Skip to main content

Find out what data a company holds about you

This advice applies across the UK.

The short version

  • You can ask any organisation for a copy of the personal data it holds about you. This is known as a subject access request.
  • It’s free, and you don’t have to give a reason or use a form.
  • The organisation must reply within 1 month. It can take up to 2 more months for a complex request.
  • Before it answers, it can ask you to prove who you are, narrow a broad request, or in rare cases pay a fee.
  • It can hold back some data, such as information about other people, but only the part an exemption covers.
  • If it misses the deadline, you can complain to the organisation, then to the Information Commissioner.

What you can ask for

You have the right to ask any organisation whether it holds personal data about you. If it does, you can get a copy and some other information. This is your right of access, known as a ‘subject access request’. It comes from Article 15 of the UK GDPR.

The request is free. You don’t have to give a reason, and you don’t have to use a form.

What the organisation must give you

You’re entitled to a copy of the personal data the organisation holds about you. You’re also entitled to be told:

  • why the organisation uses your data
  • the types of data it holds, such as your contact details or your payment history
  • who it has shared your data with, or will share it with, including anyone outside the UK
  • how long it will keep your data, or how it decides that period
  • that you can ask to correct, erase, restrict or object to the use of your data
  • that you can complain to the organisation
  • that you can complain to the Information Commissioner
  • where it got any of your data that didn’t come from you
  • whether it makes solely automated decisions about you that have a significant effect, and if so the logic involved and what the consequences might be

You can ask for the actual names of the organisations your data has been shared with. A general description, such as ‘credit reference agencies’, isn’t enough, unless naming them is impossible or the whole request can be refused. The ICO’s right-of-access guidance sets this out.

You’re entitled to your personal data, not to the documents that contain it, so the organisation can send you extracts. It only has to give you what a reasonable and proportionate search finds, under section 78 of the Data (Use and Access) Act 2025.

Who to ask

Send your request to the ‘controller’. This is the organisation that decides how your data is used. That could be a shop, a bank, a streaming service, your employer, your landlord, a school, a GP surgery, a council or a credit reference agency.

A ‘processor’ is a supplier that only acts on the controller’s instructions. A processor doesn’t have to answer your request. If a controller points you to its processor, the controller still owes you the answer.

The police and other law-enforcement bodies answer under a separate set of rules in Part 3 of the Data Protection Act 2018. You get fewer entitlements, and more can be held back, for example where an answer would harm an investigation. Section 45 of the Data Protection Act 2018 sets out this right.

How to make the request

Say clearly that you’re asking for your personal data. You can do this in writing, in person or by phone, and you can send it to any part of the organisation. Keep a copy or a note of what you asked for and when.

When you should get a reply

The organisation must reply within 1 month. This deadline is set by Article 12A of the UK GDPR, added by section 76 of the Data (Use and Access) Act 2025.

The 1 month starts from the latest of these:

  • the day the organisation gets your request
  • the day it gets any proof of identity it asked you for
  • the day you pay any fee it is allowed to charge

An identity check doesn’t pause the clock. It means the clock hasn’t started. If you ask on day 1 and send your documents on day 20, the organisation has a full month from day 20.

If the organisation asks you to narrow a broad request, the clock pauses. It stops on the day it asks and starts again on the day you reply. A question about the format of your reply doesn’t pause the clock.

The organisation can take up to 2 more months if your request is complex, or if you have made several requests. It must tell you before the first month ends and give its reasons. Needing to ask you a question doesn’t by itself make your request complex.

What the organisation can ask for first

Before it answers, the organisation can ask you for the following, and nothing else:

  • proof of your identity, but only if it has a genuine reason to doubt who you are
  • clarification, but only if it genuinely needs it to find your data
  • a fee, but only if your request is ‘manifestly unfounded or excessive’

It can hold your request until you prove your identity. But it should use checks it already has, such as your existing login, and ask for formal documents only if it needs them. If who you are is obvious, it’s unlikely to need more.

It must not ask you to narrow your request as a matter of routine.

A fee is rare. ‘Manifestly unfounded’ means you have no genuine intention to use the right, for example if you offer to withdraw the request for money. ‘Excessive’ weighs your request against the cost of answering it. Asking for a lot of data isn’t excessive by itself. The organisation must show clear evidence that a request is manifestly unfounded or excessive, not just claim it. It can also charge a reasonable fee for further copies of data it has already given you.

What the organisation can hold back

The organisation can hold back some of your data. This is known as an ‘exemption’. The exemptions are listed in Schedule 2 of the Data Protection Act 2018. The ones most likely to affect you are:

  • data about another person who can be identified, unless they agree or it is reasonable to share it without their agreement
  • legal advice the organisation has taken, known as ‘legal professional privilege’
  • data it uses to prevent, investigate or detect crime, or to collect tax, where an answer would harm that
  • its management forecasting or planning, where an answer would harm it
  • its negotiations with you, where an answer would harm them
  • confidential references it has given, for a job, a course, or volunteering
  • exam scripts, though your marks aren’t exempt and carry a longer deadline

An exemption only covers the part it applies to. The organisation must still give you the rest of your data. If it refuses part or all of your request, it must give its reasons. It must also tell you that you can complain to it, complain to the Information Commissioner and go to court.

When extra rules apply

If you ask a credit reference agency

A plain request to a credit reference agency covers only your financial-standing information. To get everything it holds, say so in your request. The agency must also tell you about your right to correct a wrong entry under section 159 of the Consumer Credit Act 1974.

If the records are about health, education, or social work

Extra rules apply to health, education and social-work records, in Schedule 3 of the Data Protection Act 2018. Health data can be held back where sharing it would be likely to cause serious harm to you or someone else. A suitable health professional must make that decision.

If someone makes the request for you

You can ask someone else to make the request for you, such as a solicitor or a relative. The organisation treats their request as if it were your own. There is an exception for a child’s health record: information the child gave in confidence can be held back. The same applies to a court-appointed deputy.

If the data has been deleted or backed up

The organisation must search its archives and backups, even where that is hard. But the ICO doesn’t expect it to rebuild data it has genuinely deleted as part of normal records management.

If you don’t get a reply

If the organisation misses the deadline, or you’re not happy with its reply, complain to the organisation first. Since 19 June 2026 you have had this right under section 164A of the Data Protection Act 2018. The organisation must make it easy to complain, acknowledge your complaint within 30 days, and tell you the outcome.

If that doesn’t fix it, complain to the Information Commissioner. Use the ICO complaints service. The ICO can issue a reprimand, order the organisation to act or fine it.

A court can also order the organisation to answer, under section 167 of the Data Protection Act 2018. It can award you compensation, including for distress, under Article 82 of the UK GDPR.

What the organisation must not do

Once you have made your request, it is a criminal offence for the organisation to alter, deface, block, erase, destroy or conceal your data to stop it being disclosed. This is set out in section 173 of the Data Protection Act 2018.

No one can force you to make a subject access request and hand over the results. Doing that as a condition of a job, a service or a contract is a criminal offence. It is known as ‘enforced subject access’, under section 184 of the Data Protection Act 2018. It covers your health records and your record of any convictions or cautions. An employer that wants to see your criminal record must use an official criminal record check instead.

What you can do

Read the ICO’s right-of-access guidance if you want more detail on how a subject access request works. Contact the ICO complaints service if an organisation ignores your request or misses the deadline.

This guide explains your rights in general terms. It is not legal advice for your own situation.

Report a problem with this page