FREE TEMPLATE INCLUDED
How to Make a Subject Access Request
Updated August 2026 · 8 min read · By Silent Erase | ICO Registered C1971457
Before you ask a company to delete your data, it is worth finding out what they actually hold. That is what a Subject Access Request does — and it is free, legally binding and one of the most under-used rights UK residents have.
This guide explains how to make one, what to expect back and what to do if you are ignored. There is a template at the bottom you can copy and use immediately.
What a Subject Access Request is
A Subject Access Request — usually shortened to SAR — is a formal request under Article 15 of UK GDPR asking an organisation for a copy of all the personal data they hold about you.
It is not a favour they can decline. Any organisation processing your personal data must respond, and must do so within one calendar month.
It costs nothing. Organisations cannot charge a fee for a SAR in the vast majority of cases. If a company asks you to pay to see your own data, they are almost certainly in breach — and that is worth reporting to the ICO.
What you are entitled to receive
A SAR gets you considerably more than a data dump. You are legally entitled to all of the following:
A copy of the personal data itself
Everything they hold that identifies you — not just the obvious fields.
Why they are processing it
The purposes, and the lawful basis they rely on.
Who they have shared it with
Recipients or categories of recipient. For data brokers this is often the most revealing part.
Where they got it from
If they did not collect it from you directly, they must tell you the source. This is how you trace how a company you have never dealt with ended up with your address.
How long they will keep it
Their retention period, or the criteria used to determine it.
Whether any automated decisions are made
Including profiling, and meaningful information about the logic involved.
Why you would send one
Before requesting erasure
An erasure request is far more effective when you know what you are asking them to erase. A SAR first, then an Article 17 request, is the stronger sequence.
To trace how you were found
The "source of the data" element is powerful. If a marketing company has your details and you never gave them to anyone, a SAR forces them to name where they bought them — which often leads you back up the chain to the original broker.
To correct things that are wrong
Data brokers hold a great deal of inaccurate information. Wrong addresses, wrong ages, relatives who are not related to you. You cannot correct what you have not seen.
After a data breach
If a company has been breached, a SAR tells you precisely what of yours was in the affected systems.
How to send one — step by step
1
Find the right contact
Check the organisation's privacy policy for a Data Protection Officer or data protection contact. UK organisations are required to publish a route for exercising your rights. If you genuinely cannot find one, any official contact address is legally sufficient — the obligation is on them to route it internally.
2
Put it in writing
Email is fine and gives you a timestamp. You do not need to use the phrase "Subject Access Request", but doing so removes any ambiguity about what you are asking for.
3
Include enough to identify you
Full name, address, and any account or reference number you have. Enough that they can find you, no more.
4
Note the date and diarise one month
The clock starts when they receive it. Put a reminder in your calendar.
5
Keep a copy of everything
Your sent email is your evidence if you later need to complain to the ICO.
What they can and cannot ask of you
| They can | They cannot |
| Ask for proportionate ID if genuinely unsure who you are | Demand ID as a delaying tactic when they already know you |
| Ask you to clarify an extremely broad request | Use clarification to restart the one-month clock unreasonably |
| Extend by two months if genuinely complex — but must tell you within one month | Extend silently or without explanation |
| Redact other people's personal data | Redact your own data because it is inconvenient |
| Refuse if manifestly unfounded or excessive — and must justify it | Refuse simply because responding is effortful |
A common stalling tactic: asking for photo ID and proof of address when you have emailed from an address already on their system. This is sometimes legitimate, but frequently used to slow things down. If you have an existing relationship with them, push back and ask why identification is necessary and proportionate given they already hold your contact details.
Your free SAR template
Copy this, fill in the bracketed sections and send it. It cites the relevant articles and sets out each element you are entitled to — which makes a partial response harder to justify.
[Your full name]
[Your address]
[Your email address]
[Date]
The Data Protection Officer
[Organisation name]
Dear Sir or Madam,
Re: Subject Access Request under UK GDPR Article 15
I am writing to make a Subject Access Request under Article 15 of the UK General Data Protection Regulation.
Please provide me with a copy of all personal data you hold relating to me, together with the supplementary information I am entitled to under Article 15(1) and 15(2), specifically:
1. The purposes of the processing
2. The categories of personal data concerned
3. The recipients or categories of recipient to whom my data has been or will be disclosed
4. The envisaged retention period, or the criteria used to determine it
5. The source of the data, where it was not collected directly from me
6. The existence of any automated decision-making or profiling, including meaningful information about the logic involved
7. Confirmation of whether my data is transferred outside the UK, and the safeguards applied
My details for identification:
Full name: [your name]
Address: [your address]
[Any account or reference number]
I would prefer to receive this response electronically in a commonly used format.
Under Article 12(3) you are required to respond without undue delay and within one calendar month of receiving this request. If you consider you require an extension under Article 12(3), please notify me within that first month together with your reasons.
If you require further information to locate my records, please contact me promptly so that this can be resolved without delay. Please note that requests for identification documentation should be proportionate and necessary.
Should I not receive a satisfactory response within one calendar month, I reserve the right to lodge a complaint with the Information Commissioner's Office under Article 77.
Yours faithfully,
[Your name]
If they ignore you
1
Send a written follow-up
Reference your original date and state that the statutory deadline has passed. Give them 14 days.
2
Complain to the ICOFree, straightforward, and you do not need a solicitor. Report at ico.org.uk/make-a-complaint or call 0303 123 1113. You will normally be expected to have raised it with the organisation first — which is why step one matters.
The ICO takes non-response seriously. Failing to answer a SAR is a straightforward, easily evidenced breach. Organisations know this, which is why a clearly worded follow-up referencing Article 77 often produces a response where the original request did not.
A realistic note on expectations
Some organisations respond thoroughly and promptly. Others send a thin extract and hope you do not press. If what comes back is obviously incomplete — no source information, no recipients — say so in writing and cite the specific sub-articles they have not addressed.
And be prepared for what arrives. People are frequently surprised by how much is held, how much of it is inferred rather than factual, and how much of it is simply wrong.
What to do next
Once you know what a company holds, you have options:
• Ask for erasure under Article 17 — your GDPR rights explained
- Object to marketing under Article 21(2) — free letter generator
- Correct inaccuracies under Article 16
- Trace the source and send a SAR to whoever sold it to them
Do not want to do this 55 times over?
Silent Erase sends erasure requests to data broker sites on your behalf and chases anyone who ignores the deadline. Or use our free tools and do it yourself — genuinely, either is fine.