Skip to content
itzgee.com

Blog Guides

How to request your data under GDPR (and delete it)

How to ask a company for a copy of your data, or to delete it, under UK GDPR. Email templates, the one-month deadline, and what to do if they ignore you.

Geeitzgee.comUpdated 28 Sept 20265 min read

Most people vaguely know they have “GDPR rights”. Almost nobody uses them, which suits the companies fine. So first, why it’s worth thirty minutes of your time.

Why you’d bother

Because the file on you is bigger than you think, and you’re the only person who never gets to read it.

Your car may be scoring your braking. When American drivers got their files from the data broker (a company that buys and sells personal data) their carmaker sold to, one ran to 258 pages of individual trips. Your supermarket holds years of your shopping baskets, item by item, and sells what it learns. Every free app on your phone is quietly building a profile of your behaviour that it will never show you.

A subject access request is the one legal tool that turns all that from a rumour into a document on your screen. People who send one (to a bank, a data broker, an old employer, a social network) are often startled by what comes back.

What the law actually gives you

Two rights matter here, both from the UK GDPR. The EU version works the same way, through your own country’s regulator.

The right of access (Article 15). This is called a subject access request, or SAR. You’re entitled to a copy of the personal data a company holds about you. You also get the details around it: what they use it for, what kinds of data are involved, who they have shared it with, how long they keep it, and where they got it if not from you. According to the ICO’s guidance, you don’t need special wording, you can ask any part of the company, and it’s free. They can only charge if a request is clearly unfounded, excessive, or a repeat copy.

The right to erasure (Article 17). Also called the “right to be forgotten”. You can make them delete your data when they no longer need it for its purpose, or when you withdraw the consent it relied on. You can also object, and they must delete it unless they have stronger grounds to keep it. If the data was used for direct marketing, your objection always wins. The ICO’s plain-English page covers it well. One useful detail: a company that deletes your data must also tell anyone it shared it with to do the same.

the shape of a request
  1. 01you send one emailno form, no fee, no legal wording needed
  2. 02they check who you arereasonable ID checks only; the clock starts once they have it
  3. 03one calendar monthup to three for complex requests, if they tell you why
  4. 04your data arrivesor you tell the regulator, at no cost to you

The same route works for deletion (Article 17 instead of Article 15). Both go to an inbox that somebody is required by law to act on.

The whole process, start to finish. The only step you control is the first one, so it's worth doing properly: in writing, with the right words.

How to send it

Find the right inbox. Look in the company’s privacy policy for a contact. Usually privacy@, dpo@ (the data protection officer), or a form. Failing that, any official contact address counts in law, and it’s their job to pass it on, not yours.

Put it in writing. A spoken request is valid, but an email gives you a dated record for the one-month countdown, and for the regulator if it comes to that.

Expect an identity check. They can check you are who you say. That protects you: otherwise they’d send your file to anyone who asked. Checks must be reasonable, and the clock starts once they have what they need. So offer ID up front, and send from the email address they already have for you.

Template one: the subject access request

Fill in the brackets, delete anything that doesn’t apply, and send.

subject-access-request.txt
Subject: Subject access request: [your full name]

Dear [company name],

I am making a subject access request under Article 15 of the UK GDPR.

Please provide me with:

1. A copy of all personal data you hold about me, including account
   records, transaction history, correspondence, notes, call
   recordings, location data, device identifiers, and any behavioural
   or profiling data, scores or inferences derived about me.
2. The purposes you process my data for, and the categories involved.
3. The recipients or categories of recipient you have disclosed my
   data to (including processors, group companies, advertising or
   analytics partners and data brokers), and what was shared.
4. How long you retain each category of my data, or the criteria used.
5. The source of any data about me not collected from me directly.
6. Details of any automated decision-making or profiling applied to
   me, including the logic involved.

The following should help you locate my records:
- Full name: [name]
- Email address on the account: [email]
- [Account / customer / order number, postcode, phone number]

Please supply the data in a commonly used electronic format. I am
happy to provide proof of identity if required. Please tell me
promptly what you need.

As you will know, you are required to respond without undue delay and
at the latest within one calendar month of this request. If you
believe an extension applies, please tell me within that month, with
reasons.

Kind regards,
[your name]
[date]

Template two: the erasure request

Send this on its own, or after a SAR has shown you what they hold. That is often the better order, because you can’t ask them to delete what you don’t know exists.

erasure-request.txt
Subject: Request for erasure of my personal data: [your full name]

Dear [company name],

I am exercising my right to erasure under Article 17 of the UK GDPR.

Please erase all personal data you hold about me. [If you wish to
keep the account: Please erase the following data: ...]

I make this request on the basis that: [pick what applies]
- the data is no longer necessary for the purpose it was collected
  for;
- I withdraw the consent on which the processing relied;
- I object to the processing, including any processing for direct
  marketing purposes, to which my objection is absolute.

Please also:

1. Confirm in writing that erasure is complete, including from backup
   systems or, where immediate erasure from backups is not possible,
   that the data has been put beyond use pending deletion.
2. Inform any third parties to whom you have disclosed my data of
   this request, as required, and tell me who they are.
3. If you refuse any part of this request, state the specific legal
   basis for each category of data you retain, and how long you will
   keep it.

The following should help you locate my records:
- Full name: [name]
- Email address on the account: [email]
- [Account / customer / order number]

Please respond within one calendar month of this request.

Kind regards,
[your name]
[date]

What happens next, and what if they ignore you

The company must reply within one calendar month, counted from the day your request arrives (the ICO publishes the exact rules). For really complex requests they can take up to two extra months, but they must tell you so, with reasons, within the first month. Saying nothing doesn’t give them extra time. Saying nothing breaks the law.

If the month passes with nothing, or the reply is clearly incomplete, chase them once in writing. Mention your original email and its date. If that doesn’t work, complain to the ICO (the UK’s data protection regulator) at ico.org.uk. It’s free, it’s set up for individuals, and companies take a letter from the regulator far more seriously than one from you. A court route exists too, but for most people the ICO complaint is what works.

What erasure can’t do

Erasure is a right, not a magic word. A company can lawfully keep data it’s required by law to keep. Your bank, for example, must hold your transaction records under anti-money-laundering law however nicely you ask. It can also keep data it needs for legal claims, and on a few narrower grounds. What it must do, according to the ICO’s erasure guidance, is tell you exactly which exception it’s relying on, and for which data. “We keep everything, for reasons” is not a lawful answer.

And be ready for the data they send to be a mess: a zip of spreadsheet files, PDFs of screenshots, columns of codes with no explanation. That isn’t you failing to understand it. It’s what a profiling business really looks like on the inside, printed out.

Send one this month. Pick the company you’re most curious about, such as your car’s manufacturer, your supermarket or your oldest social media account, and use the template. Whatever comes back, you’ll know more about your own digital life, and one more company will know that somebody checks. In the long run, the aim is to need fewer of these letters at all: data kept in apps that don’t sell it is data nobody can hold back from you.

Written by

Gee

We run itzgee.com, a private cloud in daily use, on servers run by us. How it works has the full picture.