Your data rights with financial firms: access, erasure and complaints

How do you find out what a bank, lender or insurer knows about you? This page explains how to ask for your personal data, the one-month reply deadline, your rights to have wrong information corrected or deleted, how to stop marketing, and what to do if a firm mishandles your information or suffers a data breach.

Your data rights with financial firms: access, erasure and complaints

Every bank, lender, insurer and credit reference agency in the UK holds a file of personal information about you: your name and address history, your transactions, your payments and arrears, the calls you have made to its complaints line, and sometimes the notes a member of staff has typed about you. You have a legal right to see that information, to have it corrected if it is wrong, to have it deleted in some circumstances, and to object to how it is used. The regulator that polices all of this is the Information Commissioner's Office (ICO).

The main tool for finding out what a firm holds is the subject access request, often shortened to SAR. It is free in almost every case, it can be made verbally or in writing, and the firm normally has one calendar month to reply. This page explains how the request works, what you will and will not get back, and what to do if a firm refuses, delays, or loses your information in a data breach. These rights sit alongside your wider consumer protection rights with financial firms.

What a subject access request gets you from a bank or lender

A subject access request asks an organisation to give you a copy of the personal information it holds about you. With a bank that can include account records, transaction histories, statements, the notes staff have made on your file, records of calls, and the information it has used to make decisions about you, including automated ones. The firm's response should also explain what it is using your information for, who it shares it with, how long it stores it and why, where it got your information from, whether it uses your data for profiling or automated decision-making, and what security measures apply if it transfers your information to a country outside the UK6.

A SAR is not the only route to information about your finances, and for some purposes a narrower, faster one exists. If what you want is your credit file, the Consumer Credit Act 1974 gives you a separate statutory right: a credit reference agency must disclose all the information it keeps about you, in whatever form it is stored, and if the information is not in plain English it must give you a transcript that is7. You can request your statutory credit report from the credit reference agencies verbally or in writing, and they usually provide an online form as well8. Making this request is free of charge8.

The two routes overlap but are not identical. A SAR to a bank reaches the bank's own records; a statutory credit report reaches what the credit reference agencies hold, which includes information supplied by lenders. If you are trying to understand why you were refused credit, the credit report is usually the place to start, because it shows what lenders see. If you want to know what a specific firm itself recorded about you, for example in a complaint or a fraud investigation, a SAR to that firm is the right tool. The ICO's guidance on subject access requests is under review and may change, so it is worth checking its current wording before you make a request6.

How to make a subject access request

There is no special form and no fixed wording. A request can be verbal or in writing, and the ICO recommends following up any verbal request in writing so there is a clear record of what you asked for and when3. You can send it to any part of the organisation: there is no requirement to address it to a particular person or department. A letter or email to the firm's head office or its data protection team is enough, and many firms publish a dedicated address for these requests.

To make the request effective, say clearly that you are asking for a copy of the personal information the organisation holds about you. It helps to narrow the scope: asking for "everything you hold about me" from a bank you have used for twenty years can produce a huge response and may prompt the firm to ask you to clarify what you actually want. Asking for a specific product, account or period is usually better. If your request is unclear, the organisation may stop the clock until you explain what information you are looking for9.

A subject access request needs no special form: a clear written request, sent to any part of the organisation, is enough.

If you have said how you would like to receive the information, for example electronically or by post, the organisation should send it in that format where possible6. It should not ask you to take action to receive the information, such as downloading particular software or collecting it from its premises, unless you have agreed to that6. The organisation must also take steps to help you with your request if you have a physical or cognitive impairment, or difficulty accessing or understanding information6.

The one-month deadline and when the clock stops

The firm must respond no later than one calendar month, starting from the day it receives your request, and a calendar month starts on that day even if it is a weekend or a public holiday1. The same one-month limit applies to other data rights requests, including objections and requests for erasure4.

The clock does not always run straight through. If the organisation asks you for identification, the one-month time limit only starts once it has what it needs from you9. If your request is unclear, it may stop the clock until you explain what information you are looking for9. This is why a precise written request matters: a vague one gives the firm a legitimate reason to pause while it waits for you to narrow it down.

For complex requests the organisation can take longer, but it must tell you within one month of getting your request that it needs more time, and explain why9. The ICO's guidance on responding to data protection complaints gives the same outer limit: a response within one calendar month at the latest, which can be extended for complex requests10. One boundary worth knowing: the extra time for complex requests does not apply to information collected or used for law enforcement reasons9.

Fees: normally free, with limited exceptions

A subject access request is free. The same is true of the statutory credit report: making this request is free of charge8. The fee rules for the other rights on this page follow the same pattern. An organisation can only charge a fee for erasure if the request is, as the law puts it, "manifestly unfounded or excessive", and even then only a reasonable fee to cover its administrative costs2. The same test applies to objections: organisations can only charge a fee if the objection is manifestly unfounded or excessive4, and to requests about automated decisions3.

What counts as manifestly unfounded or excessive is deliberately narrow. The ICO gives examples such as having no clear intention of exercising your right of access, or using a request to harass an organisation or cause disruption11. A genuine request from a person who wants to see their own file does not come close to that test. If a firm asks you for a payment before dealing with a straightforward request, that is a signal something is wrong, and it is worth questioning in writing before you pay anything.

ID checks and asking on someone else's behalf

Firms are entitled to check that you are who you say you are before handing over financial information, but the check must be proportionate. The ICO would not expect an organisation to ask for ID when it is already confident about your identity, for example because you are logged into your online banking. It would expect an organisation to ask for ID if you have asked for sensitive information, such as health or finance information9. The organisation should only ask for just enough information to be sure you are the right person2.

Financial firms routinely verify identity electronically. NS&I, for example, normally checks identity and address electronically through a credit reference agency, and asks for documents only if that check is unsuccessful; it is required by law to check identity and address when a customer applies to invest or registers for its online and phone service12. Documents that have been altered in any way, and printed copies of online documents, are not accepted12.

If you make a request for another person, the organisation will probably need proof that you have that person's permission9. The same applies to objections: someone else can submit the request for you, but they must send proof they are authorised to act on your behalf, such as written permission or a power of attorney document4. A firm cannot simply hand one person's data to another on request.

Joint accounts raise a related point. A joint account normally allows two or more people to receive payments, pay by debit card, transfer money and manage the account, depending on the bank13. But joint ownership of an account does not give one holder a right to the other holder's personal data through a subject access request. The financial link itself is visible in other ways: where two people are financially linked, a lender can have full access to your credit file in the same way it could if it were you applying for credit, and closing a joint account will not remove the link to the other person from your credit file13.

Why you may get redacted extracts rather than full documents

A subject access request gives you your personal information, not the documents it sits in. Organisations do not have to give you full copies of the original documents you have requested: you can only get your personal information that is contained in the documents6. Where information is removed or edited out of a document before it is sent to you, that is commonly known as redaction6.

The main reason for redaction is other people's data. You may receive information that identifies another person in response to your request if that person gives their permission, or if it is reasonable for the organisation to comply without the other person's permission11. If another person's information is included in the documents you have asked for, for example a family member's or colleague's, the organisation might redact it or not provide the document at all11. In a joint account or a joint borrowing situation, that can mean seeing your own transactions but not the other holder's.

There are also situations where an organisation can refuse some or all of your request. Sometimes it is acceptable for an organisation to refuse some or all of your request without telling you why11. That is unusual, but it is a real feature of the rules, and it means a partial response is not necessarily a sign the firm is hiding something from you. If you believe a firm has withheld information wrongly, the route is to complain to the firm first and then to the ICO.

Correcting inaccurate data

If a firm holds inaccurate information about you, you have the right to rectification: you can ask for it to be corrected. The same one-month response limit applies as to other data rights requests1. If you remain dissatisfied with how the firm has handled the correction, you can make a complaint to the ICO.

On credit files the process has a practical shape. Check your statutory credit report first8. To request it you will need to give your full name, any other names you have been known by in the last six years, your full address including postcode, any other addresses you have lived at in the last six years, and your date of birth8. If you find an entry that is wrong, take it up with the lender that supplied it as well as the credit reference agency. If a lender refuses to amend its entry, or fails to amend it within one month of receiving your proof of discharge in a bankruptcy case, you can complain to the ICO8.

Wrong entries on a credit file matter because lenders rely on them. A misrecorded missed payment or an outdated default can affect decisions on credit cards, loans and mortgages. The broader guide to credit scores and credit reports explains how the files are built and how lenders use them.

Right to erasure: when a firm must delete your data

The right to erasure, sometimes called the "right to be forgotten", lets you ask an organisation to delete your personal information. You can make the request verbally or in writing, and you can contact any part of the organisation with it2. In most circumstances it is free2.

The right applies in particular situations. The clearest one is where the organisation no longer needs your data for the original reason it collected or used it for2. Others include where you withdraw a consent that the processing was based on, and where you object to processing and the organisation has no overriding reason to continue. There is also a specific rule for data collected from children: even if you are now an adult, you have a right to have your data erased if it was collected from you as a child2.

If the organisation agrees, deletion is not just a matter of removing the data from its own systems. It should also tell anyone else it has shared your data with about the erasure, and it can only refuse to do that if it would be impossible or involve disproportionate effort2. Where the data has been made public online, the organisation must take reasonable steps to inform the people responsible for those sites to erase links or copies2. If the organisation refuses, it must still respond to you: it should explain why it believes it does not have to erase your data, and let you know about your right to complain about the decision to the ICO or through the courts2. It can also refuse if the request is manifestly unfounded or excessive2.

For complex requests the organisation can take up to an extra two months, but it should let you know within one month that it needs more time and the reasons why2. One related point that catches people out: if you have used your right to data portability to have your data sent to another organisation, the first organisation may not automatically delete your data afterwards. Deletion may require a separate erasure request14.

Where erasure does not apply to financial records

Financial firms keep records because the law tells them to, and that limits erasure in practice. The right does not apply where keeping your data is necessary for a legal obligation, such as complying with financial or other regulations, for establishing, exercising or defending legal claims, for tasks in the public interest, for freedom of expression, or for scientific or historical research and archiving in the public interest2. For special category data, such as health information, there are further exemptions for public health and for the provision of health or social care under professional obligations of secrecy2.

What this means is that a bank can delete your marketing preferences on request but cannot delete six years of transaction records, anti-money-laundering checks or evidence behind a lending decision, because financial regulations require it to retain them. Data protection law says organisations should not keep information for longer than they need it, and firms usually publish how long they keep each type of record in their privacy notice or on their website6. If you want to know how long a particular firm keeps something, that notice is the first place to look.

The ICO's erasure guidance is under review following changes made by the Data (Use and Access) Act and may be subject to change2, so check the current position if your request turns on a fine point.

Right to object: stopping marketing and other uses of your data

You can ask organisations to stop using your personal information. This is known as the right to object4. To use it, contact the organisation directly, tell it what use of your information you are objecting to, and explain why you are objecting4. The organisation must deal with and respond to your objection within one calendar month, and it can extend that by up to two months for complex requests, provided it tells you it needs more time and explains why4.

The strongest form of the right concerns direct marketing. You have the right to object to organisations using your personal information for sending advertising or marketing via any form of communication targeted at you specifically, whether emails, post or calls, and organisations cannot refuse your request if you are objecting to direct marketing4. That is an absolute rule: no firm can insist on keeping you on a marketing list because it thinks the messages are useful to you.

Beyond marketing, the right depends on why the organisation is using your data. You can object to the use of your data when the organisation is relying on the "legitimate interests" basis for processing15. Organisations may refuse your request if they can demonstrate a strong reason to continue using your information, need it for legal reasons or a legal claim, need it to comply with a contract, need it to save a life, can rely on an exemption, or believe the request is manifestly unfounded or excessive4. You also have rights around automated decisions: the right not to be subject to a decision based solely on automated processing if it affects your legal rights or other equally important matters, and the right to object to profiling in certain situations, including for direct marketing3. An organisation has one month to respond to a request not to be subject to an automated decision3.

After a data breach

If a firm has lost your information, for example through a cyber attack or an email sent to the wrong person, there are practical steps to take. The ICO's guidance sets out what to do if you have experienced a data breach: start by contacting the organisation to find out what has happened and what it is doing about it16. The ICO recommends giving the organisation an opportunity to investigate and respond first16.

You can make a complaint to the ICO if an organisation has not kept your information safe17. The ICO updated its breach guidance for the public in August 2026 to add more detail on breaches, examples, and when organisations must report breaches to the ICO5. If the breach has exposed information a fraudster could use, act on that quickly: request a copy of your credit file to check for any suspicious credit applications17. The ICO cannot deal with cases of identity theft themselves, but its guidance on identity theft sets out the steps to take, and the wider guide to scams and fraud covers protecting your accounts.

Complaining to the Information Commissioner's Office

The ICO is the regulator for data protection in the UK. Its role is set by law: it must investigate a data protection complaint to the extent appropriate, and inform the person making the complaint of the outcome10. It asks people to use its complaint form, because it prompts you to provide the information the office needs10. You can make a complaint online, in your own time16.

The route to a complaint runs through the firm first. The ICO recommends giving the organisation an opportunity to investigate and respond before you complain16. If you then complain to the ICO, it will handle the complaint in accordance with its complaints handling framework18, and the ICO's own guidance notes that this framework is under review following the Data (Use and Access) Act and may change18.

There are limits to what the ICO does. It does not handle complaints that are not about data protection issues, complaints that should have gone to another organisation or regulator, or complaints that are solely about an organisation's customer service10. It may take regulatory action, but it is not able to do so for each individual complaint, and it would not be proportionate for it to do so10. If you disagree with the outcome, a reviewing officer looks at how the ICO handled the complaint and writes to you explaining what they have found, within 30 calendar days10. Organisations can also complain to the ICO if they disagree with the outcome of a complaint10.

The ICO also monitors firms that generate lots of complaints. The current threshold is 12 complaints within one month, reviewed quarterly; organisations that reach it are reviewed every six months for at least two years, although the ICO does not reopen cases it closed and recorded for information purposes10. For help with the underlying financial dispute, the Financial Ombudsman Service is the right body, and the guide to making a complaint covers the firm-first process. The ICO's helpline number is 0303 123 1113, and it also offers live chat5.

Sources19 cited
  1. Time limits for responding to data protection rights requests Information Commissioner's Office, 2026-09-26
  2. Your right to get your data deleted Information Commissioner's Office, 2026-09-26
  3. Your rights relating to decisions being made about you without human involvement Information Commissioner's Office, 2026-09-25
  4. The right to object to the use of your information Information Commissioner's Office, 2026-07-23
  5. I'm worried an organisation hasn't kept my information safe: what should I do? Information Commissioner's Office, 2026-08-20
  6. Getting a response to your subject access request Information Commissioner's Office, 2026-09-26
  7. Consumer Credit Act 1974, Section 158 legislation.gov.uk, 2026
  8. Credit: your data protection rights Information Commissioner's Office, 2026-09-25
  9. What to expect after making a subject access request Information Commissioner's Office, 2024-05-23
  10. Data protection framework: how we handle complaints Information Commissioner's Office, 2026-09-26
  11. Why organisations might partially or fully refuse a subject access request Information Commissioner's Office, 2026-09-26
  12. Evidence of identity NS&I, 2026-04-15
  13. Joint accounts MoneyHelper, 2026-09-25
  14. Your right to data portability Information Commissioner's Office, 2026-09-26
  15. Does an organisation need my consent? Information Commissioner's Office, 2026-09-26
  16. What steps should I take if I have experienced a data breach? Information Commissioner's Office, 2026-09-25
  17. Identity theft Information Commissioner's Office, 2026-09-25
  18. How to make a data protection complaint Information Commissioner's Office, 2026-06-29
  19. What steps to take after a data breach Information Commissioner's Office, 2026-09-25

Related guides

The Financial Ombudsman Service: what it does and who can use it
The Financial Ombudsman ServiceExplains the free, independent service that settles disputes between consumers and financial firms: which firms and complaints it can look at, who is eligible and what it cannot consider.
How to complain to a financial firm
Complaining to a Financial FirmWalks through complaining to a bank, insurer, lender or other firm: what to include, the evidence to keep and the deadlines firms must meet, including the shorter deadline for payment services complaints.
The Financial Services Compensation Scheme (FSCS) explained
The FSCS ExplainedExplains what the FSCS is, who funds it and when it pays out: only when an authorised firm has failed and cannot pay what it owes.
FSCS compensation limits for savings, investments, insurance and more
FSCS Compensation LimitsSets out the compensation limit for each type of product: deposits, investments and advice, insurance, pensions, debt management and funeral plans.
What the FSCS does not cover
What the FSCS Does Not CoverLists what falls outside FSCS protection: falls in investment value, e-money and payment firms, crypto-assets, many overseas firms and unauthorised firms.
How to claim compensation from the FSCS
Claiming from the FSCSExplains how FSCS claims work: automatic payouts for failed banks, online claims for failed advisers and investment firms, and the evidence needed.

Frequently asked questions

Can a bank refuse a subject access request if we are in a court dispute?

A firm cannot refuse simply because you are in dispute with it, but the rules do allow an organisation to withhold some information in certain circumstances, for example where releasing it would affect someone else's rights or a legal claim. If it refuses part or all of your request it should normally explain why. In limited situations an organisation can refuse without telling you the reason. If you are unhappy with a refusal you can complain to the firm and then to the ICO.

Can I see payment details for a joint account holder?

Not automatically. A subject access request only entitles you to your own personal information. Where a document you have asked for also contains another person's details, such as a joint account holder's, the organisation may redact that person's information or withhold the document. It can disclose it if the other person gives permission, or if it is reasonable to do so without their permission. Closing a joint account does not remove the financial link between you on your credit file.

What is the ICO's phone number?

The Information Commissioner's Office helpline number is 0303 123 1113. You can also start a live chat through the ICO website. The helpline is for questions about your data rights and for raising concerns about how an organisation has handled your information. Complaints themselves are made online, and the ICO asks people to use its complaint form because it prompts you for the information the office needs.

How long do I have to take a complaint to the ICO after the firm's final response?

There is no fixed deadline in the way there is with some ombudsman schemes, but the ICO recommends complaining as soon as you can after the firm has responded. The organisation itself has 30 days to acknowledge a data protection complaint you make to it. The ICO handles complaints in accordance with its complaints handling framework and will tell you the outcome of its investigation.

Can the ICO award me compensation?

No. The ICO does not award compensation to individuals. Its role is to investigate data protection complaints to the extent appropriate and to tell you the outcome, and it may take regulatory action against an organisation, although not in every individual case. If you want compensation for a data protection failure, that is a matter for the courts. The ICO also does not handle complaints that are solely about customer service.

Can I make a subject access request over the phone?

Yes. A request can be verbal or in writing, and you do not have to use any particular form of words or a special form. The ICO recommends following up a verbal request in writing so there is a clear record of what you asked for and when. The one-month response clock starts on the day the organisation receives your request, even if that day is a weekend or public holiday.

How do I correct wrong information on my credit file?

Ask the credit reference agency and the lender that supplied the information to correct it. Your right to rectification covers inaccurate personal information, and a request can be verbal or in writing. If a lender refuses to amend an entry, or fails to amend it within one month of receiving proof, you can complain to the ICO. If you suspect identity theft, request a copy of your credit file to check for credit applications you did not make.