Skip to main content

Talk to us: 0333 004 4488 | hello@brabners.com | Contact us

DSARs in the age of AI — why you should resist the siren call of simplicity

AuthorsMatt Brown

Abstract digital network scene: a glowing blue hub at the left with streaming fibre-like lines and scattered colourful squares fanning out toward the right.

Data Subject Access Request (DSAR) refusal letter recently crossed our desk that looked — at first sight — legally persuasive. It relied heavily on Recital 63 UK GDPR and the judgment in the case of X v Transcription Agency Ltd [2023] EWHC 1092 (KB) to justify treating the request as manifestly unfounded.

The argument was attractively simple: 

  1. The right of access exists to allow a data subject to verify the lawfulness of processing. 
  2. The courts have confirmed that data protection legislation shouldn’t be used as a substitute for wider disclosure rights. 
  3. Therefore, where a request appears motivated by some wider dispute, the DSAR can be refused.

All our prayers had been answered…

Or had they? On closer examination, the legal analysis was far less straightforward than the letter suggested.

While we can’t know whether a lawyer, an AI tool or both drafted the response, it highlighted a growing problem: correspondence that builds legal arguments around selective quotations from legislation, Information Commissioner's Office (ICO) guidance and case law but doesn’t properly test whether those authorities apply to the given situation.

The problem isn’t that AI gets the law wrong — it’s that it can produce arguments that look legally persuasive while skipping over the detailed analysis required to support them.

Here, Matt Brown from our data protection team examines the risks of relying on oversimplified legal arguments in DSAR disputes and highlights the key lessons for both controllers and data subjects.

 

A legal framework designed for a different era

Neither the UK GDPR, Data Protection Act 2018 (DPA 2018) or ICO's guidance was drafted with widespread use of generative AI in mind.

Organisations now receive requests that appear AI-generated or AI-influenced. Some responses also appear to be AI-generated. Both sides may cite legislation, guidance and case law without addressing the facts and legal nuances that determine whether those authorities apply.

The legal framework hasn’t yet caught up. It assumes human analysis and judgement. AI makes legal arguments easier to generate but not easier to assess.

 

The attraction of simple answers

This challenge is particularly acute in the context of DSARs.

Few organisations welcome them. DSARs can require extensive searches, careful review and difficult decisions about exemptions, privilege and third-party information. That creates an understandable temptation to find a quick basis for refusal.

That temptation is understandable. It’s also dangerous.

A controller shouldn’t rely on a single line from a case or one paragraph of ICO guidance to apply a blanket refusal. 

It must assess the request properly, including whether: 

  • it holds the requester’s personal data
  • reasonable and proportionate searches are required
  • any exemption applies on a case-by-case basis 
  • disclosure would prejudice a protected interest.

That kind of shortcut is precisely the type of simplification that AI-generated analysis can encourage.

 

The risk of reading too much into X v Transcription Agency

The refusal letter that prompted this article relied heavily upon the judgment in X v Transcription Agency and Recital 63 of the UK GDPR.

Those authorities undoubtedly have an important role.

Recital 63 says that the right of access allows individuals to understand and verify the lawfulness of processing. In X v Transcription Agency, the High Court also stressed that data protection law serves a specific purpose and shouldn’t replace wider disclosure rights. However, the Judges’ comments had been taken out of context. This case was primarily about the judicial exemption under Schedule 2, Part 2, Paragraph 14 of the DPA 2018, not a general test for refusing DSARs as manifestly unfounded.

A statement of purpose isn’t the same thing as a test for refusal. A legal authority explaining why a right exists doesn’t necessarily establish when that right can be denied.

That distinction matters.

Many DSARs arise alongside employment disputes, litigation, complaints, regulatory investigations, family disagreements or shareholder disputes. A requester may have several reasons for seeking their personal data. That doesn’t, by itself, make the request invalid, abusive or manifestly unfounded.

The question remains whether the statutory test for refusal has actually been satisfied.

That requires evidence, not assumption.

 

The dangers of blanket exemptions

The same concern arises in relation to exemptions. Organisations often identify a potentially relevant exemption and then try to apply it wholesale.

For example, a law firm may conclude that material is confidential. An employer may decide that management discussions are exempt. A regulated business may determine that internal deliberations should be withheld.

Sometimes those conclusions will be correct. Very often, however, the position is considerably more nuanced. For example, take a set of senior management minutes discussing an employee. 

The minutes may contain:

  • Information unrelated to the employee.
  • Personal data concerning the employee's performance.
  • Legal advice.
  • Potential redundancy planning.
  • Settlement discussions.
  • Information relating to clients or other third parties.

Each category may need a different analysis. A requester is entitled to their personal data, not necessarily to copies of the documents that contain it. Some information in the minutes may not be the individual's personal data. Some may be disclosable. Some may attract privilege. Some may fall within management planning or negotiations exemptions. Some may need redaction to protect third-party rights.

The legislation generally requires that analysis.

A potentially relevant exemption rarely removes the need for it.

 

A wider regulatory issue

For regulated organisations, the risks extend beyond data protection law.

Law firms, accountants, financial services businesses and other regulated professionals are subject to broader obligations relating to competence, integrity, governance and client care.

That raises an uncomfortable question: what happens if an organisation refuses a DSAR on the basis of a legal proposition that isn’t supported by the underlying authority?

It may expose the controller to ICO scrutiny and — depending on the circumstances — civil claims where the refusal results in damage, distress or a failure to comply with the individual’s access rights.

In addition, this isn’t simply a data protection issue. It may also become a question of professional standards.

No lawyer gets every argument right but there’s a clear difference between reaching a defensible conclusion on a difficult point and relying on an authority for a proposition that it doesn’t establish.

If someone challenges the refusal, scrutiny may come from several directions: the ICO, clients, complaint bodies, insurers, regulators or the courts.

That risk is particularly acute where a client is the individual making the request. An incorrect or overstated interpretation of the law may generate concerns that extend well beyond the original DSAR.

 

Key takeaway: there are no shortcuts

The broader lesson is straightforward: AI can quickly identify authorities, summarise legislation and assemble arguments. What it can’t do is remove the need for legal analysis.

Whether acting for a controller or a data subject, the answer usually lies in the detailed facts rather than in a selective quotation from a judgment or a single paragraph of guidance.

Controllers should be wary of relying on broad assertions that a request is manifestly unfounded, strategically motivated or caught by an exemption without undertaking the careful analysis required by the legislation.

Likewise, data subjects should recognise that not all personal data is necessarily disclosable and that exemptions continue to play an important role.

AI has changed how parties draft and challenge DSARs. It makes legal arguments easier to generate and deploy. It hasn’t changed the law.

For now at least, the legislation still requires something rather old-fashioned: evidence, analysis and judgement.

In the world of DSARs, there remains no shortcut around any of them. Assess each request on its facts, avoid blanket application of exemptions and don’t use AI as a decision maker.

 

Talk to us

DSARs often involve complex legal and practical considerations. If you need support making, responding to or challenging a request, our data protection team can help.

Talk to us by giving us a call on 0333 004 4488, sending us an email at hello@brabners.com or completing our contact form.

Matt Brown

Matt is a Partner and leads our commercial law team in Liverpool.

Read more
Matt Brown

Talk to us

Loading form...

Related insights

Data Protection FAQs

Working on laptop at night bokeh

Find answers to our most frequently asked questions about data protection and privacy from our lawyers.

Read more