
Subject access request: no working way to ask
At a glance
UK-09HighUK GDPR Art. 12(2); Art. 12A; Art. 83(5)(b); DPA 2018 s. 164A
Peeky looks for a described way to ask for your data, and a contact route that opens, in the privacy policy and contact pages.
Last checked against the source:
The rule
Article 12 of the UK GDPR, in the text in force since 5 February 2026, asks the controller to provide information and communications about people’s rights “in a concise, transparent, intelligible and easily accessible form, using clear and plain language”. Paragraph 2 says: “The controller shall facilitate the exercise of data subject rights arising under or by virtue of Articles 15 to 22D.” The Data (Use and Access) Act 2025 changed the wording around that sentence. The duty to facilitate stayed.
Access is Article 15, which gives a person confirmation of whether their data is being used, a copy of it and supplementary information. The 2025 Act added a limit: under new Article 15(1A) the person is entitled only to what the controller can provide “based on a reasonable and proportionate search”. That narrows how far a controller has to look. It does not change the duty to give people a way in.
Article 12A, also new, defines the time limit. The “applicable time period” is “one month beginning with the relevant time”, meaning the latest of when the request arrives, when requested identity information arrives and when any fee is paid. The controller can extend it by two further months for complexity or the number of requests, by notice with reasons given within the first month. Time does not run while the controller waits for further information it reasonably needs to find the data.
There is a second route that is new this year. Section 164A of the Data Protection Act 2018, in force in full from 19 June 2026, lets a person complain to the controller directly. It requires the controller to “facilitate the making of complaints … by taking steps such as providing a complaint form which can be completed electronically and by other means”, to acknowledge a complaint within 30 days and to tell the person the outcome. Article 12(4) now refers to that route when a controller declines a request, and Article 15(1)(ea) lists it among the information a person is given.
The ICO does not ask for a particular channel for requests. Its guidance says there are “no formal requirements for a valid request”: a person can ask verbally or in writing, including through social media, can ask any part of the organisation, and need not use the words “subject access request”. It adds that organisations “should enable people to make SARs electronically where possible”, and says a standard form or secure online system “could” be offered, provided it is made clear that using it is not compulsory. Its preparation guidance says an organisation “could” make information available about how to make a request, for example on a website or in a privacy notice. That is guidance, not a statutory requirement for a web page.
Penalties are in the upper tier. Article 83(5)(b) puts data subjects’ rights in the group with a ceiling of GBP 17.5 million or 4% of total worldwide annual turnover, whichever is higher. The consolidated text on legislation.gov.uk now names “the Commission” as the regulator in several of these provisions, after consequential regulations under the 2025 Act took effect on 30 September 2026. The ICO pages used on this page still carry the ICO’s name.
What PeekWell checks and how
UK-09 asks the same two questions as EU-07: does the site describe a way to ask for access and the other rights, and does the contact route it names open? The UK ruleset reads for UK GDPR wording. Complaint routes are covered by UK-08.
The scan fetches the public privacy policy and the contact pages the site links to. It looks in them for language about the rights and for a mechanism: an email address, a web form or a portal. It then checks that the link or form resolves. A right the page never mentions, or a contact link that goes nowhere, becomes a finding.
The scan never sends a request, fills in a form, writes to an address or signs in. It cannot see whether the inbox is read, whether replies arrive within the time in Article 12A, or whether the right data is found. The Virgin Media and care home matters below turned on exactly those things.
The scan has the limits the report states. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. A route offered only by letter, by phone or inside an account may not show up. A Passed means the expected wording and a working route were observed on the pages scanned. It does not say requests are handled correctly. The same limits apply as for the EU check.
Why it matters for a company
The ICO’s published action in this area is mostly about what happens after a request arrives. In September 2022 it reprimanded Virgin Media after over 9,500 requests in six months, 14% of them unanswered in time. It noted the company’s compliance had improved by 2022. A reprimand is not a fine, and the case shows the regulator looks at the volume, the delay and the fix.
At the other end, the ICO took a criminal case against a care home director. A woman had asked for information about her father’s care. The ICO found the director had blocked, erased or concealed records to prevent disclosure, and it prosecuted under section 173 of the Data Protection Act 2018. The ICO’s head of investigations called subject access “a fundamental right” because it helps people understand how and why organisations use their information. The offence in that case was concealing records, not lacking a web page.
For a company the common thread is the complaint. Both matters began when a person asked, did not get what they were entitled to, and complained. Since 19 June 2026 the first stop for that complaint is meant to be the company itself, through a route it has to make easy. The ICO’s complaints guidance says plainly that the process is required and that “there are no exemptions to this”.
Smaller companies and larger companies
The duty has no size threshold, though the ICO says appropriate preparation depends on the number of requests and the organisation’s size and resources.
In a small company the route is often a general contact address, a form on a website builder, or a phone number, with no one named as responsible. Requests may arrive at a sales mailbox or a social media message. Under the ICO’s guidance that can still be a valid request, because it need not go to a specific person. The risk is that nobody recognises it and the one-month clock runs. In the care home case a single director’s refusal to respond, his silence during the ICO’s investigation and an attempt to cancel the registration led to a prosecution, with a fine of GBP 1,100 and costs of GBP 5,440.
In a larger company the numbers are the issue. Thousands of requests can arrive through apps, call centres and accounts, and data sits in many systems. The Virgin Media reprimand turned on volume and timing. Larger companies also usually have a privacy team, so the questions are whether the route is easy to find from every page and whether the people who take calls and chats can recognise a request.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Virgin Media Limited
The ICO records that over a six month period in 2021 Virgin Media received over 9,500 subject access requests, and 14% of them were not answered within the statutory timeframe. The ICO issued a reprimand and noted that the company's compliance had improved in 2022. The case is about handling after a request arrives, which a website scan cannot see.
Read the ICO (UK) publication about Virgin Media Limited
Smaller companies
Jason Blake, director of Bridlington Lodge Care Home
After a woman asked the care home for information about her father, with lasting power of attorney to act for him, the ICO reports that the director was found to have blocked, erased or concealed records between 12 April and 12 May 2023 so they would not be disclosed. A complaint reached the ICO, and he gave no explanation during its investigation. He was found guilty under section 173 of the Data Protection Act 2018 at Beverley Magistrates Court on 3 September 2025.
Read the ICO (UK) publication about Jason Blake, director of Bridlington Lodge Care Home
How to fix it
These steps follow the ICO’s guidance on recognising and preparing for requests, and its complaints guidance. They are practical choices, and the ICO labels much of its advice as what an organisation should or could do.
- Say how to ask. In the privacy notice, name the rights and give one clear way to use them: an email address, a form or a portal. Make clear that other ways of asking still work.
- Link it from every page. Put a link to the privacy notice in the footer, and link from the notice to a short “Your data rights” page with the route on it.
- Add an electronic route. The ICO says organisations should enable electronic requests where possible. A shared mailbox with an autoreply is enough to start.
- Add a complaints route. Since 19 June 2026 you need a way for people to complain to you about data protection, such as an electronic form, with acknowledgment within 30 days. A link next to the rights route is easy to keep up to date.
- Name an owner and a deputy. The ICO says to appoint a specific person or central team, and to make sure more than one person knows how to deal with a request. Train anyone who answers calls, chats or social accounts to recognise a request.
- Log the date. Record the day each request arrives, since Article 12A runs from then, and note when you ask for identity details or clarification.
- Re-scan. Run a scan again once the wording and the working link are live. The finding should clear when the page describes the rights and the contact route opens.
Whether a given setup meets Article 12 is a question for your legal adviser, and Peeky reports only what it sees.
Questions
What is a subject access request?
It is a person's request to an organisation for the personal information it holds about them. Article 15 of the UK GDPR entitles them to confirmation of whether the organisation is using their data, a copy of it, and information about how it is used.
They do not have to use a particular form or the words subject access request, according to the ICO.
What is the time limit for a subject access request?
One month from the relevant time, which is usually when the request arrives. Article 12A allows two more months where that is necessary because the requests are complex or numerous, but the organisation must tell the person, with reasons, within the first month.
The clock can also stop while the organisation waits for details it reasonably needs to find the data.
How do I make a subject access request?
Ask the organisation for your personal information, by email, post, phone or social media. The ICO says there are no formal requirements and the request can go to any part of the organisation. Writing to the address in its privacy notice is the clearest route, and it leaves a record of the date.
Do I need a subject access request template?
No. The ICO says people can make a request by any means and do not have to use a standard form. A template can still help you include what the organisation needs to find your data, such as your name and the accounts you hold.
Does a company have to offer an online form for subject access requests?
Not a form as such, but the ICO says organisations should enable people to make requests electronically where possible. It suggests a standard form or a secure online system as options, and says it must be clear that using them is not compulsory. Since 19 June 2026 section 164A also expects a way to make complaints, such as an electronic form.
Filed with
The rule
UK GDPR, Arts. 12, 12A, 15 and 83(5)(b), as amended by the Data (Use and Access) Act 2025
Read the rule (UK GDPR, Arts. 12, 12A, 15 and 83(5)(b), as amended by the Data (Use and Access) Act 2025)Sources
- UK GDPR, Art. 12 (revised text, amended by the Data (Use and Access) Act 2025), legislation.gov.uk
- UK GDPR, Chapter III incl. Arts. 12A and 15 (revised text), legislation.gov.uk
- UK GDPR, Art. 83 (revised text), legislation.gov.uk
- Data Protection Act 2018, s. 164A, complaints by data subjects to controllers (in force 19 June 2026)
- Data (Use and Access) Act 2025, s. 78, searches in response to data subjects' requests
- ICO, How do we recognise a subject access request (SAR)? (right of access guidance, updated 7 April 2026)
- ICO, How can we prepare for a subject access request (SAR)? (right of access guidance, updated 8 December 2025)
- ICO, How to deal with data protection complaints (published 12 February 2026, updated 8 May 2026)
- ICO, Virgin Media Limited, reprimand of 20 September 2022
- ICO, Care home director found guilty of ignoring request for personal information, 4 September 2025
Last checked against the source:
For information only. Not legal advice.


