Telecoms provider
Subject Access Request to giffgaff
What giffgaff holds about you, where to send the request, and what to expect back.
GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of giffgaff. The contact details below are published so you can make a request yourself free of charge.
Where to send your request
Verified 17 August 2026- Postal address
- Data Protection Officer giffgaff Ltd Belmont House Belmont Road Uxbridge UB8 1HE
- dpo@giffgaff.co.uk
- Contact
- Data Protection Officer
- ICO registration
- Z1998681
- ID they ask for
- giffgaff says it must verify your identity before it will process a request, and asks for a coloured copy of your passport, driving licence, birth certificate or a utility bill showing the account holder's name, plus your SIM Serial Number (SSN) if the request relates to your phone account. It says it may refuse a request if it cannot verify who you are, or if the request is clearly unreasonable or excessive.
Source: giffgaff published information. Organisations change these details — tell us if this is out of date.
Specific to giffgaff
Email or post are the routes to use. giffgaff's privacy policy names both for exercising your data rights, and neither needs a giffgaff account. Its other two online routes do not work for that purpose: the "Ask a giffgaff Agent" option and giffgaff's support form both redirect to a member login, and the button on giffgaff's own subject access page labelled "Submit a SAR request" — under a heading calling it the quickest and easiest route — links back to the page you are already on. If the online route defeats you, you can write the request yourself and send it to the address above; a written request is valid however it arrives. giffgaff publishes its data protection officer at two addresses: dpo@giffgaff.co.uk on its privacy policy and on its ICO register entry, and dpo@giffgaff.com on one of its help articles. The .co.uk one is above. The Reading address in giffgaff's regulatory footer, 500 Brook Drive, is its registered office and the building it shares with O2 — giffgaff does not ask anyone to send a data request there. Before you file, note that giffgaff's own advice is that 12 months of call and text records are faster to get by asking an agent, and that account details can be changed in your dashboard. Both of those are behind the member login, so they are open to the account holder and to nobody else. A request reaches things the dashboard does not show — contact and complaint notes, your giffgaff Community posts and messages, credit and fraud-check records, and the file behind an account someone says they did not open. What giffgaff says it will send is narrower than what it holds. Its subject access page says records go back 12 months only, cover outgoing calls and texts, and exclude incoming records and the content of any message — while its privacy policy says it holds the numbers, dates, durations and costs of communications made and received by you. That is a limit on what giffgaff will disclose rather than a statement that the data does not exist, and it is worth naming the incoming records in your request. giffgaff also says it replies within 30 days and may charge an admin fee in rare cases; in law a subject access request is free unless it is manifestly unfounded or excessive, and the reply is due within one calendar month. Ask early. giffgaff says raw network data about calls is kept for up to 12 months, that account information including your profile, contact details and payment history may be kept for up to 7 years, and that information used to provide your service is held for as long as you are a member plus 12 months after you leave. The two figures overlap and giffgaff does not reconcile them, so a former member should assume about a year. giffgaff publishes no retention period for call recordings at all. giffgaff runs on O2's mobile network and Virgin Media's broadband network, and all three are separately registered controllers — an O2 or Virgin Media account is a separate request to a different company. giffgaff also sits in a different complaints scheme from both of them: if a service complaint is unresolved after six weeks or you reach deadlock, giffgaff's adjudicator is the Communications Ombudsman, not CISAS. For someone who has died, giffgaff publishes no route to their records. Its bereavement team, bereavementteam@giffgaff.com, will close or keep the account and asks for a copy of the death certificate, but says nothing about data. Rights of access end at death, so this is not a subject access request.
Making a request to a telecoms provider
Made under UK GDPR Article 15
Telecoms providers hold account and billing records, itemised usage, call recordings and chat transcripts from customer service, contact and complaint notes, and the credit checks run when the contract was opened.
Requests here usually follow a billing dispute, a contract taken out fraudulently in the person's name, or a complaint that went nowhere. Call recordings and chat transcripts are typically the useful part, because they show what was actually promised.
Records of who you called or messaged and when are traffic data, and a provider has to erase or anonymise them once they are no longer needed to carry the communication or to bill you for it. That is why usage records reach back months where account paperwork survives for years, and it is the main reason a request made long after the events comes back with less in it than the person expected.
What people commonly ask for
- Account and billing history
- Call recordings and live chat transcripts
- Customer service contact and complaint notes
- Credit checks run at contract opening
- Records of a contract you say you did not open
Watch out for
- Ask early. A provider has to erase or anonymise usage data once it no longer needs it, so the gap between the events you care about and the request often decides what comes back.
- Give the phone numbers, the dates and the approximate times you are asking about. A request that does not narrow the period tends to come back as billing data without the calls you actually wanted.
- Another person's number is their personal data as well as part of your record, so records of incoming calls and messages are commonly withheld or redacted, and some providers will release them only under a court order or witness summons.
- Providers carry your calls and messages but do not normally keep what was said in them, so a subject access request will not produce the content of a call or a text. Recordings of calls you made to the provider's own customer services are a different thing and can be asked for.
- A subject access request gets you the records; it does not get a bill or a service problem put right. Complain to the provider first — after six weeks, or once it issues a deadlock letter, one of the two Ofcom-approved ADR schemes will consider a service complaint free of charge, and which one depends on your provider. A complaint about how the provider handled your data goes to the Information Commissioner's Office instead.
Your rights, whoever you are asking
Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.
Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.
Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.
How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.
If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.
Send it to giffgaff
You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.
This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.