Insurer
Subject Access Request to Admiral
What Admiral holds about you, where to send the request, and what to expect back.
GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of Admiral. The contact details below are published so you can make a request yourself free of charge.
Where to send your request
Verified 6 September 2026- Postal address
- Data Protection Officer Admiral Group plc Ty Admiral David Street Cardiff CF10 2AA
- Contact
- Information Rights Team
- ICO registration
- Z5299783
Source: Admiral published information. Organisations change these details — tell us if this is out of date.
Specific to Admiral
Admiral is a trading name of EUI Limited, and EUI Limited is the company most Admiral customers hold their policy with. Admiral's privacy policy says the data controller is whichever of its UK companies you got a quote or bought your policy from, and that the same policy covers all of them. EUI Limited also trades as Bell, Diamond, Elephant, Gladiator and MoreThan, so one request covers those brands too. Veygo belongs to a different company in the group, Able Insurance Services Limited, and Veygo's own privacy page says it operates under the same shared group privacy policy. Admiral names Admiral Insurance Company Limited and Admiral Insurance (Gibraltar) Limited separately as data controllers for motor insurance, alongside Great Lakes Insurance SE. Whichever of them holds your policy, the request goes to the same place. Admiral asks for subject access requests by email, to its Information Rights Team. Its summary of the route says only "contact the Information Rights Team" and puts the address behind the link, so a reader skimming the privacy policy home page will not see an address at all. The rights page spells it out: "To ask for access to your personal data, you can email us at InformationRightsTeam@admiralgroup.co.uk or give us a call." Admiral publishes no number against that invitation to call, and no online form for a request. Three other data protection mailboxes appear on the same estate and none of them is the request route. DPOoffice@admiralgroup.co.uk is offered for questions, concerns or feedback about the policy, and for working out which Admiral company is your controller. yourinformationrights@admiralgroup.co.uk is the Data Protection Officer's, for questions about your rights or for saying they have not been met. marketingpreferences@admiralgroup.co.uk, which sits on the same page as the subject access route, is for marketing opt-outs only. The postal address on this page is the Data Protection Officer's too, because Admiral publishes no postal address specifically for making a request. A request in writing is valid however you send it. One thing worth knowing if you download Admiral's complete privacy notice as a PDF: its "How to get in touch" page gives the Data Protection Officer's mailbox and not the Information Rights Team's, so the document sends you to the escalation route rather than the request route. Admiral says it has one month to respond and that in some situations it can extend that by another two months, and that in most cases you do not have to pay. A request reaches more than the policy paperwork. Admiral lists voice recordings of calls to its call centres, webchat transcripts, and emails to its customer care team; and claims data including where the incident happened, claim evidence such as photographs, dashcam footage, CCTV or automatic number plate recognition, details of any injuries, and information from your car's on-board diagnostics device or telematics app. It lists ID documents "including photographs and videos, which may include biometric data". Complaints are not a separate category: Admiral lists resolving complaints among the things it uses your account, claims and customer service data for. If you have a black box or app-based policy, Admiral says the telematics data it collects is the date and time, your location as latitude and longitude, speed, distance and duration, and acceleration, braking and cornering. It also says that if the device detects a serious crash it will try to contact the policyholder and the named drivers, and share details with the emergency services if it cannot reach anyone. Admiral says it usually keeps policy records for seven years after the end of its relationship with you, and longer where a claim has not been settled. If you get a quote and do not buy, it says the data it took from the DVLA database is made anonymous or deleted no later than 30 days after it receives it. Admiral names the Motor Insurers' Bureau as the operator of the databases your claims history sits on. In its own words, it passes information to the Claims and Underwriting Exchange Register and the Motor Insurance Anti-Fraud and Theft Register, "These are both managed by the Motor Insurance Bureau (MIB)", and it adds your policy to the Motor Insurance Database, "which is managed by the Motor Insurers' Bureau (MIB)". One request to MIB reaches all of them, and MIB rather than Admiral holds them. Admiral also checks your driving licence number against the DVLA driver database, and names its fraud prevention agencies as Cifas, the Insurance Fraud Bureau and Lexis Nexis. Admiral's privacy policy claims no exemption from subject access. The word "exempt" does not appear in it anywhere, and neither does legal privilege, which insurers commonly rely on once a claim dispute has escalated. Every policy has a policy administrator, and Admiral says that person "will have access to all the documents, information and personal data relating to anyone who's insured on the policy". So a named driver's own request is the way to see what Admiral holds about them without going through the policyholder. Beyond that, Admiral says it will only deal with people named on the policy or an "acceptable caller", which it defines as the policyholder, a named driver, the spouse, partner or parent of a policyholder, a secretary or personal assistant added by the policyholder, and "any other person, or organisation, that can show evidence they have the authority to act on the policyholder's behalf, and passes our data protection procedure". To nominate someone to deal with your policy regularly, Admiral asks you to contact it online or write to Admiral Group plc, Ty Admiral, David Street, Cardiff, CF10 2EH. All of that is written about managing the policy rather than about a subject access request, and Admiral publishes no separate rule for a representative making one. Data protection rights end when someone dies, so a subject access request cannot be used to get a deceased person's records. Admiral's privacy policy says nothing about death, executors or probate at all. It runs a separate bereavement route instead, with an online form to tell it the policyholder has died and a dedicated phone line. A subject access request gets you the records; it does not get a claim decision or a price reviewed. Admiral says it will respond to a complaint within eight weeks, and that you must refer it to the Financial Ombudsman Service within six months of the date of Admiral's final response. Its own published complaints data for the first half of 2026 records 65,577 complaints opened across the group's insurance brands, 3.73 for every thousand policies, with 64% upheld and general administration and customer service errors the main cause. Separately, where an automated decision has a legal or significant effect Admiral says it is your right to ask it to explain the logic, and it names a dedicated Pricing Queries team for questions about how a price was calculated. If you need Admiral's response in Braille, large print, on coloured paper or as an audio file, it publishes a "request adjusted documents" form for exactly that, and it points people with hearing or speech difficulties at Relay UK.
Making a request to an insurer
Made under UK GDPR Article 15
An insurer's claim file usually contains far more than the correspondence you have seen: internal claim notes, loss adjuster and investigator reports, underwriting and pricing records, surveillance where it was commissioned, and any medical evidence obtained.
These requests are usually made during a dispute about a declined or underpaid claim. That timing matters, because material created once litigation was in contemplation may be withheld under the legal professional privilege exemption in Schedule 2, Part 4 of the Data Protection Act 2018.
Insurers also share data through industry databases that other organisations run, so records held there need their own requests. The Claims and Underwriting Exchange and the Motor Insurance Database are both operated by the Motor Insurers' Bureau, which now runs the vehicle register under the name Navigate, so a single request to MIB covers both. The Insurance Fraud Register is managed and administered by the Insurance Fraud Bureau, which is a separate request again.
What people commonly ask for
- The full claim file and internal claim notes
- Loss adjuster and investigator reports
- Underwriting and premium calculation records
- Medical evidence and reports obtained about you
- Records of a claim declined or a policy voided
Watch out for
- Legal professional privilege is commonly claimed once a dispute has escalated.
- CUE and MID entries are both held by the Motor Insurers' Bureau, so one request covers both; the Insurance Fraud Register is a separate request to the Insurance Fraud Bureau.
- Ask explicitly for surveillance material if you believe any was commissioned.
- A SAR is not a complaint — if you want the claim decision reviewed, the Financial Ombudsman Service is the separate route.
Your rights, whoever you are asking
Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.
Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.
Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.
How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.
If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.
Send it to Admiral
You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.
This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.