How to make a subject access request in Ireland
Five steps and a template. A valid request is just a clear written ask — who you are, what you want, where to send the answer — and the organisation has one month to respond.
On this page
1. Before you start
Work out which legal entity actually holds your data — the company you dealt with, not its brand name. An organisation’s privacy policy names its data controller and usually gives a data protection officer (DPO) contact; that address is where your request should go. Where none is published, any address the organisation demonstrably reads — info@, its registered office — starts the clock.
Gather what identifies your records: account numbers, customer or policy references, the email address and any previous names or addresses the organisation would know you by. A request that helps the organisation find you gets answered faster.
2. What to include
- the words “subject access request”;
- the legal basis: Article 15 of the GDPR and the Data Protection Act 2018;
- who you are, with the details that locate your records;
- what you want — all your personal data, or specific records if you know exactly what you are after;
- how you want the response delivered.
Asking for “everything” is valid. Being specific where you can — a date range, a department, particular records — tends to get a fuller answer to the part you actually care about.
3. Template letter
Copy this, fill in the brackets, and send it — email is fine. Or answer a few questions and our free generator writes it for you, including the on-behalf-of wording this static version leaves out.
[Today's date] [Organisation name] Dear Sir or Madam, SUBJECT ACCESS REQUEST I am making a subject access request under Article 15 of the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 for a copy of the personal data [organisation name] holds about me. MY DETAILS Name: [your full name] Date of birth: [date of birth] Address: [your address] Email: [your email] Account or reference numbers: [any references that help find your records] WHAT I AM ASKING FOR Please provide all the personal data you hold about me, in any format and on any system, including emails, letters, notes, call recordings, images and records held by anyone processing data on your behalf. PLEASE ALSO CONFIRM - the purposes you are using this personal data for; - the categories of personal data concerned; - who you have disclosed it to or will disclose it to, including any recipients in other countries and the safeguards that apply; - how long you will keep it, or how you decide how long to keep it; - where you obtained it, if you did not obtain it from me; - whether you use it for automated decision-making, including profiling, and if so what logic is involved and what the consequences are for me; and - that I have the right to ask you to correct or erase this data, to restrict or object to its use, and to complain to the Data Protection Commission. HOW TO RESPOND Please send the information electronically to [your email address]. I understand that there is normally no fee for this request, and that you must respond without undue delay and within one month of receiving it. If you need anything further from me to confirm my identity, or if you need me to narrow this request down, please tell me as soon as possible so that it can be dealt with quickly. Yours faithfully, [Your full name]
The “please also confirm” list is Article 15(1)(a)–(h) and 15(2) — the supplementary information most templates leave out. Keep it in unless you genuinely only want the records; the answers are often the most useful part of the response.
The regulator’s own wording, if you want something shorter
The Data Protection Commission publishes a template of its own, and it is about as short as a valid request gets:
“I wish to make an access request under Article 15 of the General Data Protection Regulation (GDPR) for a copy of any information you keep about me, on computer or in manual form in relation to…”
Two things worth taking from it. The first is “on computer or in manual form” — a reminder that paper files are in scope, which organisations occasionally pretend otherwise about. The second is the DPC’s instruction alongside it: “please be as specific as possible in relation to the personal data you wish to access”. The regulator and the template above agree — specificity gets you a better answer than “everything” does.
You do not actually have to write anything
A request does not have to be in writing to be valid. The DPC is explicit: “the GDPR does not set out any particular method for making a valid access request, therefore a request may be made by an individual in writing or verbally”. It encourages writing “to avoid disputes over the details, extent, or timing of an access request”, which is the right advice — but if you asked on the phone and were told it did not count, you were told wrong, and the clock started then.
One large exception. Records held for policing purposes run under Part 5 of the Data Protection Act 2018 instead, and there section 91(1) does require a request “by notice in writing”. See Garda records.
How the answer should come back
Say how you want it, because the default follows your request. The DPC’s rule is that “a controller should respond to your access request in the same way the request was made, or in the way in which you specifically asked for a response”, and that where you asked electronically the information should come “in a commonly used electronic format” unless you say otherwise. If you would rather not receive a box of photocopies, one sentence in the request prevents it.
4. Identity checks
An organisation may ask you to confirm your identity, but only where it has reasonable doubts about who you are, and it should ask for no more than it needs. Where it genuinely needs that information, it can wait for it before acting on your request — so provide it promptly.
An organisation asking for proportionate ID — a copy of a driving licence or passport where sensitive records are involved — is normal. One demanding notarised documents to hand over a copy of your own emails is not; ask it to justify the demand, and mention that you will raise it with the Data Protection Commission if it maintains it.
5. What happens after you send it
An organisation must respond without undue delay and within one month of receiving your request. It may extend by up to two further months where requests are complex or numerous, but it must tell you within the first month that it is extending, and why.
There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies of your data.
Diary the date one month out. If the response is late, partial or never comes, the Data Protection Commission route is free and does not need a solicitor. Received a response you suspect is incomplete? Our free response checker walks through what a complete answer contains.