Skip to content

UK GDPR and your study data: what you can ask for

By · Notibo

Published · 12 min read · updated

Key takeaways

  • A lecture recording, its transcript and the notes made from it are personal data. Under the UK GDPR you can ask for a copy, for deletion, for a portable format, and you can object to some processing.
  • Organisations usually have one month to answer a subject access request, the ICO says, and the UK GDPR lets them charge only for further copies. Put the words subject access request in the subject line.
  • Your own private study recording sits outside the UK GDPR under the domestic purposes exclusion only while it stays purely personal. Post it to a class group and the exclusion ends.
  • Stored in the UK or the EU is not the same as processed there. A US transfer is lawful under the UK Extension to the Data Privacy Framework or under the IDTA or Addendum, and both mean the audio leaves the country.
  • Your university holds far more about you than any app does, including disability status and support plans. Its lecture capture recordings of you are made without your consent, under legitimate interests or public task.

Short answer first: a recording of your lecture, the transcript made from it and the notes generated off that transcript are all personal data, and the UK GDPR gives you four rights over them that matter in practice. You can ask for a copy, ask for them to be deleted, ask for them in a format you can take elsewhere, and object to some kinds of processing. The organisation usually has one month to reply and cannot charge you for the first copy.

The part most students get wrong is not the rights. It is what the rights do not cover, and what "UK-based" or "stored in the EU" actually means when you read it in a privacy notice.

Whose data is in a lecture recording?

Usually three sets of people in one file. You, through your account and how you use the tool. The lecturer, whose voice and material fill most of the hour. Your classmates, if anyone asked a question from the floor.

Record for your own study and keep the file to yourself, and the law leaves you alone. Article 2 of the UK GDPR says the regulation does not apply to "the processing of personal data by an individual in the course of a purely personal or household activity". The Information Commissioner's guide to the exemptions explains what that covers: personal data "processed in the course of a purely personal or household activity, with no connection to a professional or commercial activity, is outside the UK GDPR's scope", and gives writing to friends and family or taking pictures for your own enjoyment as the examples.

Read the word "purely". The ICO's example is someone who only uses personal data for writing to friends and family or for photographs taken for their own enjoyment. A recording of a lecturer and forty classmates posted to a course group chat is hard to describe as purely personal. So the rule you can act on is simple. Your own drive, yes. Anyone else's, no.

What do UK universities require before you press record?

Stricter rules than the UK GDPR, and they differ by university. King's College London permits audio recordings on personal devices for personal study "with prior permission of the lecturer". UCL's Academic Manual says students are not ordinarily permitted to make recordings or transcripts of teaching sessions, and treats inappropriate recording or sharing as a breach of the student disciplinary code. Bristol requires the prior consent of the lecturer and the other participants, and says a recording made by a student "must only be used as a personal aid for study purposes".

The universities also process your data when they record you. King's says recording educational activities is "in the legitimate interests of the educational objectives of King's College London" and a reasonable expectation of students and staff, so personal data "can be processed without obtaining prior consent". Manchester relies on its public task basis and says the same: consent "is not required from staff and students for data protection purposes", though it does seek students' consent where a session involves significant participation. Both are lawful bases under Article 6, and both mean the university's recording of you exists whether or not you agreed to it. Your rights over that recording are the ones below.

We go through the recording rules university by university in can you record lectures at UK universities, and what the university records for you in lecture capture at UK universities.

Which rights are worth knowing?

The law is the UK GDPR, the retained and amended version of the EU regulation, read together with the Data Protection Act 2018, and the regulator is the Information Commissioner's Office. The rights that matter for study data sit in four articles.

Right Article What it gets you Limits
Access Article 15 A copy of your personal data, the purposes, the recipients including any in third countries, the retention period, and the safeguards used for transfers The controller only has to do a reasonable and proportionate search. The first copy is free; further copies may carry a reasonable fee
Erasure Article 17 Deletion where the data is no longer needed, you withdraw consent, you object and there are no overriding grounds, or the processing was unlawful Not absolute. Exceptions for freedom of expression, legal obligations, public health, research and archiving, and legal claims
Portability Article 20 Your data in a structured, commonly used, machine-readable format, sent to another provider where technically feasible Only data you supplied, processed by automated means, on the basis of consent or a contract
Objection Article 21 Stops processing based on legitimate interests or public task unless the controller shows compelling legitimate grounds Absolute only for direct marketing

Name the right when you write. A request that says "Article 15 subject access request" is harder to lose than one that says "can I have my stuff".

Portability is the one to notice for a note-taking app. Your recordings and the notes made from them are data you supplied, processed automatically, under a contract. That is the exact case Article 20 was written for. An export button in the app is the same right without the email.

How long do they have, and what does it cost?

The ICO's guide for the public puts it plainly: "Organisations usually have one month to respond to a SAR." Anyone can make one, and you do not need a solicitor. The UK GDPR allows the period to be extended by up to two further months for complex requests, which is why it pays to make the request specific. Article 12 makes the information free, and lets a controller charge or refuse only where a request is "manifestly unfounded or excessive", with the burden of proving that on the controller. Article 15 adds that further copies may carry a fee based on administrative costs, so the first copy is the free one.

Keep the clock on your side

  1. Send the request by email so the date of receipt is not in doubt.
  2. Say which right you are using and which data you mean: the recordings, the transcripts, the notes, the account logs.
  3. Diary the date one month out.
  4. If nothing arrives, reply on the same thread and ask them to confirm when they received it.

How do you make a subject access request in practice?

The ICO suggests what to include, and it is worth following the list because a vague request invites a request for clarification, which pauses the clock.

  • A subject line that says "subject access request".
  • The date you are making it.
  • Your name, including any former names the organisation may hold.
  • Your email, home address and phone number, so they can match you to an account.
  • Account numbers or similar identifiers that help them find you.
  • What personal information you want. For a note-taking app: the audio files, the transcripts, the generated notes and flashcards, and any usage or account logs. Ask also for the recipients and the retention period, because Article 15 entitles you to both.

Send it to the address in the privacy notice, which every controller has to publish. If the notice gives no address at all, that is already an answer about the company.

What does "UK" or "EU" mean in a privacy notice?

Where your files are stored and where they are processed are two different questions. A tool can keep your recordings and notes on servers in the UK or the EU and still send the audio to a speech-to-text provider in the United States, because many of the strongest ones are there. Both sentences can be true at once. "Your data is stored in the EU" is not a promise that your audio never leaves it.

The ICO calls a transfer to a separate organisation outside the UK a restricted transfer, and its guide says every one "must be covered by one of the following transfer mechanisms: UK adequacy regulations; appropriate safeguards; or an exception". Three places matter to a student.

  • The EEA. Every EU member state plus Iceland, Norway and Liechtenstein has full adequacy under the UK's regulations, so a UK controller can send personal data to an EU provider without extra paperwork. The reverse is also covered: the ICO's guidance on receiving personal information from the EEA says the UK has adequacy decisions from the EU under the EU GDPR, which let personal information flow to the UK without additional safeguards.
  • The United States, route one. The UK Extension to the EU-US Data Privacy Framework is, in the ICO's words, "a partial adequacy finding". It covers transfers only to US businesses that have self-certified and have "an active status on the DPF list". The ICO also notes that although it is based on the EU framework, the UK Extension "is a separate arrangement".
  • The United States, route two. Where the recipient is not on that list, the sender needs an appropriate safeguard. The ICO names the International Data Transfer Agreement, the International Data Transfer Addendum to the EU standard contractual clauses, or binding corporate rules, plus a transfer risk assessment to check "that the standard of protection for people's information is not materially lower after we transfer it".

Neither US route is a loophole. Both are lawful, and both mean the audio leaves the country. So do not ask whether a tool is British or European. Ask where the audio goes, and see whether the notice will tell you.

What to check before you upload a term of lectures

Article 15 tells you what a controller must be able to hand over, which is a good test of what a privacy notice should already say. Read it for these.

  • Who the controller is. A company name and an address, not just a product name.
  • Recipients, or categories of recipients. The good version is a named list of processors, including the speech-to-text and AI providers, because those are the companies that actually hear the audio.
  • Transfers outside the UK and the safeguard used. The UK Extension for a listed US company, or the IDTA or Addendum for anyone else. A notice that says "we comply with GDPR" and nothing about transfers has skipped the question.
  • How long they keep it. The retention period, or the criteria used to set it, is something Article 15 requires them to tell you on request. Better if it is in the notice already.
  • Your right to complain to the ICO, and how to reach the controller.

Two more are not legal requirements but tell you a great deal. Is there an export button and a delete button in the product, so that the Article 20 and Article 17 rights are a click rather than an email? And does the notice say, provider by provider, whether your content is used to train models? "We never train on your data" is an easy sentence to write and a hard one to keep, because the audio passes through companies the tool does not own. A notice that names each provider and says what each one is contractually allowed to do is the more honest document. If you are still choosing a tool, we compared the main options on exactly that point in the best note-taking app for UK students.

What does your university hold about you?

More than any app does, and it is all personal data. King's College London's student data collection notice lists special category data collected for widening participation, including forced migrant, asylum seeker or refugee status, care leaver status, disability status and ethnicity, and says personal information is shared internally "on a need-to-know basis". Add your UCAS route in, your marks, your attendance, your support plan, your fee records and every lecture capture recording in which your voice was picked up, and you have a file no note-taking app comes close to. A subject access request under Article 15 reaches all of it, and the university's own student data notice is where to find the address to send it to.

Three things to do with that, none of which require a law degree. Read the transfers section and the retention section of any tool before you trust it with a term of lectures. Ask your lecturer before you record, because the university rules are stricter than the UK GDPR. And when a module ends, delete what you no longer need, instead of leaving four years of audio in an account you stopped thinking about in second year.

What if they ignore you?

Chase in writing first. The ICO's public guidance includes a complaint letter template rewritten specifically for subject access requests, and that letter to the organisation is the first step. Keep the correspondence. If the organisation still does not answer, or answers with less than Article 15 requires, you can complain to the ICO, which regulates data protection across the UK. A missed one-month deadline is a well trodden path, and you are not being awkward by walking it.

Where Notibo fits

Notibo is an example of the storage and processing split rather than an exception to it. Your recordings, notes and flashcards are stored in the EU on Supabase in Frankfurt. The audio is transcribed by speech-to-text providers in the United States, and the AI notes are also produced on US processors, under standard contractual clauses. Uploads are capped at 50 MB, long recordings are split into 30-minute files on the phone and joined back into one transcript, and the free plan covers 30 minutes of recording a month. Our privacy policy names each provider, so you can run it through the checklist above the same way you would run any other tool through it.

Frequently asked questions

How long does an organisation have to answer a subject access request in the UK?
The Information Commissioner's Office says organisations usually have one month to respond. The UK GDPR allows that period to be extended for complex requests, so a silent organisation is not necessarily a compliant one. Send the request by email so the date of receipt is clear, and diary the deadline.
Does the UK GDPR apply to a recording I make for my own study?
Not while it stays with you. The ICO's guide to the exemptions says personal data processed in the course of a purely personal or household activity, with no connection to a professional or commercial activity, is outside the UK GDPR's scope. Sharing a recording of your lecturer and classmates with a group of two hundred people is not a purely personal activity, and your university's own rules on sharing are stricter still.
Is it legal for a study app to send my audio to the United States?
Yes, if the transfer is covered. The UK's adequacy regulations for the US cover only businesses with an active self-certification under the UK Extension to the EU-US Data Privacy Framework. Any other transfer needs appropriate safeguards such as the International Data Transfer Agreement or the Addendum to the EU standard contractual clauses, backed by a transfer risk assessment. Neither route is a loophole, and both mean the audio leaves the UK.
Can the EU-based app I use send my data to the UK, and the other way round?
Yes, in both directions. The UK's adequacy regulations give every EEA country full adequacy, so a UK organisation can send personal data to an EU provider without extra safeguards. The European Commission has adequacy decisions for the UK under the EU GDPR, which the ICO says were renewed, so data can flow from the EEA to the UK too. What still needs checking is any onward hop to the US.
What can I do if an organisation ignores my request?
Chase it in writing on the same email thread and ask them to confirm the date they received the request. The ICO publishes a complaint letter template written specifically for subject access requests. If the organisation still does not respond, you can complain to the ICO, which regulates data protection in the UK.
Can I see what my university holds about me?
Yes. A university is a data controller like any other, and its student data notice will list what it collects. King's College London's notice, for example, covers special category data such as disability status and ethnicity for widening participation, and says data is shared internally on a need-to-know basis. A subject access request under Article 15 reaches all of it.
Whose data is in a lecture recording?
Usually three sets of people in one file. You, through your account and how you use the tool. The lecturer, whose voice and material fill most of the hour. Your classmates, if anyone asked a question from the floor. Record for your own study and keep the file to yourself, and the law leaves you alone. Article 2 of the UK GDPR says the regulation does not apply to "the processing of personal data by an individual in the course of a purely personal or household activity".
What do UK universities require before you press record?
Stricter rules than the UK GDPR, and they differ by university. King's College London permits audio recordings on personal devices for personal study "with prior permission of the lecturer". UCL's Academic Manual says students are not ordinarily permitted to make recordings or transcripts of teaching sessions, and treats inappropriate recording or sharing as a breach of the student disciplinary code. Bristol requires the prior consent of the lecturer and the other participants, and says a recording made by a student "must only be used as a personal aid for study purposes". The universities also process your data when they record you.

Sources

  1. Getting copies of your information (SAR) (Information Commissioner's Office) (one month to respond, what to include in a request, complaint template)
  2. A guide to the data protection exemptions (Information Commissioner's Office) (domestic purposes: purely personal or household activity is outside the UK GDPR's scope)
  3. International transfers, a guide (Information Commissioner's Office, updated 15 January 2026) (restricted transfers, adequacy regulations, IDTA, Addendum, transfer risk assessments)
  4. How does the UK Extension to the EU-US Data Privacy Framework work? (Information Commissioner's Office, updated 30 July 2026) (partial adequacy for the US, active status on the DPF list)
  5. Is the restricted transfer covered by adequacy regulations? (Information Commissioner's Office) (full adequacy for every EEA country, partial adequacy for the US)
  6. UK GDPR, Article 15: right of access by the data subject (legislation.gov.uk) (what you are entitled to, third country safeguards, first copy free)
  7. UK GDPR, Article 2: material scope (legislation.gov.uk) (processing by an individual in the course of a purely personal or household activity is outside the regulation)
  8. Student Data Collection Notice (King's College London) (what a university collects, including special category data, and internal sharing)

About the author

Farhad Ba-Ali

Farhad Ba-Ali builds Notibo in Odense, Denmark. He writes about study methods, memory and note-taking from the questions students send in, and from what the product's own data shows.

Ready to take better notes?

Let Notibo listen along and write your notes and summaries. Free to get started.

Create free account

Back to the blog