Car distributor and aftersales
Subject Access Request to Nissan
What Nissan holds about you, where to send the request, and what to expect back.
GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of Nissan. The contact details below are published so you can make a request yourself free of charge.
Where to send your request
Verified 18 August 2026- Postal address
- Nissan Motor (GB) Limited The Rivers Office Park Denham Way Maple Cross Rickmansworth WD3 9YS
- Contact
- Data Protection Officer
- Their own SAR form
- Open Nissan’s request form
- ICO registration
- Z2408899
- ID they ask for
- For an access or portability request Nissan says it will have to verify your identity, and the form asks you to upload a scan of an identity document — an identity card or passport — or a driving licence. If you are asking on someone else's behalf, Nissan also asks for a letter signed by that person authorising the request, plus proof of their identity. Attachments must be jpg, jpeg, png or pdf, no more than 4MB each, and no more than five files per request. The form also carries a reCAPTCHA challenge before it will submit.
Source: Nissan published information. Organisations change these details — tell us if this is out of date.
Specific to Nissan
Nissan names its UK controller outright: the company responsible for the personal data you give it is Nissan Motor (GB) Limited, registered in England and Wales as company 02514418. One online form covers access, correction, erasure, unsubscribing and portability, and it is the only route Nissan describes for making a request. It is a shared European form reached with a UK country parameter, so check that the country field says United Kingdom before you send it. The form asks two questions before anything else — whether you are a Nissan customer, and whether you use connected services. Answer yes to the second and the same request covers NissanConnect data. That matters, because Nissan says a different company controls it: "Your personal data is processed by Nissan Automotive Europe S.A.S (who are the data controller in this instance) for the purposes of providing you with connected services and on-board driving assistance applications" — geolocation, remote locking, battery and charging data, and data about how the car is driven. Nissan publishes two mailboxes and neither is offered as a way of making a request. gb@nissan-services.eu reaches customer services and dpo@nissan-europe.com reaches the Data Protection Officer, both for questions about the policy. The sentence about getting a copy of your data points at the form and nothing else. Car finance is a separate company. Nissan's own policy names it: RCI Financial Services Limited trading as Mobilize Financial Services. If your request is about a PCP or hire purchase agreement, an affordability assessment or a commission arrangement, that is where the file is. Mobilize publishes its own route: post to Data Protection Officer, RCI Financial Services Limited, Rivers Office Park, Denham Way, Maple Cross, Rickmansworth, WD3 9YS, email dataprotectionofficer-uk@rcibanque.com, or phone 0333 009 0231. It says it will reply "within 30 days after we have received any request (including any identification documents requested)", which starts later than the statutory clock. Your local dealer is a different business again, and its own controller. Service history, MOT records, test drives and what you discussed at the showroom sit with the dealer, not with Nissan. Nissan says its dealers are "independent controllers" and that its marketing preferences and its dealers' preferences "are held and stored separately", so changing one does not change the other. The Sunderland plant is a separate company too. Employment records belong to Nissan Motor Manufacturing (UK) Limited, which holds its own ICO registration. Nissan's UK privacy policy is scoped to customers and website visitors and gives employees no route at all — see making a subject access request to an employer. Nissan publishes nothing about requests for the records of someone who has died, and data protection rights end at death in any case.
Making a request to an organisation
Made under UK GDPR Article 15
Any organisation that decides how and why your personal data is used is a data controller, and must respond to a subject access request. That covers retailers, employers, membership bodies, landlords, charities, gyms and online services alike.
The organisation must confirm whether it is processing your data, provide a copy of it, and explain why it holds it, who it shares it with and how long it keeps it. There is normally no fee.
What people commonly ask for
- All personal data held about you
- Correspondence and internal notes referring to you
- Account, order or membership history
- Call recordings and chat transcripts
- Marketing preferences and consent records
Watch out for
- Identify the right legal entity — brand names and registered companies often differ.
- Large groups may hold your data across several companies, each a separate controller.
- Be specific about what you want if the organisation is likely to hold a lot.
Your rights, whoever you are asking
Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.
Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.
Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.
How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.
If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.
Send it to Nissan
You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.
This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.