When Subject Access Requests Become Part of the Dispute: Are Organisations Ready for AI-Assisted SARs?
Subject Access Requests (SARs) have always had the potential to be challenging.
They frequently arise when something has already gone wrong: an employment dispute, a complaint about treatment, a breakdown in a relationship with an organisation, concerns about a decision or potential legal proceedings.
What is changing is how easy it has become for an individual to produce a highly detailed request.
With readily available generative AI tools, someone with little or no knowledge of data protection law can produce, within seconds, a lengthy SAR referring to Article 15 of the UK GDPR, multiple systems, internal communications, named employees, search terms, audit trails, meeting notes and specific categories of information.
The same tools can then be used to review the response, identify potential gaps and draft a challenge or complaint.
For organisations, particularly those operating in the health and care sector, this raises an important question: are our SAR processes prepared for increasingly sophisticated requests, particularly when the SAR forms part of a wider dispute?
Has AI changed the SAR?
Legally, no. The right remains the same.
An individual is entitled to confirmation as to whether their personal information is being processed, access to that personal information and the supplementary information required under Article 15.
The ICO’s current guidance is clear about those basic principles. A SAR can be made verbally or in writing and does not require any particular form of words. Organisations will normally need to respond without undue delay and within one month.
What AI potentially changes is not the right itself, but the individual’s ability to formulate and pursue the request.
Consider the difference between: “Please provide the information you hold about me” and a multi-page request asking an organisation to search the mailboxes of 15 employees, Teams messages, meeting minutes, handwritten notes, call recordings, audit logs, deleted items and communications containing a list of specified search terms over several years.
The second request may look as though it has been prepared by a specialist. Increasingly, it may simply have been generated following a short conversation with an AI tool.
That does not make the request invalid. But neither does the level of detail in the request automatically determine how the organisation must conduct its searches.
That distinction is important.
When a SAR becomes part of a wider dispute
As a data protection consultant, one of the more difficult situations I see is where the SAR cannot realistically be separated from a wider dispute.
In healthcare, for example, a patient may be dissatisfied with their treatment or with the handling of a complaint. They may want to understand not only what appears in their clinical record, but what was said internally about them, who was involved in particular decisions and why those decisions were made.
Similarly, a member of staff may submit a SAR during an employment dispute or grievance.
The request may therefore be one part of a much wider disagreement between the individual and the organisation.
It can be tempting to describe these requests as being “weaponised”. However, organisations need to exercise some caution.
The existence of a dispute does not remove the individual’s right of access. Nor does the fact that the information may subsequently be used for a complaint or legal proceedings automatically make the SAR invalid.
The starting point should remain straightforward:
What personal information is the individual entitled to receive, and what reasonable and proportionate searches are required to find it?
A five-page request does not necessarily create a five-page legal obligation
This is where organisations sometimes make SARs considerably more difficult than they need to be.
A sophisticated request may contain instructions such as: “Search the email accounts of the following 12 employees using my full name, initials, NHS number and these 15 keywords.”
The organisation should consider what the requester is seeking and where their personal information is reasonably likely to be held. However, a requester does not automatically determine the organisation’s search methodology simply by providing a long list of instructions.
The right of access is fundamentally a right to personal information. It is not an unrestricted right to every document that mentions an individual. Nor does every reference to someone’s name necessarily mean that an entire document becomes their personal information.
This distinction can make an enormous difference to how a complex SAR is managed.
Reasonable and proportionate searches matter
This has become particularly relevant following the Data (Use and Access) Act 2025. The ICO’s current guidance expressly states that organisations must undertake a reasonable and proportionate search for the requested information. It also explains that organisations are not required to conduct searches that would be unreasonable or disproportionate to the importance of providing access to the information.
This does not give organisations permission to conduct superficial searches.
If an organisation decides that a particular search would be unreasonable or disproportionate, it needs to be able to justify that conclusion. However, the framework is important when dealing with requests containing extensive search instructions.
The question should not simply be: “The requester has asked us to search this. Do we have to?”
Instead, organisations should ask: “Taking account of the scope of the request and what we know about our information, what searches are reasonable and proportionate to identify the individual’s personal information?”
That requires judgement, and that judgement should be documented.
What about manifestly unfounded or excessive requests?
This is another area where organisations need to be careful. Receiving a 10-page SAR generated with the assistance of AI does not automatically make the request manifestly excessive.
The ICO says a request is not necessarily excessive simply because an individual requests a large amount of information. When considering whether a request is manifestly excessive, organisations need to consider all the circumstances, including the nature of the information, the context and relationship with the requester, the resources available and whether the request substantially repeats or overlaps with previous requests.
The threshold is deliberately high. The excessiveness must be clear or obvious, and the organisation needs strong justification for its conclusion.
There are circumstances where the purpose and context of a request can become relevant. Current ICO training materials, for example, give an example involving repeated requests where the evidence shows that the requester is attempting to cause disruption and put pressure on a DPO rather than genuinely seeking further personal information.
But this needs to be distinguished from someone who is simply persistent, angry, involved in a dispute or asking for a large amount of information. Those factors alone should not lead an organisation to label a SAR as manifestly unfounded.
AI can also make challenging the response easier
There is another development organisations should prepare for.
AI not only makes it easier to draft the initial request. It can also make it easier to scrutinise the response.
An individual can provide an AI tool with their original request and the organisation’s response and ask it to identify apparent gaps. They can ask it to draft follow-up correspondence, question exemptions relied upon by the organisation or help prepare a complaint to the ICO.
The quality of that advice will vary, and an AI-generated challenge is not necessarily legally correct.
But from an organisational perspective, there is an important lesson: SAR decisions need to withstand scrutiny.
That means keeping a clear record of what was searched, why particular custodians and systems were selected, what search terms were used where appropriate, what information was excluded and why, and the basis for any exemptions or restrictions applied.
A well-managed SAR should be defensible from its records without having to reconstruct the reasoning several months later.
Why healthcare organisations should pay particular attention
SARs in healthcare can already involve substantial amounts of highly sensitive information.
The ICO has dedicated guidance on the right of access, including the particular considerations that arise when dealing with health information. Its individual rights resources also specifically direct organisations to guidance concerning health, social work and education information.
A patient involved in a complaint about their care may want considerably more than a copy of the formal clinical record.
They may want correspondence between clinicians, internal discussions about their complaint, notes relating to decisions, communications with other organisations and information about how concerns they raised were handled.
That can create difficult questions around scope, third-party information, professional opinions, confidentiality and applicable restrictions.
It also makes poor information management considerably more visible.
An organisation that cannot establish where information about a patient may be held will find a sophisticated SAR particularly difficult to manage.
So how should organisations respond?
The answer is not to treat detailed SARs more aggressively. It is to manage them better.
Separate the SAR from the dispute
The person dealing with the SAR should understand the wider context, but avoid allowing that context to determine the response.
A difficult complainant can still make a valid SAR. An employee involved in litigation can still exercise their right of access. A patient who has made repeated complaints can still be entitled to their personal information.
Deal with the SAR as a statutory information rights request while managing the underlying complaint, grievance or litigation through the appropriate separate process.
Establish what the individual is actually asking for
Do not automatically translate every sentence in a lengthy request into a separate search exercise. Read the request as a whole.
What personal information are they seeking? What period does it cover? Which parts are clear? Where is that information reasonably likely to exist?
Where appropriate, clarification can make a significant difference to the search exercise.
Create a search strategy
For complex SARs, avoid simply forwarding the request to dozens of employees with the instruction: “Please send us anything you have about this person.”
Identify likely data sources and custodians, determine proportionate search terms and date ranges, and record what you have decided to search and why.
Remember: personal information, not documents
This distinction should be understood by everyone involved in the review.
Finding the requester’s name within a 30-page document does not necessarily mean the individual is entitled to the entire document. The review needs to identify the requester’s personal information within the material retrieved.
This is particularly important when dealing with internal correspondence containing information about several people.
Document proportionality decisions
If searching a particular system, mailbox, archive or category of information would be unreasonable or disproportionate, document the reasoning.
Record the likely relevance of the information, the scale of the search, alternative searches undertaken and why the organisation considers its approach reasonable.
Do not wait for an ICO complaint to reconstruct that reasoning.
Be cautious before relying on “manifestly unfounded” or “manifestly excessive”
These are not convenient labels for difficult SARs. The ICO expects organisations to consider each request individually and to have strong justification for refusing one on these grounds.
Escalate these decisions internally or obtain specialist advice where appropriate.
Keep an audit trail
For significant SARs, the SAR file should tell the story of the response. It should be possible to establish:
- what was requested;
- how scope was determined;
- which systems and custodians were searched;
- what searches were undertaken;
- what was retrieved;
- what decisions were made about personal and third-party information;
- what exemptions or restrictions were considered and applied; and
- why any searches were considered unreasonable or disproportionate.
This becomes particularly valuable if the response is subsequently challenged.
Do not fight the request. Strengthen the process.
It would be easy to view AI-assisted SARs negatively.
Individuals can now create lengthy requests, quote legislation, ask for information across numerous systems and challenge responses with considerably less effort than would previously have been required.
For organisations, that can undoubtedly create additional work.
But the technology has not changed the fundamental legal position.
A genuine SAR remains a SAR whether it was drafted by the individual, a solicitor, an online template or an AI tool. At the same time, organisations are not required simply to follow every search instruction contained within a sophisticated request.
They are required to understand the scope of the right, identify the individual’s personal information and undertake reasonable and proportionate searches for it.
The organisations that manage this well will not necessarily be those with the biggest SAR teams.
They will be those that know where their information is, have clear processes for scoping complex requests, document their decisions and understand when to challenge internally the assumption that “the requester asked for it, therefore we must search everything”.
As a consultant, that is where I believe organisations should be focusing their attention.
The question is not whether individuals will continue to use new tools to exercise their rights, because they will.
I think the more useful question is: if your next SAR is detailed, extensive and written with the sophistication of a specialist, is your organisation’s process robust enough to deal with it?
Further reading