As of 13 August 2026, AI can only partly draft a response to a subject access request.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita professional
What the alternative costsNo alternative price is provided in the available tool data.
If this goes wrong: you disclose another person's information, miss relevant personal data or give an incomplete response, leaving your organisation to deal with the consequences.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the original subject access request, the identity or authority check, your organisation's SAR procedure and the relevant case folder.
- Gather the search log, results from each relevant system, proposed attachments, correspondence with the requester and any records containing third-party information.
- Remove unnecessary personal data from the material before putting it into a chatbot, and label each document with its source and purpose.
- Paste the material into the prompt in separate sections, then ask the model to produce the covering letter, data schedule, issue list and approval checklist.
- Compare every statement in the draft with the source records, checking the requester’s details, data categories, attachments, missing searches and explanations for redactions.
- Send the draft and the underlying search record to your data protection lead or solicitor for decisions on exemptions, third-party information, privilege, scope and any deadline issue.
- Apply the approved redactions and amendments, obtain the organisation's required sign-off, then send the final response and retain the search and approval record.
Prompt
Draft a UK GDPR subject access request response using only the materials supplied below. Requester and request: [PASTE THE REQUEST AND ANY IDENTITY OR AUTHORITY CHECK INFORMATION] Search results and personal data to consider: [PASTE THE RECORDS, SEARCH LOG, EMAILS, DOCUMENT EXTRACTS AND ATTACHMENT LIST] Relevant organisation policy and procedure: [PASTE THE CURRENT SAR PROCEDURE, RETENTION RULES AND ESCALATION RULES] Known issues: [PASTE ANY THIRD-PARTY DATA, CONFIDENTIALITY CONCERNS, PRIVILEGE CONCERNS, MISSING RECORDS, EXTENSIONS OR OTHER UNCERTAINTIES] Produce: 1. A clear draft covering letter in plain British English. 2. A schedule listing each category of personal data supplied and where it appears. 3. A separate list of records or information that may need withholding, redaction or specialist review, with the reason stated as an issue to verify, not as a final legal decision. 4. A list of unanswered questions, missing searches and factual inconsistencies. 5. A final checklist of attachments and approval steps before sending. Do not invent facts, records, dates, legal conclusions, exemptions or reasons for withholding information. Do not include personal data that is not in the supplied material. Do not decide that an exemption applies without flagging the decision for review by the organisation's data protection lead or solicitor. Mark every uncertainty clearly. This is a drafting exercise, not professional advice.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot access every relevant mailbox, system, archive or paper file unless you search and provide the results.
- AI cannot take responsibility for deciding whether a UK GDPR exemption, redaction or third-party restriction applies.
- AI cannot reliably distinguish an apparently complete search from a search that missed an informal system or local record.
- AI cannot protect sensitive requester or third-party information unless you control what is uploaded and how the tool handles it.
- AI cannot transfer the organisation's accountability for the response to the requester.
What caps this at PARTLY: legal accountability, verification cost and private data access.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI write a response to a subject access request?
- Yes, it can draft the covering letter, data schedule and list of unresolved issues from material you provide. It cannot perform the searches or make final decisions about exemptions and redactions.
- Is it safe to use AI for a subject access request?
- It is only safe with an approved tool, controlled data handling and human review before anything is sent. Do not upload unnecessary personal data, and do not rely on the model to identify every redaction or exemption.
- What information does AI need to draft a subject access request response?
- It needs the request, identity or authority checks, search results, proposed records and attachments, relevant procedures, and details of third-party or withheld information. It also needs clear labels showing which facts are confirmed and which are still unresolved.
- Can AI decide what to redact from a subject access request?
- No. It can flag third-party information, confidential material and possible legal issues for review, but an accountable data protection lead or solicitor must decide what can be withheld or redacted. This is not professional advice, and a serious or disputed case needs a data protection solicitor.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI audit my website cookies for PECR compliance?PARTLY
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether an AI tool creates UK GDPR risks for my business?NO
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my email marketing consent process under UK PECR?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.