itzgee.com

How to request your data under GDPR (and delete it)

How to send a subject access request and an erasure request under UK GDPR, with email templates, the one-month deadline, and what to do if ignored.

gdprsubject-access-requestright-to-erasureprivacydata-rights

Most people know, vaguely, that “GDPR rights” exist. Almost nobody exercises them, which suits the companies fine. So before the how, a short reminder of why this is worth thirty minutes of your life.

Why you would bother

Because the file on you is bigger than you think, and you are the only person who never gets to read it.

Your car may be scoring your braking — when American drivers pulled their files from the data broker their carmaker sold to, one ran to 258 pages of individual trips. Your supermarket holds years of your baskets, item by item, and sells the insight. Every free app on your phone is quietly building a behavioural profile it will never show you.

A subject access request is the one legal instrument that turns all of that from a rumour into a document on your screen. People who send one — to a bank, a broker, an old employer, a social network — are routinely startled by what comes back. That reaction is the point.

What the law actually gives you

Two rights matter here, both from the UK GDPR (the EU version works the same way, via your national regulator).

The right of access — Article 15. Known as a subject access request, or SAR. You are entitled to a copy of the personal data a company holds about you, plus the paperwork around it: what they use it for, the categories involved, who they have shared it with, how long they keep it, and where they got it if not from you. Per the ICO’s guidance, no special wording is required, you can ask any part of the organisation, and it is free — a fee is only chargeable if a request is manifestly unfounded, excessive, or a repeat copy.

The right to erasure — Article 17. The “right to be forgotten”. You can require deletion when the data is no longer needed for its purpose, when you withdraw the consent it relied on, when you object and they have no overriding grounds — and if the data was used for direct marketing, your objection is absolute. The ICO’s plain-English page covers it well; notably, a company that erases your data must also tell the third parties it shared it with to do the same.

the shape of a request
  1. 01 you send one email no form, no fee, no legal wording required
  2. 02 they confirm who you are reasonable ID checks only; the clock runs once they have it
  3. 03 one calendar month extendable to three for complex requests, with reasons given
  4. 04 the data arrives or the regulator hears about it, at no cost to you

The same route works for deletion — Article 17 instead of Article 15 — and both land in an inbox somebody is legally required to act on.

The entire process, end to end. The only step you control is the first — which is why it is worth doing properly, in writing, with the right words.

How to send it

Find the right inbox. Check the company’s privacy policy for a contact — usually privacy@, dpo@ (data protection officer), or a named form. If you cannot find one, any official contact address legally counts; the onus to route it correctly is on them, not you.

Put it in writing. A verbal request is technically valid, but an email gives you a dated record for the month-countdown — and for the regulator, if it comes to that.

Expect an identity check. They are allowed to verify you are you — that protects you, since the alternative is posting your file to anyone who asks. Checks must be reasonable and proportionate, and the response clock runs from when they have what they need. So state upfront that you will provide ID, and use the email address they already hold for you.

Template one — the subject access request

Fill the brackets, delete what does not apply, send.

subject-access-request.txt text
Subject: Subject access request — [your full name]

Dear [company name],

I am making a subject access request under Article 15 of the UK GDPR.

Please provide me with:

1. A copy of all personal data you hold about me, including account
   records, transaction history, correspondence, notes, call
   recordings, location data, device identifiers, and any behavioural
   or profiling data, scores or inferences derived about me.
2. The purposes you process my data for, and the categories involved.
3. The recipients or categories of recipient you have disclosed my
   data to — including processors, group companies, advertising or
   analytics partners and data brokers — and what was shared.
4. How long you retain each category of my data, or the criteria used.
5. The source of any data about me not collected from me directly.
6. Details of any automated decision-making or profiling applied to
   me, including the logic involved.

The following should help you locate my records:
- Full name: [name]
- Email address on the account: [email]
- [Account / customer / order number, postcode, phone number]

Please supply the data in a commonly used electronic format. I am
happy to provide proof of identity if required — please tell me
promptly what you need.

As you will know, you are required to respond without undue delay and
at the latest within one calendar month of this request. If you
believe an extension applies, please tell me within that month, with
reasons.

Kind regards,
[your name]
[date]

Template two — the erasure request

Send this on its own, or after a SAR has shown you what they hold — which is often the better order, since you cannot ask them to delete what you do not know exists.

erasure-request.txt text
Subject: Request for erasure of my personal data — [your full name]

Dear [company name],

I am exercising my right to erasure under Article 17 of the UK GDPR.

Please erase all personal data you hold about me. [If you wish to
keep the account: Please erase the following data: ...]

I make this request on the basis that: [pick what applies]
- the data is no longer necessary for the purpose it was collected
  for;
- I withdraw the consent on which the processing relied;
- I object to the processing, including any processing for direct
  marketing purposes, to which my objection is absolute.

Please also:

1. Confirm in writing that erasure is complete, including from backup
   systems or, where immediate erasure from backups is not possible,
   that the data has been put beyond use pending deletion.
2. Inform any third parties to whom you have disclosed my data of
   this request, as required, and tell me who they are.
3. If you refuse any part of this request, state the specific legal
   basis for each category of data you retain, and how long you will
   keep it.

The following should help you locate my records:
- Full name: [name]
- Email address on the account: [email]
- [Account / customer / order number]

Please respond within one calendar month of this request.

Kind regards,
[your name]
[date]

What happens next — and what if they ignore you

The company must respond within one calendar month, counted from the day the request lands (the ICO publishes the exact rules). For genuinely complex requests they can extend by up to two further months — but they must tell you so, with reasons, inside the first month. Silence is not an extension. Silence is a breach.

If the month passes with nothing, or the response is plainly incomplete: chase once in writing, referencing your original email and its date. If that fails, complain to the ICO at ico.org.uk — it is free, it is designed for individuals, and companies take regulator letters considerably more seriously than yours. A court route also exists, but for most people the ICO complaint is the working lever.

Being honest about the limits

Erasure is a right, not a magic word. A company can lawfully retain data it is legally required to keep — your bank must hold transaction records under anti-money-laundering law no matter how nicely you ask — or data needed for legal claims, and a few narrower grounds. What it must do, per the ICO’s erasure guidance, is tell you exactly which exemption it is relying on, for which data — “we keep everything, for reasons” is not a lawful answer.

And be ready for the export itself to be a mess: a zip of CSVs, PDFs of screens, machine columns with no key. That is not you failing to understand it. That is what the inside of a profiling operation actually looks like, printed out.

Send one this month. Pick the company you are most curious about — your car’s manufacturer, your supermarket, your oldest social account — and use the template. Whatever comes back, you will know more about your own digital life than you did, and you will have reminded one more company that somebody checks. The longer game is needing fewer of these letters at all: data that lives on your own hardware is the one file nobody else can hold back from you.

more in guides

← back to blog more in guides →