Organisation
Subject Access Request to Google
What Google holds about you, where to send the request, and what to expect back.
GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of Google. The contact details below are published so you can make a request yourself free of charge.
Where to send your request
Verified 16 August 2026- Postal address
- Google LLC 1600 Amphitheatre Parkway Mountain View California 94043 USA
- Their own SAR form
- Open Google’s request form
- ICO registration
- Z2451429
- ID they ask for
- You have to be signed in to the Google Account the request is about. The form shows which account you are signed in as and offers to switch, and Google's stated reason is "to protect user privacy and to ensure that we disclose data to the user concerned". It then asks which country you live in, which Google product you are asking about, and what personal data you are seeking — "Please provide specific information to enable us to locate and identify the relevant data" — in a box capped at 1,000 characters. Google asks for no identity documents on the form.
Source: Google published information. Organisations change these details — tell us if this is out of date.
This only works from your own Google Account, and Takeout is not a subject access request
For someone in the United Kingdom the controller is Google LLC, not Google's British or Irish company. Google's privacy policy says the controller "depends on where you are based" and names "Google LLC for users of Google services based in the United Kingdom, located at 1600 Amphitheatre Parkway, Mountain View, California 94043, USA", with Google Ireland Limited covering the European Economic Area and Switzerland instead. Google LLC is also the controller for what is indexed and displayed in Search and Maps, wherever you are. You have to be signed in, and nobody can do it for you through this route. The Data Access Request Form says: "In order to protect user privacy and to ensure that we disclose data to the user concerned, we can only process data access requests sent from the user's Google Account. If you are seeking information on behalf of someone else, please ask that person to fill out this form once they have signed into their own Google Account." So a request sent by a representative, a solicitor or a paid service is not processed here — the account holder has to send it. A written request is valid in law however you send it, but Google publishes no postal or email route for one, and the address above is the controller's registered location rather than a submission address. Try the free tools first, because Google asks you to. The form's own instruction is: "We've created tools that allow you to access the data that Google holds about you. Please check out your Account page, Google Dashboard, Google Takeout, and the relevant Google product account settings. You should only submit a request through this form for specific categories of personal data that you believe are not available in the tools mentioned above." Google Takeout exports "a copy of content in your Google Account", free and immediately. Content you created is not the same thing as everything Google holds about you, though, and neither Google page calls Takeout a subject access request. Be specific, and expect a limit. Google warns on the form that "Certain information cannot be provided for security reasons", and publishes no timescale for a reply on any of these pages — the one month you are entitled to comes from the law, not from a commitment Google has made. Getting something taken down is a different request. Removing a search result about you, or content from a Google service, goes through Google's reporting route, which "will help you get to the right place to report content that you would like removed from Google's services under applicable laws". A subject access request will not remove anything. Deleting your data and closing your account are separate again, and are done from your Google Account rather than by request. If a reply arrives and you cannot tell whether it is complete, our free response checker will show you what is missing.
Making a request to an organisation
Made under UK GDPR Article 15
Any organisation that decides how and why your personal data is used is a data controller, and must respond to a subject access request. That covers retailers, employers, membership bodies, landlords, charities, gyms and online services alike.
The organisation must confirm whether it is processing your data, provide a copy of it, and explain why it holds it, who it shares it with and how long it keeps it. There is normally no fee.
What people commonly ask for
- All personal data held about you
- Correspondence and internal notes referring to you
- Account, order or membership history
- Call recordings and chat transcripts
- Marketing preferences and consent records
Watch out for
- Identify the right legal entity — brand names and registered companies often differ.
- Large groups may hold your data across several companies, each a separate controller.
- Be specific about what you want if the organisation is likely to hold a lot.
Your rights, whoever you are asking
Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.
Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.
Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.
How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.
If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.
Send it to Google
You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.
This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.