Published

DSARs in the age of AI — why you should resist the siren call of simplicity

By
A Data Subject Access Request (DSAR) refusal letter recently crossed our desk that looked — at first sight — legally persuasive. It relied heavily on Recital 63 UK GDPR and the judgment in the case of X v Transcription Agency Ltd [2023] EWHC 1092 (KB) to justify treating the request as manifestly unfounded.

The argument was attractively simple: 

  1. The right of access exists to allow a data subject to verify the lawfulness of processing. 
  2. The courts have confirmed that data protection legislation shouldn’t be used as a substitute for wider disclosure rights. 
  3. Therefore, where a request appears motivated by some wider dispute, the DSAR can be refused.
All our prayers had been answered…

Or had they? On closer examination, the legal analysis was far less straightforward than the letter suggested.

While we can’t know whether a lawyer, an AI tool or both drafted the response, it highlighted a growing problem: correspondence that builds legal arguments around selective quotations from legislation, Information Commissioner's Office (ICO) guidance and case law but doesn’t properly test whether those authorities apply to the given situation.

The problem isn’t that AI gets the law wrong — it’s that it can produce arguments that look legally persuasive while skipping over the detailed analysis required to support them.

Here, Matt Brown from our data protection team examines the risks of relying on oversimplified legal arguments in DSAR disputes and highlights the key lessons for both controllers and data subjects.

A legal framework designed for a different era

Neither the UK GDPR, Data Protection Act 2018 (DPA 2018) or ICO's guidance was drafted with widespread use of generative AI in mind.

Organisations now receive requests that appear AI-generated or AI-influenced. Some responses also appear to be AI-generated. Both sides may cite legislation, guidance and case law without addressing the facts and legal nuances that determine whether those authorities apply.

The legal framework hasn’t yet caught up. It assumes human analysis and judgement. AI makes legal arguments easier to generate but not easier to assess.

The attraction of simple answers

This challenge is particularly acute in the context of DSARs.

Few organisations welcome them. DSARs can require extensive searches, careful review and difficult decisions about exemptions, privilege and third-party information. That creates an understandable temptation to find a quick basis for refusal.

That temptation is understandable. It’s also dangerous.

A controller shouldn’t rely on a single line from a case or one paragraph of ICO guidance to apply a blanket refusal. 

It must assess the request properly, including whether: 

  • it holds the requester’s personal data
  • reasonable and proportionate searches are required
  • any exemption applies on a case-by-case basis 
  • disclosure would prejudice a protected interest.
That kind of shortcut is precisely the type of simplification that AI-generated analysis can encourage.

To continue reading the full article, please see our website:
https://www.brabners.com/insights/data-protection/dsars-in-the-age-of-ai-why-you-should-resist-the-siren-call-of-simplicity

Talk to us

DSARs often involve complex legal and practical considerations. If you need support making, responding to or challenging a request, our data protection team can help.

Talk to us by giving us a call on 0333 004 4488, sending us an email at hello@brabners.com or completing the contact form on our website.
Published by
Brabners

Brabners

Sceptre Way, Preston, Lancashire, PR5 6AW

01772823921

View details