GetMySAR

Organisation

Subject Access Request to Uber

What Uber holds about you, where to send the request, and what to expect back.

GetMySAR is an independent service and is not affiliated with, endorsed by, or acting on behalf of Uber. The contact details below are published so you can make a request yourself free of charge.

Where to send your request

Verified 18 August 2026
Postal address
Uber B.V. Burgerweeshuispad 301 1076 HR Amsterdam the Netherlands
Contact
Data Protection Officer
Their own SAR form
Open Uber’s request form
ICO registration
ZB593724
ID they ask for
Uber asks for no identity documents. The account route asks you to sign in instead: "To access this data, you'll need to sign in to your account using 2-step verification for an extra measure of security." The version of the form that needs no account asks for the first and last name you used with Uber, the phone number you used with Uber, an email address where its support team can contact you, and free text under "(Required) Provide additional information about your reason for contacting Uber"; one JPG, JPEG or PNG attachment is optional. Uber then emails that address — "An automated message will be sent here to confirm this is really you. Please open it and choose 'Confirm email address' to be connected with a member of our team."

Source: Uber published information. Organisations change these details — tell us if this is out of date.

Specific to Uber

Uber does not name a single UK company as the controller of your account data. Its privacy notice says "UTI and Uber B.V. are joint controllers of the data processed in connection with all other uses of Uber's services in the EEA, UK and Switzerland", where UTI is Uber Technologies, Inc.; payments are separate again, with "Uber Payments UK Ltd." joining them "for users of those services in the UK". The notice for drivers and delivery people adds that "UTI, Uber B.V., and the Uber entities that contract with drivers in the UK are joint controllers of those drivers' data for purposes of complying with UK licensing and workers' rights requirements" — without naming those entities. Uber London Limited holds its own ICO registration and appears in neither notice. You do not have to work out which one to write to: there is one route for everybody. Riders, Uber Eats customers, drivers and couriers all use the same privacy inquiry form, and Uber's own short link for it is uber.com/privacy-dpo. If you are signed in you complete it inside your account. If you do not have an account, or you had one and can no longer sign in, use the version that needs no Uber account — Uber says it "is meant to be used by individuals who do not have or previously had an Uber account". Drivers and couriers have their own copy of the same form. It asks what you were — Driver or courier, Passenger or Uber Eats user, Freight user, Other — and why you are contacting Uber, offering "I would like to contact Uber's DPO" and "I have another question about my data". Nothing on the form uses the words subject access, so pick the DPO option and say in the free-text box what you want. Uber's own privacy overview answers "How do I request a copy of my data?" with "You can request a copy of your data here (login required)", but that sentence is about the download tool; the DPO route beside it carries no login condition. Download Your Data is not a subject access request. Uber says it "contains the most frequently requested relevant data about how you use the Uber platform", needs you to "sign in to your account using 2-step verification", and "may take up to 30 days". Uber also lists what it leaves out: your mailing address and bank and card details, "content from support tickets, email exchanges with Uber, or messages you've received", mobile event data older than 30 days, and — withheld as proprietary — "estimated arrival time, pricing calculations, and details about marketplace-driven promotional discounts" for riders and "delivery fee calculations and promotional discount details" for Uber Eats. Uber's own instruction for anything on that list is to use the form: "If you have questions about your personal data, would like to receive specific data that is not available in your download, would like to request a correction of your data, or would otherwise like to contact Uber's Data Protection Officer (DPO), you can submit a request." Drivers and couriers are kept longer than riders, and it is worth knowing before you assume old records have gone. Uber's driver retention table gives account, background check, demographic and device data as "Life of account + 7 years", and communications, location and trip or delivery data as "7 years". The rider table gives the same categories as "Life of account" or "The sooner of life of account or 7 years". So a driver who left years ago can often still ask for records a former rider cannot. One UK-specific line sits in the driver table: user-submitted selfies are held "3 years for user-submitted selfies, except 2 years in EEA / UK / Switzerland". The same asymmetry runs the other way on deletion — Uber says deletion happens "within 90 days of a deletion request for riders and order recipients, and 7 years of a deletion request for drivers and delivery persons". Drivers should also know their records are not all in one place: Uber says "Drivers can find additional information such as weekly pay statements, tax information and banking information on partners.uber.com". The ICO register lists dpo@uber.com as the data protection officer contact on Uber B.V.'s registration and on Uber London Limited's. Uber's own pages never offer it as a way of making a request — they offer the form and the Amsterdam postal address — so it is recorded here rather than under where to send your request. Uber publishes no response time for a request made through the form. The one month you are entitled to comes from the law, not from a commitment Uber has made, and the 30 days on the download applies to the download. A request about someone who has died is not a subject access request, because rights of access end at death, and Uber publishes no bereavement or estate route in its data protection pages at all. If a reply to your own request arrives and you cannot tell whether it is complete, our free response checker will show you what is missing.

Making a request to an organisation

Made under UK GDPR Article 15

Any organisation that decides how and why your personal data is used is a data controller, and must respond to a subject access request. That covers retailers, employers, membership bodies, landlords, charities, gyms and online services alike.

The organisation must confirm whether it is processing your data, provide a copy of it, and explain why it holds it, who it shares it with and how long it keeps it. There is normally no fee.

What people commonly ask for

  • All personal data held about you
  • Correspondence and internal notes referring to you
  • Account, order or membership history
  • Call recordings and chat transcripts
  • Marketing preferences and consent records

Watch out for

  • Identify the right legal entity — brand names and registered companies often differ.
  • Large groups may hold your data across several companies, each a separate controller.
  • Be specific about what you want if the organisation is likely to hold a lot.

Your rights, whoever you are asking

Deadline. An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.

Cost. There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies.

Proving who you are. An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.

How hard they have to look. An organisation has to carry out a reasonable and proportionate search — not an exhaustive one. What counts as reasonable depends on the volume of information, the difficulty of locating it, and the size and resources of the organisation. This is a common reason for a partial response, and it is worth being specific about what you want.

If they ignore you. Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.

Send it to Uber

You can do this yourself for free using the details above. If you would rather not handle the wording, the submission and the chasing, GetMySAR prepares, sends and follows up your request for a fixed £20 fee.

This page is general information about your right of access under UK data protection law. It is not legal advice. If your situation is complex or contested, consider speaking to a solicitor or contacting the Information Commissioner’s Office.