← All industries

GDPR Data Request to a Credit Reference Agency

Credit reference agencies — Experian, Equifax, and TransUnion in the UK — hold detailed financial profiles used by lenders, landlords, and employers to assess your creditworthiness. Errors in these files can affect mortgage applications, mobile phone contracts, and insurance premiums.

Data typically held by credit reference agencys

Note: Each of the three main credit reference agencies holds different data. A request to one does not cover the others — you may need to send three separate requests to get the full picture.
Tip: UK credit reference agencies offer free statutory credit reports, but a full Subject Access Request under GDPR returns more data — including soft search records, linked associates, and marketing profiles. Ask specifically for all data including marketing and fraud prevention files.

Generate your request letter

Fill in your details below. The letter covers all nine data points required under Article 15 GDPR. Copy it or send it via email to the organisation's Data Protection Officer.

Need help finding the right contact? Check our DPO directory for major companies, or search for "[company name] data protection officer" to find their contact details.

Dear Data Protection Officer,

I am writing to exercise my rights under the General Data Protection Regulation (GDPR). As an individual whose personal data you process, I am requesting the following information:

  1. Confirmation that you are processing my personal data.
  2. A copy of my personal data.
  3. The purposes of the processing.
  4. The categories of personal data concerned.
  5. The recipients or categories of recipients to whom my personal data has been or will be disclosed.
  6. The envisaged period for which my personal data will be stored, or the criteria used to determine that period.
  7. The existence of my right to request rectification or erasure of my personal data, or restriction of processing, or to object to such processing.
  8. Information about the source of my personal data if it was not collected directly from me.
  9. The existence of automated decision-making, including profiling, and meaningful information about the logic involved.

Below is my information for your reference:

Name:
Email:
Address:

This request is of utmost importance to me and should not be ignored. The GDPR mandates that you respond within one month. Failure to comply may result in further action being taken.

Thank you for your prompt attention to this matter.

Sincerely,

Text copied to clipboard

1. Copy and send this letter to the data controller of the organisation.

2. Follow up until you hear back. The GDPR requires a response within one month.

3. No response? Lodge a complaint with your local data protection authority.

No response after one month? File a complaint with your DPA →

Select your country to find your data protection authority:

Share: