How do I find out what data a company holds about me?
Ask in writing, and you should receive a reply within 1 month. The request is free, and you do not have to say why you want it.
The short version
- Write to the organisation and ask for the data it holds about you. The request is free.
- Say that you are making a subject access request under Article 15 of the UK GDPR.
- You are entitled to a copy of your data, and to 9 other things.
- The reply is due within 1 month, counted from the day the organisation has everything it needs from you.
- The organisation can ask you to prove who you are, and can ask you to narrow a broad request. Both requests delay your reply, so answer the same day.
- If the deadline passes, complain to the organisation, then to the Information Commissioner.
What you can ask for
Under Article 15 of the UK GDPR, you can ask any organisation whether it holds data about you. If it does, you can have a copy, together with 9 other things. The request is known as a subject access request (SAR).
You do not have to give a reason, fill in a form, or use the organisation’s own web page. The Information Commissioner’s Office (ICO) says a request can be spoken or written, and can go to any part of an organisation.
What is included
You are entitled to 10 things:
- A copy of the personal data the organisation holds about you.
- The purposes the data is used for.
- The types of data held, such as your contact details or your payment history.
- Who the data has been or will be shared with, including anyone outside the UK.
- How long the data will be kept, or how that period is worked out.
- Your rights to correct the data, erase it, restrict how it is used, and object to that use.
- Your right to complain to the organisation itself.
- Your right to complain to the Information Commissioner.
- The source of any data you did not give the organisation yourself.
- Whether an automated system alone makes decisions that significantly affect you, and if so, how it works and what its decisions mean for you.
The ICO says you are entitled to the names of the organisations your data went to. A description by type, such as ‘credit reference agencies’, is not enough. An organisation can use types only if naming is impossible, or if it could refuse your request altogether.
You are entitled to your personal data, not the documents holding it, so an organisation can send extracts instead of files. Under the Data (Use and Access) Act 2025, you are entitled only to what a reasonable and proportionate search finds.
Who you can ask
Ask any organisation that decides how your data is used. The law calls that organisation the controller. Shops, banks, streaming services, employers, landlords, schools, GP surgeries, councils, and credit reference agencies are all controllers.
A supplier acting on a controller’s instructions, known as a processor, does not have to answer you. Send your request to the controller instead. An organisation that points you to a supplier still owes you the answer.
The police and other law enforcement bodies answer under a separate part of the Data Protection Act 2018. You are entitled to fewer of the 10 things above, and the police can hold back more. For example, they can hold back an answer that would put an investigation at risk.
How to ask
Email is enough. Write from the address registered to your account, and include:
- Your full name, and your account number or customer reference.
- A line saying you are making a subject access request under Article 15 of the UK GDPR.
- The 10 things above, set out one by one, so each must be answered.
- An offer to confirm your identity, and a line asking exactly what proof the organisation wants.
Keep a copy, and note the date you sent it. If an organisation publishes an address for its data protection officer, use that address. A request that goes to general customer support still counts, and the deadline still runs from the day it arrives.
How long the organisation has
One month, under Article 12A of the UK GDPR.
An organisation can take 2 further months if that is necessary because your request is complex, or because you have made several requests. It must tell you before the first month ends, and it must state its reasons. The ICO says that needing to ask you a question does not by itself make a request complex.
What the organisation can ask you for first
Three things, and nothing else:
Proof of who you are
Under Article 12(6), an organisation can check who you are, but only if it has reasonable doubts about your identity. It can then ask you for proof, and it can hold your request until you send it.
The ICO says an organisation should use checks it already has, such as your existing login. It should ask for formal documents only if they are necessary. If your identity is obvious, the ICO says more information is unlikely to be needed.
Clarification of a broad request
Under Article 12A(5), an organisation can ask you to narrow your request. It can ask only if it reasonably needs that to work out which information you want.
The ICO says an organisation must not ask for clarification as a matter of routine. You can narrow the request yourself, by giving dates or naming the part of the service you mean, but you do not have to.
A fee
The reply is free. An organisation can charge only if your request is manifestly unfounded or excessive, and it must prove that, not simply claim it. It can also charge a reasonable fee for further copies of data it has already sent you.
The ICO sets a high threshold for both grounds. A request is manifestly unfounded if you have no real intention of using the right. One example is offering to withdraw the request in return for money. A request is excessive if it is clearly unreasonable, weighing what you asked for against what answering would cost. Asking for a lot of data is not by itself excessive.
When the month starts and pauses
The month starts at the ‘relevant time’, set by Article 12A(2). It is the latest of 3 days:
- The day the organisation receives your request.
- The day it receives any identity information it asked for.
- The day you pay any fee it charged.
An identity check does not pause the month. It means the month has not started. An organisation that asks for identity documents on day 1, and receives them on day 20, has a full month from day 20 to reply.
A request for clarification works differently. Under Article 12A(5), the days between the organisation asking and you answering do not count. The month pauses rather than starting again. The same pause applies to the deadline for claiming an extension.
The ICO counts the pause in whole days, and the month starts again the day after your answer arrives. It also says the pause covers questions about the information you asked for, and nothing else. A question about the format of the reply does not pause the month.
What the organisation can hold back
Schedule 2 of the Data Protection Act 2018 lists the exemptions. The ones you are most likely to meet:
- Data about another person who can be identified from it, unless that person agrees, or sharing it with you is reasonable without their agreement.
- Legal advice the organisation has taken, known as legal professional privilege.
- Data used to prevent, investigate, or detect crime, or to collect tax, if an answer would harm that work.
- Management forecasts and planning, if an answer would harm that planning.
- Records of the organisation’s intentions in a negotiation with you, if an answer would harm the negotiation.
- References given in confidence for a job, a course, or a volunteering place.
- Answers you wrote in an exam. Exam marks are not exempt, but carry a longer deadline.
An exemption covers only the part it applies to, so an organisation should black out that part rather than refuse the whole request. If it refuses, it must give its reasons, under Article 12(4). It must also tell you that you can:
- Complain to the organisation.
- Complain to the Information Commissioner.
- Go to court.
If the deadline passes
Complain to the organisation first. You have had that right since 19 June 2026, under section 164A of the Data Protection Act 2018. The organisation must:
- Make complaining straightforward.
- Acknowledge your complaint within 30 days.
- Tell you the outcome.
Then complain to the Information Commissioner’s Office. It can issue a reprimand, an enforcement notice ordering the organisation to comply, or a fine.
A court can order an organisation to comply, under section 167. It can also award you compensation under section 168, which covers distress as well as financial loss.
What the organisation must not do
An organisation commits an offence by altering, erasing, hiding, or destroying data to keep it out of your reply. The same applies to anyone working for it, under section 173.
Under section 184, an organisation also commits an offence if it requires you to make a subject access request and show it your records. The rule covers health records, records of convictions and cautions, and certain government records. It applies to an employer asking as a condition of a job. It also applies to a company asking as a condition of a service or a volunteering place. An employer that wants your criminal record must ask for a criminal record check instead.
Special cases
Credit files
A request to a credit reference agency covers only information about your financial standing. To get everything the agency holds, say so in your request. The agency must also tell you about your right under section 159 of the Consumer Credit Act 1974 to have a wrong entry corrected.
Health, education, and social work records
All 3 have extra rules, in Schedule 3 of the Data Protection Act 2018. An organisation can withhold health data if releasing it would be likely to cause serious harm to you or to another person. A suitable health professional must make that judgement.
Asking on someone else’s behalf
Someone can make the request for you, and the organisation must treat it as though you had made it yourself. Health records are an exception. If a parent asks for a child’s record, information the child gave in confidence can be withheld. The same applies to a court-appointed deputy asking for an adult’s record.
Deleted and backed up data
An organisation must search its archives and its backups, even if that is hard. The ICO does not expect it to rebuild data it genuinely deleted as part of normal records management.
What changed in 2026
The Data (Use and Access) Act 2025 altered these rules during 2026. Four changes affect what you get, and when:
- The month now starts when the organisation has your request, proof of your identity, and any fee it charged.
- An organisation can pause the month while it waits for you to narrow a broad request.
- An organisation owes you only what a reasonable and proportionate search finds. The change is backdated to 1 January 2024.
- You have a new right to complain to the organisation, and its reply must tell you about that right.
The ICO last updated its guidance on the right of access on 8 December 2025, and says it is under review because of the Act.
This guide explains your rights in general terms. It is not legal advice for your own situation.
Back to advice