免责声明:本网站不构成法律建议。法律法规和判例法会发生变化。请务必就您的具体情况咨询合格的律师。

所有指南
Data Protection
5 步骤
更新 March 2026

提出数据主体访问请求

如何请求组织持有的个人数据副本。

概述

Under Article 15 of the UK GDPR, you have the right to obtain confirmation of whether an organisation is processing your personal data and, if so, to receive a copy of that data. This is known as a Subject Access Request (SAR) or Data Subject Access Request (DSAR). Organisations must respond within one calendar month. The request is free.

逐步流程

1

Identify the Organisation

Determine which organisation holds your data. This could be your employer, bank, GP, school, social media platform, or any organisation that processes your personal data.

2

Write Your Request

Send a written request (email or letter) asking for a copy of all personal data held about you. You do not need to use any specific form or mention the UK GDPR, but it helps to be clear. Include enough information to identify yourself (name, account number, etc.).

时间范围: Day 1
3

Organisation Must Respond

The organisation must respond within one calendar month of receiving your request. They can extend this by two further months for complex requests, but must tell you within the first month.

时间范围: Up to 1 month (3 months if complex)
4

Review the Response

Check the data provided is complete. You should receive a copy of your personal data, information about the purposes of processing, who the data has been shared with, and how long it will be kept.

5

Complain to the ICO if Unsatisfied

If the organisation fails to respond, provides an incomplete response, or refuses without valid reason, you can complain to the Information Commissioner's Office (ICO) for free.

时间范围: At any point after non-compliance

费用

DSAR feeFree
ICO complaintFree

重要警告

Organisations can refuse or charge a reasonable fee for requests that are 'manifestly unfounded or excessive'.

Some data may be exempt from disclosure (e.g., legal professional privilege, crime prevention).

有用链接

Related Content

Related Legislation