Organisation
Subject Access Request to Instagram
What Instagram holds about you, where to send the request, and what to expect back.
GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of Instagram. The contact details below are published so you can make a request yourself free of charge.
Where to send your request
Verified 18 August 2026- Postal address
- Meta Platforms, Inc. ATTN: Privacy Operations 1 Meta Way Menlo Park, CA 94025, USA
- Their own SAR form
- Open Instagram’s request form
- ICO registration
- ZB540144
- ID they ask for
- Meta asks for no identity document at any point — no passport, no driving licence, no proof of address. What it asks for instead is an Instagram sign-in, and the signed-out route asks for account details rather than documents. The privacy rights portal at help.meta.com/support/privacy throws a full-screen Instagram login dialog the moment you choose Instagram, and it cannot be dismissed with Escape or by clicking away. The only way past it is the link inside it reading "Click here if you are having trouble accessing your account or if you don't have an account". The form that route reaches, "Contact the Data Protection Officer (DPO)", collects a query type from a fixed list, First name, Last name, Email address, Username — "Your username is often a variation of your name, such as jane.doe.33 or janedoe3" — and an optional Account URL. It has no free-text box at all. Meta adds: "Note that we can only assist with one account per query. If you would like to submit a query related to more than one account, please use the form separately for each account."
Source: Instagram published information. Organisations change these details — tell us if this is out of date.
Specific to Instagram
Instagram has no privacy policy of its own. instagram.com/legal/privacy redirects to Meta's privacy policy on the Instagram domain, which says: "The data controller responsible for your information is Meta Platforms, Inc., which you can contact online, or by writing to: Meta Platforms, Inc., ATTN: Privacy Operations, 1 Meta Way, Menlo Park, CA 94025, USA." So for someone in the United Kingdom the controller is an American company, not a British or an Irish one. The same policy names the Information Commissioner's Office as the regulator you can complain to, which is how you can tell it is the version written for the UK, and the sentence introducing the address covers "questions, complaints or requests regarding your information" — so it is a route for requests and not only a company identity. Meta Platforms Ireland Limited holds a separate UK data protection registration and is not the controller here. Start with the export, which is free and needs no letter: More, then Settings, Meta Account, Your information and permissions, Export your information, Create export. There is a choice inside it that matters more than it looks. Instagram offers "Available information", which it says will "include information and activity for the accounts and profiles you selected but won't include data logs", and "Specific types of information", which "includes all of the files in Available information as well as data logs". The narrower option is the one most people will take, and it quietly leaves a category out. Instagram says "it may take up to 30 days for us to email you an export link", and that once it is ready "you'll have 4 days to export your information in the Available downloads section". Deleted material will not be in it: Instagram says content you have deleted "may be stored temporarily for safety and security purposes, but will not appear when you access or download your information", and the recycle bin starts emptying itself after 30 days. So if something matters, take the export now. If you want something the export does not contain — data logs, advertising information, or what Meta says it collects "about you based on others' activity" — that is a request, and the route is Meta's privacy rights portal. Follow the path exactly, because the page looks closed when it is not. Choose Instagram and an Instagram login dialog covers the topic list the moment it loads; the topics underneath are never clickable, and neither Escape nor clicking away will dismiss it. The way through is the link inside the dialog reading "Click here if you are having trouble accessing your account or if you don't have an account". Answer the account question, choose "How can I get support for a privacy issue from the Data Protection Officer?", and Meta finishes with "To submit a query, please create a case below." Do not type a deep link from that funnel into the address bar: the portal's classification URLs work when clicked and strip to an empty menu when typed. The form that path reaches, "Contact the Data Protection Officer (DPO)", offers eight query types including "I want to access my information" and "My query is on behalf of someone else", and asks for a name, an email address, a username and an optional account URL. It has no box to write the request in. Meta says "Once you submit your case, we will contact you via email to ask for more details about your query", so the substance is stated in a later reply rather than at submission, and it will only handle one account per query. The phrase "subject access request" appears nowhere in the funnel, on the privacy policy, or on the export article. If you cannot get into your account, Instagram's own advice is a dead end: its export article tells you to contact it, and that link goes to a page that renders an empty menu behind a login dialog. For anyone in that position the honest routes are the postal address above, which our free letter generator will word for you, or a complaint to the ICO. Meta publishes no response time for a data request. The one month you are entitled to comes from the law, not from a promise Meta has made, and the 30 days on the export is that tool's own turnaround. Meta publishes no email address on any of its own pages and no telephone route. The address dpowallc@meta.com appears on Meta Platforms Inc's entry in the ICO register as the data protection officer's contact; Meta does not offer it as a way of making a request, which is why it is not printed as the route above. The register also gives the company's address as 1601 Willow Road rather than 1 Meta Way — both are Meta's Menlo Park campus, and the address above is the one Meta publishes for privacy correspondence. A request about someone who has died is not a subject access request, because the right of access ends at death, and GetMySAR cannot take one. Instagram's routes for that are memorialising or removing the profile, and neither is a request for data. It says it requires "proof of death, such as a link to an obituary or news article, to memorialize a profile", that "verified immediate family members may request the removal of a loved one's profile" on proof including a death certificate or "proof of authority under local law that you are the lawful representative of the deceased person, or his/her estate", and that "we can't provide login information for a memorialized profile". Both of those forms redirect a signed-out visitor to Instagram's login page, so a relative who does not use Instagram cannot open either one without first creating an account. Facebook is the same controller, the same postal address and the same complaint route, and only the request route differs — the Facebook branch of Meta's portal has no access option at all, where Instagram's does. WhatsApp is a different company again — WhatsApp LLC, under its own UK privacy policy and its own registration — so a request about WhatsApp goes somewhere else entirely. Snapchat gives the same answer about content that has gone. Google and Amazon work the same way as the export — the easy route runs through your own signed-in account. If a reply arrives and you cannot tell whether it is complete, our free response checker will show you what is missing.
Making a request to an organisation
Made under UK GDPR Article 15
Any organisation that decides how and why your personal data is used is a data controller, and must respond to a subject access request. That covers retailers, employers, membership bodies, landlords, charities, gyms and online services alike.
The organisation must confirm whether it is processing your data, provide a copy of it, and explain why it holds it, who it shares it with and how long it keeps it. There is normally no fee.
What people commonly ask for
- All personal data held about you
- Correspondence and internal notes referring to you
- Account, order or membership history
- Call recordings and chat transcripts
- Marketing preferences and consent records
Watch out for
- Identify the right legal entity — brand names and registered companies often differ.
- Large groups may hold your data across several companies, each a separate controller.
- Be specific about what you want if the organisation is likely to hold a lot.
Your rights, whoever you are asking
Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.
Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.
Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.
How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.
If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.
Send it to Instagram
You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.
This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.