Telecoms provider
Subject Access Request to Three
What Three holds about you, where to send the request, and what to expect back.
GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of Three. The contact details below are published so you can make a request yourself free of charge.
Where to send your request
Verified 9 August 2026- Postal address
- Data Protection Officer Hutchison 3G UK Ltd 450 Longwater Avenue Green Park Reading RG2 6GF
- Their own SAR form
- Open Three’s request form
- ICO registration
- Z5513412
- ID they ask for
- Three asks you to send a copy of your photo ID with the form, and says it validates your identity before releasing anything so that it does not disclose your information to somebody else in error. Its form asks for proof of name and address, and gives a photocopy of a photo driving licence or passport as the example. The form also asks you to give a start and end date for the period you want covered, and to say which of your outgoing calls and texts, account notes, customer service call recordings or other records you are asking for. If you are applying for somebody else, Three asks for their proof of identity and address, their written authority that you are acting on their behalf, and proof of your own identity and address.
Source: Three published information. Organisations change these details — tell us if this is out of date.
The new email address after the merger, and what Three cannot release
Three asks you to download its Request for Access to Personal Information form, fill it in and email it with a copy of your photo ID. You can write to the Data Protection Officer instead. Note the email address: Three says to use Three.DataProtection@vodafonethree.com from now on, and that mail to its older addresses, including dpa.officer@three.co.uk, will still be received. Three UK and Vodafone merged in June 2025 and are now part of VodafoneThree, but Three says the two "remain separate Data Controllers", with some processing done jointly. So a request about your Three account goes to Three, and a request about a Vodafone account goes to Vodafone, even though the reply arrives from a vodafonethree.com address. Three says it has one month to comply once it has validated your identity, and may extend that to three months where a request is complex or extensive, telling you inside the first month if it does. Answers are sent through the VodafoneThree OneTrust platform unless you ask for something else. If you only want your bills there is a faster free route: your last 12 months are in your My3 account and in the Three app. Four limits worth knowing before you ask. Three will not release details of 999, 111, 0800 or other free-to-call numbers, because Ofcom's general conditions say calls that are free to the customer must not appear on an itemised bill or in other records given to you. It does not record customers' private calls at all. It does not record every call with its own customer services and keeps those it does for six months, so give the date and if possible the time. And a deleted voicemail is gone from the system and cannot be retrieved.
Making a request to a telecoms provider
Made under UK GDPR Article 15
Telecoms providers hold account and billing records, itemised usage, call recordings and chat transcripts from customer service, contact and complaint notes, and the credit checks run when the contract was opened.
Requests here usually follow a billing dispute, a contract taken out fraudulently in the person's name, or a complaint that went nowhere. Call recordings and chat transcripts are typically the useful part, because they show what was actually promised.
Records of who you called or messaged and when are traffic data, and a provider has to erase or anonymise them once they are no longer needed to carry the communication or to bill you for it. That is why usage records reach back months where account paperwork survives for years, and it is the main reason a request made long after the events comes back with less in it than the person expected.
What people commonly ask for
- Account and billing history
- Call recordings and live chat transcripts
- Customer service contact and complaint notes
- Credit checks run at contract opening
- Records of a contract you say you did not open
Watch out for
- Ask early. A provider has to erase or anonymise usage data once it no longer needs it, so the gap between the events you care about and the request often decides what comes back.
- Give the phone numbers, the dates and the approximate times you are asking about. A request that does not narrow the period tends to come back as billing data without the calls you actually wanted.
- Another person's number is their personal data as well as part of your record, so records of incoming calls and messages are commonly withheld or redacted, and some providers will release them only under a court order or witness summons.
- Providers carry your calls and messages but do not normally keep what was said in them, so a subject access request will not produce the content of a call or a text. Recordings of calls you made to the provider's own customer services are a different thing and can be asked for.
- A subject access request gets you the records; it does not get a bill or a service problem put right. Complain to the provider first — after six weeks, or once it issues a deadlock letter, one of the two Ofcom-approved ADR schemes will consider a service complaint free of charge, and which one depends on your provider. A complaint about how the provider handled your data goes to the Information Commissioner's Office instead.
Your rights, whoever you are asking
Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.
Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.
Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.
How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.
If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.
Send it to Three
You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.
This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.