Data subject requests sent via AI: What businesses need to bear in mind

Businesses are now increasingly receiving data subject requests that are automatically generated and sent by AI agents – such as requests for access or erasure. Such requests are legally valid and must be taken seriously. In principle, the request should be treated in the same way as any other data subject request: 

  • A request formulated by AI is valid if it clearly indicates which rights are being asserted, e.g. the right of access or erasure.
  • The statutory one-month time limit also applies to AI-generated requests.
  • The data subject’s identity must be verified. However, where there are reasonable doubts as to the data subject‘s identity, controllers may request additional proof. The requirements for identity verification increase in line with the sensitivity of the data concerned. If the data subject’s identity cannot be verified, the controller can refuse to provide the information.

Particularly when AI agents or service providers submit a data subject’s request, it may initially be unclear to the business whether the request actually originates from the data subject. If, in such a situation, information is provided without adequate identity verification, there is a risk of disclosing personal data to an unauthorised person. Such unauthorised disclosure may constitute a data protection breach.

To avoid data protection breaches resulting from the provision of incorrect information, the following options are possible:

  • The response to the request is sent to an e-mail address or postal address previously known to the controller, rather than to the AI agent or authorised service. Such information, which establishes a link to the request and thus to the data subject, may serve to facilitate further identification. We recommend this method of identity verification.
     
  • We require additional proof or identification, for example by asking the data subject to resend the request from the specified e-mail address for which the request is to be processed. When contacting the data subject directly for the first time, the e-mail correspondence with the AI or the AI agent should not be forwarded, as we cannot be certain that the request actually originated from the data subject.
     
  • Alternatively, the data subject may be asked to confirm their identity in another way, for example by providing a copy of a valid identity document (with irrelevant data blacked out where necessary).

AI-generated data subject requests require a careful verification of identity. Businesses should therefore put procedural safeguards in place to prevent misuse – without unnecessarily complicating the rights of data subjects. When in doubt, always request proof! This helps to avoid data protection breaches and ensures that legal obligations are met.