Compliance
The AI Complainant: Why Subject Access Requests Are Getting Harder in 2026
Updated 17 September 2026
A former employee raises a grievance. It goes to a disciplinary process. Somewhere along the way, a subject access request arrives. Routine so far.
Then the scope lands. It isn't just their own mailbox. It's theirs plus four other people who were party to the process, over an eighteen-month window. We ran it through Microsoft Purview eDiscovery because doing it by hand at that scope wasn't viable. The initial return was over 27,000 items. From one request.
That wasn't a worst case chosen to frighten anyone. It was an ordinary employment matter that happened to touch the wrong number of mailboxes. It's also becoming a more common shape of request, and the reason is sitting in everyone's browser.
This article covers what's driving the change, what a request now looks like, what you actually owe in response, and the process and licensing that keep the workload sane.
Why requests are changing
Three things have shifted at once.
The cost of asking has collapsed. A client, an ex-employee, anyone, can type two sentences into ChatGPT, Claude or Gemini and get back a subject access request that reads like a paralegal drafted it, citing the right articles of UK GDPR, in under five minutes. That used to take real effort, and the effort filtered people out. It doesn't any more.
The follow-up is just as fast. Once you respond, the same tools will review your response for gaps and draft a complaint challenging your redactions or your coverage, line by line. The follow-up is the real workload driver, and it arrives with the same statutory confidence as the original.
Complaints are now a legal duty. From 19 June 2026, the Data (Use and Access) Act requires every controller to have a formal, logged process for receiving and handling data protection complaints. Grumbles that used to be handled informally over the phone are now cases with a clock on them.
The numbers behind it
The Information Commissioner's Office has reported data protection complaints climbing from around 42,000 to over 76,000 in a single year. In its most recent quarterly figures, 43% of closed complaints concerned the right of access, which makes subject access the single largest category and still growing. The ICO doesn't say how much of that is AI-assisted, but it is hard to see what else explains the curve.
The regulator is feeling it too. The ICO has acknowledged it is meeting its 90-day response target on only around 30% of complaints.
Around two thirds of requests come from employees or former employees rather than customers. In the UK, they are routinely used as a tactical tool during disciplinaries, grievances, and in the run-up to tribunal claims.
What a request looks like now
Requests read as if they were written by someone who knows the legislation, because in a sense they were. Expect exact statutory phrasing from people who have never worked in compliance.
The follow-up quotes your own redaction schedule back at you and asks you to justify each exemption individually. You have to answer that too.
One caution in the other direction. If you use AI to help draft a response, check every citation. AI tools will confidently invent case law and statutory provisions that don't exist, and at least one UK law firm has already had to self-refer to its regulator after a fabricated citation slipped into a filing. Nobody on either side of this should send AI output that a person hasn't verified.
When the request never reaches you
Here is a scenario that catches businesses out. The request is emailed, but it never lands in front of a human. It sits in a quarantine queue, a spam folder, or an unmonitored shared mailbox that nobody has opened since a colleague left.
The one-month clock starts on receipt, not on you noticing. If it entered a system you control, it counts, including on a weekend or a bank holiday. If you later find a request that sat in quarantine for three weeks, you have a week left, not a month.
Practical impact: make sure someone owns the mailboxes that requests plausibly arrive in, and that quarantine and spam queues are reviewed, not just emptied.
What they are actually entitled to
A request asks for everything. It doesn't get everything.
- Their own personal data only. A person's name appearing in a document doesn't hand over the rest of the document. Extract or redact what isn't theirs.
- Other people are protected too. Colleagues, clients and anyone else named in the same records have their own rights, and their data needs to be balanced or redacted first.
- Genuinely anonymised data is out of scope, as are informal personal notes that were never intended for a formal file.
- The format can be yours. You can present the personal data in a new document rather than handing over original source files.
The Data (Use and Access) Act also confirms that you only need to carry out a reasonable and proportionate search. You don't have to turn the office upside down for every scrap if the time and cost would be wildly out of proportion to the request.
The bar for that is high. Poor filing, disorganised systems or a shortage of staff are not acceptable reasons to call a search disproportionate. A clear data inventory, on the other hand, is exactly what lets you defend the point against an overly broad request.
Why smaller organisations feel this most
Most businesses hold more personal data than they realise: HR files, payroll, customer records, supplier contacts, and years of email in which all of it gets discussed. A single project or client relationship mixes staff data, customer data and third-party data in the same mailbox, which makes scoping a request harder than it looks.
The data also lives in more places than most people can list from memory: a CRM or line-of-business system, a document store, email, Teams and SharePoint. Each one needs searching separately unless you've unified them. Larger organisations have a compliance team for this. Smaller ones have whoever picked up the email.
The workload, honestly
These figures are illustrative rather than from any named client, but they're a realistic shape for a broadened request across separate systems.
- Manual mailbox search: about a working day, assuming you know what you're doing.
- Add SharePoint and Teams, because the request covers those too: nearly two more days.
- Review and redaction of what you found: the biggest single chunk, close to three days.
- The follow-up complaint challenging your response: another day and a half.
Call it fifty to sixty hours. The best part of a week and a half for a single request that, a few years ago, was an afternoon's work. That is before counting the time your IT provider spends on licensing, creating the case and adjusting search sets.
What actually works
Four pillars, technology and process together. Neither solves this alone.
Unified eDiscovery. Microsoft Purview lets you search email, Teams, SharePoint and OneDrive from one case rather than exporting mailboxes one at a time. Our guide to running a SAR with Priva walks through the hands-on steps.
Retention and legal hold, decided in advance. Set a proper retention schedule by data category and automate it with Purview Data Lifecycle Management so it runs on rules rather than on someone remembering to clear an inbox on a Friday. Then make sure a legal hold overrides the schedule automatically the moment a request or dispute is reasonably anticipated, so nothing scheduled for deletion disappears mid-case. Some of these Microsoft settings take days to propagate, so this is not something to configure the week a request arrives.
Human-checked redaction. AI finds relevant material quickly. A person still makes the privilege and exemption calls. That judgement doesn't get automated, and if a complaint follows, it's a person who has to defend it.
A logged complaints process with a named owner. This is what satisfies the new statutory duty. It needs to be a real process with a record, not a shared inbox that everyone assumes someone else is watching. We have a Word template for this process that we handed out at the conference. Get in touch if you'd like a copy.
Minimise at the point of collection too, not just at deletion. Fewer sprawling CC chains carrying personal data that never needed to exist means less to find and less to redact.
Licensing: the point that saves real money
Most of the capability above sits on Microsoft 365 Business Premium, which many businesses already have. It includes eDiscovery Standard for search and export, basic data loss prevention and a 90-day audit log.
For proper casework, you add the Purview Suite on top. That brings legal hold, custodian management, review sets, near-duplicate detection, technology-assisted review and defensible redaction. Current pricing is in our Microsoft 365 pricing guide.
Here is the part most people miss, and it comes straight from Microsoft's own licensing documentation. Only custodians need the Purview Suite licence. A custodian is someone whose mailbox or files are placed on hold or brought into a review set. The people running the case, your compliance lead, a partner, a paralegal, don't need that licence themselves to search, review or export.
Practical impact: licence your compliance lead, a partner or two, and anyone likely to be named a custodian. Add more only when a real case requires it. Organisations that licence everyone "to be safe" routinely overspend by a wide margin.
Where to start
- Confirm who owns incoming requests and which mailboxes they can arrive in, including quarantine.
- Write a tiered retention schedule by data category and get the periods signed off by whoever holds legal or compliance responsibility.
- Automate that schedule, and the legal hold that overrides it, in Purview.
- Stand up a logged complaints process with a named owner. The duty has been live since June 2026.
- Build a data inventory. It is the foundation of any proportionality argument.
- Licence custodians only, and review it when a case opens.
- Keep a human checking the output, whether the AI is on your side of the request or theirs.
None of this is exotic. Most businesses already have the tools. What they don't yet have is the process.
The pitfalls we see most
- Treating it as purely an IT problem. Technology speeds up the search. Scope and exemptions are legal judgement calls, and someone qualified has to make them.
- Forgetting the deadline still applies. One month, regardless of how the request was drafted or how many follow-ups arrive.
- No named owner for complaints. The statutory duty needs an accountable person, not an inbox.
Three things to take away
Put the complaints process in place now.
Custodians only. That alone can save real money.
Keep a human checking the output on both sides.
If you'd like a review of how your Microsoft 365 tenant is set up for retention, hold and eDiscovery, or you want the complaints process template, get in touch. We work through this with clients across professional services, construction, care and more.
