Blog
How can AI help a law firm handle a subject access request?
AI can help you find the personal data across a file, build a working index and draft the covering correspondence. The judgement calls, exemptions, third party data and redaction, stay with a qualified person.
Alesis · · 5 min read
AI can take on the retrieval and organisation part of a subject access request: working through the correspondence, attendance notes, emails and enclosures on a file to find where an individual's personal data appears, and giving you a page level index to work from. It can also help draft the covering letter and the internal note that records your reasoning. What it cannot do is decide what to withhold, apply an exemption or sign the response, and it should not be asked to.
What actually takes the time in a SAR
The deadline set by UK GDPR arrives quickly, and most of the pressure comes from three things rather than the law itself.
The first is scope. The request may name one matter, or it may be open ended, and the personal data may sit in closed files, in billing notes, in an email account and in a case management system. Someone has to decide what is in scope and record why.
The second is volume. Even a modest file can run to hundreds of pages, and the requester's personal data is scattered across them rather than gathered in one place.
The third is judgement. Deciding whether legal professional privilege applies, whether another exemption is engaged, whether third party information can be disclosed without that person's consent, and how much of a document to redact: all of that is lawyer work, and it is the part the Information Commissioner's Office is most likely to look at if the requester complains.
AI helps most with the second of these, and usefully with parts of the first. It helps least with the third.
Where AI genuinely helps
Locating personal data across a file. Ask for every page on which a named individual appears, including references by role or initials rather than full name, and you get a list to review rather than a pile to read. That turns a week of paging through bundles into a day of checking.
Building a working index. A table of document, date, author, recipients and a one line description of the personal data it contains gives you the spine of your review. You then work down it making decisions, rather than rediscovering the file each time you open a new folder.
Spotting third party data. AI can flag pages where someone other than the requester is named or described, so those pages go into your redaction pile rather than slipping through. It flags; you decide.
Drafting the correspondence. Acknowledgement letters, clarification requests where the scope is genuinely unclear, and the covering letter that goes out with the disclosure can all be drafted quickly, then checked and adjusted by the person responsible.
Recording the reasoning. A note that sets out what was searched, what was found, what was withheld and on what basis is worth having if the request turns into a complaint. AI can assemble the first version of that note from the decisions you have already made.
Where a person has to decide
Do not delegate any of the following, even partially:
- whether a document or part of a document is privileged;
- whether an exemption applies and how far it extends;
- whether third party information can be disclosed, and what balancing was done;
- whether the request is manifestly unfounded or excessive;
- the final content of what leaves the building.
The risk with redaction in particular is asymmetric. An over redacted response can be challenged and corrected. An under redacted one has already disclosed someone else's personal data, and you cannot take it back. Treat AI output on redaction as a candidate list, and check every page yourself before it goes out.
A workflow that holds up
- Log the request and the date it was received, in the system the firm actually relies on. Do not let a tool's internal record become the only record.
- Define and write down the scope, including which files, mailboxes and systems are being searched and which are not, and why.
- Use AI to search the papers you have gathered and produce a page level index of where the requester's personal data appears.
- Review the index yourself. Look for gaps: a file that returned nothing at all usually means the search missed something, not that the file is empty.
- Make the exemption, privilege and third party decisions document by document, and record them as you go.
- Apply redactions and check the redacted set page by page before release.
- Keep the reasoning note on file with the response.
One practical point on scanned material. Old files often contain faxes, handwritten attendance notes and poor photocopies. If a tool silently skips a page it cannot read, your index is incomplete and you will not know. Insist on knowing which pages could not be read, and read those yourself.
Where Alesis fits
Alesis answers questions about a matter from the matter's own papers and names the page each answer came from; if the papers do not say, it says so. Documents are read page by page, so citations point at pages, and any page it could not read is flagged rather than skipped. It prepares drafts for a qualified person to review and sign off; it does not file, serve or email anything. The firm's information is held in the UK and processed only in the UK and the EU, kept apart from every other firm, and never used to train anything for anyone else.