How to Request Your Data From a Company: Simple Guide 2026

Yes, you can request your data from a company. Under the GDPR, the UK GDPR, the CCPA and most modern privacy laws, you have the right to get a copy of the personal data a company holds about you by sending a formal access request, usually called a data subject access request (DSAR) or subject access request (SAR). You send it to the privacy team or the Data Protection Officer, and the company normally has to answer free of charge within about a month.

It is the only practical way to find out what a company actually knows about you: which records it keeps, who it shared them with and how long it holds them. Most people who file one say the export is bigger and stranger than expected, which is exactly why it is worth sending.

Table of Contents

What You Need

What You Need

You do not need a lawyer or any special form. You need enough information to prove the account is yours, and a way to reach the company that actually holds the data.

  • Identifying details. The email address on the account, your full name, username, customer or member number, and approximate dates of use. Companies are allowed to ask for enough to confirm you are who you say you are.
  • Proof of identity, ready but not sent. A copy of an ID document or a selfie may be requested later. Send it only through a secure upload form or a link, never as an unencrypted attachment to a support chat.
  • The scope of the request. Say whether you want everything, or only certain categories such as messages, purchase history, payment records or profile data.
  • The right contact point. Usually a privacy@ address, a data protection contact listed in the privacy policy, an in-app download tool, or a web form.
  • A date to work from. Note the day you send it so you know when the response deadline starts running.

The exact process depends on the company and the country you live in. US state laws, EU rules and UK rules set different deadlines, and a small employer may only respond to an email. What follows is the part that works nearly everywhere.

Step-by-Step: How to Request Your Data From a Company

Step-by-Step: How to Request Your Data From a Company

Step 1: Identify the Company and the Data You Want

Start by working out which legal entity is behind the service. A single app can be run by several companies, and the one that answers you may not be the brand you recognise from the app icon. The privacy policy footer usually names the registered company and its address.

Then decide the scope. Asking for everything is legitimate and free, but the file can be enormous and arrive in a format you cannot read. Most people get more out of a narrower request, such as account profile data, messages and support history, or payment records between two specific dates.

One thing to clear up here: you can only ask for data about you, not the company’s internal records, accounts or financials. A data request and a data portability request are different things. Access means a copy of everything held about you; portability means a technical file designed to move to another service.

Step 2: Find the Correct Privacy or Data Request Channel

Work through the company’s privacy policy in a specific order. Look for a section on access requests, your rights, or a “contact our privacy team” link, and check the footer for a postal address and a Data Protection Officer name.

Many large platforms also ship a self-service export tool inside account settings or a privacy dashboard. Using it is faster, and the file arrives automatically, but the tool often returns a narrower export than a written request. If you want recipients, retention period and profiling details as well, send a written request.

Avoid ordinary customer support chat for this. Support agents usually cannot open a formal request, and pasting your ID number or a photo of your passport into a live chat window is a bad idea. If the only channel offered is a public email address, say in your message that you are sending a formal access request under the relevant law.

Step 3: Write a Clear Request

A short, formal message works better than a long one. You are exercising a legal right, so state that plainly, name the law, give the details that identify the account, and say what you want delivered.

Copy this template and fill in the brackets. Send it as the body of an email, or as the text of a letter.

Subject: Formal access request for my personal data

To Whom It May Concern,

I am making a formal request for access to my personal data under
[GDPR Article 15 / UK GDPR / the CCPA and CPRA / other applicable law].

Details that identify my account:
- Full name: [your name]
- Email address on the account: [your email]
- Username or member number: [if applicable]
- Approximate dates of use: [if useful]

I request a copy of all personal data you hold about me, including:
- [account and profile data]
- [messages, orders, payments or browsing activity]
- the recipients or categories of recipient you have shared my data with
- the source of the data if it was collected indirectly
- your retention period or the criteria you use to decide when to delete it
- any automated decision-making or profiling applied to my data, and the logic behind it

Please send the data in a commonly used electronic format such as JSON,
CSV or plain text, to the email address above, or via a secure download link.

If you need to verify my identity, please tell me exactly what you require
and how you would like me to send it securely.

I would appreciate a response within the deadline set by the applicable law.
Please confirm receipt of this request.

Kind regards,
[your name]
[date]

Beyond raw records, the last three lines matter. They cover the information most people never think to ask for, and they are the parts that tell you whether your data was sold, shared or used to score you.

Step 4: Submit and Keep a Record

Send it through the channel you identified, then do the boring part. Save the email you sent, the exact wording, every attachment and the date. If you get an automated case number or reference, write it down and quote it in every follow-up.

Take a screenshot of the submission confirmation. If you post a letter, keep the copy and the proof of delivery, and note the first weekday after delivery as the start of the clock.

Expect a reply that is either an acknowledgement with an identity check, a request for more information, or the data itself. Some companies send an automatic confirmation and then go quiet, which is a stalling tactic rather than a completed request.

Step 5: Follow Up or Escalate

Check whether the reply actually answers the request. A partial export that omits the recipients, the retention period or the profiling details is not a full response, and you can say so in writing and ask for the remainder.

Know your deadline before you chase. Responses are measured in calendar time from the day the company received a complete request, and identity checks can pause the clock in some jurisdictions.

Where you liveNormal deadlineCan it be extended?
European Union (GDPR)One calendar monthUp to two more months for complex requests, with written notice
United Kingdom (UK GDPR)One calendar monthTwo further months, same rule
California (CCPA and CPRA)45 daysExtension of 45 days with notice
Other US statesVaries by state, often 30 to 45 daysVaries

Requests are free of charge. A company may only charge where the request is manifestly unfounded or excessive, and it has to explain why before it does.

When the deadline passes, send one short reminder quoting your reference and the date, then escalate. In the UK that means the Information Commissioner’s Office. In the EU it is the data protection authority in the country where you live, not necessarily where the company is based. In the US, start with the state attorney general or the state privacy agency; federal complaints go to the FTC, which acts on patterns rather than single cases. Legal-aid services and consumer organisations can help you draft the complaint, which costs nothing.

One note worth knowing: a data request has leverage of its own. A clear, dated, legally framed letter often moves a stalled support queue faster than another ticket, because it creates a record the company has to answer.

Common Mistakes

Sending it to the wrong department. A general support inbox treats your request as a ticket and closes it. Fix: address it to the privacy team or Data Protection Officer named in the privacy policy, and put “formal access request” in the subject line.

Asking vaguely. “Send me my data” invites a partial answer. Fix: list the categories you want and ask for a commonly used electronic format.

Using an unsafe channel for ID. Never attach a passport scan to an ordinary email or paste one into chat. Fix: ask for a secure upload link or accept verification through an existing account login.

Failing to verify identity at all. If the details do not match the account, the request stalls while someone works out who you are. Fix: include the email, username and any customer number that tie the account to you.

Assuming a privacy policy can override the law. Boilerplate that says “we do not respond to individual requests” does not remove a statutory right. Fix: cite the law in your request and keep a copy.

Expecting unlimited records. Access covers personal data about you, not other people’s, and it does not reach another company’s copy of it. Fix: ask each company that holds the data separately.

A few more tips that save time. Ask for machine-readable output such as JSON or CSV rather than a PDF nobody can search. Narrow by date range if your request is enormous. File before you close an account, because exports often arrive after the account is gone. And if a request returns something wrong, a follow-up correcting or erasing it is a separate right, usually with its own deadline.

Frequently Asked Questions

What is a company data request?

A company data request is a formal written demand for a copy of the personal data an organisation holds about you. It is usually called a data subject access request (DSAR) or a subject access request (SAR). Privacy laws such as GDPR Article 15 and the CCPA create the right, and your request is the tool that exercises it. The company must respond, disclose supporting details such as recipients and retention periods, and may not charge unless the request is manifestly unfounded or excessive.

How long does a company have to respond to a data request?

Under the GDPR, the normal deadline is one calendar month from receipt, extendable by two further months for complex requests if the company tells you in writing. UK rules use the same one-month period. In California the CCPA and CPRA allow 45 days, with a further 45-day extension on notice. Other US states set their own windows, commonly 30 to 45 days. Identity checks can pause the clock in some jurisdictions.

Can a company charge me to provide my personal data?

No, not in normal circumstances. GDPR and CCPA both require the response to be free of charge. A company can only charge, or refuse, where the request is manifestly unfounded or excessive, usually meaning a repetitive, excessive or disproportionate request aimed at someone else’s data. Even then it must explain its reasoning in writing and you can complain to the relevant data protection authority. Ordinary one-off requests are always free.

What if a company asks me to verify my identity?

That is normal and permitted. Privacy laws let a company ask for reasonable evidence that you are the data subject, to protect everyone else in the database. Ask exactly what they need and how they want it delivered, and prefer a secure upload link, an in-account confirmation or a partial document such as a passport page without the signature. Never send identification through live chat or an unencrypted form, and know that verification is not a reason for an unlimited delay.

What should I do if my data request is denied or ignored?

First check whether the reply addressed everything you asked for, since a partial export is an incomplete response rather than a refusal. Send a short written reminder quoting your reference and the original deadline. If nothing happens, escalate to the relevant regulator: the ICO in the UK, your local data protection authority in the EU, or the state attorney general or privacy agency in the US. Keep every message, since a complaint is far easier with a dated paper trail.

What to Do First

Send one written request today, addressed to the privacy contact in the policy footer, using the template above and keeping the proof. Save your reference number, set a reminder for the deadline in your country, and check the reply against what you asked for before deciding whether to escalate.

This is general information about privacy rights, which vary by country and state and change over time. For advice about your own situation, a local data protection authority or a legal-aid service is the right place to start.

Leave a Comment

Daily news, sports and entertainment, explained

Read today's explainers