Getting your Garda records
An Garda Síochána holds records on far more people than it arrests — witnesses, complainants, drivers, correspondents. You can ask for yours; the law is just a different Part of the 2018 Act than most guides describe, and it has a deadline.
GetMySAR is an independent service. We are not An Garda Síochána and not a law firm. Nothing here is legal advice. Every route on this page is one you can use yourself, and asking for your own records is free.
On this page
1. This is not Garda vetting
Garda vetting and a subject access request are different things, and people arrive here wanting one and asking for the other.
- Garda vetting is a check an employer or organisation applies for, through the National Vetting Bureau, when you will be working with children or vulnerable adults. You cannot apply for it on your own behalf.
- A subject access request is you asking An Garda Síochána for the personal data it holds about you. That is what this page covers.
If an employer has told you to make a subject access request and hand over the result, be careful — that practice is what data protection law calls enforced subject access, and it is treated as an abuse of the right rather than a normal use of it. A vetting disclosure is the proper route for an employer’s question.
2. Garda records run under a different Part of the Act
Data processed for policing purposes — investigating and prosecuting offences — does not run under the GDPR. It runs under Part 5 of the Data Protection Act 2018, which transposes the EU’s separate law-enforcement directive.
The right of access itself is section 91. It is a real right with a real deadline, and three things about it differ from the GDPR request most guides describe:
- It must be in writing. Section 91(1) applies where an individual “so requests the controller by notice in writing”. Under the GDPR a verbal request is valid; here it is not. Put it in writing and keep a copy.
- The deadline is one month. Section 91(2) requires a controller to respond “as soon as may be and … in any event not later than one month after the date on which the request is made”. This page previously left that unsaid, and readers reasonably concluded there was no clock. There is.
- The clock can stop, and the statute says so plainly. Under section 91(4), where the controller has reasonable doubts about your identity or reasonably needs more information to locate the data, the period from that request until you answer it “shall not be reckonable” for the deadline. Answering an identity query slowly is answering it at your own expense.
Section 91(5) also allows extra time where the request is complex or the controller has received a number of them — the same idea as the GDPR extension.
Garda data that is not policing data — its dealings with you as an employee or a correspondent, for example — stays under the GDPR, where the standard rules apply: An organisation must respond without undue delay and within one month of receiving your request. It may extend by up to two further months where requests are complex or numerous, but it must tell you within the first month that it is extending, and why.
You do not have to work out which regime each record falls under before you write. Cite the Data Protection Act 2018 rather than the GDPR alone and the request is valid either way.
3. What section 91 actually entitles you to
Worth knowing before you read the response, because the list is longer than “a copy of my file”. Section 91(1)(b) entitles you to confirmation that your data is being processed and then:
- a description of the purpose of, and the legal basis for, the processing — the legal basis is an item the GDPR list does not spell out in the same terms;
- the categories of personal data concerned;
- the recipients or categories of recipients the data has been disclosed to;
- the retention period, or the criteria used to work it out where it cannot be stated;
- information about your right to ask for rectification or erasure;
- information about your right to complain to the Data Protection Commission, and the DPC’s contact details;
- “a communication of the personal data concerned” — the data itself; and
- any available information about where the data came from, “unless the communication of that information is contrary to the public interest”.
That last item is the one worth asking about explicitly. On a Garda record the origin is often the substance of what you want to know — who reported something, or which body passed information across — and it is also the item most likely to be withheld, with the public- interest qualifier sitting right there in the section.
4. How to make the request
An Garda Síochána publishes its route on its data protection page, and asks you to use its form: “To assist An Garda Síochána in processing your Subject Access Request (SAR) please complete the Subject Access Request form (F20)”. The form is linked from that page as An Garda Síochána F20, a 52KB PDF dated October 2019.
“To assist” is the operative phrase. Section 91 requires a notice in writing, not a particular form, so a letter that gives the same information is a valid request.
Where to send it
An Garda Síochána publishes a single data protection contact for all queries:
An Garda SíochánaData Protection Unit
Third Floor
89–94 Capel Street
Dublin 1
D01 E3C6
Email DataProtection@garda.ie · Phone +353 (01) 666 9521
Office hours: Monday to Thursday 10.00–13.00 and 14.00–16.30; Friday 10.00–13.00 and 14.00–16.00.
Published by An Garda Síochána and checked 6 September 2026.
Section 91(3) puts an obligation on you as well as on them: when making the request you must provide “such information as the controller may reasonably require to satisfy itself of the identity of the individual and to locate any relevant personal data”. So say what records you are after and what they relate to — dates, locations, the station, and any incident or PULSE reference a letter has ever quoted at you. Doing that up front is also what stops the section 91(4) clock-stop being triggered.
The general Irish guide covers wording, and the free letter generator writes the request for you.
5. What comes back, and what will not
Expect redactions. Other people’s data comes out; so can anything whose disclosure would prejudice an active investigation, reveal intelligence, or endanger someone. A response can lawfully neither confirm nor deny that certain records exist.
The restrictions are not open-ended, though — section 91 opens “Subject to subsections (7), (9) and (12) and sections 93(4)(ii) and 94”, which is a closed list of places a restriction can come from rather than a general discretion. What you should still get is everything releasable, and a response that says restrictions have been applied.
If a record you want relates to a prosecution rather than to policing — court files, for instance — that is a different holder again, and the Garda Data Protection Unit will not be the right address for it.
6. If you are ignored or refused
Raise it with the organisation first — its data protection officer, if it has one, is the right address. If that gets you nowhere, Article 77 of the GDPR gives you the right to lodge a complaint with the Data Protection Commission, which supervises data protection law in Ireland.
The Data Protection Commission supervises Garda processing under both regimes, complaining is free, and the DPC can examine restricted material that you are not allowed to see yourself — which is the whole point of having a regulator on this subject.
Two different addresses are in circulation for the DPC. The Garda data protection page gives 21 Fitzwilliam Square South, Dublin 2, D02 RD28. The DPC’s own website gives 6 Pembroke Row, Dublin 2, D02 X963. Both were read on 6 September 2026. Use the DPC’s own — a regulator’s current address is the one it publishes about itself — and note that the DPC’s preferred route is its online form rather than post anyway.
How to complain to the DPC sets out what the DPC asks you to send, which differs depending on whether your complaint is about silence, an incomplete response, or an exemption you think has been misapplied.
Where this comes from
The statutory detail is quoted from section 91 of the Data Protection Act 2018 itself, and the contact details and form from An Garda Síochána’s own data protection page. Both are linked at the point they are used.
Sources checked 6 September 2026.