How AI Is Reshaping the DPO Role in 2026
Data Protection Made Easy
Written by Amber Sivill
AI is reshaping subject access requests, workplace data risk, and the DPO role itself. Amber Sivill, Data Protection Consultant here at Data Protection People, breaks down what’s changing and what to do about it, ahead of this Friday’s podcast episode.
By Amber Sivill, Data Protection Consultant and AI Specialist at Data Protection People
Artificial intelligence is not only changing the way organisations handle information, it is changing the way individuals understand, exercise and challenge their individual rights. That shift is now landing firmly on the DPO’s desk. Ahead of this Friday’s podcast episode on how AI is reshaping the DPO role, I wanted to share what I am seeing in practice, and why I think the roles and responsibilities of a DPO are becoming more strategic, visible, and more closely connected to AI governance than ever before.
Subject access requests are changing shape, not just volume
Most DPOs I speak to will recognise the same trend: subject access requests are coming in fast and strong, and the requests themselves are becoming more broad complex. Some of that is the result of greater public awareness of data rights. But it is increasingly clear that data subjects are using AI tools to assist them with drafting more detailed and legally focused requests.
A request that once said, “please send me my data”, may now arrive with references to specific processing activities, legislation, ICO guidance and carefully worded follow-up questions. That does not mean the individual is being difficult. In many cases, they have simply had support from an AI tool to articulate what they are asking for. For organisations, the practical effect is clear: SARs can take longer to assess, scope and respond to, even where the underlying request is perfectly legitimate.
The regulatory position has also moved on. Since February of this year, the Data (Use and Access Act) 2025 has given organisations more room to take a reasonable and proportionate approach to searches, rather than treating every request as requiring an exhaustive search of every system and record. It also allows organisations to “stop-the-clock” whilst waiting for identity verification or clarification where a request is unclear. Whilst those changes provide more flexibility to organisations, they do not remove the need for a robust process or adequate resources to address a request. In my experience, many complaints arise not because an organisation neglected their responsibilities under data protection law, but because expectations were not managed, communication was unclear, or the SAR process did not hold up under pressure.
The workplace risk nobody’s policy covers yet
The SAR challenge is only part of the picture. The other, and often less visible, issue is what is happening inside organisations. Staff are increasingly experimenting with consumer AI tools to save time, summarise information, draft communications and sense-check their work. That behaviour is understandable, particularly where approved tools are not available, but it creates real data protection risk when there are no clear rules around what can and cannot be shared.
In practical terms, this might mean someone pasting a client email thread into a personal AI account to help draft a reply. It might mean uploading a contract, pricing document or HR note to create a quick summary. In the moment, that may feel like a harmless productivity shortcut. From a data protection perspective, however, personal data and confidential business information may have left the organisation’s control, with little or no record of what was shared, where it went, or how it may be used afterwards.
This is where policy, training and governance need to catch up with day-to-day behaviour. If an organisation has no approved AI tools, no written position on staff use, and no practical examples of what is and is not acceptable, employees will make their own judgement calls. That is not just a training gap. It is a governance gap, and it is exactly the kind of issue a DPO should be helping the organisation to identify and close.
Where AI is actually helping, not just complicating things
It would be too simplistic to present AI only as a risk. Used properly, it can also support better data protection practice. The organisations making the strongest progress are not necessarily the ones banning AI outright. They are the ones setting sensible boundaries, choosing appropriate tools, and making sure human oversight remains built into the process.
For example, AI-assisted triage can be genuinely useful in SAR handling. It can help identify likely duplicate documents, flag material that may contain third-party data, and support the first review of large data sets. It can also help organisations spot patterns across complaints, requests and internal queries that may point to a wider process issue. Used carefully, those capabilities can give DPOs more time to focus on judgement, accountability and risk, rather than manual administration.
The key point is that AI should not be treated as a shortcut around governance. It should be assessed in the same practical way as any other tool or processor: what data does it use, where does that data go, what controls are in place, and what role does human review play in the final decision?
What this means for your organisation
None of this is a reason to panic. It is a reason to take stock. If SARs are becoming harder to scope, if staff are using AI tools without clear guidance, or if your organisation does not have the internal capacity to keep pace with the rate of change, it may be time to look at whether your current data protection arrangements are still fit for purpose. An experienced outsourced DPO can bring both the day-to-day capacity and the AI-specific knowledge needed to turn uncertainty into a practical, proportionate plan.
We will be exploring this in more detail on this Friday’s episode of the Data Protection Made Easy podcast, including what we are seeing across client organisations and what a sensible, usable AI policy looks like in practice.