Search

How can we help?

Icon

The rise of the AI-powered individual: Is your business ready?

Artificial intelligence is changing the data protection landscape, but perhaps not in the way many organisations expected.

Much of the discussion has centred on businesses adopting AI and ensuring they comply with the UK GDPR. Yet an equally significant shift is taking place on the other side of the relationship. Individuals are increasingly using AI to draft complaints, generate Data Subject Access Requests (DSARs), challenge organisational decisions and scrutinise privacy practices.

For employers and businesses, this presents an entirely new challenge.

What once might have been a straightforward request for personal information can now arrive as a lengthy, highly technical document citing legislation, ICO guidance, and case law. AI tools are enabling individuals to produce detailed correspondence in a matter of minutes, often without legal advice. While everyone is entitled to exercise their data protection rights, the practical reality is that organisations are receiving requests that are broader in scope, more complex to interpret, and significantly more time-consuming to manage.

This is particularly evident in the employment context. DSARs have long been used alongside grievances, disciplinary proceedings, and Employment Tribunal claims. AI now allows employees to generate sophisticated requests that seek extensive categories of information, challenge exemptions before they have even been applied, and demand detailed explanations of an organisation’s processing activities.

The changing nature of data protection requests

The challenge for employers is not simply the increased volume of information requested. It is ensuring that responses remain legally compliant while protecting the personal data of other individuals, preserving legal professional privilege where appropriate and applying the exemptions available under the UK GDPR correctly.

Businesses should also remember that AI-generated requests are not necessarily legally accurate. A professionally drafted-looking DSAR may cite legislation incorrectly, misunderstand the scope of an individual’s rights, or request information that falls outside the requirements of the UK GDPR. Organisations should therefore resist the temptation to assume that every AI-generated request is legally sound simply because it appears persuasive.

The ICO has consistently made clear that organisations remain responsible for complying with data protection law, regardless of how a request is drafted. This means having robust procedures in place to identify the scope of a request, conduct proportionate searches, apply appropriate redactions, and respond within the statutory time limits.

Businesses should also remember that AI-generated requests are not necessarily legally accurate.

Navigating the legal and practical challenges for employers

For many organisations, particularly those dealing with employment disputes or high volumes of personal data, this is becoming an increasingly resource-intensive exercise. A poorly handled DSAR can result in complaints to the ICO, unnecessary litigation, and significant management time being diverted away from the day-to-day running of the business.

As legal advisers, we are increasingly seeing the practical impact of AI-powered individuals. Our role is not to frustrate legitimate requests but to help organisations respond confidently, proportionately and in accordance with the law. That includes advising on the scope of DSARs, applying the relevant exemptions, protecting third-party data, managing complex searches and supporting organisations through ICO complaints where they arise.

AI has undoubtedly made it easier for individuals to understand and exercise their rights. That is, in many respects, a positive development. However, it also means businesses need to be better equipped than ever to navigate increasingly sophisticated requests without losing sight of their own legal obligations.

The question is no longer whether AI will change the way organisations receive data protection requests: it already has.

The real question is this: When every individual has an AI assistant capable of producing legally convincing correspondence in seconds, is your organisation confident it can distinguish between what the law requires and what AI merely suggests?

If your organisation is receiving increasingly complex DSARs, privacy complaints, or other data protection requests, obtaining early legal advice can help ensure responses are both compliant and proportionate while reducing the risk of unnecessary disputes. Please contact a member of our data protection team, who will be more than happy to help.

Disclaimer

This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

Monica Mastropasqua

Solicitor

View profile

+44 20 7539 8021

About this article

Read, listen and watch our latest insights

art
  • 14 September 2026
  • Corporate and M&A

Key provisions found in a Shareholders’ Agreement – SHA Series Part 2 of 5

Discover the key provisions in a shareholders’ agreement, including ownership, decision-making, share transfers, exits and leaver clauses.

art
  • 11 September 2026
  • Privacy and Data Protection

Data Protection Breaches – Personal Liability for Employees

It is well known that employers have obligations under the Data Protection Act 2018 (the “Act”) but, perhaps lesser known, is that employees can be held personally liable for certain actions amounting to criminal offences under the Act.

Pub
  • 07 September 2026
  • Corporate and M&A

Frequently Asked Questions About Shareholders’ Agreements – Episode 1

Join Emma Docking and Jonathan Hayes as they explore some of the most frequently asked questions about shareholders’ agreements, including what they are, how they work alongside articles of association, and the risks of operating without one.

art
  • 03 September 2026
  • Employment

Employment Rights Act – October Changes

We are well and truly underway with implementation of the Employment Rights Act 2025 (“ERA 2025”) and October brings the next tranche of changes that employers will need to be ready for.

art
  • 02 September 2026
  • Immigration

Mandatory MFA for Sponsor Management System Users: What Sponsors Need to Know

The Home Office is introducing a significant security change to the Sponsor Management System (SMS). From 3 September 2026, the Home Office will begin a phased rollout of mandatory Multi-Factor Authentication (MFA) for SMS users.

art
  • 01 September 2026

Orwins continues growth with investment in Milners and Acquisition of Roe Lawyers

Clarkslegal is pleased to share the news that Orwins, the legal services group we joined earlier this year, has announced a significant investment in Yorkshire law firm Milners and the acquisition of London-based specialist practice Roe Lawyers.