GetMySAR

Organisation

Subject Access Request to Tesco

What Tesco holds about you, where to send the request, and what to expect back.

GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of Tesco. The contact details below are published so you can make a request yourself free of charge.

Where to send your request

Verified 9 August 2026
Postal address
Tesco Customer Service Centre Baird Avenue Dundee DD1 9NF
ICO registration
Z6712178
ID they ask for
Tesco says it may collect identity verification documents from you, such as a copy of your ID or confirmation of your address, for more sensitive interactions with you — and gives raising a data rights request as its example. It does not publish a list of the documents it accepts.

Source: Tesco published information. Organisations change these details — tell us if this is out of date.

Clubcard history, facial recognition, and what a CCTV request can reach

Most people asking Tesco for their data want their Clubcard history, and there is a quicker route to that than a subject access request. Tesco runs a separate data portability service that returns the personal information you gave it, and says it will process that request within 30 days; you can start it online or by calling 0800 917 6895, which it says is open 8am to 8pm Monday to Friday and 9am to 6pm Saturday. That number is for portability and Tesco does not offer it as a way of making a subject access request. The subject access request is the wider one — everything Tesco holds about you, including things you never gave it — and Tesco asks you to make it by email to subjectaccess.request@tesco.com. Tesco publishes two data protection email addresses and they are not interchangeable. A request for a copy of your data goes to subjectaccess.request@tesco.com. DPO@Tesco.com is separate, and Tesco says it is only for data protection queries and that it cannot answer anything else there. Tesco is trialling retrospective facial recognition, which changes what a request to it might find. It says that where someone is suspected of criminal activity in store, trained staff review the CCTV after the event, extract facial images of the suspect and send them to Auror Europe Limited, its crime intelligence partner, which uses AI to suggest matches against images from other incidents. Tesco says the technology is non-live, so no face is scanned in real time, that it is being trialled in selected stores where signage is displayed, and that Tesco and Auror act as joint controllers for it. A CCTV image of you is personal data, and Tesco says the images and templates from an incident are deleted within two years. Tesco also uses automatic number plate recognition in its car parks and some petrol forecourts, body-worn cameras worn by staff, and in some stores a scan-free checkout system whose cameras record you as you move around the shop and analyse what you pick up. It says footage from those is recorded in the same way as its other CCTV, and that the scan-free checkout images are usually deleted within five days. On retention generally it says that in most circumstances it will not keep your personal data for more than seven years after the end of your relationship with it. A request reaches your own personal data and nothing else, so it is not a way of getting footage of another person or of an incident you were not part of. Tesco's privacy policy and privacy centre give one route for a copy of your data, the subject access email above, and no separate one for camera footage, so a request for footage goes the same way as any other. What decides whether anything is still there to send is how long Tesco keeps it: five days for scan-free checkout images, and two years for the images and templates it holds from a facial recognition incident. The controller is Tesco Stores Limited, which the policy states at the top. Tesco Bank and Tesco Mobile are separate companies with their own ICO registrations, so a request about a bank account, an insurance policy or a phone contract goes to them and not to Tesco Stores. The postal address above is the one Tesco publishes for personal data contact, under a heading asking whether you have questions or complaints about how it has used your data. The route Tesco asks you to use for a copy of your data is the subject access email.

Making a request to an organisation

Made under UK GDPR Article 15

Any organisation that decides how and why your personal data is used is a data controller, and must respond to a subject access request. That covers retailers, employers, membership bodies, landlords, charities, gyms and online services alike.

The organisation must confirm whether it is processing your data, provide a copy of it, and explain why it holds it, who it shares it with and how long it keeps it. There is normally no fee.

What people commonly ask for

  • All personal data held about you
  • Correspondence and internal notes referring to you
  • Account, order or membership history
  • Call recordings and chat transcripts
  • Marketing preferences and consent records

Watch out for

  • Identify the right legal entity — brand names and registered companies often differ.
  • Large groups may hold your data across several companies, each a separate controller.
  • Be specific about what you want if the organisation is likely to hold a lot.

Your rights, whoever you are asking

Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.

Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.

Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.

How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.

If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.

Send it to Tesco

You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.

This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.