, any term that restricts or removes a consumer’s personal property must be fair, transparent, and agreed to. I have not been presented with any clear, written agreement that lawfully authorises the school to confiscate my child’s phone, retain it, or impose sanctions linked to its possession or use. My child’s phone is personal property, and neither my child nor I have entered into any contract that permits the school to interfere with that property in the way current policy suggests.

Under UK common law and basic property law principles, an item of personal property cannot be taken or retained without lawful authority, parental consent, or a clear statutory power. I am not aware of any Act of Parliament that grants schools the right to permanently or conditionally confiscate personal devices, nor to penalise a child or parent for refusing to surrender such property. Any confiscation beyond a brief, proportionate classroom management measure risks being unlawful.

Under the Data Protection Act 2018 and UK GDPR, you are required to provide clear, accessible information before processing a child’s personal data. This includes data collected and processed through digital behaviour platforms, identity systems, communication apps, and any biometric tools (such as fingerprints or facial recognition). I have not been given full, plain‑English explanations of what data is being taken, how it is used, who it is shared with, how long it is kept, or what systems are involved. Consent obtained without this information is not informed, specific, or freely given, and therefore cannot be relied upon as a lawful basis for processing.

If my child’s data has been processed through any digital behaviour system (for example, ClassCharts, SIMS, Arbor, Bromcom, CPOMS, MyConcern, Satchel One, or similar), or any biometric system (for example, fingerprint or facial recognition for access, payments, or registration), without my explicit, informed consent, this may constitute unlawful processing under UK GDPR and the Data Protection Act 2018. I do not consent to my child’s data being used to record, track, or enforce mobile phone‑related behaviour incidents.

Under Article 8 of the Human Rights Act 1998, my family has the right to respect for private and family life, which includes personal autonomy and the use of personal property. A blanket phone ban, enforced through sanctions and digital recording, interferes with this right. Any such interference must be lawful, necessary, and proportionate. I do not accept that the current policy meets these tests, particularly where it extends beyond the school day or attempts to control possession rather than misuse.

Under the Children Act 1989, I retain parental responsibility for my child’s welfare, property, and communication. The school cannot override parental responsibility without statutory authority or informed parental consent. I have not given such consent for the school to control my child’s access to their own phone as a matter of blanket policy, nor for the school to use digital or biometric systems to enforce that policy.

Under contract law principles, a valid contract requires offer, acceptance, consideration, capacity, and intention. My child does not have legal capacity to enter corporate contracts. I have not been presented with any clear offer of terms regarding phone confiscation, biometric use, or digital behaviour systems, nor have I accepted such terms. There is therefore no binding contract that allows the school or trust to impose these conditions on my child or on me as a parent.

For these reasons, I do not accept:

  • that the school has lawful authority to confiscate and retain my child’s phone as a matter of policy;

  • that the school has lawful authority to penalise my child or me for possession of a phone;

  • that the school has lawful authority to process my child’s data through digital behaviour or biometric systems without my informed consent;

  • that any sanctions, detentions, or recorded behaviour incidents linked to phone possession or biometric use are lawful or valid.

I require the following:

  1. Confirmation in writing of the legal basis (including specific Acts and statutory powers) relied upon to confiscate and retain pupils’ personal phones beyond immediate classroom management.

  2. A full list of all digital behaviour, identity, communication, and biometric systems used in relation to my child, including the names of external providers and a description of what data is processed.

  3. Copies of any policies, contracts, or agreements that you believe authorise the school or trust to enforce the phone ban and use biometric or digital systems on my child.

  4. Confirmation that no further sanctions or penalties will be applied to my child or to me as a parent in relation to phone possession, pending lawful clarification of these issues.

This letter is not an attack on staff. It is a formal assertion of my rights and my child’s rights under Consumer Rights Act 2015, Data Protection Act 2018, UK GDPR, Human Rights Act 1998, Children Act 1989, and basic contract and property law principles. I expect a clear, written response.

Yours sincerely,

[Parent Name]

[Child Name]

[Date]


 


 


⭐ LETTER 2 — TRUST CHALLENGE LETTER


 

To: Trust CEO, Trust Governance Team, Trust Data Protection Officer

Subject: Formal challenge to phone ban, confiscation policy, biometric use, and digital behaviour systems

Dear [Trust CEO / Governance Lead / DPO],

I am writing to formally challenge the legal basis of the trust‑wide mobile phone ban, the confiscation of pupils’ personal devices, and the use of biometric and digital behaviour systems applied to my child without my informed consent. This letter follows my initial objection to the school and is now escalated to the trust, as the trust is responsible for policy creation, legal compliance, procurement, and data‑processing agreements.

Under the Consumer Rights Act 2015, any term that restricts or removes a consumer’s personal property must be fair, transparent, and agreed to. I have not been provided with any lawful, contractual agreement that authorises the trust or its schools to confiscate my child’s phone, retain it, or impose sanctions linked to its possession. My child’s phone is personal property, and neither my child nor I have entered into any contract that permits the trust to interfere with that property.

Under UK common law and property law principles, personal property cannot be taken or retained without lawful authority, parental consent, or a clear statutory power. I am not aware of any Act of Parliament granting trusts the right to permanently or conditionally confiscate personal devices, nor to penalise a child or parent for refusing to surrender such property. Any confiscation beyond a brief, proportionate classroom management measure risks being unlawful.

Under the Data Protection Act 2018 and UK GDPR, the trust is required to provide clear, accessible information before processing a child’s personal data. This includes data processed through:

  • digital behaviour platforms

  • identity systems

  • communication apps

  • external processors

  • cloud‑based systems

  • biometric tools (fingerprints, facial recognition, etc.)

I have not been given plain‑English explanations of:

  • what data is taken,

  • how it is used,

  • who it is shared with,

  • how long it is retained,

  • what systems are involved,

  • what external vendors process the data,

  • or what lawful basis is relied upon.

Consent obtained without this information is not informed, specific, or freely given, and therefore cannot be relied upon as a lawful basis for processing.

If my child’s data has been processed through any digital behaviour or biometric system (including but not limited to ClassCharts, SIMS, Arbor, Bromcom, CPOMS, MyConcern, Satchel One, or any biometric access/payment system), without my explicit, informed consent, this may constitute unlawful processing under UK GDPR and the Data Protection Act 2018.

Under Article 8 of the Human Rights Act 1998, families have the right to respect for private and family life, including personal autonomy and the use of personal property. A blanket phone ban, enforced through sanctions and digital recording, interferes with this right. Any interference must be lawful, necessary, and proportionate. I do not accept that the trust’s policy meets these tests, particularly where it attempts to control possession rather than misuse.

Under the Children Act 1989, I retain parental responsibility for my child’s welfare, property, and communication. The trust cannot override parental responsibility without statutory authority or informed parental consent. I have not given such consent for the trust to control my child’s access to their own phone, nor for the trust to use digital or biometric systems to enforce that policy.

Under contract law principles, a valid contract requires offer, acceptance, consideration, capacity, and intention. My child does not have legal capacity to enter corporate contracts. I have not been presented with any clear offer of terms regarding phone confiscation, biometric use, or digital behaviour systems, nor have I accepted such terms. There is therefore no binding contract that allows the trust to impose these conditions on my child or on me as a parent.

For these reasons, I do not accept:

  • that the trust has lawful authority to confiscate and retain pupils’ personal phones as a matter of policy;

  • that the trust has lawful authority to penalise pupils or parents for possession of a phone;

  • that the trust has lawful authority to process children’s data through digital behaviour or biometric systems without informed parental consent;

  • that any sanctions, detentions, or recorded behaviour incidents linked to phone possession or biometric use are lawful or valid.

I require the following:

  1. The specific statutory powers the trust relies upon to confiscate and retain pupils’ personal phones beyond immediate classroom management.

  2. A full list of all digital behaviour, identity, communication, and biometric systems used across the trust, including all external processors and vendors.

  3. Copies of all data‑processing agreements, contracts, and procurement documents relating to these systems.

  4. The lawful basis under UK GDPR relied upon for processing children’s data through these systems.

  5. Confirmation that no further sanctions or penalties will be applied to my child or to me as a parent in relation to phone possession, pending lawful clarification of these issues.

This letter is not an attack on staff. It is a formal assertion of my rights and my child’s rights under Consumer Rights Act 2015, Data Protection Act 2018, UK GDPR, Human Rights Act 1998, Children Act 1989, and basic contract and property law principles. I expect a clear, written response.

Yours sincerely,

[Parent Name]

[Child Name]

[Date]

 

 

 

 

 

 

 

⭐ LETTER 3 — LEGAL WORDING LETTER


 

To: Headteacher, Trust Governance Team, Trust Data Protection Officer

Subject: Formal notice of invalid consent and unlawful enforcement of phone ban, biometric use, and digital behaviour systems

Dear [Headteacher / Governance Lead / DPO],

This letter formally states that any consent previously assumed, implied, or bundled regarding the school’s mobile phone ban, confiscation policy, biometric systems, and digital behaviour platforms is not valid under UK law. As a result, any enforcement, sanctions, or data processing linked to these policies cannot be lawfully applied to my child.

Under the Data Protection Act 2018 and UK GDPR, consent must be:

  • informed

  • specific

  • freely given

  • unambiguous

  • separate from other agreements

  • based on clear, plain‑English information

None of these conditions were met.

I was not provided with:

  • a clear explanation of what data is collected,

  • how it is used,

  • who it is shared with,

  • how long it is retained,

  • what systems or vendors process it,

  • what lawful basis is relied upon,

  • or any meaningful choice to refuse without detriment.

Consent obtained through:

  • bundled documentation,

  • implied acceptance,

  • lack of clarity,

  • lack of choice,

  • or absence of plain‑English information

is not valid consent under UK GDPR.

Therefore, any processing of my child’s data through:

  • digital behaviour systems (ClassCharts, SIMS, Arbor, Bromcom, CPOMS, MyConcern, Satchel One, etc.),

  • identity systems,

  • communication apps,

  • external processors,

  • cloud‑based platforms,

  • biometric systems (fingerprints, facial recognition, etc.),

is unlawful unless supported by another lawful basis — which has not been provided.

Under the Consumer Rights Act 2015, any term that restricts or removes personal property must be fair, transparent, and agreed to. I have not agreed to any term authorising confiscation or retention of my child’s phone. My child’s phone is personal property, and neither my child nor I have entered into any contract permitting the school or trust to interfere with that property.

Under UK common law and property law principles, personal property cannot be taken or retained without lawful authority, parental consent, or a clear statutory power. I am not aware of any Act of Parliament granting the school or trust the right to confiscate personal devices beyond immediate classroom management.

Under Article 8 of the Human Rights Act 1998, families have the right to respect for private and family life, including personal autonomy and the use of personal property. A blanket phone ban enforced through sanctions and digital recording interferes with this right. Any interference must be lawful, necessary, and proportionate. I do not accept that the current policy meets these tests.

Under the Children Act 1989, I retain parental responsibility for my child’s welfare, property, and communication. The school and trust cannot override parental responsibility without statutory authority or informed parental consent.

Under contract law principles, a valid contract requires offer, acceptance, consideration, capacity, and intention. My child does not have legal capacity to enter corporate contracts. I have not been presented with any clear offer of terms regarding phone confiscation, biometric use, or digital behaviour systems, nor have I accepted such terms. Therefore, no binding contract exists.

For these reasons, I do not accept:

  • that any consent previously assumed is valid;

  • that the school or trust has lawful authority to confiscate or retain my child’s phone;

  • that the school or trust has lawful authority to penalise my child or me for possession of a phone;

  • that the school or trust has lawful authority to process my child’s data through digital or biometric systems without valid consent;

  • that any sanctions, detentions, or behaviour records linked to phone possession or biometric use are lawful or enforceable.

I require the following:

  1. Confirmation that all consent previously assumed or implied is now recognised as invalid under UK GDPR.

  2. Confirmation that no further sanctions or penalties will be applied to my child or me in relation to phone possession or refusal to surrender personal property.

  3. Confirmation that no further data processing relating to phone‑related behaviour, biometric systems, or digital behaviour platforms will occur without valid, informed parental consent.

  4. A written explanation of the lawful basis the school or trust believes it can rely upon in the absence of valid consent.

This letter is not an attack on staff. It is a formal assertion of my rights and my child’s rights under Consumer Rights Act 2015, Data Protection Act 2018, UK GDPR, Human Rights Act 1998, Children Act 1989, and basic contract and property law principles. I expect a clear, written response.

Yours sincerely,

[Parent Name]

[Child Name]

[Date]

 

 

 

 

 

 

 

 

⭐ LETTER 4 — SUBJECT ACCESS REQUEST (SAR)

To: Trust Data Protection Officer

Cc: School Data Protection Officer, Trust Governance Team

Subject: Subject Access Request (SAR) — Full disclosure of all data, systems, vendors, and processing relating to my child

Dear [DPO / Governance Lead],

This is a formal Subject Access Request (SAR) made under Article 15 of UK GDPR and Part 3 of the Data Protection Act 2018. I am requesting all personal data held, processed, shared, stored, retained, or accessed by the school or trust in relation to my child, [Child’s Name].

This request includes all data, all systems, all vendors, all processors, and all copies, regardless of format or location.

Under UK GDPR, you are legally required to respond within 30 days. This deadline is mandatory and cannot be extended without lawful justification.

⭐ I require the following information in full:

1. All personal data relating to my child

Including but not limited to:

  • identity data

  • behaviour logs

  • phone‑related incidents

  • biometric data (fingerprints, facial recognition, templates, scans)

  • attendance data

  • safeguarding notes

  • communication records

  • internal notes

  • external notes

  • disciplinary records

  • access logs

  • audit logs

  • device logs

  • system flags

  • risk indicators

  • profile data

  • any data used for behaviour scoring or categorisation

2. All digital systems used to process my child’s data

Including but not limited to:

  • ClassCharts

  • SIMS

  • Arbor

  • Bromcom

  • CPOMS

  • MyConcern

  • IRIS Adapt

  • Satchel One

  • ParentMail

  • Wonde

  • Edulink

  • Biometric payment systems

  • Biometric access systems

  • Identity management systems

  • Cloud‑based storage systems

  • Trust‑wide platforms

  • Any third‑party apps used by staff

Provide:

  • system name

  • system provider

  • system purpose

  • system location

  • system data categories

  • system retention periods

  • system access permissions

3. All external vendors and processors

Including:

  • software companies

  • cloud storage providers

  • biometric vendors

  • behaviour platform vendors

  • communication app vendors

  • identity management vendors

  • safeguarding platform vendors

  • any third‑party contractor with access to my child’s data

Provide:

  • vendor name

  • vendor address

  • vendor role

  • vendor contract

  • vendor data categories

  • vendor retention periods

  • vendor access levels

  • vendor lawful basis

4. All data‑processing agreements (DPAs)

Provide copies of:

  • trust‑vendor DPAs

  • school‑vendor DPAs

  • biometric system DPAs

  • behaviour system DPAs

  • identity system DPAs

  • communication system DPAs

  • cloud storage DPAs

  • any agreement involving my child’s data

5. All retention periods

Provide:

  • how long each category of data is stored

  • how long biometric data is stored

  • how long behaviour logs are stored

  • how long identity data is stored

  • how long external vendors store data

  • deletion schedules

  • retention policies

6. All lawful bases relied upon

Under UK GDPR, provide the lawful basis for:

  • behaviour data processing

  • biometric data processing

  • identity data processing

  • communication data processing

  • external vendor processing

  • phone‑related incident processing

  • any automated decision‑making or profiling

7. All copies of my child’s data

Provide:

  • digital copies

  • paper copies

  • archived copies

  • backup copies

  • cloud copies

  • vendor copies

  • system copies

  • exported copies

  • shared copies

8. All individuals or roles who have accessed my child’s data

Provide:

  • names or job roles

  • dates of access

  • reasons for access

  • systems accessed

  • data categories accessed

⭐ Legal basis for this request

This SAR is made under:

  • Article 15 UK GDPR (right of access)

  • Data Protection Act 2018 (Part 3)

  • Right to obtain confirmation of processing

  • Right to obtain copies of all personal data

  • Right to obtain information about processing

  • Right to know all recipients of data

  • Right to know retention periods

  • Right to know lawful bases

  • Right to know all external processors

You must respond within 30 days.

You must provide the data free of charge.

You must provide the data in a commonly used format.

You must provide all data, not selective data.

You must disclose all vendors, not only internal systems.

You must disclose all copies, not only primary records.

⭐ Important notice

This SAR is not an attack on staff. It is a formal assertion of my rights and my child’s rights under:

  • UK GDPR

  • Data Protection Act 2018

  • Consumer Rights Act 2015

  • Human Rights Act 1998

  • Children Act 1989

  • Contract and property law principles

I expect a full, lawful response within the statutory timeframe.

Yours sincerely,

[Parent Name]

[Child Name]

[Date]

 

 

 

 

 

 

 

 

⭐ LETTER 5 — DELETION DEMAND LETTER

To: Trust Data Protection Officer Cc: School Data Protection Officer, Trust Governance

 

Team Subject: Formal demand for deletion of all personal data relating to my child

Dear [DPO / Governance Lead],

Following my Subject Access Request (SAR) and previous correspondence, I am formally requesting the deletion of all personal data relating to my child, [Child’s Name], that has been processed unlawfully or without valid consent. This request is made under Article 17 of UK GDPR (Right to Erasure) and the Data Protection Act 2018.

This deletion demand applies to all data, all systems, all vendors, and all copies, regardless of format or location.

⭐ 1. I require deletion of ALL behaviour‑related data

Including:

  • phone‑related behaviour logs

  • sanctions, detentions, or incident records

  • digital behaviour points or scores

  • categorisation or profiling data

  • risk indicators

  • system flags

  • any behaviour data stored in ClassCharts, SIMS, Arbor, Bromcom, CPOMS, MyConcern, Satchel One, or similar systems

This data was processed without valid consent and must be deleted.

⭐ 2. I require deletion of ALL biometric data

Including:

  • fingerprints

  • facial recognition data

  • biometric templates

  • biometric scans

  • biometric identifiers

  • biometric access/payment records

  • any biometric data held by external vendors

Biometric data is special category data under UK GDPR and cannot be processed without explicit consent, which was not provided.

⭐ 3. I require deletion of ALL identity data used for digital systems

Including:

  • identity tokens

  • digital profiles

  • system IDs

  • access credentials

  • cloud‑stored identity data

  • vendor‑stored identity data

This includes identity data used for:

  • behaviour systems

  • safeguarding systems

  • communication apps

  • external processors

  • cloud platforms

⭐ 4. I require deletion of ALL phone‑related incident data

Including:

  • confiscation records

  • possession records

  • refusal records

  • any notes, logs, or flags relating to mobile phone policy enforcement

These records were created without lawful authority.

⭐ 5. I require deletion of ALL external vendor copies

Including:

  • cloud backups

  • archived copies

  • exported data

  • shared data

  • vendor‑stored data

  • contractor‑stored data

  • any data held outside the school or trust

You must instruct all processors to delete this data and provide written confirmation.

⭐ 6. I require deletion of ALL automated decision‑making or profiling data

Including:

  • behaviour scoring

  • risk profiling

  • categorisation

  • automated flags

  • automated sanctions

  • automated escalation triggers

This data was processed without valid consent.

⭐ 7. I require deletion of ALL safeguarding‑adjacent data created solely due to phone policy enforcement

If any safeguarding notes were created only because of phone possession or refusal to surrender personal property, they must be deleted.

Safeguarding cannot be used to enforce unlawful policy.

⭐ Legal basis for this deletion request

This deletion demand is made under:

  • Article 17 UK GDPR (Right to Erasure)

  • Data Protection Act 2018

  • Right to remove unlawfully processed data

  • Right to remove data processed without valid consent

  • Right to remove data no longer necessary

  • Right to remove data used for profiling

  • Right to remove data used for automated decision‑making

The trust must respond within 30 days.

You must:

  • delete all data listed above,

  • delete all copies,

  • delete all vendor copies,

  • delete all archived copies,

  • delete all cloud copies,

  • delete all system copies,

  • delete all exported copies,

  • delete all shared copies,

  • delete all backups containing this data (where technically possible),

  • and confirm deletion in writing.

⭐ Important notice

This deletion demand is not an attack on staff. It is a formal assertion of my rights and my child’s rights under:

  • UK GDPR

  • Data Protection Act 2018

  • Consumer Rights Act 2015

  • Human Rights Act 1998

  • Children Act 1989

  • Contract and property law principles

I expect full deletion and written confirmation within the statutory timeframe.

Yours sincerely,

[Parent Name]

[Child Name]

[Date]

 

 

 

 

 

 

 

⭐ LETTER 6 — CONSENT WITHDRAWAL LETTER

To: Headteacher, Trust Governance Team, Trust Data Protection Officer

 

Subject: Withdrawal of consent for all digital, biometric, behavioural, and identity data processing relating to my child

Dear [Headteacher / Governance Lead / DPO],

I am formally withdrawing all consent previously assumed, implied, bundled, or relied upon for the processing of my child’s personal data through any digital, biometric, behavioural, identity, or external systems. This withdrawal applies to all processing activities carried out by the school, the trust, and any external vendors or processors.

This withdrawal is made under:

  • Article 7(3) UK GDPR (right to withdraw consent at any time)

  • Article 6 UK GDPR (lawful bases for processing)

  • Article 8 UK GDPR (children’s data protections)

  • Data Protection Act 2018

  • Consumer Rights Act 2015

  • Human Rights Act 1998 (Article 8)

  • Children Act 1989

  • Contract and property law principles

Consent withdrawal must take effect immediately.

⭐ 1. I withdraw consent for ALL digital behaviour systems

Including:

  • ClassCharts

  • SIMS

  • Arbor

  • Bromcom

  • CPOMS

  • MyConcern

  • Satchel One

  • IRIS Adapt

  • Edulink

  • Wonde

  • any trust‑wide or school‑wide behaviour platform

This includes:

  • behaviour logs

  • incident records

  • phone‑related records

  • sanctions

  • detentions

  • automated scoring

  • profiling

  • categorisation

  • risk indicators

  • system flags

No further behaviour data may be processed.

⭐ 2. I withdraw consent for ALL biometric systems

Including:

  • fingerprints

  • facial recognition

  • biometric templates

  • biometric scans

  • biometric identifiers

  • biometric access/payment systems

Biometric data is special category data under UK GDPR and cannot be processed without explicit consent, which is now withdrawn.

⭐ 3. I withdraw consent for ALL identity systems

Including:

  • digital profiles

  • identity tokens

  • system IDs

  • access credentials

  • cloud‑stored identity data

  • vendor‑stored identity data

This includes identity data used for:

  • behaviour systems

  • safeguarding systems

  • communication apps

  • external processors

  • cloud platforms

⭐ 4. I withdraw consent for ALL communication and notification systems

Including:

  • ParentMail

  • Edulink

  • Wonde

  • Satchel One

  • any trust‑wide communication app

  • any system that sends automated messages or notifications

No further communication data may be processed without lawful basis.

⭐ 5. I withdraw consent for ALL external vendor processing

Including:

  • cloud storage providers

  • software vendors

  • biometric vendors

  • behaviour platform vendors

  • identity management vendors

  • safeguarding platform vendors

  • any third‑party contractor with access to my child’s data

You must instruct all external processors to cease processing immediately.

⭐ 6. I withdraw consent for ALL automated decision‑making and profiling

Including:

  • behaviour scoring

  • risk profiling

  • categorisation

  • automated flags

  • automated sanctions

  • automated escalation triggers

These activities cannot continue without valid consent.

⭐ 7. I withdraw consent for ALL phone‑related data processing

Including:

  • confiscation records

  • possession records

  • refusal records

  • any phone‑related behaviour logs

  • any digital enforcement of phone policy

These records were created without lawful authority.

⭐ Legal consequences of consent withdrawal

Under Article 7(3) UK GDPR, once consent is withdrawn:

  • processing must stop immediately

  • data cannot be used for any purpose

  • data cannot be shared

  • data cannot be retained without lawful basis

  • data cannot be used for enforcement

  • data cannot be used for profiling

  • data cannot be used for automated decision‑making

Under Article 6 UK GDPR, if consent is withdrawn, the trust must identify another lawful basis for processing. If no lawful basis exists, processing must cease entirely.

Under Article 17 UK GDPR, any data processed without valid consent must be deleted.

⭐ I require the following:

  1. Written confirmation that all consent has been withdrawn and recognised as invalid.

  2. Written confirmation that all processing has stopped immediately.

  3. Written confirmation that all external vendors have been instructed to cease processing.

  4. Written confirmation of the lawful basis (if any) the trust believes it can rely upon in the absence of consent.

  5. Written confirmation that no further sanctions or penalties will be applied to my child or me in relation to phone possession or refusal to surrender personal property.

⭐ Important notice

This letter is not an attack on staff. It is a formal assertion of my rights and my child’s rights under:

  • UK GDPR

  • Data Protection Act 2018

  • Consumer Rights Act 2015

  • Human Rights Act 1998

  • Children Act 1989

  • Contract and property law principles

I expect full compliance and written confirmation within 10–20 working days.

Yours sincerely,

[Parent Name]

[Child Name]

[Date]

 

 

 

 

 

 

⭐ LETTER 7 — PLAIN‑ENGLISH REQUEST LETTER

To: Trust Governance Team, Trust Legal/Compliance Team Cc: Trust Data Protection Officer, Headteacher

Subject: Formal request for plain‑English versions of all policies, contracts, systems, and data‑processing information

Dear [Governance Lead / Legal Team / DPO],

I am formally requesting plain‑English versions of all policies, contracts, system descriptions, and data‑processing information relating to the school’s mobile phone ban, confiscation policy, biometric systems, digital behaviour platforms, identity systems, and external data processing involving my child.

This request is made under:

  • Article 12 UK GDPR (right to clear, accessible information)

  • Data Protection Act 2018

  • Consumer Rights Act 2015 (requirement for fair, transparent terms)

  • Human Rights Act 1998 (Article 8)

  • Children Act 1989

  • Contract law principles

  • Unfair Terms Regulations

Under UK GDPR, all information provided to parents must be:

  • concise

  • transparent

  • intelligible

  • easily accessible

  • written in clear, plain language

None of the current documentation meets these requirements.

⭐ I require plain‑English versions of the following:

1. The mobile phone policy

Including:

  • the legal authority relied upon

  • the scope of enforcement

  • confiscation rules

  • retention rules

  • sanctions

  • behaviour logging

  • digital enforcement

  • parental rights

  • pupil rights

2. The biometric systems used

Including:

  • what biometric data is taken

  • how it is processed

  • how it is stored

  • how long it is retained

  • who has access

  • what vendors are involved

  • what lawful basis is relied upon

  • how parents can refuse or withdraw consent

Biometric data is special category data and requires clear, explicit explanation.

3. All digital behaviour systems

Including:

  • ClassCharts

  • SIMS

  • Arbor

  • Bromcom

  • CPOMS

  • MyConcern

  • Satchel One

  • IRIS Adapt

  • Edulink

  • Wonde

  • any trust‑wide or school‑wide platform

Provide plain‑English explanations of:

  • what data is collected

  • how it is used

  • how it is shared

  • how long it is retained

  • how behaviour scoring works

  • how profiling works

  • how automated decision‑making works

  • how parents can refuse or withdraw consent

4. All identity systems

Including:

  • digital profiles

  • identity tokens

  • system IDs

  • access credentials

  • cloud‑stored identity data

  • vendor‑stored identity data

Provide plain‑English explanations of:

  • what identity data is used

  • why it is used

  • how it is stored

  • how long it is retained

  • who has access

  • how parents can refuse or withdraw consent

5. All external vendors and processors

Provide plain‑English descriptions of:

  • each vendor

  • each system

  • each contract

  • each data category

  • each retention period

  • each lawful basis

  • each access level

Parents must be able to understand who holds their child’s data.

6. All data‑processing agreements (DPAs)

Provide plain‑English summaries of:

  • trust‑vendor DPAs

  • school‑vendor DPAs

  • biometric DPAs

  • behaviour system DPAs

  • identity system DPAs

  • communication system DPAs

  • cloud storage DPAs

Parents must be able to understand what they are agreeing to.

7. All lawful bases relied upon

Provide plain‑English explanations of:

  • the lawful basis for behaviour data

  • the lawful basis for biometric data

  • the lawful basis for identity data

  • the lawful basis for communication data

  • the lawful basis for external vendor processing

  • the lawful basis for phone‑related incident processing

Parents must be able to understand how their child’s data is legally justified.

⭐ Legal basis for this request

This request is made under:

  • Article 12 UK GDPR (requirement for clear, plain‑English information)

  • Article 13 UK GDPR (right to know how data is processed)

  • Article 14 UK GDPR (right to know how data is obtained)

  • Consumer Rights Act 2015 (requirement for fair, transparent terms)

  • Data Protection Act 2018

  • Human Rights Act 1998 (Article 8)

  • Children Act 1989

  • Contract and property law principles

You must provide this information in clear, accessible, plain‑English format.

⭐ I require the following:

  1. Plain‑English versions of all documents listed above.

  2. Plain‑English explanations of all systems, vendors, and processing activities.

  3. Plain‑English summaries of all contracts and DPAs.

  4. Plain‑English descriptions of all lawful bases relied upon.

  5. Confirmation that all future documentation will be provided in plain English.

⭐ Important notice

This request is not an attack on staff. It is a formal assertion of my rights and my child’s rights under:

  • UK GDPR

  • Data Protection Act 2018

  • Consumer Rights Act 2015

  • Human Rights Act 1998

  • Children Act 1989

  • Contract and property law principles

I expect a clear, plain‑English response within 20–30 working days.

Yours sincerely,

[Parent Name]

[Child Name]

[Date]

 

 

 

⭐ LETTER 8 — COLLECTIVE PARENT ACTION LETTER

To: Headteacher, Trust CEO, Trust Governance Team, Trust Data Protection Officer

Subject: Collective parental action regarding phone ban, confiscation policy, biometric systems, and digital behaviour platforms

Dear [Headteacher / Trust CEO / Governance Lead / DPO],

This letter is to formally notify you that multiple parents are now acting collectively regarding the school’s mobile phone ban, confiscation policy, biometric systems, digital behaviour platforms, identity systems, and external data processing involving our children.

Each parent involved has:

  • submitted formal objections,

  • challenged the legal basis of the policy,

  • requested clarification from the trust,

  • submitted Subject Access Requests (SARs),

  • demanded deletion of unlawfully processed data,

  • withdrawn consent for all digital and biometric processing,

  • requested plain‑English versions of all policies and contracts.

We are now acting together because:

  • the policy has not been lawfully justified,

  • confiscation of personal property has no statutory authority,

  • biometric and digital processing occurred without valid consent,

  • behaviour logs and sanctions were applied unlawfully,

  • external vendors were used without clear parental agreement,

  • information provided to parents was not clear, accessible, or plain‑English,

  • and enforcement has continued despite multiple lawful challenges.

⭐ 1. Collective withdrawal of consent

All parents involved hereby withdraw consent for:

  • digital behaviour systems,

  • biometric systems,

  • identity systems,

  • communication apps,

  • external vendor processing,

  • automated decision‑making,

  • profiling,

  • phone‑related data processing.

Consent withdrawal must take effect immediately under Article 7(3) UK GDPR.

⭐ 2. Collective demand for deletion

All parents involved demand deletion of:

  • behaviour logs,

  • phone‑related incidents,

  • biometric data,

  • identity tokens,

  • vendor copies,

  • cloud copies,

  • archived copies,

  • exported copies,

  • any data processed without valid consent.

Deletion must occur under Article 17 UK GDPR.

⭐ 3. Collective demand for plain‑English documentation

All parents require plain‑English versions of:

  • the mobile phone policy,

  • confiscation rules,

  • biometric system explanations,

  • digital behaviour system explanations,

  • identity system explanations,

  • vendor lists,

  • data‑processing agreements (DPAs),

  • lawful bases relied upon.

This is required under Article 12 UK GDPR and the Consumer Rights Act 2015.

⭐ 4. Collective challenge to the legal basis of the phone ban

All parents request:

  • the specific statutory powers relied upon,

  • the lawful basis for confiscation,

  • the lawful basis for retention of personal property,

  • the lawful basis for sanctions linked to phone possession,

  • the lawful basis for digital enforcement of the policy.

No Act of Parliament grants schools or trusts authority to confiscate personal property as a blanket policy.

⭐ 5. Collective notice of non‑retaliation

Under:

  • Equality Act 2010 (victimisation),

  • Human Rights Act 1998 (Article 8),

  • Children Act 1989,

  • Education Act principles,

  • UK GDPR,

  • Data Protection Act 2018,

  • Consumer Rights Act 2015,

  • contract and property law principles,

the school and trust cannot retaliate against:

  • any parent,

  • any child,

  • any family,

  • or any group of parents

for asserting lawful rights.

Any attempt to penalise a child because of a parent’s legal position is unlawful victimisation.

Any attempt to penalise a parent for asserting statutory rights is unlawful retaliation.

⭐ 6. Collective expectation of compliance

All parents expect:

  1. Immediate cessation of all unlawful processing.

  2. Immediate cessation of digital enforcement of the phone ban.

  3. Immediate cessation of sanctions linked to phone possession.

  4. Immediate cessation of biometric processing.

  5. Immediate cessation of profiling and automated decision‑making.

  6. Full deletion of unlawfully processed data.

  7. Full plain‑English documentation of all systems and policies.

  8. Full transparency regarding external vendors and processors.

⭐ 7. Collective escalation if required

If the school or trust refuses to comply, all parents will escalate collectively to:

  • the Trust Board,

  • the Local Authority,

  • the Information Commissioner’s Office (ICO),

  • the Department for Education (DfE),

  • Ofsted (if safeguarding concerns arise).

Collective escalation carries significantly more weight than individual complaints.

⭐ Important notice

This letter is not an attack on staff. It is a formal assertion of parental rights and children’s rights under:

  • UK GDPR

  • Data Protection Act 2018

  • Consumer Rights Act 2015

  • Human Rights Act 1998

  • Children Act 1989

  • Contract and property law principles

We expect a clear, written response within 10 working days.

Yours sincerely,

[Parent Names]

[Child Names]

[Date]

bottom of page