Home · Business · Legal & Compliance · Data protection & GDPR

PARTLY

As of 13 August 2026, AI can only partly handle a UK GDPR subject access request.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededpower-user

Who has to check ita professional

What the alternative costsThe listed tools data gives no price for a UK subject access request handling service.

If this goes wrong, you can disclose the wrong person's data, miss relevant records or apply an unlawful redaction, creating a data-protection incident and an invalid response.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, power-user skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the request, your current data map and the ICO subject access request guidance, then record the request date, the requester, the scope and the identity-verification status.
    2. Ask the requester for clarification only where the scope is genuinely unclear, and keep the original request and all correspondence together.
    3. Export or collect potentially relevant records from each approved system and custodian, preserving the source, date, access controls and search terms rather than pasting live personal data into an unapproved chatbot.
    4. Remove unnecessary personal data from the material you plan to use with AI, then paste the prompt with the request, search coverage and redacted records into an approved AI tool.
    5. Use the generated search plan and record index to identify missed systems, custodians, date ranges, duplicates, irrelevant records and third-party information, then update the evidence pack.
    6. Compare every proposed exemption and redaction with the current ICO guidance and the underlying record, and have your data protection lead or solicitor decide each disputed disclosure.
    7. Prepare the final response from the approved disclosure schedule, check the recipient and attachments, record the decisions and send it through your organisation's approved channel.

    Prompt

    Help me prepare a UK GDPR subject access request response pack, but do not make the final legal decisions or send anything. Use only the information I provide and identify every assumption.
    
    Request date: [DATE]
    Requester and identity-verification status: [DETAILS, WITH ONLY THE MINIMUM NECESSARY PERSONAL DATA]
    Organisation and contact details: [DETAILS]
    Relevant systems, custodians and date ranges searched: [DETAILS]
    Records and documents found: [PASTE OR ATTACH REDACTED RECORDS WHERE POSSIBLE]
    Known third-party information: [DETAILS]
    Known special-category or criminal-offence data: [DETAILS]
    Any previous correspondence or scope clarification: [DETAILS]
    
    Produce:
    1. A factual chronology and a list of unanswered questions.
    2. A search plan showing each system, custodian, date range and search term still needed.
    3. A record index linking each item to the requester and flagging duplicates, irrelevant material, third-party data and special-category data.
    4. A proposed disclosure schedule.
    5. A proposed redaction schedule. For every proposed redaction, quote the smallest relevant passage, state the reason, identify the UK GDPR or Data Protection Act 2018 exemption that may be relevant, and mark it as requiring human or solicitor approval. Do not invent an exemption.
    6. A draft acknowledgement and response letter in plain British English, with placeholders for dates, contact details, complaint rights and the final decision.
    7. A final checklist of decisions that must be made by the organisation's data protection lead or solicitor.
    
    Separate facts, source text, legal rules, assumptions and recommendations. Do not infer identity, consent, employment status or legal exemptions. Do not include personal data that is not needed. If the current rule or deadline is uncertain, tell me to check the current ICO guidance rather than guessing. Cite the relevant ICO or GOV.UK source for each procedural point.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot access every relevant mailbox, case-management system, paper file or backup unless you collect and supply the material through an approved process.
  • AI cannot establish that the requester is entitled to the data or decide whether a third-party disclosure and a specific exemption are legally justified.
  • AI cannot guarantee that its redactions remove all indirectly identifying information or preserve the meaning of the disclosed record.
  • AI cannot take responsibility for the response, the disclosure decision or a data-protection breach.
  • AI cannot replace your organisation's retention, access-control, audit-trail and incident-reporting procedures.

What caps this at PARTLY: legal accountability, verification cost and private data access.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability0
Effort delta1
Total5 / 10

FAQ

Can ChatGPT handle a subject access request?
Partly. It can organise supplied records, suggest search gaps, draft correspondence and create a proposed redaction schedule, but it cannot access your systems or take responsibility for the legal decisions. A data protection lead or solicitor should approve exemptions, redactions and the final response.
Can AI search all my company data for a subject access request?
No, not by itself. You must identify the systems, custodians and date ranges, then run or supervise searches through approved access-controlled tools. Do not upload unnecessary personal data to a public chatbot.
Can AI redact documents for a subject access request?
It can propose redactions and explain which passages may need review, but it cannot reliably decide every exemption or remove every indirect identifier. A competent data protection professional must check the source documents and approve the final disclosure.
Is using AI for a subject access request legal?
It can be lawful as part of a controlled process, but you remain responsible for confidentiality, security, accuracy and the response decision. This is not professional advice, so involve your data protection officer or a solicitor in a serious or disputed case.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.