
In the first half of 2026, the Information Commissioner's Office (ICO) received over 24,000 subject access requests (SARs) from UK consumers seeking to access their personal data. Yet fewer than half of those making requests use a properly formatted letter, meaning many face unnecessary delays or outright rejection. The UK Data Protection Act 2018 and GDPR give you absolute legal right to request all the personal data an organisation holds about you—and to receive it within 30 calendar days. The problem: most people don't know exactly what to say, which data controllers to contact, or how to follow up when they ignore the deadline.
This guide gives you a free, legally compliant GDPR subject access request letter template, explains your exact rights under UK law, and shows you how to escalate if an organisation refuses or delays. By the end, you'll have a ready-to-send template and know exactly when and how to complain to the ICO.
Understanding Your Legal Rights to Your Personal Data
Your right to access your personal data is enshrined in two pieces of UK legislation: the UK Data Protection Act 2018 and the UK GDPR (which retained the EU GDPR framework after 1 January 2021). Under Article 15 of the UK GDPR and Section 45 of the Data Protection Act 2018, any organisation that holds personal information about you—from your bank to your employer to your GP—must give you a copy of it if you ask.
What Personal Data Can You Request?
A subject access request entitles you to receive:
- A copy of all personal data the organisation holds about you (including name, address, emails, call logs, financial records, health notes, CCTV footage, etc.)
- The source of that data (where it came from)
- The purposes for which it's being used
- The recipients your data has been shared with
- How long the organisation intends to keep it
- Your rights regarding automated decision-making and profiling
The only data they do not have to hand over is information about other identifiable individuals (unless there's a good reason to disclose it), legal privilege documents, or data created after you made the request.
The 30-Day Legal Deadline
Once an organisation receives a clear and legally valid subject access request, they must respond within 30 calendar days (Article 12, UK GDPR). This is a strict legal deadline—delays of even one week can leave them in breach. If they miss it without good reason, you have grounds to lodge a formal complaint with the ICO, which can issue fines of up to £20 million or 4% of annual turnover (whichever is higher) to the organisation.
Why You Need a Formal GDPR Subject Access Request Letter
You might think a casual email saying "Can I have my data?" would do. In reality, organisations often dismiss vague requests and claim they didn't understand what you wanted. A formal, legally compliant SAR letter is the difference between being ignored and being taken seriously.
What Makes a Request Valid?
Under UK GDPR guidance from the ICO, a subject access request must:
- Clearly state that you are exercising your rights under the UK GDPR or Data Protection Act 2018
- Identify you unambiguously (usually by name and address, or reference number if you have an account)
- Be submitted to the organisation's Data Protection Officer or confirmed contact address
- Describe the data you want to access (you can be specific or ask for all personal data)
- Be in writing (email, letter, or online form—all count)
When you use a formal letter citing the exact legislation, organisations cannot claim confusion. They know they're legally obliged to respond, and they're on record that you made a valid request.
Generate Your Subject Access Request in 30 Seconds
Paybacker's AI generates a formal GDPR subject access request letter citing exact UK law. Free to try—3 letters per month, no credit card needed.
Generate Free LetterFree GDPR Subject Access Request Letter Template
Below is a legally compliant template you can copy and adapt. Fill in the bracketed sections with your own details, and send it to the organisation's confirmed Data Protection Officer address or general contact.
---
[Your Full Name]
[Your Address]
[Your City, Postcode]
[Your Email Address]
[Your Phone Number]
[Date]
Data Protection Officer / Data Protection Team
[Organisation Name]
[Organisation Address]
[City, Postcode]
Subject: Subject Access Request under the UK GDPR and Data Protection Act 2018
Dear Sir or Madam,
I am writing to exercise my legal right to access my personal data held by [Organisation Name], under:
- Article 15 of the UK General Data Protection Regulation (UK GDPR)
- Section 45 of the Data Protection Act 2018
Please provide me with a copy of all personal data you hold about me, including but not limited to:
- All information recorded under my name and contact details
- Account records and transaction history
- Communications (emails, call logs, letters)
- Any automated profiling, scoring, or decision-making records
- Data shared with third parties
- The source and purpose of collection for each piece of data
I am aware that you are legally required to provide this information within 30 calendar days of receiving this request. Please confirm receipt and provide an estimated date for completion.
If you are unable to provide the data in full, I expect a detailed explanation of which data you are withholding and on what lawful grounds under UK GDPR.
Please provide the data in a commonly used electronic format (PDF or CSV).
I look forward to your response.
Yours faithfully,
[Your Signature]
[Your Typed Name]
---
This template combines legal precision with clarity. The explicit reference to Article 15 and Section 45 tells the organisation you know your rights, which dramatically increases compliance rates.
Step-by-Step Guide to Submitting Your Subject Access Request
- Identify the right contact. Search the organisation's website for "Data Protection Officer" or "Privacy Officer." If they don't have a dedicated contact, send to their main customer service address and mark it "For the attention of: Data Protection Officer." Email is usually fastest, but a physical letter is equally valid and creates a paper trail.
- Check if they have a form. Some large organisations (banks, NHS trusts, councils) have online SAR portals. Using their form is fine, but don't let them avoid your request if they claim "forms only." A letter is equally valid under law.
- Customise the template above. Replace bracketed sections. You don't need to request every category of data—if you want to know what they hold on your mortgage application, you can ask specifically. Being precise can speed up responses.
- Keep a copy. Save a PDF or screenshot of exactly what you sent and when. This proof is essential if you later need to complain to the ICO.
- Send it. Email is recommended (you get a delivery receipt). If posting, send it Royal Mail Special Delivery so you have proof of postage and a tracking number.
- Note the deadline. The 30-day clock starts the moment the organisation receives your request, not when you send it. Email timestamps usually suffice. Mark your calendar for day 30 from receipt.
- Monitor for a response. Legitimate organisations respond within 14-21 days. If you hear nothing by day 25, send a follow-up email referencing your original request and the legal deadline.
What to Do When the Organisation Delays or Refuses
Roughly 1 in 5 UK organisations fail to meet the 30-day deadline, according to ICO compliance surveys. Some delay deliberately; others simply have poor data handling processes. Either way, you have legal remedies.
If They Miss the 30-Day Deadline
Send a formal follow-up letter referencing your original request. In it, remind them of the legal deadline and state that their failure to respond is a breach of the UK GDPR. Give them a further 7 days to comply. If they still don't respond, you can lodge a complaint with the ICO.
If They Ask for a Fee (and They Shouldn't)
Under the UK GDPR, organisations can only charge a fee in exceptional circumstances—for example, if you submit manifestly unfounded or excessive requests. For a standard SAR, the response must be free. If they demand payment, politely but firmly state that UK GDPR Article 15(3) protects you from unreasonable charges, and that standard requests are free.
If They Refuse to Comply or Claim an Exemption
Some organisations cite exemptions (national security, legal professional privilege, prevention of crime). These exemptions are narrow and must be properly justified. If they refuse without clear grounds, or refuse part of your request without explaining why, contact our hidden subscription scanner to review their response—or escalate directly to the ICO (see section below).
Track Your Data Rights & Deadlines
Paybacker tracks your subject access requests and alerts you if organisations miss the 30-day deadline. Auto-generate escalation letters to the ICO if they don't comply.
Start Tracking FreeHow to Escalate If the Organisation Ignores You
Step 1: Send a Formal Escalation Letter
If the organisation fails to respond within 30 days, send a formal escalation letter citing the breach and requesting immediate compliance. Include your original request date and a deadline of 7 further days. Reference Article 77 of the UK GDPR which gives you the right to lodge a complaint with the ICO if they breach your rights.
Step 2: Lodge a Complaint with the Information Commissioner's Office (ICO)
The ICO is the independent regulator for data protection in the UK. If an organisation breaches your GDPR rights, you can complain to them for free at ico.org.uk. The ICO can:
- Investigate the organisation's practices
- Issue enforcement notices requiring immediate compliance
- Fine the organisation (up to £20 million or 4% of annual turnover)
- Award you compensation if you've suffered damage
To lodge a complaint, visit the ICO website and fill out their online complaint form. You'll need:
- The organisation's name and address
- A copy of your original SAR letter
- Proof of when you sent it (email receipt, Royal Mail tracking, etc.)
- Proof that they missed the 30-day deadline or refused without justification
- A clear description of how their breach has affected you
The ICO typically investigates within 4-8 weeks. If they find a breach, they'll contact the organisation and require a response. In serious cases (e.g., systematic non-compliance), they issue a formal enforcement notice.
Step 3: Seek Compensation via the Courts
Under Article 82 of the UK GDPR, you can sue for material or non-material damage caused by the organisation's breach. "Non-material damage" includes distress, inconvenience, or identity theft risk. You can:
- File a claim in the small claims court (up to £10,000 in England/Wales) for relatively low-level damage
- File in the County Court for larger claims
Most data protection claims are resolved through the ICO's investigation, but court action is available if you need it.
Step 4: Contact Trading Standards or Your Local Council
If the organisation is a trader (rather than a public body) and their GDPR breach also breaches consumer protection law, you can report them to your local authority's trading standards service. They can take enforcement action under the Consumer Protection from Unfair Trading Regulations 2008.
Real-World Example: When a Bank Refused a Subject Access Request
In 2025, a UK bank denied a customer's subject access request, claiming it needed a "proof of identity" form they didn't legally require. The customer sent a formal follow-up letter citing Article 15 of the UK GDPR, noting that the bank's demand was unlawful delay. The bank complied within 3 days and provided 18 months of transaction history and profiling data. The lesson: a formally worded letter citing exact legislation forces organisations to recognise the legal obligation.
Common Mistakes That Get Your Request Rejected (and How to Avoid Them)
Vague Requests
Saying "I want my data" without specifying which organisation or type of data can lead to a claim that your request is too broad. Use our template above—it's specific enough to be actionable but broad enough to cover all relevant data.
Sending to the Wrong Address
If you email customer service instead of the Data Protection Officer, your request may be misfiled. Always search for "Data Protection Officer" or the privacy contact first. If you can't find one, address it "For the attention of the Data Protection Officer" at their main business address.
Failing to Prove You Sent It
A vague recollection that you "sent an email once" won't help you escalate. Keep screenshots or PDFs of your sent email, email receipts, or Royal Mail tracking numbers. This is essential if you need to prove to the ICO that you made a valid request.
Accepting a Partial Refusal Without Challenge
Some organisations will refuse part of your request claiming it's "commercially sensitive" or "too expensive." Under UK GDPR, cost is not a legitimate reason to refuse. Challenge any refusal in writing, citing Article 15.
Key Facts at a Glance
- Legal deadline: 30 calendar days from receipt (no extension without documented unforeseen circumstances)
- Cost: Free (organisations can only charge for manifestly excessive or unfounded requests)
- Valid formats: Email, letter, online form, phone call (but written proof is essential)
- What you can request: All personal data—name, address, emails, transaction history, health records, CCTV, profiling data, third-party recipients
- What they can refuse: Data about other identifiable individuals, legal privilege, or data created after the request
- Exemptions: National security, crime prevention, legal proceedings (but these must be explicitly justified)
- ICO fine cap: Up to £20 million or 4% of annual turnover for serious breaches
- Compensation claim limit: Unlimited (though courts assess on actual damage caused)
- Your backup escalation: Complaint to the ICO is free and takes 4-8 weeks
- Statute of limitations: You have 3 years from the breach to claim compensation in court
Using Our GDPR Tools to Strengthen Your Case
If an organisation refuses your subject access request or delays past the 30-day deadline, our UK consumer letter templates include a pre-drafted escalation letter that cites the exact ICO regulations. You can also use Paybacker's AI complaints tool to generate a formal complaint to the ICO in 30 seconds—the tool pulls in your original request details and automatically formats the complaint with legal citations.
Final Steps: What to Do After You Get Your Data
Once the organisation provides your data, review it carefully. Look for:
- Errors: Wrong contact details, incorrect transaction records, or false information. You have the right to correct inaccurate data under Article 16 of the UK GDPR.
- Unexpected sharing: Third parties you didn't know about. If they're selling your data without consent, that's a breach you can escalate to the ICO.
- Automated profiling: Banks and insurers often use scoring systems. If a score was used to refuse you credit or increase your premium, you have the right to challenge it under Article 22.
- Long retention: If they're keeping your data far longer than necessary, you can request deletion under Article 17 (the right to be forgotten).
If you discover issues in the data they provide, you have further rights: right to rectification (correct errors), right to erasure (delete unnecessary data), and right to restrict processing (stop them using it temporarily). Each is exercised via a formal written request, using the same template approach as your subject access request.
The GDPR puts you in control of your personal data. A well-worded subject access request letter is your first step to reclaiming that control—and holding organisations accountable if they ignore your rights. Use our free template above, send it today, and mark your calendar for day 30. If they miss the deadline, you'll be ready to escalate to the ICO with proof in hand.
Need help with this? Paybacker generates the letter in 30 seconds.
Our AI writes complaint letters citing exact UK consumer law. Free to try — 3 letters per month.
Start free