GetMySAR

GetMySAR Guides

How to Make a GDPR Request

A GDPR request is how you use your data protection rights against any UK organisation — most often, to get a copy of the personal data it holds about you. This guide covers what a GDPR request is, how it relates to a subject access request, how to word one, and what has to happen once it arrives.

1. What is a GDPR request?

A GDPR request is a request you make to an organisation to exercise one of your rights under the UK GDPR — most often, the right to get a copy of the personal data it holds about you.

“GDPR request” is not a term the law itself uses. The UK GDPR gives you a set of individual rights, and a request under any of them is what people mean when they say GDPR request. By far the most common is the right of access — asking an organisation what data it has on you and for a copy of it. If that is what you want, this page walks you through it.

You can make a GDPR request yourself, directly to the organisation, for free. You do not need a solicitor, a template bought online, or any paid service to have the right honoured.

In the UK the relevant law is the UK GDPR, which sits alongside the Data Protection Act 2018 — the UK kept the GDPR’s substance after leaving the EU. Our guide to the UK GDPR explains the law itself; if you are in Ireland or dealing with an Irish organisation, the EU GDPR applies and our Irish guide covers that side.

2. GDPR request, GDPR subject access request or SAR — the same thing?

When you are asking for a copy of your data — yes. A subject access request (SAR, or DSAR) is the formal name for a GDPR request made under the right of access. The two phrases describe the same request: “GDPR request”, “GDPR subject access request”, “SAR” and “data subject access request” all reach the same right and get the same response.

The vocabulary matters only because organisations tend to use the formal name. Writing “subject access request” in your request can help route it to the right team faster, but it is not required — a request is valid however you phrase it, as long as it is clear you are asking for your personal data.

For the full picture of what a SAR is and what you get back, see what is a Subject Access Request. This page concentrates on making the request.

3. The kinds of GDPR request you can make

The UK GDPR gives you eight individual rights, and a request under any of them is a GDPR request:

  • Access — a copy of your data and information about how it is used. The most common request, and the rest of this page.
  • Rectification — correcting inaccurate or incomplete data.
  • Erasure — deletion of your data, widely known as the right to be forgotten. See our guide to the right to be forgotten.
  • Restriction — limiting what is done with your data while a dispute is resolved.
  • Portability — receiving data you provided in a machine-readable format, or having it sent to another provider.
  • Objection — objecting to processing, including direct marketing, which must then stop.
  • Being informed, and rights around automated decision-making — met mostly through privacy notices and safeguards rather than requests you send.

Each right is explained in plain English, with how to use it, in your data protection rights under UK GDPR.

4. How to make a GDPR request

There is no official form and no fee for a normal request. Three steps:

  • Find the right organisation. Requests go to the organisation that holds your data — the data controller — not to a regulator. If it is a large organisation, its privacy policy usually names a data protection contact or a dedicated route. Our directory of UK organisations lists verified routes for many of them.
  • Put it in writing. Email is fine, a letter is fine, and many organisations have an online form. A request is valid if it is clear that you are asking for your personal data — you do not have to cite the GDPR, name an article, or use legal wording.
  • Keep a record. Note the date you sent it and keep a copy. The response deadline runs from when the organisation receives the request, so your record is what settles a dispute about timing.

5. What to include in the request

A request that is easy to act on tends to get a better response:

  • enough detail to identify you — your name, and the details the organisation knows you by, such as an account number, customer reference or the email address on file;
  • what you want — “a copy of the personal data you hold about me” covers everything, or you can be specific: emails mentioning you between two dates, call recordings, notes on your account, CCTV from a particular time and place;
  • how you would like to receive it;
  • the date you sent it.

Being specific is not a legal requirement, but it helps. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.

Our free letter generator produces a complete, properly-worded request you can download or email — no charge, no sign-up. It is the fastest way to get the wording right.

6. Time limits, fees and identity checks

An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.

There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.

An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.

7. The GDPR right of access: Article 15

The right of access is Article 15 of the UK GDPR. It entitles you to confirmation of whether your data is being processed and, where it is, to a copy of the data and to supporting information — including the purposes of the processing, who your data has been shared with, how long it will be kept, and where it came from if not from you.

The ICO publishes guidance on the right of access that organisations are expected to follow when they respond. For what the law says in more depth — including the exemptions that can narrow a response — see our plain-English guide to the UK GDPR.

8. If the organisation does not respond

Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.

Our free SAR response checker helps you judge whether a response you have received is complete, and what to do next if it is not.

9. Making a GDPR request with GetMySAR

You can make a GDPR request yourself for free, and many people do. The right is yours either way.

Some people prefer to have the process handled: the request worded correctly, sent to a verified route, tracked against the deadline, and followed up if the organisation is slow, asks for clarification or sends an incomplete response. That is what GetMySAR does, for a service fee of £20.

Using GetMySAR does not create extra legal rights — an organisation should apply the law fairly whether you act alone or through a representative. The fee pays for preparation, submission, tracking and follow-up, not for the right itself.