Access Granted: How the DSAR Became a Stress Test for Your Entire Data Estate
Editor’s Note: Data subject access requests have moved from the periphery of privacy compliance to the center of legal, HR, and information governance operations, and the organizations fielding them are feeling the strain. Employee-driven requests now account for roughly two-thirds of all DSARs; volumes are climbing 40 to 60% year over year, and generative AI (GenAI) is making requests broader, sharper, and harder to fulfill. In a recent HaystackID® hosted webcast, experts from data intelligence, global privacy practice, and in-house legal leadership examined why the traditional, reactive approach to DSAR response is breaking down. Their discussion covered the rise of the weaponized access request, what regulators examine when they test a response, and how AI-enabled workflows borrowed from eDiscovery can deliver speed without sacrificing defensibility. This article distills the key insights from that conversation for legal technology, privacy, and compliance professionals. The takeaway is a practical one: the organizations that treat each request as a diagnostic rather than a fire drill will spend less, risk less, and build a durable data governance capability in the process.
Access Granted: How the DSAR Became a Stress Test for Your Entire Data Estate
By HaystackID Staff
The data subject access request (DSAR) has quietly changed jobs. Article 15 of the EU and UK GDPR, echoed in California, Brazil, and a lengthening list of jurisdictions, framed the right of access as a transparency measure: an individual asks what an organization knows about them, the organization discloses it, and a compliance box gets ticked.
For years, that description held. A customer requested their profile and purchase history. From there, whoever owned privacy that year—legal, compliance, sometimes IT—pulled structured records from known systems, and the file closed.
That version of the DSAR still exists. It just no longer describes most of what lands in the inbox, a shift that industry professionals examined at length in a HaystackID® webcast, “The Rising Tide of DSARs: Transforming Access Requests from Compliance Burden to Strategic Capability,” moderated by HaystackID’s Ryan Costello, EVP of Global Advisory and Client Engagement, Advisory Group, with a panel drawn from data intelligence, global privacy practice, and in-house legal leadership.
Their collective diagnosis: the data subject access request has outgrown its reputation as a routine compliance chore. It now functions as a stress test of an organization’s entire data estate, and most organizations are taking it unprepared, one expensive scramble at a time.
Two-Thirds of Requests Come from Inside the Building
The numbers tell the first part of the story, and Costello laid them out early in the program. Of all DSARs reported annually, 67% now come from current employees, former employees, or job applicants. More than 70% of EU and UK organizations have fielded at least one employee-driven request, and total request volumes are climbing 40 to 60% year over year.
That shift matters because customer DSARs and employee DSARs place very different demands on an organization. When a customer asks an airline for their data, the response draws mostly on structured systems: a customer profile, purchase history, and loyalty records. The organization knows where that data lives and can pull it cleanly. An employee request extends into unstructured territory: email, chat platforms, performance discussions, and—most uncomfortably—conversations about the requester conducted by others. A rocky exit or a disputed review can put years of internal commentary within scope.
Patrick Zeller, FIP, CCEP-I, General Counsel, JetStream Security, watched the curve bend in real time.
“When CCPA and CPRA went into effect in California, I was at a company. We built the processes to respond. We did not see very many. And then over time, we’ve seen those numbers skyrocket. We’ve also been seeing an increase in the number of requests from attorneys on behalf of clients,” he said during the webcast.
That last detail—attorneys filing on behalf of individuals—hints at where the trend leads. More on that shortly.
Generative AI Writes Better Requests, Too
Requesters have discovered a new drafting assistant. Esther Birnbaum, EVP of Legal Data Intelligence at HaystackID, who helped build our company’s AI-enabled DSAR response workflow, sees GenAI reshaping both sides of the exchange.
“When requesters are using GenAI, they are able to really understand the scope of what they’re able to request,” she explained. “And that could be a good thing or a bad thing because I’ve seen DSAR requests that are basically throwing the book at you and say, ‘Every mention of an employee in a company needs to be produced,’ which is just a huge burden and usually negotiated down.”
The same technology that helps an ex-employee draft a maximally broad request also generates a new category of responsive data. If HR data feeds an internal enterprise GPT, employee information may now surface in AI-generated answers to routine queries, and those outputs may fall within scope. Zeller pushed the point further: companies deploying Copilot and similar tools rarely consider whether AI search queries need to be preserved for investigations, litigation, or access requests. Every hour, every employee generates more data, and much of it sits outside traditional retention thinking.
“DSARs are really, really interesting right now because they sit at that intersection of privacy, data governance, defensibility, execution, and now also AI. Because everything’s AI now, right? And that’s a very, very busy intersection,” said Christopher Wall, DPO and Special Counsel for Global Privacy and Forensics, HaystackID, during the webcast. “We see near misses. We see collisions. We see fender benders every day at that intersection.”
Wall also flagged the arrival of so-called DSAR trolls, requesters hunting for lapses in response, and the potential windfall those lapses present.
When the Bill Arrives, Read It as a Symptom
Complexity converts directly into cost. A customer request that draws on structured systems stays contained. An employee request that spans email, chat platforms, and shared drives, sometimes across jurisdictions, often with counsel on both sides, can cost an order of magnitude more to fulfill. With volumes climbing 40 to 60% a year, a manual, non-repeatable response process becomes a budget line no one ever approved.
Wall argued that the mounting expense is a symptom, not the disease.
“DSAR is analogous to a patient who shows up presenting with chest pain,” he said. “The underlying condition might be heartburn, but it might also be sclerosis, congestion, or an organization’s inability to quickly locate, validate, and then manage personal data across its systems. So, until that underlying heart condition can be addressed, the organization’s going to continue to have those high costs every time that they receive a data subject request.”
Birnbaum named the disease outright: information governance work that everyone acknowledges, and nobody funds. Every large company harbors messy data somewhere, she noted, and that mess is the real problem behind every DSAR: where does the data live, and can you find it in time to produce it? A botched response also carries a second-order risk beyond immediate cost. Non-compliance lands on a data protection authority’s radar, and a regulator who starts digging into one bad DSAR response rarely stops there.
Wall pressed the point to its practical conclusion: defensible deletion and data minimization remain the single biggest cost lever an organization controls. Data that no longer exists never enters scope; there is nothing to search, review, or redact.
Discovery by Another Name
Then there is the question of why these requests arrive at all. Workplace disputes, contested exits, and pre-tribunal positioning drive a large share of employee DSARs. The panel called this what it is: pre-litigation discovery wearing a privacy costume.
“Very often the DSAR requests are used as really pre-litigation discovery,” Birnbaum observed. “So, they are weaponized, even though that’s not the intention… It might just be the starting point for some greater action.”
Zeller, a former federal computer crimes prosecutor, drew on a familiar precedent. Courts, he noted, long ago blessed the use of Freedom of Information Act requests to supplement discovery in the government context, and he sees no reason access requests will play out differently. He also posed the question that should keep response teams honest: What happens when a company answers a DSAR with ten documents, litigation follows, and discovery produces hundreds of pages about the same person?
The delta between those two productions becomes an exhibit.
“If your response to one of these data subject requests is different from what you end up producing in discovery, you’d better have a good reason for why that is,” said Wall, drawing the operational conclusion. “And that comes down to your documentation of your processes and making sure that you can demonstrate that you took all reasonable steps to respond to that DSAR in the first place.”
What Regulators Actually Read First
What does a defensible response look like from the regulator’s chair? Not, primarily, the production itself. Wall’s view: enforcement begins with the question of what documented processes existed before the request arrived, whether the organization followed them consistently, and whether it recorded each step along the way. The deliverable comes second. The process record comes first because it reveals whether the organization ever took the obligation seriously.
Zeller offered the image of the giant red insurance umbrella: organizations need to operate under “the red umbrella of good faith,” and regulators can spot its absence at a glance.
“It’s pretty easy to look at a file and tell how much work was put into this, right? Do you have anything from Slack or Teams or whatever else the company is using? … It’s very easy to tell if somebody’s just phoning it in and printing a couple of pages,” Zeller said.
A response drawn solely from a tidied-up HR folder, from an organization whose litigation productions routinely span a dozen data sources, tells a regulator everything. Birnbaum added the tempering note that perfection is not the standard—demonstrated diligence is. Given the burst of new data types, technologies, and obligations organizations have absorbed in just a few years, regulators understand that no response will be flawless. What they expect to see is the effort: the policies, the procedures, and the documented good faith that a polished-looking but unsupported response never conveys.
40,000 Documents, Five Runs, Less Than 1% Deviation
The panel’s prescription borrows heavily from a discipline legal technologists already know: eDiscovery, and it pairs the technology with the same expert judgment that discipline has always demanded.
In practice, contested employee DSARs usually get negotiated down to a familiar shape: find the data relevant to the underlying dispute that contains the requester’s personal information, then redact everything else, often under punishing redaction requirements and a response clock that, in some jurisdictions, runs as short as 30 days. That is a relevance review followed by a redaction pass, and Birnbaum and her colleagues run both with GenAI. A low-cost model handles first-pass relevance and auto-redaction—but the model never has the last word. Expert human reviewers validate every output before anything moves toward production.
The inevitable audience question arrived mid-hour: if a regulator challenges an AI-assisted response, how do you defend it as complete? Document the methodology, audit every step, validate with sampling, recall, and precision; the same statistical toolkit the industry built for technology-assisted review. Birnbaum’s old test for project teams: could you write a defensibility memo covering the entire process, from collection through redaction? If the answer is yes, the workflow holds.
She then turned the skepticism around, pointing to a validation exercise her team ran on a live workflow. They ran the same set of data with the same model with the same prompts with 40,000 documents five times, and a standard deviation of less than 1%.
GenAI output, she argued, faces a higher evidentiary bar than human review ever did, and clears it more measurably.
Zeller landed on the same principle from the buyer’s side of the table, wrapped in a joke.
“Everybody’s heard that AI is working with a really smart intern. I would argue it’s like working with a really smart intern who’s dating the son or daughter of the CEO, so you need to be careful what you’re doing. You need to have an expert in the loop and document what you’re doing.”
You Can’t Repeat a Scramble
Strip the jargon from “scalability”—a word the industry has worn thin—and what remains is consistency: a process that, in Wall’s terms, “works just as well on your busiest day as it does on the quietest day.” Same steps, same documentation, whatever the volume. A scramble, however heroic, never clears that bar, because a scramble cannot be repeated.
When treated as an isolated fire drill, every DSAR costs too much and leaves behind a little more regulatory exposure and another discovery inconsistency. Treated as a diagnostic—a symptom pointing to data-mapping gaps, bloated retention schedules, and ungoverned AI output—the same request becomes the business case for information governance work that legal and privacy teams have struggled for years to fund. The obligation stays the same either way. The return on it does not.
How does a team that has lost this funding argument before win it now? Zeller’s advice from the webcast was to let the organization’s own numbers testify: track the trajectory of incoming requests and what each one actually consumes, and build the case on that curve rather than on industry statistics.
And the case is broader than DSARs. Readiness here, Wall noted, pays out “through enforcement and into discovery, into litigation, and into information governance across the board”—the same data map, the same documented processes, the same defensible workflows serve every one of those obligations.
The heart attack, to close Wall’s metaphor, becomes the catalyst for healthy living. The requests are coming regardless. The only open question is whether the next one triggers a scramble or a workflow.
About HaystackID®
HaystackID® solves complex data challenges related to legal, compliance, regulatory, and cyber requirements. Core offerings include Global Advisory, Cybersecurity, Core Intelligence AI™, and ReviewRight® Global Managed Review, supported by its unified CoreFlex™ service interface and eDiscovery AI™ technology. Recognized globally by industry leaders, including Chambers, Gartner, IDC, and Legaltech News, HaystackID helps corporations and legal practices manage data gravity, where information demands action, and workflow gravity, where critical requirements demand coordinated expertise, delivering innovative solutions with a continual focus on security, privacy, and integrity. Learn more at HaystackID.com.
Assisted by GAI and LLM technologies.
SOURCE: HaystackID
Advisory Note: As DSAR volumes climb and employee-driven requests grow more complex, organizations need response capabilities that combine speed, precision, and defensibility across vast stores of structured and unstructured data. HaystackID’s DSAR Response Service integrates legal and regulatory expertise with advanced artificial intelligence, powered by Core Intelligence AI Case Insight™, a GenAI matter intelligence engine that enables rapid identification, classification, and redaction of personal data at scale. The service follows a structured five-phase framework—from request scoping and forensic-grade collection through AI-enabled review, redaction, and delivery—ensuring repeatable, defensible results within demanding regulatory timelines. Expert validation and human-in-the-loop oversight anchor every phase, so responses withstand scrutiny from regulators and opposing counsel alike. Combined with HaystackID’s deep expertise in information governance, data privacy, eDiscovery, and cross-border advisory services, these capabilities help organizations transform DSAR compliance from an operational burden into a scalable, strategic advantage.