GetMySAR

Bank or lender

Subject Access Request to Monzo

What Monzo holds about you, where to send the request, and what to expect back.

GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of Monzo. The contact details below are published so you can make a request yourself free of charge.

Where to send your request

Verified 6 September 2026
Postal address
Monzo Broadwalk House 5 Appold Street London EC2A 2DA
ICO registration
ZA108184
ID they ask for
Monzo asks you to send a selfie with your emailed request: "please ensure that you include a Selfie holding ID or a selfie holding a piece of paper with today's date written on it (ensuring that they're both clear and you haven't sent the same image to us before)". It also asks you to say what you are looking for, and says it will act "once we've verified your identity". Monzo explains elsewhere that it uses a selfie because it has no branches at which to check identity in person. It publishes no list of acceptable identity documents and no separate process for a representative.

Source: Monzo published information. Organisations change these details — tell us if this is out of date.

Specific to Monzo

The Monzo app already gives you your statements, so most people asking Monzo for their information do not need a request at all. Monzo's own instructions are to tap Home, tap the three dots underneath your card, tap Bank statements, then "Choose the date range you'd like" and "Choose the format you'd like (PDF, CSV, QIF)". What the app does not have is a download-your-data export: there is no button anywhere in Monzo that hands you a copy of your record. A request is for what the statements do not show, and Monzo confirms it holds most of it: "information you give us through in-app chat, emails and in-app forms", and if you phone instead, "the phone number you're calling from and information you give us during the call (we record all calls)". Add complaint files, fraud and affordability assessments, and the reasoning recorded behind a frozen account or a declined application. The request itself is an email or a phone call, and Monzo asks for a selfie. Its Getting a copy of your data article says "You can ask for a copy of the information we hold about you by making a Data Subject Access Request. You can do this either by emailing help@monzo.com or calling on 0800 088 4040", and asks that an emailed request "include a Selfie holding ID or a selfie holding a piece of paper with today's date written on it". It explains elsewhere that it works this way because it has no branches at which to check identity in person. You can also write, and Monzo publishes no process at all for someone making a request on your behalf, so a representative should expect to be asked for the same selfie. Monzo publishes no deadline for answering. Its privacy notice does not say how long a request takes, and neither does the help article — the words "one month", "30 days" and "calendar month" appear nowhere in that context on Monzo's site. The one month you are entitled to comes from the law rather than from anything Monzo has promised, and if a reply arrives and you cannot tell whether it is complete, our free response checker will show you what is missing. A closed account is still worth asking about, for ten years. Monzo's notice says "We'll keep your information for 10 years after your account closes, in case we need to respond to a legal claim", and adds that in cases of anti-money laundering or fraud it may keep data longer still. That figure is for customers; if you never held an account and Monzo holds data about you because you paid one of its customers or were named on a policy, the notice gives six years instead. If you only want the transaction history of a closed account, that is a separate and simpler route: Monzo emails a password-protected statement when it closes an account, and will send another through a form or bank-statements@monzo.com, normally within 7 business days. Two postcodes and two mailboxes, and it matters which you use. Monzo's privacy notice asks you to "write to us at Monzo, Broadwalk House, 5 Appold Street, London, EC2A 2DA, UK", while its website footer, its ICO registration and its "writing to our legal team" page all give the same building as EC2A 2AG. Both are live postcodes for the same address, so either will arrive. On mailboxes: dpo@monzo.com is Monzo's Data Protection Officer, published for complaints about how Monzo uses your information rather than for making a request, and it is also the address on Monzo's ICO registration — a request sent there is going to the wrong desk. complaints@monzo.com is for complaints, which Monzo answers in 15 days to 8 weeks and which escalate to the Financial Ombudsman Service rather than to the ICO. Fraud records are the reason many people ask, and some of them sit elsewhere. Monzo says it checks your record with fraud prevention agencies "like Cifas" when you apply and may share information with them afterwards, and warns that "Other organisations may use information we share with FPAs about fraud to refuse their services, finance or employment". Monzo's file will show what it recorded and why; to see what the fraud database itself holds you need a separate request to Cifas. Monzo also decides some things by machine, including "if we need to take action, like freezing a transaction or account because we suspect fraud or money-laundering", and publishes a separate right to have a person look again: "If we make a solely automated decision about you that significantly affects you, you have the right to request a manual review of that decision by a person." If you want the decision changed rather than the records, that is the right to ask for. If a scam claim was turned down, the reasoning is what a request gets you. Under the Payment Systems Regulator's rules Monzo reimburses eligible authorised push payment fraud "within 5 business days, or for more complex cases this could take up to 35 business days", up to £85,000, and "may not pay the first £100" of a claim; it does not cover fraud reported more than 13 months after the final payment to the fraudster. A request will show what Monzo recorded about the payment, the warnings it says it gave you and how it assessed the claim. The credit score in the Monzo app is not Monzo's data. Monzo's credit insights terms say that turning the feature on means "you're asking us to make a 'data subject access request' on your behalf to the credit reference agencies under Article 15" — so that request goes to TransUnion and Equifax, not to Monzo, and what comes back is their file rather than Monzo's. Business accounts use the same route and the same company. Monzo's Business Account Privacy Notice names the same controller and the same ICO registration as the personal one and points to the same contact details. Card payments taken through Monzo Business are the exception: Monzo says "you'll have opened an account with Stripe" and directs those to Stripe directly. A request about someone who has died is not a subject access request, because rights of access end at death. Monzo handles a bereavement through its own bereavements page or bereavements@monzo.com and says it will reply within 3 business days. If you would rather send the request yourself, our free letter tool will write it for you.

Making a request to a bank or lender

Made under UK GDPR Article 15

Banks hold considerably more about you than statements: call recordings, branch and chat notes, complaint files, internal correspondence, fraud and affordability assessments, and the reasoning recorded behind lending decisions. Statements are usually available in online banking already, so a SAR is most useful for everything that is not.

Requests here are usually made for a reason — a complaint, a disputed transaction, an affordability argument, or a fraud marker. Being specific about dates, account numbers and the events you care about produces a far more useful response than a blanket request for everything.

Fraud markers are often not held by the bank alone. CIFAS and National Hunter are separate organisations, and a marker recorded with them needs its own request sent directly to them.

What people commonly ask for

  • Call recordings and contact notes
  • Complaint files and internal investigation notes
  • Lending and affordability decision records
  • Fraud markers and the reasons recorded for them
  • Account opening and closure correspondence

Watch out for

  • Call recordings are frequently held on shorter retention schedules than written records — request them early.
  • CIFAS and National Hunter markers require separate requests to those organisations.
  • Material created once litigation was contemplated may be withheld as legally privileged under DPA 2018 Schedule 2, Part 4.
  • Credit reference agency data sits with Experian, Equifax or TransUnion, not with the lender.
  • A subject access request gets you the records; it does not get a decision reviewed. If you want the bank to put something right, complain to it first — after eight weeks with no final response, or within six months of the date on one, the Financial Ombudsman Service will consider it free of charge. For a complaint about fraud, a scam or a payment service the bank has 15 days rather than eight weeks.

Your rights, whoever you are asking

Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.

Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.

Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.

How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.

If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.

Send it to Monzo

You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.

This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.