top of page

AI-Generated Subject Access Requests Are on the Rise. Is Your Organisation Ready?

  • fabiodocarmoesouza7
  • Jul 1
  • 2 min read

Updated: 2 days ago

If your organisation handles Subject Access Requests, you may have noticed something changing. Over recent months, we've seen an increase in requests that appear to have been drafted using AI.


A robot touching a keyboard

They are often well-written, professionally structured, and reference everything from audit

trails and metadata to system logs, legal holds, digital footprints, and details of every person

who has accessed a record.


At first glance, they can look intimidating. Many of these requests are using the same generic legal jargon and don't necessarily reflect what the individual is actually trying to obtain. This creates a challenge for organisations. Teams can feel pressured to search for every system they have access to, even when the request is extremely broad or lacks sufficient detail to identify the information the individual really needs.


We've seen examples where someone simply wanted records relating to a recent episode of

care or information for an ongoing legal matter, but the request asked for every record held,

dating back many years. Responding without clarification could mean producing a huge volumeof information that isn't useful to the requester while significantly increasing the work involved for the organisation.


Thats why its becoming increasingly important for organisations to have a robust Subject Access Request process. Your team should understand when a request is clear enough to begin searching and when it's appropriate to go back to the requester to seek clarification.


A conversation at the start of the process can often save hours of unnecessary work and help ensure the individual receives information that is genuinely relevant to them.

It's equally important that staff understand the difference between information that falls within the scope of a Subject Access Request and information that may not. Just because an AI-generated template asks for metadata, technical logs or every audit trail available doesnt

automatically mean it must be disclosed. Each request still needs to be assessed against the

UK GDPR, the Data Protection Act 2018 and any applicable exemptions.


As AI becomes more accessible, we expect these requests to become even more common.

Organisations that rely on outdated procedures or provide little staff training are likely to findthem increasingly difficult to manage.


Now is a good time to review your Subject Access Request procedure. If it does not explain how to deal with overly broad requests, cover seeking clarification where appropriate, or give staff confidence in assessing what falls within scope, update it now.


AI isnt changing peoples rights, but it is changing the way many Subject Access Requests are

being written. Review your procedures and training now so your organisation can respond

consistently, efficiently and in line with the law.

If youre questioning whether your current process is fit for purpose, dont wait until a

challenging request exposes the gaps. We regularly help organisations assess, refine and

strengthen their procedures. From policy reviews to practical staff training, small changes can have a significant impact—making complex requests easier to handle, reducing risk and

improving compliance. Get in touch to discuss how we can help.



 
 
 

Comments


bottom of page