DSARs in the age of AI — why you should resist the siren call of simplicity

Our data protection team examines the risks of relying on oversimplified legal arguments in DSAR disputes and highlights key lessons for data controllers.
Talk to us: 0333 004 4488 | hello@brabners.com | Contact us
A Data Subject Access Request (DSAR) refusal letter recently crossed our desk that looked — at first sight — legally persuasive. It relied heavily on Recital 63 UK GDPR and the judgment in the case of X v Transcription Agency Ltd [2023] EWHC 1092 (KB) to justify treating the request as manifestly unfounded.
The argument was attractively simple:
All our prayers had been answered…
Or had they? On closer examination, the legal analysis was far less straightforward than the letter suggested.
While we can’t know whether a lawyer, an AI tool or both drafted the response, it highlighted a growing problem: correspondence that builds legal arguments around selective quotations from legislation, Information Commissioner's Office (ICO) guidance and case law but doesn’t properly test whether those authorities apply to the given situation.
The problem isn’t that AI gets the law wrong — it’s that it can produce arguments that look legally persuasive while skipping over the detailed analysis required to support them.
Here, Matt Brown from our data protection team examines the risks of relying on oversimplified legal arguments in DSAR disputes and highlights the key lessons for both controllers and data subjects.
Neither the UK GDPR, Data Protection Act 2018 (DPA 2018) or ICO's guidance was drafted with widespread use of generative AI in mind.
Organisations now receive requests that appear AI-generated or AI-influenced. Some responses also appear to be AI-generated. Both sides may cite legislation, guidance and case law without addressing the facts and legal nuances that determine whether those authorities apply.
The legal framework hasn’t yet caught up. It assumes human analysis and judgement. AI makes legal arguments easier to generate but not easier to assess.
This challenge is particularly acute in the context of DSARs.
Few organisations welcome them. DSARs can require extensive searches, careful review and difficult decisions about exemptions, privilege and third-party information. That creates an understandable temptation to find a quick basis for refusal.
That temptation is understandable. It’s also dangerous.
A controller shouldn’t rely on a single line from a case or one paragraph of ICO guidance to apply a blanket refusal.
It must assess the request properly, including whether:
That kind of shortcut is precisely the type of simplification that AI-generated analysis can encourage.
The refusal letter that prompted this article relied heavily upon the judgment in X v Transcription Agency and Recital 63 of the UK GDPR.
Those authorities undoubtedly have an important role.
Recital 63 says that the right of access allows individuals to understand and verify the lawfulness of processing. In X v Transcription Agency, the High Court also stressed that data protection law serves a specific purpose and shouldn’t replace wider disclosure rights. However, the Judges’ comments had been taken out of context. This case was primarily about the judicial exemption under Schedule 2, Part 2, Paragraph 14 of the DPA 2018, not a general test for refusing DSARs as manifestly unfounded.
A statement of purpose isn’t the same thing as a test for refusal. A legal authority explaining why a right exists doesn’t necessarily establish when that right can be denied.
That distinction matters.
Many DSARs arise alongside employment disputes, litigation, complaints, regulatory investigations, family disagreements or shareholder disputes. A requester may have several reasons for seeking their personal data. That doesn’t, by itself, make the request invalid, abusive or manifestly unfounded.
The question remains whether the statutory test for refusal has actually been satisfied.
That requires evidence, not assumption.
The same concern arises in relation to exemptions. Organisations often identify a potentially relevant exemption and then try to apply it wholesale.
For example, a law firm may conclude that material is confidential. An employer may decide that management discussions are exempt. A regulated business may determine that internal deliberations should be withheld.
Sometimes those conclusions will be correct. Very often, however, the position is considerably more nuanced. For example, take a set of senior management minutes discussing an employee.
The minutes may contain:
Each category may need a different analysis. A requester is entitled to their personal data, not necessarily to copies of the documents that contain it. Some information in the minutes may not be the individual's personal data. Some may be disclosable. Some may attract privilege. Some may fall within management planning or negotiations exemptions. Some may need redaction to protect third-party rights.
The legislation generally requires that analysis.
A potentially relevant exemption rarely removes the need for it.
For regulated organisations, the risks extend beyond data protection law.
Law firms, accountants, financial services businesses and other regulated professionals are subject to broader obligations relating to competence, integrity, governance and client care.
That raises an uncomfortable question: what happens if an organisation refuses a DSAR on the basis of a legal proposition that isn’t supported by the underlying authority?
It may expose the controller to ICO scrutiny and — depending on the circumstances — civil claims where the refusal results in damage, distress or a failure to comply with the individual’s access rights.
In addition, this isn’t simply a data protection issue. It may also become a question of professional standards.
No lawyer gets every argument right but there’s a clear difference between reaching a defensible conclusion on a difficult point and relying on an authority for a proposition that it doesn’t establish.
If someone challenges the refusal, scrutiny may come from several directions: the ICO, clients, complaint bodies, insurers, regulators or the courts.
That risk is particularly acute where a client is the individual making the request. An incorrect or overstated interpretation of the law may generate concerns that extend well beyond the original DSAR.
The broader lesson is straightforward: AI can quickly identify authorities, summarise legislation and assemble arguments. What it can’t do is remove the need for legal analysis.
Whether acting for a controller or a data subject, the answer usually lies in the detailed facts rather than in a selective quotation from a judgment or a single paragraph of guidance.
Controllers should be wary of relying on broad assertions that a request is manifestly unfounded, strategically motivated or caught by an exemption without undertaking the careful analysis required by the legislation.
Likewise, data subjects should recognise that not all personal data is necessarily disclosable and that exemptions continue to play an important role.
AI has changed how parties draft and challenge DSARs. It makes legal arguments easier to generate and deploy. It hasn’t changed the law.
For now at least, the legislation still requires something rather old-fashioned: evidence, analysis and judgement.
In the world of DSARs, there remains no shortcut around any of them. Assess each request on its facts, avoid blanket application of exemptions and don’t use AI as a decision maker.
DSARs often involve complex legal and practical considerations. If you need support making, responding to or challenging a request, our data protection team can help.
Talk to us by giving us a call on 0333 004 4488, sending us an email at hello@brabners.com or completing our contact form.

Loading form...

Our data protection team examines the risks of relying on oversimplified legal arguments in DSAR disputes and highlights key lessons for data controllers.

We outline the legal protections that may be available if you face a threat to expose personal information such as your sexual orientation.

We examine the key changes introduced by the Digital Omnibus on AI, what remains unchanged and how businesses should respond.

We explore the legal issues under consideration by the ICO and Ofcom and what the case tells us about the UK's future regulation of AI-generated content.

What can we learn from the BrewDog shareholder emails? We outline key compliance risks and practical steps to consider before sending communications.

We explore the allegations against Roblox, wider challenges of protecting children online and steps that platforms are expected to take.

We explore how the Housing Ombudsman’s role is changing and outline the practical steps to remain compliant.

We explain why uncontrolled use of public AI tools creates real confidentiality and data protection risks and outline how you can manage them safely.

We delve into the key changes coming into force on 19 June 2026 and explain how businesses should prepare.

We explore the implications of the attacks for UK businesses and outline the practical measures that can help to mitigate similar disruption.

We explore why retailers are particularly affected by deepfakes and the implications around data protection, IP, advertising compliance and more.

We explore how AI is transforming data protection, the risks that organisations now face and what effective compliance looks like today.

We break down what the ICO found and outline three key steps that UK businesses should take now.

We look at the UK GDPR and the Data Protection Act 2018 and outline how the GDPR can apply to both organisations and individuals as data controllers.

We break down the key proposed reforms in the Digital Omnibus Package and outline what businesses should do to prepare.

Find answers to our most frequently asked questions about data protection and privacy from our lawyers.

We explore the key developments that in-house lawyers should have on their radar and what they mean for your organisation in the year ahead.

We explain the impact of the cyber-attack on JLR's workforce and outline what to do to protect your business and minimise the impact if an incident occurs.

We outline eight key steps to put your organisation in the strongest position for a prompt and effective response to any cyber-attack.

We explore how charities will need to manage their marketing activities and supporter consent once the secondary legislation takes effect.

We explore how weak cybersecurity and slow responses can trigger major data breaches and resulting ICO fines.

The EU Data Act is a regulation designed to reshape the European data economy by establishing harmonised rules for data access, sharing and portability.

Designed to amend the UK’s existing data privacy regime, the DUA Act will affect the UK GDPR, PECR and the Data Protection Act 2018.

We delve further into cyber attacks on three major retailers and outline five key steps to take in any cyber-attack preparedness and response plan.

The EU Commission handed out fines of €500m and €200m to Apple and Meta respectively. We outline each fine and the legality of 'consent or pay' models.