Skip to main content
AI-Powered DSARs Are Here. Your Workflow Isn't Ready.Data Subject Rights
6 min readFor Records & Information Managers

AI-Powered DSARs Are Here. Your Workflow Isn't Ready.

Scope - What This Guide Covers

This guide tackles the operational challenge of managing data subject access requests (DSARs) and Freedom of Information (FOI) requests enhanced by large language models. You'll find specific workflow adjustments, process controls, and technical considerations for handling requests that are longer, broader, and more technically precise than traditional submissions.

This guide doesn't cover the legal validity of AI-generated requests (they're valid under Article 15 GDPR if submitted by or on behalf of the data subject) or basic DSAR response obligations. It assumes you're already familiar with the one-month response window under Article 12(3) and the information categories required under Article 15.

Key Concepts and Definitions

AI-generated request: A DSAR or FOI request drafted, expanded, or refined using large language models like ChatGPT or Claude. These requests often include precise legal citations, multi-part questions, and exhaustive category lists that mirror template language rather than natural human phrasing.

Request complexity creep: The phenomenon where AI tools enable requesters to submit technically perfect requests covering maximum permissible scope, even when the requester wouldn't naturally know to ask for specific log types or processing categories.

Interpretation burden: The additional time required to parse requests that use broad categorical language ("all personal data relating to me") versus specific, actionable requests ("my account creation date and email address").

Requirements Breakdown

Article 15 Obligations Remain Unchanged

Your legal obligations haven't shifted. You must still:

  • Confirm whether you're processing the requester's personal data (Article 15(1))
  • Provide a copy of the data undergoing processing (Article 15(3))
  • Supply transparency information (processing purposes, categories, recipients, retention periods, source if not collected from the data subject)
  • Respond within one month, extendable by two months for complex requests under Article 12(3)

What's Changed: Volume and Scope Pressure

Lincolnshire County Council received almost 2,000 FOI requests in the last financial year, an increase of 18% compared to the previous year. While this statistic covers FOI rather than DSARs, the pattern holds: AI tools lower the friction for submitting requests.

More significantly, AI-generated requests tend to:

  • Include every possible data category mentioned in your privacy notice
  • Reference specific GDPR articles and recitals
  • Demand explanations that go beyond Article 15's requirements
  • Combine multiple request types (access, rectification, explanation of automated decision-making)

Implementation Guidance

Triage at Intake

Build a two-tier classification system at the point of receipt:

Tier 1 - Bounded requests: The requester identifies specific systems, timeframes, or data categories. Route these to standard workflow.

Tier 2 - Maximalist requests: The request uses categorical language covering all processing activities or mirrors privacy notice structure. Flag for scope clarification before beginning collection.

For Tier 2 requests, you're entitled under Article 12(5) to request additional information to identify the data subject. Extend this principle: if the request is "manifestly unfounded or excessive", particularly because of its repetitive character, you may charge a reasonable fee or refuse to act. Document your reasoning.

Scope Clarification Protocol

Don't assume you must respond to every sub-clause in a 12-paragraph AI-generated request. Instead:

  1. Identify the core request: What personal data is the requester actually seeking?
  2. Separate legal questions from data requests: If the request asks "under what lawful basis do you process my data?", that's transparency information you must provide. If it asks "is your processing compliant with the principle of data minimisation?", that's a legal opinion you're not obligated to render.
  3. Contact the requester within 5 business days: Propose a focused scope that meets Article 15 obligations without processing irrelevant data categories.

Consider a request that includes: "Please provide all personal data you hold about me, including but not limited to: IP addresses, cookie identifiers, inferred characteristics, behavioural analytics, third-party data appends, algorithmic profiling outputs, and any data obtained from data brokers."

Your clarification response: "To respond efficiently, please confirm which of our services you've used and the approximate timeframe. We don't purchase data from data brokers or perform algorithmic profiling. We do process IP addresses and cookie identifiers for users of [specific service]. Shall we focus on that service, or are you aware of other interactions with our organisation?"

Collection and Review Workflow

If you're still manually collecting data from individual systems and redacting PDFs one by one, your process will break under volume pressure.

Centralised collection: Implement a request management system that can query multiple data stores from a single interface. You need technical measures that let you execute a DSAR without emailing twelve department heads.

Automated redaction for third-party data: Train your team to identify third-party personal data (data about individuals other than the requester) that must be redacted under Article 15(4). Use tools that can flag names, email addresses, and employee identifiers rather than manual review of every page.

Response templates for standard categories: Build pre-written explanations for your most common processing activities (account management, marketing preferences, customer support interactions). Don't re-draft transparency information for each request.

Common Pitfalls

Over-interpreting the request

An AI-generated request might ask for "all algorithmic decision-making processes that affect me". If you don't use automated decision-making under Article 22, say so clearly. Don't interpret this as requiring a technical explanation of every software function that touches customer data.

Treating AI-generated requests as inherently excessive

The fact that a request was drafted with AI assistance doesn't make it excessive under Article 12(5). The test is whether the request is manifestly unfounded or excessive in character, particularly if repetitive. A first-time requester using template language still gets a full response.

Failing to verify identity

AI tools make it easy to submit requests on behalf of others. If you receive a request through a web form with language that seems copied from a template, verify the requester's identity before disclosing data. Article 12(6) permits you to request additional information necessary to confirm identity.

Ignoring pattern analysis

If you receive 15 identical requests in one week, all using the same AI-generated template, that's a signal. It might indicate a privacy campaign, a legal claim in preparation, or a competitor's research effort. Flag these for your DPO and legal team, not just your DSAR queue.

Quick Reference Table

Scenario Article Your Response Timeline
Request covers "all personal data" without specifics Art. 12(5) Request clarification to identify data subject and narrow scope Within 5 business days of receipt
Request asks for legal opinion on compliance Art. 15(1)-(3) Provide required transparency information; decline to opine on compliance Standard response window
Identical requests from multiple individuals Art. 12(5) Assess if manifestly unfounded or excessive; document pattern Before responding to any
Request includes non-personal data (company policies, general procedures) Art. 15 scope Clarify that GDPR covers personal data only; offer to respond to FOI if applicable Within initial response
Unable to verify requester identity Art. 12(6) Request additional information; pause disclosure until verified Pause clock until verification
Request is second identical submission within 3 months Art. 12(5) May refuse or charge reasonable fee if manifestly excessive due to repetitive character Within 1 month, with explanation

Processing time: One month from receipt of a valid request with verified identity. Extendable by two months if complex (Article 12(3)), but you must inform the requester of the extension and reasons within the first month.

Fee authority: You may charge a reasonable fee for manifestly unfounded or excessive requests, or for additional copies beyond the first (Article 12(5)). Document your reasoning with reference to request characteristics, not the fact that AI was used.

Redaction obligation: You must redact third-party personal data unless those individuals have consented to disclosure or disclosure is otherwise lawful (Article 15(4)). This applies regardless of how the request was generated.

Your workflow needs to handle requests that are technically perfect but operationally challenging. The solution isn't to resist AI-generated requests, it's to build processes that can scale with them.

You Might Also Like