Skip to main content

How do I find out what data a company holds about me?

Ask in writing, and you should receive a reply within one month. The request is free, and you do not have to say why you want it.

Last updated
Category
Privacy
Reading time
10 minutes

The short version

  • Write to the organisation and ask for the data it holds about you. The request is free.
  • Say that you are making a subject access request under Article 15 of the UK GDPR.
  • You are entitled to a copy of your data, and to nine other things.
  • The reply is due within one month, counted from the day the organisation has everything it needs from you.
  • The organisation can ask you to prove who you are, and can ask you to narrow a broad request. Both delay your reply, so answer the same day.
  • If the deadline passes, complain to the organisation, then to the Information Commissioner.

What you can ask for

Under Article 15 of the UK GDPR, you can ask any organisation whether it holds data about you. If it does, you can have a copy, together with nine other things. The request is known as a subject access request (SAR).

You do not have to give a reason, fill in a form, or use the organisation’s own web page. The Information Commissioner’s Office (ICO) says a request can be spoken or written, and can go to any part of an organisation.

What is included

Article 15 entitles you to ten things:

  • A copy of the personal data the organisation holds about you.
  • The purposes the data is used for.
  • The types of data held, such as your contact details or your payment history.
  • Who the data has been or will be shared with, including anyone outside the UK.
  • How long the data will be kept, or how that period is worked out.
  • Your rights to correct the data, erase it, restrict how it is used, and object to that use.
  • Your right to complain to the organisation itself.
  • Your right to complain to the Information Commissioner.
  • The source of any data you did not give the organisation yourself.
  • Whether an automated system alone makes decisions that significantly affect you, and if so, how it works and what its decisions mean for you.

The ICO says you are entitled to the names of the organisations your data went to, rather than a description by type such as ‘credit reference agencies’. An organisation can use types only where naming is impossible, or where it could refuse your request altogether.

You are entitled to your personal data, not the documents holding it, so an organisation can send extracts instead of files. Under the Data (Use and Access) Act 2025, you are entitled only to what a reasonable and proportionate search finds.

Who you can ask

Ask any organisation that decides how your data is used. The law calls that organisation the controller. Shops, banks, streaming services, employers, landlords, schools, GP surgeries, councils, and credit reference agencies are all controllers.

A supplier acting on a controller’s instructions, known as a processor, does not have to answer you. Send your request to the controller instead. An organisation that points you to a supplier still owes you the answer.

The police and other law enforcement bodies answer under a separate part of the Data Protection Act 2018. You are entitled to fewer of the ten things above, and the police can hold back more, for example where an answer would obstruct an investigation.

How to ask

Email is enough. Write from the address registered to your account, and include:

  • Your full name, and your account number or customer reference.
  • A line saying you are making a subject access request under Article 15 of the UK GDPR.
  • The ten things above, set out one by one, so each has to be answered.
  • An offer to confirm your identity, and a line asking exactly what proof the organisation wants.

Keep a copy, and note the date you sent it. Where an organisation publishes an address for its data protection officer, use that address. A request that goes to general customer support still counts, and the deadline still runs from the day it arrives.

How long the organisation has

One month, under Article 12A of the UK GDPR.

An organisation can take two further months where that is necessary because your request is complex, or because you have made several requests. It must tell you before the first month ends, and it must state its reasons. The ICO says that needing to ask you a question does not by itself make a request complex.

What the organisation can ask you for first

Three things, and nothing else:

Proof of who you are

Article 12(6) allows an identity check only where the organisation has reasonable doubts about who you are. It can then ask you to confirm your identity, and it can hold your request until you do.

The ICO says an organisation should use checks it already has, such as your existing login, and should ask for formal documents only where they are necessary. Where your identity is obvious, the ICO says more information is unlikely to be needed.

Clarification of a broad request

Article 12A(5) lets an organisation ask you to narrow your request, but only where it reasonably needs that to work out which information you want.

The ICO says an organisation must not ask for clarification as a matter of routine. You can narrow the request yourself, by giving dates or naming the part of the service you mean, but you are not obliged to.

A fee

The reply is free. An organisation can charge only where your request is manifestly unfounded or excessive, and it has to prove that, not simply claim it. It can also charge a reasonable fee for further copies of data it has already sent you.

The ICO sets a high threshold for both grounds. A request is manifestly unfounded where you have no real intention of using the right, for example where you offer to withdraw it in return for money. A request is excessive where it is clearly unreasonable, weighing what you asked for against what answering would cost. Asking for a lot of data is not by itself excessive.

When the clock starts and stops

The month starts at the ‘relevant time’, which Article 12A(2) defines as the latest of three moments: when the organisation receives your request, when it receives any identity information it asked for, and when you pay any fee it charged.

An identity check does not pause a running clock. It means the clock has not started. An organisation that asks for identity documents on day one, and receives them on day twenty, has a full month from day twenty to reply.

A request for clarification works differently. Under Article 12A(5), the days between the organisation asking and you answering do not count, so the clock pauses rather than restarting. The same pause applies to the deadline for claiming an extension.

The ICO counts the pause in whole days, and the clock resumes the day after your answer arrives. It also says the pause covers questions about the information you asked for, and nothing else. A question about the format of the reply does not stop the clock.

What the organisation can hold back

Schedule 2 of the Data Protection Act 2018 lists the exemptions. The ones you are most likely to meet:

  • Data about another person who can be identified from it, unless that person agrees, or sharing it with you is reasonable without their agreement.
  • Legal advice the organisation has taken, known as legal professional privilege.
  • Data used to prevent, investigate, or detect crime, or to collect tax, where an answer would harm that work.
  • Management forecasts and planning, where an answer would harm that planning.
  • Records of the organisation’s intentions in a negotiation with you, where an answer would harm the negotiation.
  • References given in confidence for a job, a course, or a volunteering place.
  • Answers you wrote in an exam. Exam marks are not exempt, but carry a longer deadline.

An exemption covers only the part it applies to, so an organisation should black out that part rather than refuse the whole request. Where it does refuse, Article 12(4) requires it to give its reasons. It must also tell you that you can complain to the organisation, complain to the Information Commissioner, and go to court.

If the deadline passes

Complain to the organisation first. Since 19 June 2026, section 164A of the Data Protection Act 2018 gives you a right to do so. The organisation must make complaining straightforward, acknowledge your complaint within 30 days, and tell you the outcome.

Then complain to the Information Commissioner’s Office. It can issue a reprimand, an enforcement notice ordering the organisation to comply, or a fine.

Section 167 lets a court order an organisation to comply, and section 168 allows compensation, which covers distress as well as financial loss.

What the organisation must not do

An organisation, or anyone working for it, commits an offence under section 173 by altering, erasing, hiding, or destroying data to keep it out of your reply.

Under section 184, an organisation also commits an offence where it requires you to make a subject access request and show it your records. The rule covers health records, records of convictions and cautions, and certain government records. It applies to an employer asking as a condition of a job, and to a company asking as a condition of a service or a volunteering place. An employer that wants your criminal record has to ask for a criminal record check instead.

Special cases

Credit files

A request to a credit reference agency covers only information about your financial standing. To get everything the agency holds, say so in your request. The agency must also tell you about your right under section 159 of the Consumer Credit Act 1974 to have a wrong entry corrected.

Health, education, and social work records

Schedule 3 of the Data Protection Act 2018 sets extra rules for all three. Health data can be withheld where releasing it would be likely to cause serious harm to you or to another person. A suitable health professional has to make that judgement.

Asking on someone else’s behalf

Someone can make the request for you, and the organisation must treat it as though you had made it yourself. Health records are an exception. Where a parent asks for a child’s record, or a court-appointed deputy asks for an adult’s, information the child or the adult gave in confidence can be withheld.

Deleted and backed up data

An organisation has to search its archives and its backups, even where that is hard. The ICO does not expect it to rebuild data it genuinely deleted as part of normal records management.

What changed in 2026

The Data (Use and Access) Act 2025 altered these rules during 2026. Four changes affect what you get, and when:

  • The month now runs from the latest of your request arriving, your identity being confirmed, and any fee being paid.
  • An organisation can stop the clock while it waits for you to narrow a broad request.
  • An organisation owes you only what a reasonable and proportionate search finds. The change is backdated to 1 January 2024.
  • You have a new right to complain to the organisation, and its reply has to tell you about that right.

The ICO last updated its guidance on the right of access on 8 December 2025, and says it is under review because of the Act.

This guide explains your rights in general terms. It is not legal advice for your own situation.

Back to advice

Report a problem with this page

Stay informed

Monthly digest: new scams, new rules, your rights. Unsubscribe any time.

We will never share your email address.