How to ask a company for all the data it holds on you — and what to do if they ignore or redact it
You can ask any organisation for a copy of the personal information it holds about you under Article 15 UK GDPR. There is no form and no fee, and it has one calendar month to reply — but since 5 February 2026 it can pause that month while it waits for you to say what you want.
Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.
The bottom line
A subject access request (SAR) needs no special wording and costs nothing. The organisation has one calendar month, extendable to three where the request is complex or you have made several. Two things changed recently: since 5 February 2026 it can stop the clock while it waits for you to clarify what you want, and since 19 June 2026 you have a statutory right to complain to the organisation itself, which it must acknowledge within 30 days.
How to make the request
The right is in Article 15 UK GDPR. It gives you three things: confirmation of whether the organisation is using your personal information, a copy of that information, and supplementary details — the purposes, the categories of data, who it is shared with, how long it is kept, where it came from, and any automated decision-making. Since 19 June 2026 that supplementary list also includes your right to complain to the organisation itself under section 164A (the new Article 15(1)(ea)). The right to complain to the Information Commissioner was already there, at Article 15(1)(f).
There are no formal requirements for a valid request. ICO guidance is explicit: you can make a SAR verbally or in writing, including by social media; to any part of the organisation; without using the words "subject access request" or citing Article 15; and without saying why you want it. A letter that mentions the Freedom of Information Act can still be a valid SAR. Many organisations offer a form — you can use it, but you cannot be made to.
- Step 1 Put it in writing anyway Not a legal requirement, but it fixes the date the clock starts and gives you evidence later.
- Step 2 Say what you actually want You are entitled to ask for everything. But naming what you need — your HR file, calls between two dates, emails between named managers — makes a clarification request, and a pause, far less likely.
- Step 3 Give them enough to find you Account, payroll or patient number; the email addresses and phone numbers you have used; relevant dates.
- Step 4 Expect an ID check If they have reasonable doubts about who you are, they can ask for identification under Article 12(6), and the month does not start until they have it.
- Step 5 Keep the evidence Copies of emails, proof of postage, or a screenshot of an online form before you submit it.
Is there a fee, and can they refuse because you are in a dispute with them?
There is no fee in the ordinary case. Under Article 12(5) an organisation may charge a reasonable administrative fee only where the request is manifestly unfounded or excessive; separately, Article 15(3) lets it charge a reasonable fee based on administrative costs for further copies of information it has already supplied. Section 12(1) of the Data Protection Act 2018 lets the Secretary of State cap those fees by regulations, but no such regulations have been made. The intelligence services are a narrow exception: under section 94 of the DPA 2018 they may require a reasonable fee, subject to any maximum set by regulations.
Being in a grievance, a tribunal claim, a complaint or a live dispute does not invalidate your request. The ICO's guidance for organisations puts it directly: an employer cannot refuse to provide the information just because it thinks the person wants it for litigation, because the purpose behind a request is not relevant to whether the request is valid. Purpose can be one factor among several if there is real evidence the right is being abused — but the threshold is high, and Article 12(5) expressly places the burden of demonstrating it on the organisation, not you.
How long they have — and when they can now stop the clock
Time limits are now set by Article 12A UK GDPR, inserted by section 76 of the Data (Use and Access) Act 2025 and in force since 5 February 2026. The period is one calendar month from "the relevant time" — the latest of the day they receive the request, the day they receive any identity information they asked for, and the day any fee is paid. They may extend by two further months where necessary because of the complexity or the number of your requests, but must tell you and give reasons within the first month.
The new part is Article 12A(5). Where a controller reasonably requires further information to identify what your request relates to, the days between it asking and you answering do not count towards the deadline. This applies only to Article 15 subject access requests, and only where the controller reasonably requires the information — Article 12A(6) gives processing "a large amount of information" about you as the statutory example. It is not a licence to ask as a matter of routine, and asking about the *format* of the response is not the same as needing to identify what you have asked for. You cannot be forced to narrow your request: if you simply repeat it, they must still carry out a reasonable and proportionate search.
| What | Position before 5 February 2026 | Position now |
|---|---|---|
| Basic deadline | One month from receipt of the request | One month from "the relevant time" — the request, any ID asked for, or any fee, whichever is latest (Art 12A(1)–(2)) |
| Extension | Two further months for complex or numerous requests, with notice inside month one | Unchanged for UK GDPR requests. Now also available for police and other law-enforcement requests (DPA 2018 s.54(3A)) |
| Pausing for clarification | No express provision in the legislation | Express statutory power, Article 15 requests only, and only where reasonably required (Art 12A(5)) |
| Depth of search | Already limited to a reasonable and proportionate search | Unchanged. Article 15(1A) has been in force since 19 June 2025 and is treated as in force from 1 January 2024 |
Two things people get wrong
The "reasonable and proportionate search" limit is not a February 2026 change — it came in with section 78 of the Act on 19 June 2025, the day the Act was passed. And the UK GDPR was amended, not replaced or repealed. Article 15 still exists and still says what you are entitled to. Separately, the new time limits do not apply at all to requests received before 5 February 2026 (SI 2026/82, reg. 4).
They have blacked most of it out — are they allowed to?
Some redaction is lawful. The main grounds are:
- Other people's personal information. Article 15(4) and Schedule 2, Part 3, paragraph 16 of the DPA 2018. This is not automatic — the organisation must consider whether the other person has consented, what duties of confidence it owes, and whether it is reasonable to disclose without consent.
- Legal professional privilege. Schedule 2, Part 4, paragraph 19 of the DPA 2018 covers information over which privilege could be maintained, and information subject to a legal adviser's duty of confidence to a client.
- Material outside a reasonable and proportionate search. Article 15(1A). The organisation must be able to explain why a particular search would have been unreasonable or disproportionate.
What is not a lawful reason: that the material is embarrassing, that it is critical of you, that it is commercially awkward, or that you might use it against them. None of those is an exemption. One real limit does surprise people, though — Article 15 gives you a copy of your personal information, not the documents it sits inside. As the ICO puts it, a SAR does not necessarily give you the right to obtain documents or copies of documents.
If they refuse in whole or in part, Article 12(4) requires them to tell you without delay and within the applicable time period, give reasons, and tell you that you can complain — to the organisation under section 164A and to the Commissioner under section 165 — and seek a judicial remedy.
A month has passed and nothing has arrived
Chase in writing first. The ICO publishes a complaint letter template on its SAR pages. Then use the newer route: since 19 June 2026, section 164A of the Data Protection Act 2018 gives you a statutory right to complain to the organisation itself. It must:
- make complaints easy, including by providing a complaint form that can be completed electronically and by other means (s.164A(2));
- acknowledge receipt within the period of 30 days beginning when the complaint is received (s.164A(3));
- take appropriate steps to respond, including making enquiries and telling you about progress (s.164A(4)(a) and (5)); and
- inform you of the outcome (s.164A(4)(b)).
The ICO's guidance for organisations states that every controller must have a complaints process, and nothing in the section exempts particular controllers. What the law does *not* do is set a deadline for the outcome — only for the acknowledgement. The duty applies only to complaints received on or after 19 June 2026 (SI 2026/82, reg. 7). Breaching it can attract a penalty of up to the standard maximum: £8,700,000 or, for an undertaking, 2% of total annual worldwide turnover if that is higher (DPA 2018 s.157(4A) and (6)).
When to go to the ICO, and how long it takes
You can complain to the ICO at any time, but it recommends letting the organisation finish its own process first, and asks you to raise concerns within three months of your last meaningful contact with the organisation. The ICO then triages under its published Data Protection Framework, weighing harm, the number of people affected, whether vulnerable people are involved and whether intervention would improve standards. Some complaints are recorded for information only, without any investigation.
Be realistic about timing. The ICO receives tens of thousands of data protection complaints a year. It publishes the current position — complaints received, open caseload, and the percentage answered within its 90-day and six-month service targets — in its annual report, and that is the place to check rather than any figure quoted second-hand. Plan for months rather than weeks.
If you disagree with the outcome you can ask the ICO to review it. If the ICO does not tell you about progress or the outcome, section 166 of the DPA 2018 lets you apply to the First-tier Tribunal for an order to progress the complaint. Section 166 itself sets no deadline for applying, but the Tribunal's rules do: an application must be made within 28 days of the expiry of six months from the date the Commissioner received the complaint (GRC Rules 2009, rule 22(6)). Note the limit: in *Killock and Veale v Information Commissioner* [2021] UKUT 299 (AAC) the Upper Tribunal held that section 166 is procedural only. The Tribunal can order the ICO to get on with it; it cannot rewrite the answer.
Can you get compensation?
Not from the ICO. It says plainly that it cannot award compensation and cannot act as your representative. Compensation comes from Article 82 UK GDPR, which covers material and non-material damage; section 168(1) of the DPA 2018 confirms that non-material damage includes distress. You claim against the organisation — by agreement, or in court. Separately, section 167 lets a court order a controller to take, or stop taking, specified steps where it is satisfied there has been an infringement.
This area is genuinely unsettled, so treat any figure you see advertised with caution. In *Farley v Paymaster (1836) Ltd* (trading as Equiniti) the Court of Appeal held there is no threshold of seriousness in domestic data protection law, but also that a fear of third-party misuse must be well-founded to count as non-material damage. Paymaster was granted permission to appeal to the Supreme Court on 17 December 2025 and the appeal is listed for 7–8 October 2026 (UKSC 2025-0185).
If the organisation is regulated by the FCA, the Financial Ombudsman Service can consider a complaint about how it handled your information and can direct redress. That route is free. And deliberately altering, defacing, blocking, erasing, destroying or concealing information with intent to prevent disclosure after a SAR is a criminal offence under section 173 of the DPA 2018 — one that can be committed by the controller, by its employees, and by its officers — and the ICO can and does prosecute it.
Common questions
Do I have to say "subject access request" or quote Article 15?
No. The ICO's guidance is explicit that there are no formal requirements for a valid request. You can make it verbally or in writing, to any part of the organisation, and you do not have to use the phrases "subject access request", "right of access" or "Article 15". It just has to be clear you are asking for your personal information. A request that wrongly cites the Freedom of Information Act can still be a valid SAR.
Can my employer refuse my SAR because I've raised a grievance or an employment tribunal claim?
No. The purpose behind a request is not relevant to whether it is valid, and the ICO's own worked example says an employer cannot refuse simply because it suspects the information is wanted for litigation. An organisation can refuse a request that is manifestly unfounded or excessive, but Article 12(5) puts the burden of demonstrating that on the organisation and the threshold is high.
They've asked me to narrow my request. Do I have to?
No. You are entitled to ask for everything the organisation holds about you. But since 5 February 2026 the deadline is paused from the day they ask until the day you answer, so ignoring the request just delays the response. You must reply, even if only to say you are not narrowing it — and if you repeat the request, they still have to carry out a reasonable and proportionate search.
What's the longest they can legitimately take?
Three months from the relevant start date, if they notify you inside the first month that they are extending and explain why. On top of that, any days spent waiting for you to confirm your identity, pay a lawful fee, or clarify what you want do not count. Article 12A sets no cap on how long a clarification pause can last, which is why answering quickly matters.
The ICO says it has "recorded my complaint for information purposes only". What does that mean?
It means the ICO applied its Data Protection Framework criteria and decided it did not need to make further enquiries of the organisation before giving you an outcome. Your complaint is still logged and still counts towards the ICO's picture of how that organisation behaves. If you disagree with the outcome, you can ask the ICO to review it.
Can I claim compensation for a late or badly handled SAR?
Potentially, but not through the ICO — it has no power to award compensation. A claim under Article 82 UK GDPR is made against the organisation, and section 168 of the Data Protection Act 2018 confirms distress counts as non-material damage. The Supreme Court is due to hear Farley v Paymaster on 7–8 October 2026, which may change how such claims are assessed, so be sceptical of any firm quoting typical payout figures.
Sources
This page summarises the following primary sources. Where they disagree with this summary, they take precedence.
- Article 15 UK GDPR — right of access (as amended)
- Data (Use and Access) Act 2025, s.76 — new Article 12A time limits
- Data (Use and Access) Act 2025, s.78 — reasonable and proportionate search
- Data (Use and Access) Act 2025, s.103 and Sch.10 — complaints by data subjects
- Data Protection Act 2018, s.164A — complaints by data subjects to controllers
- Data Protection Act 2018, s.157 — maximum penalty amounts
- SI 2026/82 — DUAA commencement and transitional provisions (5 Feb and 19 June 2026)
- Tribunal Procedure (First-tier Tribunal) (GRC) Rules 2009, rule 22 — time limit for s.166 applications
- UK Supreme Court — Farley v Paymaster (1836) Ltd, UKSC 2025-0185
- ICO — What to do if you don't get a response or you're unhappy with it
- ICO — Why organisations might partially or fully refuse a subject access request
- ICO — Data protection complaints framework (how the ICO triages)
- ICO — Information Commissioner's annual report
Related guidance
-
How long do we have to answer a subject access request in 2026?
The UK subject access deadline is still one month. New UK GDPR Article 12A, in force 5 February 2026, lets you pause it for Article 15 requests only.
-
New rule from 19 June 2026: every UK organisation must have a data protection complaints process
From 19 June 2026 every UK controller must accept data protection complaints, acknowledge them within 30 days and give an outcome. No size exemption.
-
My data was leaked — can I actually claim compensation, and how much?
Being in a data breach does not automatically mean compensation. What Article 82 requires, what Farley v Paymaster decided, and what payouts really look like.