GetMySAR
UK GDPR
This page explains, in plain English, what UK GDPR is, how Subject Access Requests work, and how GetMySAR helps users make and follow up requests.
Last updated: 19 March 2026
On this page
1. Overview
This page explains, in plain English, how UK GDPR relates to Subject Access Requests and how GetMySAR helps users make those requests.
It should be read alongside our Privacy Policy, Data Protection page and Your Rights.
2. What is UK GDPR?
UK GDPR is the UK's main data protection framework for the handling of personal data. It works alongside the Data Protection Act 2018.
It gives people certain rights over their personal data and places obligations on organisations that collect and use that data.
One of those rights is the right to ask an organisation for a copy of the personal data it holds about you. This is commonly called a Subject Access Request, or SAR.
What Article 15 of the UK GDPR says
The right of access is Article 15 of the UK GDPR, headed “Right of access by the data subject”. Paragraph 1 gives you the right to obtain confirmation of whether your personal data is being processed and, if it is, access to that data and to supplementary information. That information includes the purposes, the categories of data, who it has been or will be disclosed to, how long it will be kept, where it came from if not from you, whether there is automated decision-making, and the existence of your rights to rectification, erasure, restriction and objection.
Paragraph 3 says the controller must provide a copy, that it may charge a reasonable fee based on administrative costs for further copies, and that where you ask electronically the information should be provided in a commonly used electronic form. Paragraph 4 adds that the right to a copy “shall not adversely affect the rights and freedoms of others”.
The UK version is not the same text as the EU one, which is what most explanations of “Article 15 GDPR” show. The UK text has been amended, most recently on 5 February and 19 June 2026. Two of those differences change what you actually get:
- Paragraph 1A limits the search. In full: “the data subject is only entitled to such confirmation, personal data and other information as the controller is able to provide based on a reasonable and proportionate search”. An organisation does not have to search exhaustively, which is a common reason a response comes back partial.
- Paragraph 1(ea) adds the right to complain to the organisation itself, under section 164A of the Data Protection Act 2018 — alongside the existing right at 1(f) to complain to the Information Commissioner under section 165.
Checked against legislation.gov.uk on 7 August 2026, where the article is recorded as up to date with all changes in force on or before that date. Further changes may be brought into force later, so check the link above if the detail matters to you.
3. What is a Subject Access Request?
A Subject Access Request is a request made by an individual, or by someone authorised to act for them, asking an organisation for access to personal data it holds about them.
A SAR can be used to ask for copies of personal data, information about how that data is being used, and related details required by data protection law.
The organisation receiving the SAR is usually responsible for deciding how to respond and for complying with UK GDPR.
This page is about the law behind that right. For the request itself — what you receive, what you can ask for and how to make one — see what is a Subject Access Request, or, in the law’s own vocabulary, our step-by-step guide to making a GDPR request.
4. How GetMySAR helps
GetMySAR helps users prepare and submit Subject Access Requests to organisations in the UK.
Our role includes:
- helping users complete the SAR form;
- sending the request to the target organisation;
- sending supporting documents where provided; and
- following up with organisations about the request.
The organisation's substantive SAR response goes directly to the user or data subject. GetMySAR does not receive or store the organisation's actual SAR response.
5. The one calendar month timeframe
An organisation must respond without undue delay and within one month. It may extend by up to two further months where the request is complex or you have made a number of requests, but it must tell you within the first month that it is doing so, and why.
In general, the time limit begins when the organisation has received the request and, where reasonably required, enough information to confirm the requester's identity or clarify the request.
6. Identity checks
An organisation may ask you to verify your identity, but only where it has reasonable doubts about who you are, and it should ask for the minimum needed. Where it needs further information to deal with your request, the one-month clock pauses until you provide it.
In practice an organisation is most likely to ask where sensitive personal data is involved, or where someone is acting on another person's behalf — in which case it may want proof of authority to act as well as proof of identity.
7. Extensions and refusals
In some cases, an organisation may be allowed extra time to respond. For example, a request may be complex or involve a large amount of information.
An organisation may also refuse a request, or refuse part of it, in certain limited circumstances permitted by law.
For example, a request may be considered manifestly unfounded or excessive, or some information may be exempt from disclosure.
If an organisation refuses a request, it should usually explain why and tell the requester about their right to complain.
8. If an organisation does not respond
If an organisation does not respond within the expected timeframe, the first step is usually to follow up with that organisation and ask for an update.
GetMySAR may help with follow-up reminders as part of the service.
Complain to the organisation first. Since 19 June 2026 every organisation has had a legal duty to give you a clear way to raise a data protection complaint, to acknowledge it within 30 days, to look into it properly and to tell you the outcome. If it does not, or the answer is incomplete, you can then complain to the Information Commissioner's Office.
ICO guidance and complaints information can be found here: https://ico.org.uk/make-a-complaint/
9. Important points to understand
- UK GDPR rights apply in different ways depending on the organisation and the circumstances.
- The target organisation is responsible for its own compliance with UK GDPR and the Data Protection Act 2018.
- GetMySAR helps users make and follow up Subject Access Requests, but does not decide how the target organisation responds.
- The organisation receiving the request may ask for more information if it reasonably needs it to identify the person or locate the data.
10. Further information
For more information about how GetMySAR handles personal data, please see our Privacy Policy and Data Protection page.
You can also read more about your data protection rights on our Your Rights page.