Artificial intelligence may be about to fundamentally change the economics of the Subject Access Request.
Until recently, submitting a complex Subject Access Request required time, knowledge and effort from the individual making it.
Generative AI changes that.
An individual can now use an AI assistant to help formulate a detailed request, identify categories of personal data they might want, draft follow-up correspondence and challenge aspects of an organisation’s response.
That creates an interesting imbalance.
The cost of creating a sophisticated DSAR could be falling, while the cost of responding to one remains significant.
For Data Protection Officers, HR teams and organisations already struggling with DSAR volumes, that should prompt an important question:
What happens when generating a 2,000-word Subject Access Request takes someone minutes, but responding to it potentially takes an organisation weeks?
It isn’t a theoretical issue.
In May 2026, the Information Commissioner’s Office (ICO) published guidance after public authorities reported increasing volumes and complexity of AI-generated Freedom of Information requests, including requests requiring clarification and requests incorrectly interpreting legislation. While the ICO guidance relates to FOI rather than Subject Access Requests, the operational parallels for privacy teams are difficult to ignore.
For organisations handling DSARs, AI may be the next major operational challenge.
There is nothing inherently wrong with using AI to help exercise a data protection right.
Accessibility may, in fact, be one of AI’s greatest benefits.
The ICO confirms that individuals do not need to follow a particular format when making a Subject Access Request. A SAR can be made verbally or in writing, including through social media, and an organisation normally has one month to respond.
AI can make understanding and exercising those rights easier.
A person who previously might have written:
“Can I have the information you hold about me?”
can now use AI to create something significantly more sophisticated.
That could include requests covering emails, HR records, internal messages, call recordings, CRM records, CCTV and other information distributed throughout an organisation.
And generating that request costs the requester almost nothing.
Processing it is a different matter.
It is tempting to view increasingly sophisticated DSARs as a correspondence problem.
They aren’t.
They’re an information governance problem.
An organisation receiving a broad employee DSAR may potentially need to locate information across:
Finding information is only the beginning.
Someone then needs to establish whether the material contains the individual’s personal data, identify third-party information, consider exemptions, carry out redactions, maintain records of decisions and prepare the final disclosure.
AI can make generating the request easier.
It does not magically make the organisation’s underlying information easier to find.
That distinction matters.
There is, however, an important counterbalance.
The UK’s DSAR rules have evolved following the Data (Use and Access) Act 2025, and the ICO’s subject access guidance was most recently updated on 16 July 2026.
One particularly important concept is reasonable and proportionate searches.
The ICO states that organisations must make a reasonable and proportionate search for the information requested.
For privacy teams, those words are extremely important.
It means effective DSAR management should not simply become:
Request received → search absolutely everything → review absolutely everything.
Instead, organisations need a defensible methodology for deciding what should be searched and why.
That requires expertise rather than just software.
For years, operational DSAR conversations have focused on questions such as:
“Did we find everything?”
The more useful question in 2026 may increasingly be:
“Can we demonstrate why the searches we conducted were reasonable and proportionate?”
That is a subtle but important difference.
Consider an employee requesting “all emails mentioning me”.
Potentially searching every mailbox, archive and collaboration environment across a large organisation could return enormous amounts of information.
A mature DSAR process should therefore consider matters such as:
That is where DSAR governance becomes as important as DSAR technology.
There is another change organisations shouldn’t overlook.
From 19 June 2026, organisations handling personal information came under new statutory requirements concerning data protection complaints.
The ICO says organisations must provide people with a way to make data protection complaints, acknowledge complaints within 30 days, take appropriate steps to respond and communicate the outcome without undue delay.
And DSARs are expressly relevant: the ICO identifies complaints relating to Subject Access Requests as one example of the data protection matters organisations may need to address.
This creates a potentially important combination:
AI-assisted DSAR → organisational response → AI-assisted scrutiny of the response → data protection complaint
Organisations therefore need to think beyond simply getting the disclosure out before the deadline.
Quality matters.
Documentation matters.
And the ability to explain the decisions taken during the DSAR matters.
Possibly.
But blaming AI would miss the point.
AI may simply expose weaknesses that already existed.
An organisation with mature records management, sensible retention periods, clearly defined Microsoft 365 environments and established DSAR procedures should invariably be better placed to respond than one relying on individuals manually searching years of email.
The uncomfortable question for many organisations is therefore not:
“What happens if people start using AI for DSARs?”
It is:
“Why does a single DSAR consume so much internal resource in the first place?”
The answer is often fragmented data, unclear ownership, inconsistent processes and limited specialist capacity.
A request does not need to contain the words “Subject Access Request” or “DSAR”. The ICO confirms requests can be made verbally or in writing, including via social media.
Front-line teams therefore need to know what to identify and where to escalate it.
Your privacy notice or ROPA may tell you what you process.
That does not necessarily tell your DSAR team where to search for it.
Mapping systems, custodians and data sources can dramatically improve response efficiency.
A defensible DSAR is not simply the product of clicking “search”.
Record the systems, custodians, keywords, date ranges and rationale behind the searches undertaken.
This is particularly important following the 2026 changes.
The ICO says there are no exemptions from the requirement to have a process for handling data protection complaints.
Privacy operations should therefore consider the complete lifecycle from request → response → challenge → complaint.
Most businesses do not need ten DSAR specialists permanently sitting in-house.
The problem arises when several complex requests land simultaneously, particularly during employee disputes, restructures or other contentious situations.
That is where an outsourced DSAR model can provide additional capacity without requiring permanent headcount.
The obvious response to increasing DSAR volumes is automation.
Technology absolutely has a role.
eDiscovery platforms can dramatically improve how organisations search, deduplicate, review and manage large datasets.
But a DSAR involves judgement.
Technology cannot remove the need to determine appropriate scope, assess personal data, consider third-party rights, apply exemptions, decide what searches are reasonable and proportionate, and maintain a defensible record of how those decisions were reached.
The strongest DSAR operating model combines technology, process and experienced human judgement.
An effective DPO should not simply appear at the end of the process when a difficult DSAR is already overdue.
Whether the role is internal or delivered through DPO as a Service, organisations increasingly need someone who can connect privacy law with operational reality.
That includes helping the organisation build:
A good DPO therefore doesn’t just help organisations respond to DSARs.
They help organisations become easier to subject-access in the first place.
And as AI makes exercising privacy rights progressively easier, that distinction may become increasingly valuable.
AI is usually discussed as something organisations themselves are deploying.
Privacy professionals consequently spend significant time thinking about DPIAs, transparency, automated decision-making and AI governance.
But there is another side to the story.
Your customers and employees have AI too.
They can use it to understand their rights, formulate requests, scrutinise answers and potentially challenge organisations at a scale and sophistication that previously required specialist knowledge.
That isn’t something businesses should fear.
But it is something they should prepare for.
Because the organisations best equipped for the next generation of DSARs won’t necessarily be those with the most expensive software.
They’ll be the ones that understand their data.
GRC Hub provides specialist DSAR support, helping organisations manage everything from search and scoping through to review, redaction and disclosure.
We also provide DPO as a Service, giving organisations access to ongoing senior data protection expertise without the cost of building a full in-house privacy function.
If one complex DSAR can consume days or weeks of internal resource, it may be time to rethink your operating model.
Speak to GRC Hub about your DSAR or DPO requirements.