STAIRs Requests: Is Your Social Housing Organisation Ready for April 2027?

Introduction

For registered providers of social housing, transparency is about to become a much more operational challenge.

From 1 April 2027, tenants of private registered providers will be able to make requests for information about the management of social housing under the Social Tenant Access to Information Requirements (STAIRs). In most cases, providers will be expected to respond within 30 calendar days.

For housing providers, that raises an important question:

How will you receive, log, triage, manage and respond to STAIRs requests in practice?

At GRC Hub, we are working with social housing providers to help them prepare for STAIRs, bringing together regulatory readiness, information governance expertise and technology to make managing requests simpler.

What are STAIRs?

The Social Tenant Access to Information Requirements, commonly known as STAIRs, are intended to improve transparency and accountability within the social housing sector.

They give social housing tenants of private registered providers greater access to information about how their housing and associated services are managed. The government’s stated objectives include ensuring providers are open with tenants, enabling tenants to access information about their housing, and empowering tenants to hold landlords to account for the quality of housing and services they provide.

The requirements are being introduced in two stages:

  • 1 October 2026: Registered providers must comply with the STAIRs publication scheme requirements, proactively publishing specified classes of information.
  • 1 April 2027: Tenants will be able to make information requests directly to their provider concerning the management of social housing.

This second stage creates a significant new information-management requirement for housing providers.

The challenge isn’t just STAIRs compliance

Understanding the requirements is one thing.

Managing STAIRs requests operationally is another.

From April 2027, a tenant can ask their provider for information about the management of its social housing. Unless there is a good reason not to disclose it, the provider will generally need to provide that information within 30 calendar days.

For housing providers, that means thinking beyond the policy itself.

You need to consider:

  • Where will STAIRs requests be received?
  • Who will identify and triage them?
  • Where will each request be logged?
  • Who is responsible for gathering the relevant information?
  • How will deadlines be calculated and monitored?
  • How will exemptions and redactions be considered?
  • How will you maintain a clear record of decisions?
  • What happens when a tenant requests an internal review?
  • How will STAIRs interact with existing Data Subject Access Requests and other information rights?

These questions become particularly important for providers managing significant volumes of resident correspondence.

Without a defined process, STAIRs risks becoming another information governance workflow that relies on shared inboxes, spreadsheets, manual reminders and knowledge held by individual members of staff.

STAIRs and Data Subject Rights: bringing requests together

There is an important distinction between STAIRs requests and Data Subject Access Requests (DSARs).

A DSAR relates to an individual’s right to access their personal data. STAIRs provides eligible tenants with access to certain information concerning the management of social housing, which can extend beyond information about the individual making the request.

STAIRs does not replace existing data protection legislation. Housing providers will still need to consider their obligations under the UK GDPR and Data Protection Act 2018 when responding and deciding what information can lawfully be disclosed.

Operationally, however, there is significant value in considering how these different information rights are managed together.

At GRC Hub, our approach enables housing providers to manage STAIRs requests alongside existing Data Subject Rights requests through a centralised process.

Rather than creating another standalone spreadsheet or inbox for STAIRs, providers can establish a structured request-management process from the outset.

What should a STAIRs request management process include?

A well-designed STAIRs process should consider the full lifecycle of a request.

1. Request intake

Tenants need a clear way to submit requests, while staff need the ability to recognise requests received through other channels.

A structured intake process helps ensure requests enter the right workflow as early as possible.

2. Logging and categorisation

Requests should be centrally recorded and categorised, providing visibility of what has been received, when it was received and who is responsible for managing it.

This also creates a useful audit trail.

3. Triage

Not every information request will necessarily be a STAIRs request.

Your team may need to determine whether something is a STAIRs request, a Data Subject Access Request, another Data Subject Rights request, a complaint, or a combination of different rights and processes.

Having a defined triage process can help the organisation route requests correctly from the beginning.

4. Deadline management

With the 30-calendar-day response timeframe, relying on individuals to manually calculate and monitor dates introduces unnecessary risk.

A centralised workflow can provide better visibility of deadlines, ownership and outstanding actions.

5. Information collection

Responding to a STAIRs request may require input from different departments or systems.

Clear ownership and workflow management helps coordinate those activities rather than relying on lengthy internal email chains.

6. Disclosure and decision making

The STAIRs framework recognises circumstances where it may be reasonable to withhold information, and providers must also avoid disclosure where doing so would conflict with statutory provisions.

Providers therefore need appropriate processes for considering disclosure, exemptions, redactions and relevant data protection requirements.

7. Reviews and complaints

Request management does not necessarily end when the initial response is issued.

Tenants who are unhappy with the handling of their request can ask their provider for a review. If they remain dissatisfied following that process, or do not receive a response, they can complain to the Housing Ombudsman.

Maintaining an effective audit trail is therefore particularly important.

Moving beyond spreadsheets and shared inboxes

For organisations already managing DSARs manually, the introduction of STAIRs is a good opportunity to reassess the wider approach to information rights.

A manual process may work when volumes are low.

But as request numbers increase, the administrative burden can quickly grow.

You need to know:

What has come in? Who owns it? What information are we waiting for? When is the response due? Has it been reviewed? What did we disclose?

Trying to answer those questions across individual inboxes, spreadsheets and different departments can create unnecessary complexity.

A centralised approach provides a much clearer picture.

How GRC Hub can support your STAIRs readiness

At GRC Hub, we have a specialist social housing team that works with registered providers on data protection, governance and wider information governance requirements.

Our approach to STAIRs readiness combines specialist support with practical request-management technology.

Our solution can bring together:

  • STAIRs request management
  • Data Subject Access Requests
  • Other Data Subject Rights requests
  • Automated request intake
  • Centralised request logging
  • Triage and categorisation
  • Workflow and ownership
  • Deadline monitoring
  • Case management
  • Audit trails and management oversight

The objective is not simply to add another system.

It is to give housing providers a clear, manageable and consistent process for handling information requests, while reducing the administrative burden on internal teams.

Don’t wait until April to think about STAIRs requests

The publication requirements begin on 1 October 2026, followed by the tenant information-request requirements on 1 April 2027.

That gives registered providers a relatively short period to establish how STAIRs will work operationally.

Now is the time to consider:

Assess: Where are you today? How do you currently manage information and Data Subject Rights requests?

Align: What processes, responsibilities, technology and controls need to be introduced or adapted for STAIRs?

Assure: How will you ensure your approach continues to work effectively once requests start arriving?

Getting the process right before April means your organisation can approach STAIRs as a managed information governance process, rather than reacting once requests begin to arrive.

Get ready for STAIRs with GRC Hub

If you’re a registered provider of social housing and are considering how you’ll manage STAIRs requests from April 2027, we can help.

Whether you need support assessing your current readiness, developing your STAIRs procedures or implementing a solution for managing STAIRs and Data Subject Rights requests in one place, speak to the GRC Hub team.

Get in touch with GRC Hub to discuss your STAIRs readiness, or view or STAIRs service page.

The Governance Risk & Compliance Hub - Data Protection and Cybersecurity Specialists Logo.

Governance Risk & Compliance Hub LIMITED

© 2026 All rights reserved