Etoolio

GDPR Data Request Letter Generator

Free GDPR data request letter generator. Create a letter to ask a company for a copy of your personal data (a subject access request), or to delete, correct, port or stop using it, under the GDPR, UK GDPR or CCPA. Runs in your browser.

What do you want to do?
Which law applies to you?

Your letter

[Your name]

[your email address]

[date]

[Organisation name]

Dear [Organisation name],

Subject: Request for access to my personal data

I am exercising my rights under the EU General Data Protection Regulation (GDPR) (Article 15).

I am writing to request access to the personal data you hold about me. Please provide a copy of that data, along with the information about how it is used: the purposes of the processing, who it is shared with, how long it is kept, and where it was obtained if not from me.

To help you locate my records, you can identify me by my name ([Your name]), my email address ([your email address]). If you need anything further to verify my identity, please tell me exactly what you need and I will provide it.

Please respond within one month, as required by the GDPR. This request is free of charge, and I do not expect to be charged a fee. If you are able to provide the information electronically, please send it to the email address above.

If you do not respond within the required time, or you refuse this request without a valid reason, I may complain to the data protection authority in your country.

Please confirm that you have received this request.

Yours faithfully,

[Your name]

This creates a first draft of a data-rights letter for you to review, personalise and send. Fill in the organisation, your details and anything specific you want, then check it reads correctly before you send it. Send it to the organisation's privacy or data protection contact if you can find one, and keep a copy and proof of when you sent it. Organisations must usually respond within the time shown, and cannot charge a fee except in limited cases. This is general information to help you write the letter, not legal advice, and the exact rights and deadlines depend on your situation and location. Everything is generated in your browser and nothing you enter is uploaded.

Your data belongs to you. This letter proves it.

Companies hold more information about you than you might think, and the law gives you real power over it: the right to see it, correct it, delete it, take it elsewhere, or tell them to stop. The catch is that exercising those rights means writing a proper letter that cites the right law, and most people never get round to it. This free generator writes that letter for you in under a minute. Choose what you want to do, add a few details, and copy, download or print a letter ready to send. It runs entirely in your browser.

What you can ask for

  • A copy of your data (a subject access request), including how and why it is used.
  • Deletion of your data (the right to be forgotten), or correction of anything wrong.
  • A portable copy to move elsewhere, or to object to how your data is used, including stopping marketing.

The rules that make it work

Under the GDPR and UK GDPR, an organisation must normally respond within one month, and cannot charge you a fee except in limited cases. Under California's CCPA the main deadline is 45 days. The letter this tool writes names the correct right and law for your choice, for example the right of access under Article 15, so the organisation knows you understand your rights and treats the request seriously. It also asks them to confirm receipt and reminds them of the deadline, which quietly sets the tone.

How to send it, and what to keep

Send the letter to the organisation's privacy team or Data Protection Officer if you can find one, usually named in its privacy policy. Include an account or customer reference so they can locate your records, keep a copy of what you sent, and note the date, because that is when the response clock starts. If they miss the deadline or refuse without a good reason, you can complain to the relevant regulator, such as the ICO in the UK or your national data protection authority in the EU.

Private, and a first draft to make your own

Everything is generated on your device, so none of your details, including your name and email or the company involved, is ever uploaded. Treat the result as a strong first draft: read it through, adjust anything specific to your situation, and send it. This is general information to help you write the letter, not legal advice, and the exact rights and deadlines depend on where you live and the circumstances. It is free, with no signup, and there is no limit on how many letters you create.

Good to know

GDPR Data Request Letter Generator, frequently asked questions

What is a subject access request (SAR)?

A subject access request is you asking an organisation for a copy of the personal data it holds about you, along with how and why it uses that data. It is a right under the GDPR (Article 15) and the UK GDPR, and a similar right to know exists under the California CCPA. The organisation usually has to respond within one month (45 days under the CCPA) and cannot charge a fee except in limited cases. This tool writes the letter for you.

What kinds of request can I make?

This generator covers the main personal-data rights: get a copy of your data (access), have it deleted (erasure, the 'right to be forgotten'), correct data that is wrong (rectification), receive your data in a portable format to move it elsewhere (portability), and object to how your data is used, including stopping direct marketing. Pick the one you need and the letter cites the correct right.

Who do I send the letter to?

Send it to the organisation that holds your data, ideally to its privacy team or Data Protection Officer if it has one, which is often listed in the privacy policy or on the contact page. Send it in writing, keep a copy, and note the date you sent it, because the response clock starts then. If you have an account or customer number, include it so they can find your records quickly.

How long does the organisation have to respond?

Under the GDPR and UK GDPR, usually one month, which can be extended by up to two further months for complex or multiple requests, in which case they must tell you. Under the California CCPA, the main deadline is 45 days, extendable to 90. If they miss the deadline or refuse without a valid reason, you can complain to the relevant regulator, such as the ICO in the UK.

Is this legal advice?

No. This is general information and a template to help you write the letter yourself. It produces an editable draft that you should review and adapt to your situation before sending. Your exact rights and the correct deadlines depend on where you are and the circumstances, so check with the relevant data protection authority or a qualified adviser if you are unsure.

Is my information kept private?

Yes. The letter is generated entirely in your browser. None of the details you enter, including your name, email or the organisation, are sent to a server or stored.

Is it free?

Yes, free with no signup and unlimited.