Home · Business · Legal & Compliance · Data protection & GDPR
As of 13 August 2026, AI cannot find personal data for a subject access request.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
n/ait cannot be self-verified.
Cost, all in£0
Skill neededpower-user
Who has to check ita professional
What the alternative costsNo price for a comparable professional service is provided in the available tool data.
If this goes wrong: you miss relevant records or disclose another person's information, leaving the organisation with an incomplete or inappropriate response to the requester.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface gets you a draft, but you cannot verify it yourself. That is the catch.
How to actually do it
- Open the subject access request and your organisation's current data map, then make a list of every system, mailbox, messaging channel, shared drive, paper file and backup that could contain the requester's personal data.
- Ask the authorised owners of those sources for exports or search results, preserving the original record identifiers, dates and surrounding context rather than copying isolated snippets.
- Remove unrelated data only under your organisation's approved handling process, and use an approved AI environment rather than uploading personal data to an unapproved chatbot.
- Paste the source list and upload the authorised records into the prompt, asking the model to classify matches, flag third-party data and identify sources or periods that were not searched.
- Compare the model's source-by-source results with the data map and the owners' search records, then make the owners rerun any missing or weak searches and preserve the new results.
- Give the complete collection, the AI's uncertainty list and the original search log to your data protection lead or solicitor to decide what can be disclosed and to approve the final response.
Prompt
I am helping [ORGANISATION] handle a UK GDPR subject access request. Use only the records and source list I provide, and do not invent documents, people, dates or conclusions. This is not professional advice. First, create a search and collection plan covering each source in the source list, including email, messaging, file storage, case-management systems, HR or customer systems, backups and paper records where they are listed. For each source, specify the authorised person who should search it, the search terms to use, date or record filters, and the output to preserve. Then review the supplied records and produce a table with: record identifier, source, date, people mentioned, requester-related personal data found, likely relevance, possible third-party data, possible special-category or legally sensitive material, and a short reason for each classification. Quote only the minimum text needed and keep the original record identifier so a human can inspect it. Separate the results into: likely in scope, likely out of scope, needs human review, and no match. List every source or period that could not be searched and every unanswered question that could make the collection incomplete. Do not decide whether an exemption applies, do not disclose information, and do not claim the search is complete. End with a checklist for the organisation's data protection lead or solicitor to verify before any response is sent. Source list: [PASTE AUTHORISED SOURCE LIST] Records or exports: [PASTE OR UPLOAD AUTHORISED RECORDS]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot access systems, mailboxes or paper files unless an authorised person exports and supplies the records.
- AI cannot prove that every relevant source and time period was searched.
- AI cannot reliably decide whether an exemption applies or whether another person's information should be disclosed.
- AI cannot take responsibility for an incomplete or excessive response to the requester.
- AI cannot replace the organisation's data map, access controls and search log.
What makes this a NO: legal accountability, private data access and verification cost.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 0 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 3 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI find all my personal data for a subject access request?
- No. AI can search records that you supply, but it cannot independently reach every relevant system or prove that the collection is complete. A data protection lead or solicitor must check the search and disclosure decisions.
- Can I upload subject access request data to ChatGPT?
- Only if your organisation's approved handling process permits that environment and the upload is necessary and authorised. Do not place personal data in an unapproved service, and remember that this is not professional advice.
- What can AI do for a subject access request?
- It can help search supplied exports, group likely matches, retain record identifiers and list gaps for a human to investigate. It cannot decide exemptions, guarantee completeness or approve what is sent to the requester.
- Do I need a solicitor for a subject access request?
- Not every routine request needs a solicitor, but a disputed, unusually sensitive or high-risk case needs a data protection solicitor or another suitably qualified data protection professional. This is not professional advice, and the organisation remains responsible for the response.
Nearby answers
- Can AI write a GDPR-compliant data protection clause for a UK contract?NO
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether my employee monitoring complies with UK GDPR?NO
- Can AI complete a UK GDPR transfer risk assessment?PARTLY
- Can AI create a record of processing activities for my business?PARTLY
- Can AI draft a data processing agreement for my business?NO
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.