Subject Access Request Letter Template (UK)
Published 27 September 2026 · Sources listed below
A subject access request letter template gets you most of the way, but the details decide how quickly you get a useful answer. It helps to say what you are asking for, send it somewhere that records the date, and know when the clock starts and when it can pause.
The short answer
A subject access request (SAR) asks an organisation, under Article 15 of the UK GDPR, for a copy of the personal data it holds about you and information about how it uses it. It is free in most cases. You can make it in writing or verbally, though writing gives you a record. The organisation normally has one month to respond. It can extend that by up to two further months if your request is complex or you have made several, but it has to tell you within the first month and explain why.
Contents
What you are entitled to receive
A SAR is not just a request for documents. Article 15 entitles you to confirmation of whether your data is being used, a copy of it, and supporting information that explains what the organisation does with it. An organisation can sometimes refuse to provide some or all of the information, for example where releasing it would reveal another person's data, so a partly redacted response is not automatically a breach.
Under Article 15 UK GDPR
- A copy of your personal data
- Why it is being used, and the categories of data involved
- Who it has been or will be shared with, including organisations abroad
- How long it will be kept, or how that is decided
- Where it came from, if not from you
- Whether automated decision-making is used, with meaningful information about the logic involved
- Your rights to correction, erasure and restriction, and to complain to the organisation and the ICO
The deadline, and when it can start later or pause
The one-month period runs from when the organisation receives your request. Since 5 February 2026 the Data (Use and Access) Act 2025 has set this out in the UK GDPR itself. If the organisation reasonably needs ID or a fee, the month runs from when it gets that instead. If your request is unclear and it reasonably needs you to clarify what you are looking for, the clock can pause until you reply. That is why a clear, specific request tends to get a faster answer.
Timing rules
- One month from receipt, or from receipt of ID or a fee if either is reasonably required
- Up to two further months for complex requests or several requests, notified with reasons within the first month
- The clock can pause while you clarify an unclear request
- Free in most cases. A reasonable fee is allowed only if the request is manifestly unfounded or excessive, or for further copies
Identity checks
According to the ICO, an organisation may ask for ID if you have asked for sensitive information such as health or financial records, or if it does not recognise your details. It should not ask when it is already confident about who you are. The one-month clock only starts once it has what it reasonably needs, so if you expect an ID request, sending proportionate ID with the request can save time. Only send what is needed, not copies of every document you own.
What 'reasonable and proportionate' means for you
The Data (Use and Access) Act 2025 added a line to Article 15 saying you are entitled to what the organisation can provide based on a reasonable and proportionate search. This was already how the ICO approached SARs, but it is now in the legislation. In practice, the more you narrow the request, the easier it is to hold the organisation to a thorough answer. Useful limits include a date range, a department, the people involved and the type of record. A vague request for everything invites a search that is reasonable for the organisation and not very useful to you.
Send it so the date can be proved
You do not need a particular form or particular wording, and the ICO says requests can be made online, by email, by post, by phone or in person. What protects you is being able to prove when you asked. If you use an online form, the ICO suggests taking a screenshot before you submit. If the response is late or incomplete, complain to the organisation first. Since 19 June 2026 organisations have had a legal duty to handle data protection complaints and to acknowledge them within 30 days. If that does not resolve it, you can go to the ICO, which asks you to raise it within three months of your last meaningful contact with the organisation.
Subject access request letter template
Edit this template with your facts, dates, and requested outcome before sending.
Subject: Subject access request — [your full name] Dear [Data Protection Officer / Data Protection Team], I am making a subject access request under Article 15 of the UK GDPR for the personal data you hold about me. To help you find my information: my name is [full name], and I have been known to you as [any previous names]. My [customer / account / employee / patient] number is [reference], my address is [current address] [and previously [previous address]], and my email address is [email]. Please provide: 1. A copy of the personal data you hold about me, including [for example: emails that mention me, call recordings, notes on my account, CCTV footage from [location] on [date]] [between [date] and [date]]. 2. The purposes for which you process it, the categories of data, and who it has been shared with. 3. How long you will keep it, and where you got it from if not from me. 4. Whether any automated decision-making, including profiling, has been applied to me. I would like to receive this [electronically / by post]. If you need anything further to confirm my identity or to locate the information, please tell me promptly so that the response is not delayed. Yours sincerely, [Your Name] [Date]
Common mistakes to avoid
- Not keeping a dated copy of the request, so the deadline cannot be proved later
- Asking for "everything" when a date range or named department would get a faster and fuller answer
- Sending far more ID than is needed, or refusing a reasonable ID request and stalling the clock
- Paying a fee the organisation was not entitled to charge
- Addressing the request to someone with no data protection role, so it is never logged
- Assuming every redaction is bad faith. Other people's data can legitimately be withheld
Next steps
- 1Work out exactly what you need, including date ranges, departments and record types
- 2Find the organisation's data protection contact or privacy notice address
- 3Send the request by a route that records the date, and keep a copy
- 4Diarise one month from the date they received it
- 5If there is no response, follow up in writing, then complain to the ICO if needed
Sources
- ICO — Getting copies of your information (subject access request)
- ICO — What to expect after making a subject access request
- ICO — What to do if you don't get a response or you're unhappy with it
- legislation.gov.uk — UK GDPR Article 15 (right of access)
- legislation.gov.uk — Data (Use and Access) Act 2025, section 76 (time limits)
- legislation.gov.uk — Data Protection Act 2018, section 164A (complaints to the controller)
Rules and deadlines change. Check the official source before relying on a date or amount.
Generate your letter now
WorkRight.AI drafts clear, structured letters based on your specific situation — housing, work, consumer, billing and more. You keep full control — review and edit every word before sending.
Draft your subject access request →Not sure this is the right letter for your situation? Check your situation first