Skip to content
BritIndex
Consumer rights & complaintsHow to12 min read · verified

How to make a subject access request

A subject access request is free, needs no form, and forces an organisation to hand over the personal data it holds about you. It is the most powerful consumer tool almost nobody uses, and refusals are narrower than firms pretend.

Short answer

Ask any organisation, in writing or verbally, for a copy of the personal data it holds about you. There is no form and no fee. They must respond within one month, extendable by two months for complex requests. If they refuse or ignore you, complain to them first and then to the Information Commissioner's Office.

The right of access is the most useful and least used tool in UK consumer and employment law. Any organisation holding personal data about you — an employer, a bank, an insurer, a landlord, a school, a hospital, a debt collector, a social media company, a council — must, on request, give you a copy of that data. It costs nothing, there is no form, and you do not have to explain why you want it.

The reason it matters is that most disputes turn on what an organisation actually recorded, and organisations record far more than people assume. Call recordings and their transcripts. Internal emails mentioning you by name. CCTV footage. Notes on a customer relationship system. The comment a manager typed into an HR record. Credit decision notes. The reason a claim was declined. In a grievance, an insurance dispute, a complaint about a service or a claim against a landlord, the subject access request is very often the single step that changes the balance of information.

The main misunderstanding is what you are entitled to. A subject access request gets you your personal data, not a file. You are not entitled to every document that mentions the matter, and you are not entitled to other people's personal data. Organisations exploit that boundary heavily, and much of the skill in making a good request lies in framing it so that the material you actually want is clearly within scope.

This page covers how to make a request that works, what you get and what is legitimately withheld, how the response deadline operates, what to do when you are ignored, the specific situations where a request is most valuable, and how the position differs across the four nations for health records and freedom of information.

What you are entitled to receive

The right of access entitles you to confirmation that an organisation is processing your personal data, a copy of that personal data, and supplementary information about the processing. The supplementary information is the part people ignore and it is often the most useful: the purposes of the processing, the categories of data held, who it has been or will be disclosed to, how long it will be kept, where it came from if it was not obtained from you, your rights, and whether any automated decision-making or profiling is involved.

Personal data is information from which you can be identified, directly or indirectly. It is broader than a name on a document: it includes opinions about you, an identifier that maps to you, CCTV in which you appear, a voice recording of your call, an IP address linked to you, and free-text notes that describe you without naming you.

You are not entitled to whole documents. If an email refers to you in one sentence, your personal data is that sentence and its context, not the entire chain. Well-run organisations often provide the document anyway because extracting the data is harder than redacting the document, but you cannot demand a file simply because it concerns a matter you were involved in.

Other people's personal data is the main limit. An organisation does not have to disclose information about another individual unless that person consents or it is reasonable to disclose without consent. In practice this produces heavily redacted responses, and some redaction is legitimate. What is not legitimate is redacting the substance of an opinion about you because the author's name would be revealed — the author's identity can be removed while the content about you is disclosed.

There are specific exemptions. Legally privileged material, information used for management forecasting or negotiations where disclosure would prejudice them, some crime prevention and taxation material, references given in confidence in some circumstances, and certain regulatory functions can all be withheld. Exam scripts themselves are exempt, though marks and examiners' comments are not.

Health and social care records have their own overlay. Information can be withheld where disclosure would be likely to cause serious harm to the physical or mental health of the person or another individual, and where a record contains information about a third party. Requests are usually handled by the organisation's health records team.

A refusal must be explained. An organisation cannot simply decline: it must tell you why, tell you about your right to complain to the ICO, and tell you about your right to a judicial remedy.

Making a request that actually works

Send it in writing even though you do not have to. A verbal request is legally valid, but a written one starts a clock you can prove. Email is fine, and sending it to a data protection officer, a privacy address or a formal complaints address is better than sending it to an ordinary customer service inbox that may not recognise what it is.

Say explicitly that it is a subject access request under the UK GDPR and the Data Protection Act 2018. Organisations have processes triggered by that phrase, and a request that reads like an ordinary complaint is routinely mishandled and lost.

Identify yourself precisely: full name, any former names, address and previous addresses if relevant, date of birth, and the account, customer, employee, patient or reference numbers the organisation uses. Vagueness here is the most common reason a request is delayed.

Be specific about what you want, but frame it as a scope rather than a limit. Naming the systems you believe hold data — call recordings, CCTV, internal email, the HR case management system, the CRM, the underwriting notes, the collections file — is far more effective than a generic request, because it makes it harder for an organisation to search narrowly and claim it found nothing. Give a date range where you can.

Do not restrict yourself unnecessarily. If you ask only for 'my complaint file', that is what you will get. If you ask for all personal data and then say you are particularly interested in specified categories, you preserve the full right while directing the search.

Attach identity evidence proactively — a photograph of a passport or driving licence and a recent utility bill or bank statement. An organisation is entitled to verify who you are, and reforms have clarified how the response period runs while identity or clarification is being sought, so supplying it up front removes the most common source of delay.

Diarise the deadline and follow up in writing the day after it passes. Organisations respond to deadlines being noticed. A short email noting that the statutory period has expired and that you will complain to the ICO if a response is not provided within a specified number of days is generally effective.

Keep every piece of correspondence. If it ends up at the ICO, the complaint is assessed on the paper trail: when you asked, what you asked for, what they said, and when.

Deadlines, extensions and refusals

The response is due within one month. Where a request is complex, or where a person has made a number of requests, the organisation can extend by up to two further months, but it must tell you within the first month that it is doing so and explain why. An extension announced on the last day of the third month is not a valid extension.

The clock interacts with identity verification and clarification. Where an organisation reasonably needs to confirm who you are, or genuinely needs clarification about what you want, that affects when the period runs — which is exactly why supplying identity documents and a clear scope with the original request is worth the effort. It removes the organisation's most defensible reason for delay.

An organisation can refuse or charge a reasonable fee only where a request is manifestly unfounded or manifestly excessive. Those are high thresholds and are not met simply because a request is large, inconvenient, made during a dispute, or made by someone the organisation finds difficult. A request made with the intention of causing disruption rather than exercising the right, or repeated requests for the same data, are the sorts of cases the exception is aimed at.

Making a request during a grievance, a tribunal claim or a complaint is entirely legitimate. Organisations sometimes suggest it is an abuse of process. It is not, and the ICO has been clear that motive is generally irrelevant to whether the right applies.

If a response arrives and is obviously incomplete — no call recordings from a period you know you telephoned, no emails at all from a manager you know discussed you — say so specifically and ask what systems were searched. A concrete challenge is much more effective than a general complaint that the response was inadequate.

Redaction should be explained. You are entitled to know, in general terms, why material has been withheld and under which exemption. Blanket black boxes with no explanation are a legitimate ground of complaint.

When you are ignored or refused

Complain to the organisation first, in writing, and use the words 'formal complaint'. Address it to the data protection officer if there is one; large organisations and all public authorities must appoint one. Set out the date of the request, what you asked for, what you received, and what you say is missing or wrongly withheld.

Then complain to the Information Commissioner's Office. It is free, it covers the whole UK, and it can be done online. The ICO will normally expect you to have raised it with the organisation first and to have given it a reasonable time — usually a further period after the complaint — to put things right.

Be clear about what the ICO does and does not do. It regulates: it can assess whether the organisation complied, tell it to take action, and in serious cases take enforcement action or issue fines. It does not award you compensation and it does not act as your advocate in an underlying dispute.

Compensation is a court matter. The Data Protection Act 2018 provides a right to claim compensation for damage, including distress, caused by a breach of the legislation. Claims of this kind are brought in the county court, often on the small claims track, and the evidence of loss or distress matters more than the fact of the breach.

You can also apply to the court for an order requiring compliance where an organisation simply refuses to respond. In practice, the prospect of an ICO complaint resolves the great majority of cases without any of this.

For credit reference agencies there is a separate statutory route to a copy of your credit file, and all three main agencies provide free access. Where the dispute is about the accuracy of credit data rather than access to it, the correction route through the agency and the lender is usually faster than a subject access request.

If the organisation has gone out of business, the data controller obligations may have passed to an administrator, a purchaser of the business or a successor body. Find out who holds the data now and direct the request there rather than assuming the right has evaporated.

Where a subject access request is most useful

Employment disputes. An HR file, investigation notes, emails between managers, and notes of meetings are usually the decisive evidence in a grievance, disciplinary or tribunal claim, and much of it is personal data. Making a request early — before positions harden — is materially more productive than making one after proceedings have started.

Insurance and financial services. Underwriting notes, claim assessment records, call recordings and the reason codes attached to a declined application are all held, and a declined claim or a refused product often looks different once the internal notes are visible.

Housing. Landlord and letting agent records, repair logs, contractor visit notes and internal correspondence are frequently the difference between a disrepair claim that succeeds and one that fails on evidence of notice.

Debt and enforcement. A request to a creditor or debt purchaser produces the account history and the notes of what was said and agreed, which is often where an unfair or wrongly calculated balance becomes visible.

Health and social care. Access to your own medical or care records is the route to understanding a decision, supporting a complaint, or preparing a claim. Requests go to the GP practice, hospital trust or health board rather than to a central body, and the serious harm exemption applies.

Complaints about public authorities. Where you want your own data, use a subject access request. Where you want information that is not about you — policies, statistics, decision-making criteria, correspondence about a general issue — the right tool is a freedom of information request instead, and the two are frequently confused. A single letter asking for both is common and perfectly acceptable, but say which parts are which.

The four nations

Data protection is a reserved matter, so the UK GDPR and the Data Protection Act 2018 apply identically in England, Scotland, Wales and Northern Ireland, and the Information Commissioner's Office regulates all four. A subject access request works the same way wherever you live and wherever the organisation is based, provided it is subject to UK data protection law. Reforms under the Data (Use and Access) Act 2025 apply UK-wide too.

Freedom of information is not reserved, and this is the point most often missed. Requests to UK-wide public authorities and to authorities in England, Wales and Northern Ireland are made under the Freedom of Information Act 2000 and are regulated by the ICO. Requests to Scottish public authorities — the Scottish Government, Scottish local authorities, NHS boards in Scotland, Scottish universities and Police Scotland — are made under the separate Freedom of Information (Scotland) Act 2002 and are regulated by the Scottish Information Commissioner, not the ICO.

That means a complaint about a Scottish council refusing information goes to the Scottish Information Commissioner, while a complaint about the same council mishandling your personal data goes to the ICO. Sending either to the wrong regulator costs months.

Health records access differs practically rather than legally. In England requests generally go to the GP practice or NHS trust, with online access to parts of the record through the NHS App. Scotland, Wales and Northern Ireland run their own health service structures and their own record systems, so the route into the record — and the online access available — is different in each, even though the underlying right is the same.

Social care and education records also sit within devolved systems. A request about a child's education record or a social work file is made to a body operating under devolved law, and the accompanying subject-specific access regulations differ between the nations, so use the devolved guidance alongside the ICO's.

The practical rule: for anything about you, the ICO and the same UK-wide right apply everywhere. For anything that is not about you, check whether the authority is Scottish before deciding which Act and which regulator you are using.

Key takeaways

  • A subject access request is free, needs no form, can be made verbally, and does not require you to explain why you want the data.
  • You are entitled to your personal data and supplementary information about how it is used — not to whole documents, and not to other people's data.
  • Naming the specific systems you believe hold data, with a date range, produces a far broader search than asking for 'my file'.
  • The response is due in one month, extendable by up to two more for complex requests, but the organisation must tell you within the first month that it is extending.
  • Refusal is only permitted where a request is manifestly unfounded or excessive — not because it is large, inconvenient or made during a dispute.
  • Data protection is reserved and the ICO covers all four nations, but freedom of information in Scotland runs under a separate Act regulated by the Scottish Information Commissioner.

Who to contact

At a glance

Cost
FreeA fee is only allowed for manifestly unfounded or excessive requests
Form required
NoneA request can be made verbally, by email, letter or social media
Deadline
One monthExtendable by up to two further months for complex or numerous requests
What you get
Your personal dataPlus supplementary information about how it is used
Not entitled to
Whole files or other people's dataThird-party data can be redacted or withheld
Identity checks
Allowed, not unlimitedAn organisation may verify who you are but not use it to stall
Regulator
Information Commissioner's OfficeUK-wide for data protection; free to complain
Compensation
Court, not the ICOThe ICO enforces; damages are claimed in court
Questions people also ask

How to make a subject access request — FAQ

How much does a subject access request cost?

Nothing. The right of access is free. An organisation may only charge a reasonable fee where a request is manifestly unfounded or manifestly excessive, or for additional copies of the same information. Those are high thresholds, and a request is not excessive simply because it is large, inconvenient or made in the middle of a dispute.

How long does an organisation have to respond?

One month from receiving the request, or from receiving the information it reasonably needs to verify your identity or clarify what you want. It can extend by up to two further months where the request is complex or where several requests have been made, but it must tell you within the first month that it is extending and explain why.

Can I get emails that mention me?

You are entitled to the personal data within them, which is the information about you and enough context to make it intelligible — not automatically the whole email chain. Other people's personal data can be redacted. Many organisations release the document with redactions because that is simpler than extracting the data, but you cannot demand a document as such.

Can my employer refuse because I have a grievance or tribunal claim?

No. Motive is generally irrelevant to whether the right of access applies, and making a request during a dispute is entirely legitimate. Legally privileged material can be withheld, and material about other individuals may be redacted, but the existence of a dispute does not switch off the right or make the request manifestly unfounded.

What do I do if they ignore my request?

Write again noting that the statutory period has expired, mark it a formal complaint and address it to the data protection officer. If that fails, complain to the Information Commissioner's Office, which is free and covers the whole UK. The ICO can require the organisation to act but does not award compensation — that is a separate court claim under the Data Protection Act 2018.

What is the difference between a subject access request and an FOI request?

A subject access request gets you personal data about you, from any organisation, under the UK GDPR. A freedom of information request gets you information held by a public authority that is not about you — policies, statistics, criteria, correspondence. Asking for both in one letter is fine, but say which is which, because they run under different rules and different deadlines.

Is it different in Scotland?

Not for subject access. Data protection is reserved and the ICO regulates all four nations identically. Freedom of information is different: requests to Scottish public authorities run under the Freedom of Information (Scotland) Act 2002 and complaints go to the Scottish Information Commissioner rather than the ICO. Health record access routes also differ practically across the four health services.

Read next

Sources & provenance

Facts verified

  1. 1.Getting copies of your information (subject access request) RegulatorInformation Commissioner's OfficeUsed for: The right of access, what it covers and how to make a request
  2. 2.Make a subject access request RegulatorInformation Commissioner's OfficeUsed for: Practical guidance on wording, identifying yourself and who to send it to
  3. 3.Time limits for responding to data protection rights requests RegulatorInformation Commissioner's OfficeUsed for: The one-month deadline, the extension for complex requests and how the clock runs
  4. 4.Why organisations might partially or fully refuse a subject access request RegulatorInformation Commissioner's OfficeUsed for: Third-party data, exemptions and the manifestly unfounded or excessive test
  5. 5.What to do if you don't get a response or you're unhappy with it RegulatorInformation Commissioner's OfficeUsed for: Escalating to the organisation and then to the ICO
  6. 6.Right of access — guidance for organisations RegulatorInformation Commissioner's OfficeUsed for: The detailed regulator guidance organisations are expected to follow, including search obligations
  7. 7.How to make a data protection complaint to an organisation RegulatorInformation Commissioner's OfficeUsed for: Complaining to the data protection officer before escalating
  8. 8.Make a complaint — ICO RegulatorInformation Commissioner's OfficeUsed for: The free UK-wide complaints route and what the ICO can and cannot do
  9. 9.Credit — ICO RegulatorInformation Commissioner's OfficeUsed for: Access to credit reference agency files and correcting inaccurate credit data
  10. 10.Data Protection Act 2018 Legislationlegislation.gov.ukUsed for: The UK data protection framework, exemptions and the right to compensation
  11. 11.Data (Use and Access) Act 2025 Legislationlegislation.gov.ukUsed for: Reforms adjusting aspects of the access regime, including search and response requirements
  12. 12.Data protection — GOV.UK OfficialUK GovernmentUsed for: The overview of UK data protection legislation and individual rights
  13. 13.How to make a freedom of information (FOI) request OfficialUK GovernmentUsed for: The separate route for information that is not about you, and how it differs
  14. 14.Scottish Information Commissioner RegulatorScottish Information CommissionerUsed for: That Scottish public authority FOI requests run under the 2002 Act with a separate regulator
  15. 15.Accessing medical or health and social care records OfficialnidirectUsed for: The Northern Ireland route into health and social care records
  16. 16.Consumer — Citizens Advice OfficialCitizens AdviceUsed for: Free help with consumer disputes in which access to records is often the decisive step

Not a source — AI-assisted analysis on this page

  • AI-assisted analysis — the wording sets the search scopeThe judgement that request wording effectively determines how widely an organisation searches, and the resulting drafting approach of naming specific systems and a date range while preserving the full right, is our analysis. The ICO documents the right, the exemptions and the time limits, and sets out search expectations for organisations; it does not frame request drafting as the principal determinant of what is returned.

The right of access, supplementary information, third-party data and exemptions, identity verification, the one-month deadline and its extension, the manifestly unfounded or excessive test, and the ICO complaints route all come from the Information Commissioner's Office guidance, the Data Protection Act 2018 and GOV.UK as cited. The Data (Use and Access) Act 2025 is cited for the reforms adjusting the regime; because it is being implemented in stages, check the ICO for the current position on search standards and how the response clock runs. Scotland's separate freedom of information regime is sourced to the Scottish Information Commissioner, and Northern Ireland health record access to nidirect. Deliberately not quoted: any fee amounts, the precise number of days allowed for particular steps, and the compensation levels awarded by courts. These change and depend on the facts. One passage is marked as AI-assisted analysis. This is general information, not legal advice.

Facts on this page are taken from the sources listed above — UK government departments, devolved administrations, regulators, statutory bodies and official statistical releases. Comparisons, judgements and "which option suits whom" conclusions are AI-assisted analysis written over those sources; they are marked in the text and listed as an AI-analysis entry in the sources, not attributed to any authority. Rates, thresholds, fees and processing times change, usually at the start of a tax year in April; figures are current as at the review date shown and should be confirmed with the responsible body before you rely on them. Much of what follows differs between England, Scotland, Wales and Northern Ireland — where it does, this site says so.