Solutions · By organization

Access and privacy for the campus where records live everywhere

FOI and subject access requests that reach custodians in every faculty with collection tasks and digital attestations, privacy impact assessments for the systems you procure, and breach response with computed notification duties — inside the Microsoft 365 tenant your institution standardized on years ago.

For a university or college, access and privacy software has one defining test: can it reach the records? AccessPoint is built for institutions where responsive records sit with custodians across faculties, departments, the registrar, and research offices. It assigns each custodian a scoped collection task, pulls records directly from SharePoint, OneDrive, Outlook, and Teams, closes every search with a legally-defensible digital attestation, and runs the same platform for privacy impact assessments, breach response, and complaints — with flat annual pricing and no per-user fees, so the whole campus can be in the system.

The obligations are broader than many institutions assume, and they differ by country. In Ontario, universities are designated institutions under FIPPA — the same statute that binds ministries — with a 45-business-day response clock under Bill 97 and, since July 1, 2025, Bill 194's requirement to complete a written privacy impact assessment before collecting personal information. In the United Kingdom, universities are public authorities for the purposes of the Freedom of Information Act 2000, so recorded information they hold is requestable on the 20-working-day clock under section 10, environmental information runs under the Environmental Information Regulations 2004 instead, and student and staff subject access requests run under the UK GDPR and Data Protection Act 2018 on a one-calendar-month clock. In the United States, FERPA gives parents and eligible students a 45-day right to inspect education records, with an amendment-and-hearing process behind it. Whichever regime binds your institution, AccessPoint's jurisdiction packs — 106 across Canada, the US, the UK, Europe, and beyond — preload the deadlines, exemption catalogues, and letter templates, so the platform speaks your law from day one.

What makes campus access hard isn't the statute — it's the org chart, and that part is the same in Toronto, Manchester, and Ohio. The coordinator doesn't hold the records; a dean's office, a lab, and the registrar do. Whether the request is an Ontario FIPPA request, a UK FOIA request, an environmental information request, or a student's subject access request, the work is the same decentralized-custodian problem. AccessPoint's collection tasking sends each custodian a scoped task behind a PII firewall — they see what to search for, never who asked — and assessment section assignment does the same for PIAs and DPIAs, handing the security section to IT and the retention section to the registrar, with the coordinator merging on approval. And because it's Microsoft 365-native, it deploys into the tenant your institution already standardized on, authenticated by your existing Entra ID.

What colleges and universities need from access and privacy software

Whatever you evaluate — including if it isn't AccessPoint — test it against how a campus actually works: decentralized custody, sensitive student and research records, and a steady pipeline of new systems.

Collection that reaches every faculty Scoped tasks assigned to custodians and tracked to completion — not a coordinator chasing email threads across thirty departments and hoping the answers come back.
A PII firewall for custodians The faculty and staff searching for records shouldn't see who asked — whether the requestor is a student, a journalist, or a litigant. Role separation should be enforced by the system.
Attestations that close a search Each custodian should certify what they searched and produced, captured against the record — because the completeness of the search is what gets challenged on appeal, whether that's an IPC appeal or an ICO decision notice.
Records collected where they live If your institution runs on Microsoft 365, responsive records are in SharePoint, OneDrive, Outlook, and Teams. Collection should happen there directly, not through export-and-reupload.
Assessments that fit procurement New ed-tech and campus systems arrive constantly. You need screeners that decide whether a full privacy impact assessment or Article 35 DPIA is warranted, and section assignment so subject-matter experts answer only their part.
Breach response with computed duties An incident touching student data needs a risk-of-harm assessment and a checklist of who must be notified by when — computed from your legal authority, not improvised under pressure.

How AccessPoint runs access and privacy on a campus

One platform for the coordinator, the custodians in every faculty, and the privacy program — on the Microsoft 365 you already run.

Collection tasking across faculties

Assign scoped collection tasks to custodians anywhere in the institution and collect straight from SharePoint, OneDrive, Outlook, Teams, OneNote, and even Copilot interaction history — classified by relevance, de-duplicated with per-copy decisions, and tracked to completion in one faceted workspace with full-text search.

Digital attestations

Custodians certify their searches and production with legally-defensible digital attestations, captured against the record and backed by the audit ledger — so the search stands up when the decision is appealed.

An assessment engine with section assignment

Preliminary screeners, typed questionnaires, an embedded risk register, and sections delegated to the experts who actually know the answer — IT, the registrar, counsel — merged by the coordinator on approval, with a regulator-ready summary export. The same engine runs Ontario's Bill 194 PIAs and Article 35 DPIAs.

Redaction with exemption tagging

Sever student personal information, third-party content, and sensitive research material in the browser, with the statutory exemption attached to every mark — find-and-redact across documents, fall-backs recorded, and a defensible exemption manifest in the release package.

Breach intake to closure

Log an incident in seconds, record cause, affected individuals, and containment, and work a live notification checklist computed from the incident's legal authority — the IPC's real-risk-of-significant-harm test, or the ICO's 72-hour Article 33 report and the Article 34 notice to individuals — with remediation measures assigned, owned, and tracked to done.

Your regime, preloaded

Ontario FIPPA with Bill 97's 45-business-day clock and Bill 194's mandatory PIAs; UK FOIA 2000's 20 working days, EIR 2004, and UK GDPR subject access on one calendar month; US FERPA's 45-day inspection right and amendment hearing — each a jurisdiction pack among 106, carrying its deadlines, exemptions, and letters.

No per-user fees, deliberately

The whole campus can be in the system

Per-seat pricing quietly reshapes how access requests work at a large institution: when every custodian license costs money, coordinators stop tasking custodians and start forwarding email. AccessPoint's pricing is flat per organization — USD $2,990, $7,990, or $14,990 a year by size, published on the site — so a custodian in a faculty office, an expert answering one assessment section, and a reviewer in counsel's office all work in the system without a licensing conversation. The records, meanwhile, never leave your tenant.

Every custodian, no seat math Collection tasks and attestations for anyone on campus who holds records — the price doesn't change.
Role separation, enforced Custodians see their tasks behind the PII firewall; coordinators see the whole picture. Roles are enforced server-side, not by convention.
Student and research data stays home Requests, records, assessments, and audit history live in your own Microsoft 365 and Azure tenant — no vendor cloud, no vendor access.

Colleges & Universities Questions

Are universities subject to freedom of information laws?

In many jurisdictions, yes. In Ontario, universities are designated institutions under FIPPA, the Freedom of Information and Protection of Privacy Act, alongside ministries and agencies, with the same 45-business-day response clock under Bill 97 and Bill 194's mandatory privacy impact assessments in force since July 1, 2025. In the United Kingdom, universities are public authorities for the purposes of the Freedom of Information Act 2000, so recorded information they hold is requestable on the 20-working-day clock under section 10. Coverage elsewhere depends on your jurisdiction's statute. AccessPoint ships 106 jurisdiction packs across Canada, the US, the UK, and Europe, so whichever regime designates your institution, the deadlines, exemptions, and letters arrive preloaded.

How do we collect records from dozens of departments for one request?

With tasking, not email. AccessPoint assigns each custodian a scoped collection task behind a PII firewall — they see what to search for, never who asked — and can pull records directly from SharePoint, OneDrive, Outlook, and Teams. Records are classified for relevance and de-duplicated with per-copy decisions, and each custodian closes their search with a legally-defensible digital attestation. The coordinator watches it all converge in one workspace instead of a mail thread.

Can a UK university run FOI, environmental information, and student subject access in one place?

Yes, and that is usually how the information governance team is organized. AccessPoint ships UK packs for all three: Freedom of Information Act 2000 requests on the 20-working-day clock under section 10, with the Part II absolute and qualified exemptions and the section 2 public-interest test; Environmental Information Regulations 2004 requests routed separately by an environmental-scope screener, on 20 working days extendable to 40 under regulation 7, with regulation 12(2)'s presumption in favour of disclosure; and student and staff subject access under the UK GDPR on the one-calendar-month clock in Article 12(3), extendable by two further months for complex or numerous requests, with the Data Protection Act 2018 Schedule 2 and 3 exemptions applied and recorded. ICO section 50 decision notices and First-tier Tribunal appeals run on the complaints and appeals module. Scottish institutions use the separate Scotland pack, because FOISA and the Scottish Information Commissioner are their own regime.

Can AccessPoint run privacy impact assessments for new ed-tech and campus systems?

Yes — that's what the assessment engine is for, whether you call it a PIA under Ontario's Bill 194 or a DPIA under Article 35 of the UK GDPR. A preliminary screener decides whether a proposed system needs a full assessment at all; when it does, sections are assigned to the people who hold the answers — IT security, the registrar, procurement, counsel — who each complete only their part before the coordinator merges on approval. Every assessment attaches to a durable record of the program or system, with an embedded risk register and a vendor register that tracks each processor's agreement status, review cadence, and risk level.

What about FERPA and student education records?

For US institutions, AccessPoint ships a FERPA configuration that runs the 45-day inspection right for parents and eligible students, the amendment process with its hearing when the institution declines, and disclosure and consent logging — with records kept in the shape the Department of Education's Student Privacy Policy Office would expect if a complaint is filed. See /solutions/us-ferpa for the full picture.

We'd have hundreds of potential custodians — do we pay per user?

No. AccessPoint's pricing is flat per organization — USD $2,990, $7,990, or $14,990 per year by size, with every feature in every tier — precisely because decentralized institutions are the ones per-seat pricing punishes. Custodians, subject-matter experts, and reviewers across campus can all participate without a licensing discussion, and billing runs through the Microsoft commercial marketplace.

One Platform for the Whole Campus.

Try AccessPoint free for 30 days in your institution's own Microsoft 365 tenant — configured for FIPPA, UK FOIA, FERPA, or whichever statute binds you.

Start Free Trial