Scope - What This Guide Covers
This guide tackles the operational challenge of managing data subject access requests (DSARs) and Freedom of Information (FOI) requests enhanced by large language models. You'll find specific workflow adjustments, process controls, and technical considerations for handling requests that are longer, broader, and more technically precise than traditional submissions.
This guide doesn't cover the legal validity of AI-generated requests (they're valid under Article 15 GDPR if submitted by or on behalf of the data subject) or basic DSAR response obligations. It assumes you're already familiar with the one-month response window under Article 12(3) and the information categories required under Article 15.
Key Concepts and Definitions
AI-generated request: A DSAR or FOI request drafted, expanded, or refined using large language models like ChatGPT or Claude. These requests often include precise legal citations, multi-part questions, and exhaustive category lists that mirror template language rather than natural human phrasing.
Request complexity creep: The phenomenon where AI tools enable requesters to submit technically perfect requests covering maximum permissible scope, even when the requester wouldn't naturally know to ask for specific log types or processing categories.
Interpretation burden: The additional time required to parse requests that use broad categorical language ("all personal data relating to me") versus specific, actionable requests ("my account creation date and email address").
Requirements Breakdown
Article 15 Obligations Remain Unchanged
Your legal obligations haven't shifted. You must still:
- Confirm whether you're processing the requester's personal data (Article 15(1))
- Provide a copy of the data undergoing processing (Article 15(3))
- Supply transparency information (processing purposes, categories, recipients, retention periods, source if not collected from the data subject)
- Respond within one month, extendable by two months for complex requests under Article 12(3)
What's Changed: Volume and Scope Pressure
Lincolnshire County Council received almost 2,000 FOI requests in the last financial year, an increase of 18% compared to the previous year. While this statistic covers FOI rather than DSARs, the pattern holds: AI tools lower the friction for submitting requests.
More significantly, AI-generated requests tend to:
- Include every possible data category mentioned in your privacy notice
- Reference specific GDPR articles and recitals
- Demand explanations that go beyond Article 15's requirements
- Combine multiple request types (access, rectification, explanation of automated decision-making)
Implementation Guidance
Triage at Intake
Build a two-tier classification system at the point of receipt:
Tier 1 - Bounded requests: The requester identifies specific systems, timeframes, or data categories. Route these to standard workflow.
Tier 2 - Maximalist requests: The request uses categorical language covering all processing activities or mirrors privacy notice structure. Flag for scope clarification before beginning collection.
For Tier 2 requests, you're entitled under Article 12(5) to request additional information to identify the data subject. Extend this principle: if the request is "manifestly unfounded or excessive", particularly because of its repetitive character, you may charge a reasonable fee or refuse to act. Document your reasoning.
Scope Clarification Protocol
Don't assume you must respond to every sub-clause in a 12-paragraph AI-generated request. Instead:
- Identify the core request: What personal data is the requester actually seeking?
- Separate legal questions from data requests: If the request asks "under what lawful basis do you process my data?", that's transparency information you must provide. If it asks "is your processing compliant with the principle of data minimisation?", that's a legal opinion you're not obligated to render.
- Contact the requester within 5 business days: Propose a focused scope that meets Article 15 obligations without processing irrelevant data categories.
Consider a request that includes: "Please provide all personal data you hold about me, including but not limited to: IP addresses, cookie identifiers, inferred characteristics, behavioural analytics, third-party data appends, algorithmic profiling outputs, and any data obtained from data brokers."
Your clarification response: "To respond efficiently, please confirm which of our services you've used and the approximate timeframe. We don't purchase data from data brokers or perform algorithmic profiling. We do process IP addresses and cookie identifiers for users of [specific service]. Shall we focus on that service, or are you aware of other interactions with our organisation?"
Collection and Review Workflow
If you're still manually collecting data from individual systems and redacting PDFs one by one, your process will break under volume pressure.
Centralised collection: Implement a request management system that can query multiple data stores from a single interface. You need technical measures that let you execute a DSAR without emailing twelve department heads.
Automated redaction for third-party data: Train your team to identify third-party personal data (data about individuals other than the requester) that must be redacted under Article 15(4). Use tools that can flag names, email addresses, and employee identifiers rather than manual review of every page.
Response templates for standard categories: Build pre-written explanations for your most common processing activities (account management, marketing preferences, customer support interactions). Don't re-draft transparency information for each request.
Common Pitfalls
Over-interpreting the request
An AI-generated request might ask for "all algorithmic decision-making processes that affect me". If you don't use automated decision-making under Article 22, say so clearly. Don't interpret this as requiring a technical explanation of every software function that touches customer data.
Treating AI-generated requests as inherently excessive
The fact that a request was drafted with AI assistance doesn't make it excessive under Article 12(5). The test is whether the request is manifestly unfounded or excessive in character, particularly if repetitive. A first-time requester using template language still gets a full response.
Failing to verify identity
AI tools make it easy to submit requests on behalf of others. If you receive a request through a web form with language that seems copied from a template, verify the requester's identity before disclosing data. Article 12(6) permits you to request additional information necessary to confirm identity.
Ignoring pattern analysis
If you receive 15 identical requests in one week, all using the same AI-generated template, that's a signal. It might indicate a privacy campaign, a legal claim in preparation, or a competitor's research effort. Flag these for your DPO and legal team, not just your DSAR queue.
Quick Reference Table
| Scenario | Article | Your Response | Timeline |
|---|---|---|---|
| Request covers "all personal data" without specifics | Art. 12(5) | Request clarification to identify data subject and narrow scope | Within 5 business days of receipt |
| Request asks for legal opinion on compliance | Art. 15(1)-(3) | Provide required transparency information; decline to opine on compliance | Standard response window |
| Identical requests from multiple individuals | Art. 12(5) | Assess if manifestly unfounded or excessive; document pattern | Before responding to any |
| Request includes non-personal data (company policies, general procedures) | Art. 15 scope | Clarify that GDPR covers personal data only; offer to respond to FOI if applicable | Within initial response |
| Unable to verify requester identity | Art. 12(6) | Request additional information; pause disclosure until verified | Pause clock until verification |
| Request is second identical submission within 3 months | Art. 12(5) | May refuse or charge reasonable fee if manifestly excessive due to repetitive character | Within 1 month, with explanation |
Processing time: One month from receipt of a valid request with verified identity. Extendable by two months if complex (Article 12(3)), but you must inform the requester of the extension and reasons within the first month.
Fee authority: You may charge a reasonable fee for manifestly unfounded or excessive requests, or for additional copies beyond the first (Article 12(5)). Document your reasoning with reference to request characteristics, not the fact that AI was used.
Redaction obligation: You must redact third-party personal data unless those individuals have consented to disclosure or disclosure is otherwise lawful (Article 15(4)). This applies regardless of how the request was generated.
Your workflow needs to handle requests that are technically perfect but operationally challenging. The solution isn't to resist AI-generated requests, it's to build processes that can scale with them.



