How Generative AI Creates New Personal Data Challenges

Navigating Special Cases in Personal Data for DSARs
Summary 

Generative AI can create new personal data challenges by producing additional records from information provided by users. Organizations need to consider AI prompts, outputs, conversation histories, and stored information when responding to DSARs. Careful review and redaction of third-party information can help protect privacy while ensuring organizations meet their data protection obligations. 

How Generative AI Creates New Personal Data Challenges 

Generative AI is increasingly being used to create content, summarize documents, analyze information, and support everyday business tasks. However, these systems can also introduce new personal data risks, particularly when employees use personal information in prompts or upload documents containing sensitive data. 

AI-generated outputs may contain personal information from the data provided to the system, creating additional records that may need to be considered when handling a Data Subject Access Request (DSAR). Organizations should understand where AI-related data is stored, who can access it, and how long it is retained. 

When responding to a DSAR, relevant AI prompts, outputs, conversation histories, and related records may need to be identified and reviewed. Redactions may be required where outputs contain personal information relating to other individuals, while applicable exemptions should also be considered. 

Organizations should establish clear policies for using generative AI, maintain appropriate data governance, and ensure employees understand what personal information can be entered into AI tools. A structured approach can help businesses benefit from AI while reducing privacy risks and maintaining DSAR compliance.