Hands select a plain document folder from a lockable filing drawer containing organized personal records.

Before You Send a Data Access Request, Define the Records You Need

A request for personal information becomes easier to prepare when you can finish this sentence: “I want to understand what this organization recorded about me in connection with this account or event.” You may still decide to ask for everything, but first identifying your purpose helps you recognize a useful response.

In the United Kingdom, asking an organization for your personal information is commonly called a subject access request, or SAR. You do not have to explain why you want it. This guide focuses on preparing a clear request under the UK framework. For response deadlines, exceptions, or a dispute, consult current Information Commissioner’s Office guidance or qualified advice.

Identify the organization holding the records

Start with the service’s official privacy notice or account information. A familiar trading name may sit alongside a different legal organization, and a separate company may provide part of the service. Work out which organization is likely to hold the personal information you want.

Find its stated privacy contact or request channel through the official site. Avoid sending sensitive details to an address copied from an unsolicited message or an unrelated directory. If the organization offers a request form, inspect what it asks for before filling it in.

Keep the search practical. For a question about an online account, begin with the organization operating that account. If its reply identifies another holder of relevant records, you can decide whether a further request is needed.

Describe the information in ordinary language

You can ask for all the personal information an organization holds about you. Choosing a narrower request is optional. It may be helpful when your interest concerns one event and you would otherwise receive a large amount of material unrelated to that question.

Use descriptions a person can search against: an account, an approximate period, a support case, a change of address, or a set of communications. If you do not know an exact date, say that the range is approximate. Avoid inventing precision merely to make the request look formal.

For example, an invented request about an account change could say: “Please provide my personal information relating to the address change on my account during March and April 2026, including relevant support correspondence and notes about that change.” The example describes a search target without demanding a particular internal document title.

If you exclude something, do so deliberately. You might already have routine invoices, but do not exclude all billing records if the issue you are investigating concerns a charge. Read your description once as someone unfamiliar with the story.

Include useful identifiers without oversharing

Provide enough information to connect the request with the correct records. Depending on the relationship, that could include your name, the email used on the account, a customer number, or a relevant former name. Keep the contact route for the response clear.

An organization may need reasonable identity checks, especially when the request involves sensitive information or arrives from an unfamiliar address. Do not attach a passport or other identity document automatically. First check what verification is needed and how it should be supplied securely.

If an unexpected message asks for more identification, verify the request through the organization’s established contact channel. If a requirement seems excessive, ask why it is necessary and whether a less intrusive method would work. Keep a record of that exchange.

Say how you can use the response

State your preferred delivery format and any accessibility needs. An electronic response may be convenient, but ask how files will be supplied if you cannot use a proposed download system. If a secure link will expire, arrange time to retrieve the material.

Access to personal information does not necessarily mean receiving every original document in full. A response may contain extracts or redactions, including information removed to protect other people. It may also explain that some requested records are no longer held.

When the response arrives, compare it with the scope you sent. Check that files open and note any unexplained gaps. Distinguish a missing attachment from a disagreement about what the organization should disclose; those need different follow-up questions.

Keep a small request record

Save the exact request, the submission date, any receipt, and subsequent correspondence in one secure place. If using a web form, preserve a copy before submitting. Record changes to the scope so you can follow what was requested and agreed.

Reply when clarification is needed, and ask the organization to explain unclear parts of its response. The ICO’s current public guidance can help with escalation if the issue remains unresolved. A well-kept record gives that conversation a concrete starting point: what you asked for, what happened next, and what still needs an answer.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top