How to request your data under GDPR (and delete it)
How to send a subject access request and an erasure request under UK GDPR, with email templates, the one-month deadline, and what to do if ignored.
Most people know, vaguely, that “GDPR rights” exist. Almost nobody exercises them, which suits the companies fine. So before the how, a short reminder of why this is worth thirty minutes of your life.
Why you would bother
Because the file on you is bigger than you think, and you are the only person who never gets to read it.
Your car may be scoring your braking — when American drivers pulled their files from the data broker their carmaker sold to, one ran to 258 pages of individual trips. Your supermarket holds years of your baskets, item by item, and sells the insight. Every free app on your phone is quietly building a behavioural profile it will never show you.
A subject access request is the one legal instrument that turns all of that from a rumour into a document on your screen. People who send one — to a bank, a broker, an old employer, a social network — are routinely startled by what comes back. That reaction is the point.
What the law actually gives you
Two rights matter here, both from the UK GDPR (the EU version works the same way, via your national regulator).
The right of access — Article 15. Known as a subject access request, or SAR. You are entitled to a copy of the personal data a company holds about you, plus the paperwork around it: what they use it for, the categories involved, who they have shared it with, how long they keep it, and where they got it if not from you. Per the ICO’s guidance, no special wording is required, you can ask any part of the organisation, and it is free — a fee is only chargeable if a request is manifestly unfounded, excessive, or a repeat copy.
The right to erasure — Article 17. The “right to be forgotten”. You can require deletion when the data is no longer needed for its purpose, when you withdraw the consent it relied on, when you object and they have no overriding grounds — and if the data was used for direct marketing, your objection is absolute. The ICO’s plain-English page covers it well; notably, a company that erases your data must also tell the third parties it shared it with to do the same.
- 01 you send one email no form, no fee, no legal wording required
- 02 they confirm who you are reasonable ID checks only; the clock runs once they have it
- 03 one calendar month extendable to three for complex requests, with reasons given
- 04 the data arrives or the regulator hears about it, at no cost to you
The same route works for deletion — Article 17 instead of Article 15 — and both land in an inbox somebody is legally required to act on.
How to send it
Find the right inbox. Check the company’s privacy policy for a
contact — usually privacy@, dpo@ (data protection officer), or a
named form. If you cannot find one, any official contact address legally
counts; the onus to route it correctly is on them, not you.
Put it in writing. A verbal request is technically valid, but an email gives you a dated record for the month-countdown — and for the regulator, if it comes to that.
Expect an identity check. They are allowed to verify you are you — that protects you, since the alternative is posting your file to anyone who asks. Checks must be reasonable and proportionate, and the response clock runs from when they have what they need. So state upfront that you will provide ID, and use the email address they already hold for you.
Template one — the subject access request
Fill the brackets, delete what does not apply, send.
Subject: Subject access request — [your full name]
Dear [company name],
I am making a subject access request under Article 15 of the UK GDPR.
Please provide me with:
1. A copy of all personal data you hold about me, including account
records, transaction history, correspondence, notes, call
recordings, location data, device identifiers, and any behavioural
or profiling data, scores or inferences derived about me.
2. The purposes you process my data for, and the categories involved.
3. The recipients or categories of recipient you have disclosed my
data to — including processors, group companies, advertising or
analytics partners and data brokers — and what was shared.
4. How long you retain each category of my data, or the criteria used.
5. The source of any data about me not collected from me directly.
6. Details of any automated decision-making or profiling applied to
me, including the logic involved.
The following should help you locate my records:
- Full name: [name]
- Email address on the account: [email]
- [Account / customer / order number, postcode, phone number]
Please supply the data in a commonly used electronic format. I am
happy to provide proof of identity if required — please tell me
promptly what you need.
As you will know, you are required to respond without undue delay and
at the latest within one calendar month of this request. If you
believe an extension applies, please tell me within that month, with
reasons.
Kind regards,
[your name]
[date]Template two — the erasure request
Send this on its own, or after a SAR has shown you what they hold — which is often the better order, since you cannot ask them to delete what you do not know exists.
Subject: Request for erasure of my personal data — [your full name]
Dear [company name],
I am exercising my right to erasure under Article 17 of the UK GDPR.
Please erase all personal data you hold about me. [If you wish to
keep the account: Please erase the following data: ...]
I make this request on the basis that: [pick what applies]
- the data is no longer necessary for the purpose it was collected
for;
- I withdraw the consent on which the processing relied;
- I object to the processing, including any processing for direct
marketing purposes, to which my objection is absolute.
Please also:
1. Confirm in writing that erasure is complete, including from backup
systems or, where immediate erasure from backups is not possible,
that the data has been put beyond use pending deletion.
2. Inform any third parties to whom you have disclosed my data of
this request, as required, and tell me who they are.
3. If you refuse any part of this request, state the specific legal
basis for each category of data you retain, and how long you will
keep it.
The following should help you locate my records:
- Full name: [name]
- Email address on the account: [email]
- [Account / customer / order number]
Please respond within one calendar month of this request.
Kind regards,
[your name]
[date]What happens next — and what if they ignore you
The company must respond within one calendar month, counted from the day the request lands (the ICO publishes the exact rules). For genuinely complex requests they can extend by up to two further months — but they must tell you so, with reasons, inside the first month. Silence is not an extension. Silence is a breach.
If the month passes with nothing, or the response is plainly incomplete: chase once in writing, referencing your original email and its date. If that fails, complain to the ICO at ico.org.uk — it is free, it is designed for individuals, and companies take regulator letters considerably more seriously than yours. A court route also exists, but for most people the ICO complaint is the working lever.
Being honest about the limits
Erasure is a right, not a magic word. A company can lawfully retain data it is legally required to keep — your bank must hold transaction records under anti-money-laundering law no matter how nicely you ask — or data needed for legal claims, and a few narrower grounds. What it must do, per the ICO’s erasure guidance, is tell you exactly which exemption it is relying on, for which data — “we keep everything, for reasons” is not a lawful answer.
And be ready for the export itself to be a mess: a zip of CSVs, PDFs of screens, machine columns with no key. That is not you failing to understand it. That is what the inside of a profiling operation actually looks like, printed out.
Send one this month. Pick the company you are most curious about — your car’s manufacturer, your supermarket, your oldest social account — and use the template. Whatever comes back, you will know more about your own digital life than you did, and you will have reminded one more company that somebody checks. The longer game is needing fewer of these letters at all: data that lives on your own hardware is the one file nobody else can hold back from you.