A SAR request, short for subject access request, is one of the few genuinely useful tools an ordinary person has for finding out what an organisation actually knows about them. Send one to a company, a council, or an employer, and under Article 15 of the UK GDPR they have to tell you what personal data they hold, why they hold it, and who else they have shared it with. It costs nothing to make, and the law gives it real teeth.
What A SAR Request Actually Entitles You To
Once you submit a request, the organisation has to confirm whether they are processing your personal data at all. If they are, they need to describe what that data is, explain the reasons behind processing it, and tell you whether it has gone to any other organisations or people. They also need to give you an actual copy of your personal data, not just a summary, though that isn’t always the same as copies of the original documents. Where possible, they also need to tell you where the data originally came from.
That last point matters more than people expect. If a company built a profile on you using data bought from a third party, a proper SAR response should tell you that. It is one of the only ways to trace how your information moved before it ever reached the organisation you are dealing with.
Why People Actually Submit One
The motivations behind a request are usually practical rather than abstract. Someone might suspect a former employer kept notes they were never shown. A parent might want to see what a school holds on their child. Someone dealing with a data breach might want to establish exactly what was exposed and where it originated. None of these require a solicitor or a formal complaint first. A written request, addressed to the right team, is enough to start the clock.
Anyone trying to understand what triggered unwanted contact, strange account activity, or unexplained decisions about them often finds a request like this answers more than a phone call ever would. If the concern stems from an actual security incident rather than general curiosity, it’s worth pairing a request with proper incident response support, since the two processes tend to surface different pieces of the same picture.
How To Make The Request Properly
There is no required form or special wording. A short, clear email or letter stating that you are making a request under data protection law is sufficient, and a verbal request counts too, though a written one leaves you a record. It helps to be specific about what you are after, whether that is HR records, CCTV footage, call logs, or correspondence. Organisations are allowed to ask you to verify your identity first, which is a reasonable step given what they are being asked to hand over.
If you would rather not draft it yourself, you can use the ICO’s online subject access request service, which creates the email for you and gives you a copy for your records. The ICO’s guide to getting copies of your information explains what to expect afterwards, and the structure applies whether you are contacting a council, an employer, or a private company.
How Long They Have To Respond
The deadline is one month from receipt. An organisation can extend that by up to two further months if the request is complex or you have sent several, but it has to tell you within the first month and explain why. Since the Data (Use and Access) Act 2025, it can also pause the clock while it reasonably waits for you to clarify what you are asking for, and it only has to carry out a reasonable and proportionate search rather than an exhaustive one. If the month passes in silence, that is the point to chase.
What Organisations Are Allowed To Withhold
Not everything comes back unredacted. Information that would reveal another person’s identity, legal advice covered by privilege, or data genuinely exempt under specific legal provisions can be withheld or blacked out. Organisations sometimes lean on these exemptions more liberally than the rules intend, so a response that comes back heavily redacted or suspiciously thin is worth questioning rather than accepting at face value.
If a response seems incomplete, you can push back and ask for clarification on why certain material was excluded. If that doesn’t settle it, you can complain to the organisation itself and then to the ICO. Persistence tends to produce a fuller picture than accepting the first answer you get.
What This Has To Do With Your Own Security Habits
Running a subject access request occasionally works well as a personal audit. It shows you exactly what data trail you are leaving behind with banks, retailers, and service providers, and it often reveals accounts or records you had forgotten existed entirely. Treating it as a periodic check, alongside more general good practice around passwords, device security, and account settings, gives a fuller view of your own exposure. For broader reading on protecting your own information day to day, the home users section covers the practical side of that.
If a data concern has already tipped into a suspected breach, speak to us about incident response before it escalates further.