Although we can control which pupils we allow third parties to see through the Batch API, it's all or nothing in terms of which fields of pupil data are accessible. For example, we might want an integrator to be able to access pupils' contacts, but restrict them from being able to see religion, nationality or ethnicity. This would be in keeping with the spirit of GDPR, that data sharing should be the minimum needed.
When allowing access to pupils, I would like to be able to choose by area e.g. teaching sets, contacts. Something similar to the area security that now exists in Pupil Manager. This is particularly true of any fields that could be classed as special category data.