Swamped by DSARs?
Why DSARs and other GDPR rights requests are getting harder — and how organisations should prepare
Data subject access requests (DSARs) are not new, they remain the most common individual rights request but they are no longer the only type of request that organisations need to be ready for.
With the Data (Use and Access) Act 2025 (DUAA), updated ICO guidance, and the increasing use of AI tools by requesters, organisations need to be ready to handle DSARs and wider GDPR rights requests with more discipline, better scoping and stronger audit trails.
We have explored in this article, some of the areas that we know from experience are causing increased anxiety, resource burden and costs, for organisations both large and small. This includes how DSARs are evolving and becoming harder to deal with, changes under DUAA, how to deal with AI generated DSARs, handling some of the trickier types of DSARs, considering when to push back on a DSAR, how to best prepare for DSARs now, and of course, how Pritchetts Law can help.
DSARs remain the main pressure point but other rights requests are increasing in sophistication too
Many organisations are seeing an increase not only in the number of DSARs and other rights requests received, but also in their complexity.
DSARs are still the rights request most organisations are likely to receive, and often the one that creates the greatest operational burden. However, requests are also becoming more frequent for rectification, erasure, restriction, objection, portability and about use of automated decision-making/ ADM processes (including in relation to profiling and use of AI). Increasingly, these rights are not raised separately and neatly. They may be bundled into a single complaint, grievance, customer challenge or AI-generated letter. Many organisations are underprepared to handle DSARs let alone wider requests.
Requests continue to arrive in highly pressurised circumstances, often in the context of employment disputes, customer complaints, threatened litigation, internal investigations or wider breakdowns in trust.
They may ask for “everything”, name multiple complex systems and data sets, seek communications between particular individuals, and target an organisation’s decision-making processes rather than simply asking for a copy of personal data. Often we see DSARs which contain all of these.
Requesters are increasingly using AI tools to help draft DSARs and wider rights requests. That can produce requests which are longer, broader but also often more tightly legally framed, than would previously have been expected. Some are increasingly well-structured and legitimate requests, which on their face, appear reasonable. Others read more like detailed disclosure requests, litigation tactics, or fishing expeditions dressed up as privacy rights.
The ICO has already recognised the issue of AI-generated requests increasing in the context of Freedom of Information (FOI) requests, and has published guidance for public authorities on handling AI-generated FOI requests. It has also indicated that guidance on AI and DSARs is expected in Winter 2026. While FOI and DSARs are from different legislative regimes, some themes are likely to carry across to the ICO’s expected new guidance on DSARs. AI can increase request volumes, make requests appear more legally sophisticated, and generate broad or bundled requests that require careful triage rather than a knee-jerk response. It is important to understand that the AI assisted rights requests are not invalid simply because AI may have been used. They can of course be wrong, though, just like humans!
The starting point is simple but fundamental: the right of access is a right to personal data, not a general disclosure exercise. A requester may have asked for whole documents, metadata, drafts, Teams messages, audit logs or “all communications”, but the organisation still needs to identify what actual ‘personal data’ is in scope and what it is legally required to provide under the applicable UK data protection legislation (itself an increasingly tricky patchwork of laws, including both the UK GDPR and others).
The challenge for organisations is to avoid two equal and opposite mistakes: over-reacting by conducting an uncontrolled, costly search across every possible data source, or under-reacting by dismissing a difficult request as unreasonable without properly analysing what the individual is entitled to receive. We have provided a few tips on helping find a balance with this below.
Need help with a complex request? See our DSAR and data subject rights support or contact us if you are dealing with a time-sensitive DSAR, bundled rights request or AI-generated complaint.
Reasonable and proportionate searches and changes under the DUAA and ICO guidance
DUAA did not remove the right of access that already existed under the data protection legislation. Subject to various caveats and exemptions, individuals still have a fundamental right to obtain confirmation of whether their personal data is being processed, a copy of that personal data, and related information about how it is used.
The DUAA and the ICO’s updated subject access guidance, have sharpened some important practical and compliance points. Organisations must respond without undue delay and, in most cases, within one month. They may extend the time limit by up to a further two months where reasonably necessary and justified e.g., for complex or multiple requests. They may also ask for clarifications where reasonably required in relation to aspects of the request, identity of the DSAR requester or authorised third party acting on their behalf, and may pause the response period while waiting for appropriate clarifications.
Most importantly for difficult DSARs, the ICO guidance on finding and retrieving relevant information now makes clear that organisations must carry out a reasonable and proportionate search. That is certainly not a licence to do the bare minimum. It is a reminder that a DSAR response should be scoped, evidenced and defensible, rather than limitless. While it may be possible to use this to push back on certain aspects of requests made where appropriate, it is increasingly important for organisations to keep clear records to demonstrate its search methodology, DSAR handling approach and ultimate responses.
DUAA also introduced new requirements in relation to data protection complaints. The ICO’s data protection complaints guidance says organisations must have a process for handling data protection complaints, give people a way to complain, acknowledge complaints within 30 days (not 1 month), take appropriate steps to investigate and respond without undue delay, keep people informed, and tell them the outcome. In practice, this means DSAR governance should also now link clearly with the organisation’s wider complaints processes. If a requester challenges the way a DSAR has been handled, for example, because they think searches were too narrow, exemptions were wrongly applied, third-party data was over-redacted or the response was late etc., the organisation should be ready to investigate and explain its position before matters escalate to the ICO or beyond.
Why AI-generated rights requests may require stronger triage, scoping and search/ response discipline
AI-generated rights requests can look authoritative. They may combine a DSAR with other rights requests.
They may also refer to legislation, exemptions, deadlines, categories of data, metadata, every conceivable repository, communications and even inferred data. That does not always mean that each part of a request made is clear, valid, proportionate or capable of being answered in the way requested. A request may also ask for information, that is not personal data, and is therefore not required to be provided in response to a DSAR.
The right approach is not necessarily to argue with the AI-generated wording, but to translate the request into a workable scope and be clear in setting out to the requester what you are going to search and provide, which you believe they are entitled to.
This means that you will need to carefully consider issues such as: which right or rights are being exercised, what personal data is being requested, where it is likely to be held, what period is relevant, which individuals (or data custodians) are likely to be involved, which systems are most likely to contain relevant material, and what exemptions, redactions or other statutory requirements may need to be considered.
AI-generated DSARs can also create false confidence. They may sound precise and legally sophisticated but still misunderstand the limits of the right of access. Organisations should not be intimidated by the breadth of the drafting; they should analyse the request against the actual legal requirements, and ideally their own documented processes.
The practical response should not be to treat AI-assisted requests as invalid. Requesters have long used technology and publicly available information to help compile their requests, for many AI has made the process quicker and easier.
Organisations should instead, apply a structured process, which ideally is in place in advance, to: identify the right being exercised, clarify where genuinely needed, assess proportionality, record decisions and respond clearly. That approach should help organisations deal fairly with genuine requests made by individuals who choose to use AI to help them, while also managing the resource impact of potentially very broad, technical or bundled requests.
Where a request is genuinely unclear or too broad to respond to effectively, organisations should consider seeking clarification promptly. That should be framed carefully: the aim is to help identify the information requested, not to discourage the individual from exercising their rights.
Organisations should keep this area under review. As mentioned above, the ICO has said it intends to publish guidance soon on AI and DSARs. Organisations should expect that future guidance to place continued emphasis on clarity, proportionality, record-keeping and fair treatment of requesters.
Preparing your teams for requests? Our tailored data protection training can help staff understand data protection compliance obligations, and to recognise, escalate and support DSAR handling before a difficult request lands.
The difficult DSAR and rights request scenarios we are seeing
We are seeing both an increase in rights requests generally, and an increase in the complexity of those requests. The main takeaway is that they are all different, making it impossible to take a one-size-fits-all approach. We’ve set out a flavour below of the different scenarios that organisations are encountering:
- Litigation-linked DSARs: requests made before, during or after a dispute, where the individual may be seeking documents, leverage or insight into the organisation’s internal thinking. The DSAR should still be handled as a data protection rights request in its own right, alongside the wider dispute strategy. This creates tension between the litigation process, and the tight deadlines for DSAR responses.
- Employee DSARs: requests involving HR files, grievance material, disciplinary records, Teams messages, emails and manager communications. Where the DSAR overlaps with a grievance, disciplinary process or threatened claim, it should be managed objectively and separately from the underlying employment process where appropriate. Potential conflicts of interest should be anticipated and managed. Often it is senior managers who are involved in the HR issue, and those same individuals are likely to be responsible at some level for handling data protection issues.
- AI-generated broad requests: long requests which list extensive categories of systems and data, sometimes without a clear link to what the individual is actually seeking.
- Third-party data issues: documents which contain not just the requester’s personal data, but also information about colleagues, customers, witnesses or other individuals. This needs to be carefully considered to determine what third-party data it is reasonable in the circumstances to disclose or redact/ withhold.
- Privilege and legal advice: requests which capture communications with lawyers, litigation strategy or privileged advice.
- Manifestly unfounded or excessive requests: repeat, tactical or disproportionate requests, or more usually specific parts of requests, where refusal to comply (or charging a fee) may be considered, but only after careful assessment, justification and documentation of the approach.
- Search methodology disputes: challenges about whether the organisation has appropriately searched the right systems, used the right keywords, identified the right data custodians or properly recorded and justified decisions made.
- Bundled rights requests: requests which combine access, erasure, rectification, objection or restriction rights, sometimes without distinguishing between the different legal tests that apply.
- Automated decision-making and AI-related objections: requests which ask whether AI, profiling or automated decision-making has been used, or which object to certain processing without clearly identifying the processing being challenged.
Practical steps for handling a tricky DSAR or wider rights request
For most organisations, the key is to be ready. That means having systems, processes, and training in place to support staff when the time comes.
It will be important to move quickly from inevitable panic when the DSAR lands (usually on a Friday evening before a public holiday!) into a clear process.
1. Recognition
Recognition is part of readiness. A valid request does not need to mention “DSAR” or other specific named rights requests, nor does it have to be sent on a special form or directly to the CEO, legal or data protection team etc. As it could be received by anyone at your organisation, your staff should know how to spot and escalate requests made through ordinary business channels, including complaints, emails, customer service or social media interactions, HR correspondence and chat messages.
Training, and appropriate systems and processes will help hugely.
2. Triage
Key triage issues to consider:
- Identify which rights are being exercised.
- Verify requester identity (and where relevant, authorised third party acting on their behalf).
- Record the relevant deadlines.
- Identify connected issues (is there a complaint, HR issue, ongoing litigation, or any potential for these?).
- Ensure potentially relevant material is preserved.
- Decide who needs to be involved internally and externally to support the handling of the rights request and response.
3. Understand the Scope
The next step is to properly consider the scope of the request.
What is the request actually asking for? Is clarification reasonably required to allow you to respond to any or all of the requests? Is the period too wide? Are there obvious priority systems to search, such as HR platforms, document management systems, CRM records, support tickets, SharePoint locations, email accounts or messaging tools including WhatsApp, Teams etc.?
A documented scoping decision can be just as important as the searches themselves. It can also be reflected in a carefully drafted initial acknowledgement response to requesters, often helping to clarify, the intended scope of reasonable and proportionate searches at an early stage.
4. Search Methodology
Search methodology should be treated as a compliance decision, not an IT afterthought. Organisations should carefully record the systems searched, data custodians considered, keywords used, date ranges applied, exclusions made, and reasons why any further searches would be unreasonable or disproportionate.
One of the most effective ways to reduce the pressure of a difficult DSAR is to understand your own systems before a request arrives. Organisations should know where personal data is likely to be held, who controls those systems, how searches can be run, and what search limitations exist.
You should understand whether work-related data could be being created or stored outside approved business systems. This includes practical risk areas such as personal data being stored on personal phones, WhatsApp or other personal messaging apps, local downloads, unmanaged cloud storage and personal email accounts used for work purposes.
Tightening data retention policies (and wider records management practices), acceptable-use policies and bring-your-own-device (BYOD) policies and technical controls, can materially reduce the volume of data to be searched, reviewed, potentially redacted and securely disclosed.
Organisations should take sensible steps to make sure potentially relevant information is not deleted, overwritten or altered while the request is being handled. That does not mean normal retention arrangements can never continue, but there should be a clear pause or escalation process where deletion could affect information potentially relevant to the request. This is particularly important where data may sit in email accounts, Teams or chat messages, personal devices, WhatsApp, shared drives, local downloads or other less controlled locations. This is not just good housekeeping: deliberately altering, defacing, blocking, erasing, destroying or concealing information with the intention of preventing disclosure can create serious regulatory and criminal risk.
5. Control the process
Finally, review and disclosure should be carefully controlled. Personal data needs to be identified accurately. Third-party information should be carefully assessed in line with specific requirements under the data protection legislation, rather than automatically disclosed or withheld/redacted. Any exemptions (such as legal professional privilege) should be considered carefully, and justified, recorded, and applied on a case-by-case basis. Responses to requesters should explain the search methodology and response outcomes clearly.
Want practical tools rather than theory? We can help develop individual rights handling guidelines, template requester response letters, compliance checklists and registers, as part of our data subject rights support. You can also see examples of our work in our rights handling case studies.
When can an organisation push back?
Organisations do not, for example, have to accept every DSAR at face value. You can ask for clarification where it is reasonably required and justified. You can take a reasonable and proportionate approach to searches. You can withhold information where an appropriate exemption applies under the data protection legislation.
In some limited cases, you may even be able to refuse to comply with a request, or charge a reasonable fee, if the organisation can justify that the request is manifestly unfounded or excessive. These are not shortcuts, though. The threshold for refusing a request is high, and the organisation must be able to justify its decision. A request is not excessive simply because it is inconvenient, broad, will take too much resource, or made in a dispute. The safer approach is usually to appropriately narrow the request, then evidence and explain the response rather than treat the request as invalid.
The lawful way to reduce burden is not to obstruct. It is to triage early, scope carefully, search proportionately, apply exemptions properly, and keep a clear record of your reasoning for each decision. Better yet, make sure you have planned ahead!
Need wider staff awareness? Our general data protection training courses help build the baseline knowledge needed to identify and escalate rights requests across the organisation.
What should organisations do now?
Organisations that have not refreshed their DSAR and individual rights procedures recently should review them now. Any guidance issued should cover more than just DSARs. It should also help staff to manage requests for rectification, erasure, restriction, objection, portability and issues relating to automated decision-making (including in relation to profiling and the use of AI). The guidance should contemplate when requests overlap or are made as part of a wider complaint or dispute.
Effective guidance usually needs more than a policy statement. In particular, you should check whether your processes deal properly with issues such as:
- AI-generated broad or very technical requests.
- Bundled and wide rights requests.
- Initial acknowledgements and clarifications around scope, verification etc.
- Response deadline management and registers.
- How to carry out reasonable and proportionate searches.
- Handling third-party personal data, checklists to help consider relevant factors and ways to record decisions made.
- Escalation points for and application of legal and litigation privilege, and other relevant exemptions under the data protection legislation.
- Data protection complaints handling.
- Template acknowledgement and response letters/ reports for different stages of the process.
- Registers for recording key decisions, search methodologies, timelines, redactions, exemptions applied and communications with the requester.
You should also keep an eye out for the ICO’s anticipated DSAR-specific AI guidance, and be ready to further update your internal guidance, training and template responses once that has been published.
You should also test whether your processes work in practice. Can staff recognise a DSAR when it arrives in a complaint, email, chat message or social-media post? Can the organisation identify the right systems to search quickly? Is there a clear owner/ data custodian to approach for help or someone to carry out searches? Are searches appropriately carried out and recorded? Are redaction decisions documented and carried out with the right technical expertise? Are your response letters clear enough to withstand scrutiny from the requester, the ICO or a court?
Readiness to handle these requests also depends on having enough trained people to understand data protection compliance responsibilities and to resource the response. DSAR deadlines are short, and it is difficult to upskill staff only once a difficult request has already arrived. Training a wider group of staff to recognise these individual rights requests, understand the key risks and support searches, reviews and escalation can make the process much more resilient.
Privacy notices matter. A DSAR response must include specified supplementary information about how the organisation processes personal data. If your privacy notices are out of date, or do not reflect actual processing practices, you can find yourself having to fix wider transparency issues under pressure in order to provide additional supplementary information. Lack of transparency in something basic like your privacy notice, may sign-post wider data protection compliance issues – which could be scrutinised as part of a complaint, or ICO intervention.
Good records management and proportionate retention periods, that are applied consistently, can often also reduce the complexity, volume and risk of DSAR handling when a request is received.
While having robust processes in place helps ahead of time, tricky DSARs are rarely solved by processes and templates alone. They need judgement, proportionality and a defensible record of how the organisation reached particular decisions in relation to a specific DSAR. In practice, organisations that are best placed to manage difficult DSARs are those that treat them as an operational risk issue, as well as a legal compliance task.
How Pritchetts can help
We regularly help organisations to respond to complex DSARs and wider individual rights requests, including requests involving disputes, employment issues, high-volumes of information, third-party personal data, redaction, legal privilege, reputational harm, and regulatory risk.
We also help clients build the wider procedures, response templates and internal governance processes that are needed to handle difficult requests well.
If your organisation is dealing with a difficult DSAR, needs to update its individual rights handling processes, or needs staff training so requests can be recognised and managed more confidently, please contact us. You can also read more about our DSAR and individual rights support through our case studies.