Privacy Unpacked

Your rightsHow-to

Data Subject Access Requests: How to Get Your Data

Learn how to file a data subject access request under GDPR or US state law, what to ask for, the response deadline, and what to do if a company stalls.

By Privacy Unpacked · Published 28 September 2026 · How we work

A small gold envelope travels along a dotted path into the slot of a tall teal archive cabinet, which releases a fan of data-filled pages on the other side, while a clock, a stepped arrow and an abstract ID card sit nearby.
Illustration

The GDPR, California's Consumer Privacy Act and the Colorado Privacy Act all hand you the same tool: you can ask a company what it knows about you, and it has to answer within a fixed number of days — one month in the EU and UK, 45 days in California and Colorado. In the UK this is a subject access request; in the EU it is the right of access; in California it is a request to know. You need no lawyer and no magic wording. Here is how to file a data subject access request and make it stick.

Step 1: Work out which law you are using

The EU's GDPR reaches companies outside the EU that offer goods or services to people in the Union, whether or not payment is required, so a US app with European users can still be in scope. Article 15 gives you confirmation of whether your data is being processed, a copy of it, and a defined list of facts about the processing, per the consolidated GDPR text on EUR-Lex. UK public guidance comes from the Information Commissioner's Office.

In the US, rights are state by state and tied to coverage thresholds, not just residence. California's CCPA covers California residents, but only certain for-profit businesses — for example those with gross annual revenue over $25 million, per the California Attorney General's CCPA FAQ. Colorado residents have an access right under the Colorado Privacy Act, listed alongside rights to opt out, correct, delete and port data by the Colorado Attorney General.

Step 2: Know what the right covers

Access is not limited to the name, email and order history you typed in yourself. The EDPB's guidelines on the right of access say it covers observed data such as activity logs, search history, location data and clicking activity; derived data, like a country of residence worked out from a postcode; and inferred data, such as credit scores and recommendation outputs. Raw codes should be made intelligible. A company cannot point you at its download button and stop there: "The use of self-service tools should never limit the scope of personal data received."

The GDPR also entitles you to the recipients your data has gone to, including in third countries; the envisaged storage period or the criteria used to set it; the source of data not collected from you; and, where there is profiling, meaningful information about the logic and consequences for you.

California's version is narrower. You can ask for categories and specific pieces of personal information, sources, purposes, third-party categories and what is sold — but only for the 12 months before your request, and twice a year at no cost, says the Attorney General's FAQ: "You can make a request to know up to twice a year, free of charge."

Step 3: Write the request

There is no prescribed format and no need to cite the law: the EDPB guidelines say a controller cannot refuse because you did not name its legal basis, and a general request is read as covering all your personal data unless you say otherwise.

The ICO's page on getting copies of your information suggests including the date, your name and contact details, and identifiers that help staff find you, such as customer account numbers. Be specific about what you want and say what you do not need. State how you want to receive it — electronically, or posted — and flag accessibility needs.

A warning from the ICO's page on what to expect after a request: if your request is unclear, the organization may stop the clock until you explain what you want. Vagueness costs you time, because the one-month countdown does not restart until you clarify.

Step 4: Route it correctly and keep proof

Send it where the company says to. In the UK, contact details are usually in the privacy notice, the ICO notes. California requires businesses to designate at least two methods — an email, web form or paper form — and the Attorney General's FAQ says a business cannot make you open an account just to file, though it can route you through one you already have.

Keep evidence: emails, proof of postage, a screenshot of any web form before you submit. If you request by phone, note the date, time, staff member's name and any reference number, the ICO advises. You can delegate: California lets you authorize someone else to file, and the UK allows requests on someone else's behalf with proof of their permission.

Step 5: Pass the identity check without overpaying

The GDPR lets a controller ask for extra information to confirm identity where there are reasonable doubts, and California businesses must verify requesters — but anything handed over can be used only for that purpose.

The check is not a toll booth. For a customer already logged in, the EDPB guidelines say "it is disproportionate to require a copy of an identity document", and suggest lighter checks: relying on existing authentication, security questions, or a code sent to a known email or phone. Where ID genuinely is needed, you may redact unnecessary fields before sending it.

The ICO takes a similar line: expect an ID request for sensitive data or if your details do not match the records, but an organization confident of your identity should not ask. Comply when the demand is reasonable — the one-month clock only starts once the organization has what it needs.

Step 6: Count the days

In the EU and UK the deadline is without undue delay and within one month, extendable by two further months for complex or numerous requests, with notice inside the first month, per the GDPR. The EDPB guidelines stress that one month is a maximum, not a default, and that the first copy must be free. Under the GDPR text itself, a fee can be charged only for further copies beyond the first or where a request is manifestly unfounded or excessive, and the controller bears the burden of proving a request is manifestly unfounded or excessive. If a fee is charged, the ICO notes, the one-month limit does not begin until you have paid it.

In California, businesses must respond within 45 calendar days and can extend by another 45, to 90 total, if they notify you, the Attorney General's FAQ says. Colorado works the same way: the Colorado Attorney General says a company must respond within 45 days where you used the channel named in its privacy notice, and may take another 45 but must tell you and give reasons.

Step 7: Read the response critically

A compliant UK or EU response should explain what your data is used for, who it is shared with, how long it is kept and why, where it came from, whether you are profiled, and your right to complain to the ICO — the checklist on the ICO's page about getting a response.

Expect extracts, not original paperwork. Organizations need not hand over full original documents, and other people's information can be blacked out; the GDPR says the right to a copy must not adversely affect the rights and freedoms of others. A bank need not send statement images, only the personal data inside them. If told data is gone, check the organization's retention schedule.

California lets businesses withhold highly sensitive identifiers such as Social Security numbers and account passwords, the Attorney General's FAQ says, but they must tell you if they collect that type of data. The EDPB guidelines add that a controller must not dodge disclosure by erasing or modifying data in response to a request.

Step 8: Escalate if you're ignored or refused

If nothing arrives, the California Attorney General suggests first checking the privacy policy to confirm you used the designated method, then chasing the business; if denied without explanation, ask for its reasons. For all other CCPA violations only the Attorney General or the California Privacy Protection Agency can take legal action, so individuals generally cannot sue over a refused access request. Businesses also cannot retaliate by denying goods or services or charging a different price because you exercised your rights.

Colorado residents can file a complaint with the Attorney General's office, stating relevant dates, details and the specific right you believe was violated; the office cannot represent you personally.

Under the GDPR, a controller that refuses to act must say so within one month, give reasons, and tell you about complaining to a supervisory authority and seeking a judicial remedy. Article 77 gives everyone the right to complain to a supervisory authority, typically where they live or work; Article 79 gives a separate right to take the company to court.

Official guidance and request tools

Sources

  1. consolidated GDPR text on EUR-Lex eur-lex.europa.eu
  2. Information Commissioner's Office ico.org.uk
  3. California Attorney General's CCPA FAQ oag.ca.gov
  4. Colorado Attorney General coag.gov
  5. EDPB's guidelines on the right of access edpb.europa.eu
  6. what to expect after a request ico.org.uk
  7. getting a response ico.org.uk
  8. ICO: Make a subject access request ico.org.uk