This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.

Insights & Events

| 3 minute read

The rise of the complex DSAR: what to do when AI enters the picture

Data subject access requests (DSARs) have long been a fact of life for any business handling personal data. Over the last year, however, the profile of the average request has shifted. Requests are getting longer, broader and more legally-worded - and it is not always the data subject doing the drafting.

Off-the-shelf generative AI tools now make it easy for individuals to compose sweeping DSARs that cite every conceivable article of the UK GDPR, ask for "any and all" information across every possible source, and demand supplementary information that goes well beyond what the person actually wants to know. Even a routine request can arrive looking intimidatingly complex.

The good news is that the Data (Use and Access) Act 2025 (DUAA), together with existing ICO guidance, gives organisations meaningful tools to manage this new wave of requests proportionately.

Only a reasonable and proportionate search is required

DUAA amended Article 15 of the UK GDPR to confirm that a data subject is only entitled to the confirmation, personal data and other information that the controller is able to provide based on a reasonable and proportionate search. You do not have to conduct an exhaustive trawl of every system, mailbox and archive to comply. What is reasonable and proportionate depends on the specific circumstances, including the size and resources of your organisation and the nature of the information sought.

Stopping the clock when you need clarification

Where you reasonably need further information to identify what the request relates to, the clock can be paused. Under the new Article 12A of the UK GDPR (in force from 5 February 2026), the period between asking the requester for further information and receiving it does not count towards the one-month response deadline. This is particularly useful for AI-generated requests that ask for "everything" without meaningful context - for example, where you hold a large amount of information about the person across employment, customer and other relationships.

You should still be able to justify why clarification is reasonably required. Blanket clarification requests, or clarification requests used to buy time, are not acceptable - and a request is not "complex" simply because you have had to ask for clarification.

Extending the deadline for complex requests

If a request is genuinely complex, or where the same person has made a number of requests, the one-month deadline can be extended by a further two months. Crucially, the extension is not automatic: you must give the requester notice of the extension and state the reasons for the delay within the first calendar month. Miss that window and the extension is lost.

Not every difficult-looking request is "complex" for these purposes. The ICO has identified factors that may add to complexity, including technical difficulties retrieving archived information, applying exemptions to large volumes of particularly sensitive data, the need to obtain specialist legal advice (unless routinely obtained), and searching large volumes of unstructured manual records (for public authorities). A high volume of information alone is not enough.

Managing complex DSARs in practice

Alongside the statutory tools, sensible operational steps can make a real difference:

  • Triage requests on receipt to identify scope, volume and any signs of AI-generated boilerplate.

  • Ask focused clarification questions early - you cannot force a narrower scope, but you can invite one.

  • Apply exemptions carefully and specifically (third-party data, legal privilege, management information), not as blanket refusals.

  • Keep contemporaneous records of decisions on scope, extensions and searches, so you can justify your approach to the ICO if challenged.

  • Consider whether a request is manifestly unfounded or excessive, in which case a reasonable fee or refusal may be justified.

Behind every good DSAR response is a clear internal policy. The people on the front line - HR, customer service, IT support - are usually the first to see a request, and they need practical guidance on how to spot a DSAR, record the date of receipt so the clock starts on the right day, and escalate it to the right team without delay. A well-drafted policy also tells them what to say to the requester at first contact, what not to say, and when to ask for identification or clarification.

With a strong internal process behind them, and the new DUAA levers of reasonable and proportionate searches, stopping the clock, and the two-month extension for complex requests, businesses can respond to sophisticated (and AI-assisted) DSARs proportionately, on time and with confidence.

Sign up to receive the latest insights from Edwin Coe. Subscribe now!

Tags

commercial services, artifical intelligence, commercial contracts, data protection, corporate, dispute resolution, employment, intellectual property, family office, real estate, insights