General legal information, published for everyone. It does not apply the law to anyone’s particular situation and is not legal advice. Laws change and differ by place; check the primary sources below.
Quick summary
- Many privacy laws let you ask a company what personal information it holds about you, how it uses that information, and, in some places, receive a copy.
- The right is often called a subject access request, access request, or data-subject access request, but its scope and exceptions depend on where you live and which law covers the company.
What it means
Many privacy laws let you ask a company what personal information it holds about you, how it uses that information, and, in some places, receive a copy. The right is often called a subject access request, access request, or data-subject access request, but its scope and exceptions depend on where you live and which law covers the company.
How the law works
How the law usually works
A personal-data access request is a written request for information about you. It may cover information stored in customer accounts, emails, call recordings, transaction records, complaint files, marketing databases, location data, online identifiers, and information obtained from other sources.
A request commonly asks for:
- A copy of the personal information held about you.
- The purposes for which it is used.
- The categories of information involved.
- The people or organizations receiving it.
- How long it will be kept, or how that period is decided.
- Where the information came from, if it was not collected from you.
- Information about automated decision-making or profiling, where relevant.
The right is usually about your personal information, not every document that mentions your name. A company may remove information about other people, confidential business material, legally privileged communications, or information covered by a specific legal exemption.
In many places, the company may ask for enough information to confirm your identity and locate the relevant records. It generally should not demand unnecessary information or require you to explain why you want access. A request may be made through an online form, email, account portal, or another contact method the organization provides.
A company may provide the information electronically, in paper form, or in another reasonably accessible format. Some laws provide a right to a copy; others require access to the information but allow particular formats or limitations.
Access rights do not always include deletion, correction, or an explanation of every internal decision. Separate rights may apply to correcting inaccurate information, objecting to marketing, restricting use, or requesting deletion.
Common processes
- Identify the company and the applicable privacy contact. People commonly check the company’s privacy policy for its privacy team, data-protection officer, or designated request method. The correct legal entity may be different from the brand shown on a website or app.
- Prepare a clear written request. A request commonly states that it is an access request and identifies the person, account, service, and time period involved. A narrower request—such as asking for account records from a particular year—may be processed more easily than a very broad request.
- Include reasonable identity information. People commonly provide information that helps the company locate the account, such as an email address, customer number, former address, or username. If identity documents are requested, people often ask whether sensitive numbers can be covered or redacted.
- Keep proof of the request. Saving the email, online confirmation, attachments, and delivery record can help establish when the request was received. A person may also keep a timeline of follow-up messages and the company’s responses.
- Review the response. The response may include a data export, account records, a description of processing, or a notice that some information was withheld. People commonly check whether the information appears complete, whether dates and categories make sense, and whether third-party information has been properly removed.
- Ask for clarification or correction. If the response is unclear or appears incomplete, people commonly ask what searches were performed, which categories were excluded, and what legal reason was given for any withholding. A separate correction request may be appropriate for inaccurate information.
- Use a regulator or complaint process if needed. Privacy regulators may accept complaints about an organization’s failure to respond, inadequate searches, unjustified refusal, or mishandling of identity verification. Court remedies may also exist, depending on the jurisdiction and the relevant law.
Deadlines and time limits
Deadlines vary substantially.
Under the UK GDPR, organizations generally respond without undue delay and within one month. That period can usually be extended by up to two further months for complex or numerous requests, but the organization normally must explain the extension.
Under the European Union GDPR, the usual period is also one month, with a possible extension of up to two additional months for complex or numerous requests.
Under Canada’s federal private-sector privacy law, organizations are generally expected to respond within 30 days, with limited extensions in specified circumstances.
Under Australia’s Privacy Act, the Australian Privacy Principles require reasonable access, but the legislation does not use the same general one-month deadline as the UK GDPR. The organization should respond within a reasonable period, and its privacy policy or the regulator may provide further guidance.
In the United States, deadlines depend on the law. California’s privacy law generally provides a 45-day response period, with a possible extension in some circumstances. Other state privacy laws may use different periods, and sector-specific laws may have their own rules.
These are typical statutory or regulatory periods, not a guarantee that every request will be completed within them. You can confirm the applicable deadline with the company, the relevant regulator, a court, or a licensed attorney where you live.
Documents that usually matter
Commonly useful documents include:
- The original request and any confirmation of receipt.
- The company’s privacy policy and terms of service.
- Identity-verification messages and documents.
- Account statements, invoices, messages, or screenshots showing the relevant account.
- The company’s response and any explanation for withheld information.
- A correction request or follow-up correspondence.
- Records of marketing messages, account restrictions, automated decisions, or disputed data.
- Proof of delivery and a dated chronology.
People often avoid sending unnecessary sensitive information. A request normally does not require a full explanation of a dispute unless the facts are needed to identify the relevant records.
How it differs by jurisdiction
United States. There is no single, comprehensive federal access right covering every private company. Rights may arise under sectoral laws, such as health or financial privacy laws, or under state laws. California’s California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives qualifying consumers rights to know and access personal information, subject to definitions, exemptions, verification rules, and business thresholds. Colorado, Connecticut, Virginia, Utah, and other states also have privacy laws, with different coverage and deadlines. Some laws exclude employment data, business-to-business contacts, publicly available information, or information covered by another statute.
England and Wales. The UK GDPR and the Data Protection Act 2018 generally provide a right of access to personal data. The Information Commissioner’s Office can investigate complaints and issue regulatory guidance. Exemptions can apply to legal privilege, crime and taxation matters, management forecasting, confidential references, and other defined situations. Scotland and Northern Ireland use the same main UK data-protection framework, although courts and legal procedures differ.
Canada. The federal Personal Information Protection and Electronic Documents Act, commonly called PIPEDA, applies to many private-sector organizations engaged in commercial activity. Alberta, British Columbia, and Quebec have substantially similar private-sector laws for many organizations, and other sector-specific provincial rules may apply. The federal and provincial regulators can differ, so the organization’s location and activities matter.
Australia. The Privacy Act 1988 and Australian Privacy Principle 12 generally provide individuals with access to personal information held about them by covered organizations. Small-business exemptions and other exceptions can be important. State and territory privacy laws may apply to government bodies or particular sectors, while the Office of the Australian Information Commissioner handles many federal privacy matters.
When people consult a lawyer
Legal advice may be useful when:
- The request concerns a lawsuit, threatened lawsuit, investigation, employment dispute, or regulatory proceeding.
- The company claims legal privilege, confidentiality, fraud prevention, or another exemption.
- The information may reveal misconduct, discrimination, identity theft, or unlawful surveillance.
- The company refuses access, gives an apparently incomplete response, or misses the applicable deadline.
- You need correction, deletion, compensation, or an injunction in addition to access.
- The request involves health records, children’s information, biometric data, immigration records, or criminal matters.
- The organization is in another country or several privacy laws may apply.
A privacy regulator may offer a lower-cost complaint route, but regulators do not always award compensation or provide every document requested.
Primary sources
- StatuteUnited Kingdom: UK GDPR, Article 15; Data Protection Act 2018, especially the subject-access provisions; official legislation published by the UK government.England & Wales
- Official sourceUnited Kingdom: Information Commissioner’s Office, “Right of access” and guidance on subject access requests.England & Wales
- RegulationEuropean Union: Regulation (EU) 2016/679 (EU GDPR), Article 15; official EUR-Lex legislation.See citation
- StatuteUnited States—California: California Consumer Privacy Act, California Civil Code sections 1798.100 and following, as amended; official California Legislative Information.United States (federal)
- Official sourceUnited States: California Privacy Protection Agency, consumer privacy rights guidance; official agency materials.United States (federal)
- StatuteCanada: Personal Information Protection and Electronic Documents Act, especially the access provisions and Schedule 1, Principle 4.9; official Justice Laws Website.Canada
- Official sourceSourceSee citation
Links go to official or widely used free sources. Check that a source is current before relying on it. Browse all sources →
- Last updated
- Sep 26, 2026
- Jurisdiction
- General — United States, England & Wales, Canada, Australia
- Written by
- House Legal editorial (AI-generated, earlier format)