The evolution of subject access requests: What Information Governance teams need to know
Last week, I chaired an online panel for the IRMS Information Rights Group, a longer follow-up to the session we ran at the IRMS conference in March. The management of Subject access requests is evolving rapidly, and the questions came thick and fast. I was joined by Toby Davison, Head of Information Governance and Data Protection Officer at The Guinness Partnership, and Josh Schwartz, CEO and co-founder of Phaselaw. Between the three of us we cover the coalface, one of the largest housing associations in the country, and a platform handling thousands of SARs a month.
Here are the key points from the webinar that I think all IG teams can take away.
Reasonable and proportionate searches isn’t a new concept. What counts as reasonable has changed.
SAR’s don’t require a controller to conduct an exhaustive search of every system for every scrap of personal data about a data subject. The Data (Use and Access) Act put reasonable and proportionate searches into statute, but the principle has been with us since Dawson-Damer. What the DUAA codifies, practitioners have applied by convention for years.
What counted as a proportionate search before generative AI is not the same as today. If a department has rolled out an AI Assistant such as Co-Pilot and someone has asked it to summarise a case file, that summary can itself be personal data. If a requester knows the data sits there, it is reasonable for them to ask for it and proportionate for you to search it. Your search no longer stops at common systems and file stores such as the Employee file or se system and the email server. It reaches into whatever AI tools the business has bought, sometimes without procurement ever seeing them.
High Volume doesn’t make a request complex or excessive on its own
Requests that generate a high volume of personal data may increase the burden on the Controllers but if the data exists, a data subject has a right to ask for it. Volume on its own does not meet the manifestly excessive threshold. Two thousand calendar invites are not excessive, because you can see there is almost no personal data in them. Five hundred detailed email threads about one person, aimed at a small charity, is a different matter. Context decides it, usually volume combined with scope.
Toby made the practical point well: a large batch might not be excessive, but it might still fail the reasonable and proportionate test. Where email content is largely someone’s name and address, the ICO’s detailed SAR guidance lets you tell the requester what you have found, and explain that the rest is business information or relates to other people. Document the sampling and the decision. Do not open forty thousand emails one by one.
AI is on both sides of the request now.
AI-authored SARs arrive with no context and an exhaustive shopping list: search every keyword, every initial, every system from WhatsApp to Teams. You do not have to paste that straight into your process. The scoping conversation still applies, and it matters more than ever.
The harder change is what happens after you respond. Requesters drop your disclosure into an AI tool to summarise it, flag pushback and surface anything sensitive. If a single line should have been redacted and was not, it is far more likely to be found. The stakes on getting the review right have gone up. Requesters also feed your clarifications back through AI and return a reworded version of the same request, which moves nobody forward.
Controllers are adding to the problem.
The ungoverned use of AI tools is adding to the problem. When a HR professional puts a grievance into an LLM and asks it to act as an investigating officer, the output is new personal data about the people involved. Shadow AI makes it worse. Vendors switch features on without telling anyone, staff assume a new AI button must be approved, and IT often has no idea it is there. Good SAR handling now depends on good data and AI governance: know what tools you hold, enforce retention, and turn on retention tags where the licence allows it. If you do not hold it, you do not have to disclose it.
Don’t panic.
SARs have been around in some form since 1984. Volumes are rising, and so are erasures, objections and rectifications alongside them. You cannot resource your way out of a backlog indefinitely. What holds up is process: prioritise the quick ones, share load across the team, build an FAQ that answers the predictable questions up front, and make every decision defensible and documented. Leadership buy-in matters for escalation, not only for headcount.
A tool is only a tool. The policy and the process underneath it are what keep you out of trouble.
*Thanks to Toby Davison and Josh Schwartz for joining the panel. If you have a question you did not get to ask, the IRMS information rights mailbox is monitored daily.*
