European Organisations Are Falling Behind on DSARs as GenAI Expands the Search
Fewer than half of DSARs meet the GDPR deadline, and GenAI tools now rival email as a source. See what Logikcull's benchmark of 213 European teams found.

Consider a routine data subject access request (DSAR). A former employee asks for a copy of their personal data, and the privacy team knows where to begin: the HR file, the mailbox, a handful of Teams chats. Then it emerges that the business piloted Copilot last quarter and that managers have used ChatGPT to draft performance reviews. The request now reaches systems nobody has searched before as the 30-day clock races down.
Scenarios like this are fast becoming the norm. They do not reflect a team doing something wrong, per se, but a process designed for a smaller problem. To measure how wide that gap has grown, Logikcull conducted a benchmark study surveying 213 senior privacy, legal and compliance leaders across the UK, Ireland, France, Germany and the Netherlands. The findings point consistently in one direction: DSAR volume and complexity have outgrown the way most organisations handle them.
Privacy Teams Have Become the Workaround
The Information Commissioner’s Office (ICO) received more than 76,000 data protection complaints in 2025-26, up from 42,315 the year before, and the right of access is the single largest category in its published complaints data, accounting for 43% of cases completed in Q3 2025-26. At the EU level, the European Data Protection Board and European Data Protection Supervisor issued a joint opinion in February 2026 opposing Digital Omnibus changes that would narrow the GDPR’s definition of personal data. Whatever the Omnibus’s final text, this benchmark measures organisations against Article 15 as it stands today under the EU and UK GDPR.
Most organisations have absorbed that pressure through individual effort rather than infrastructure. 86% have no dedicated DSAR tool, and only 24% describe their process as fully standardised and repeatable. Ownership is fragmented: IT and security most often lead (45%), narrowly ahead of the privacy or DPO team (40%) and legal (39%). A process like this holds together because people hold it together, until a surge in volume or a new data source exposes its limits.
GenAI Tools Now Rival Email as a DSAR Source
Email used to be the obvious place to start. It still is, but it has company. GenAI tools like ChatGPT, Copilot and Gemini now sit alongside email as among the most common sources organisations must search, at 35% each, just ahead of messaging apps like Slack and Teams at 34%.
The shift in data sources is already showing up in DSARs. Nine in 10 organisations have received a DSAR seeking data held in a GenAI tool, more than double the 35% that routinely search those tools. That gap matters because a DSAR can reach any system containing relevant personal data, including systems that may not yet be part of a standard search workflow.
The Delay in Response Lies in Locating Data
Here’s the frustrating part: once a request is actively worked, organisations move fast. The average response takes just under seven days, though nearly 30% take one to two weeks or longer. Yet, on average, only 47% of DSARs are completed within the standard one-month window, while 53% require an extension.
So where does the month go? The top reasons deadlines slip are difficulty locating relevant data sources (38%), slow manual redaction or third-party review (36%), and delays from third parties or processors (36%). The challenge is often operational: finding and coordinating the relevant data quickly enough to meet the statutory clock.
Spend Tracks Complexity, Not Request Volume
Nine in 10 respondents are confident their DSAR process would withstand ICO or DPA scrutiny, despite the relatively low level of process standardisation and the fact that fewer than half of requests meet the one-month deadline.
Ireland shows the widest gap: just 10% of Irish respondents describe their process as fully standardised, while 86% remain confident. The findings suggest that confidence and process maturity do not always move together. Whether that confidence has been tested through regulatory scrutiny is a separate question.
What the Findings Suggest
None of this necessarily points to negligence. These organisations are working in good faith against an obligation that has outgrown many of the tools and processes built to meet it. The opportunities for improvement are largely operational:
- Map data sources before committing to a deadline. Difficulty locating data is the most cited reason DSARs run late.
- Consolidate ownership into a single workflow. Each handoff between IT, security, privacy and legal is another point at which a request can stall.
- Treat GenAI as a standing search target. Most organisations have already received a GenAI-related DSAR, but only around a third routinely search those tools.
- Reduce system complexity before increasing budget. Higher spend does not guarantee a standardised process.
DSAR Handling: Frequently Asked Questions
What is a DSAR, and why has it gotten harder to manage?
A data subject access request (DSAR) is a request from an individual, under Article 15 of the GDPR, to obtain a copy of the personal data an organisation holds about them. Organisations must respond within one calendar month of receipt, extendable by up to two further months for complex or numerous requests. The personal data covered by a DSAR continues to spread across systems, including the GenAI tools employees use for work.
Why do organisations miss the one-month deadline so often?
The main challenges are operational: locating relevant data, completing manual redaction or review, and coordinating with outside processors. These steps can consume time before a request is ready for final response.
Do organisations need a dedicated DSAR tool?
Most organisations still manage without dedicated tooling. Yet the manual steps that technology can help address, particularly locating data and redacting it, are among the leading reasons requests run late. A DSAR platform checklist can help teams evaluate the options.
Logikcull was built for this problem. It connects directly to the systems where data lives, including Microsoft 365, Google Workspace and Slack, and surfaces personal data automatically instead of requiring someone to already know where to look. More than 600 legal, IT, HR and infosec teams already use it to respond to DSARs faster and more consistently, without routing every request through outside counsel.
Read the full State of DSARs in Europe report for the complete country, industry, and company-size breakdowns.
Learning With Logikcull
Browse our latest resources for innovative legal teams like yours
Stay in the know
Get the latest news, expert guidance, and interviews delivered straight to your inbox so you're always one step ahead.
Get the latest updates
Want to see it work?
Request a demo today.
Managing FOIA requests with limited staff, strict deadlines, and pressure to protect sensitive data?
Logikcull is built for this.


%20(1).png)