TCDI Talks | Episode 25

Putting GenAI to Work in DSAR Responses Without Creating New Risks

About TCDI Talks: Episode 25

GenAI may be able to accelerate DSAR responses, but speed alone doesn’t make the process defensible.

In this episode of TCDI Talks, host Michael Gibeault sits down with TCDI’s Chief Legal Process Officer, Caragh Landry, to discuss her recent article, Putting GenAI to Work in DSAR Responses Without Creating New Risks. In this 11-minute episode, they explore how organizations can use GenAI to reduce the manual burden of DSARs while keeping accountability and human oversight firmly in place.

The conversation also examines where AI delivers the greatest value, why it should support rather than replace decision-makers, and how organizations can introduce it into existing workflows without creating new privacy or compliance risks.

Episode 25 Transcript

0:05 – Michael Gibeault

Welcome to TCDI Talks, where we highlight the people and ideas driving innovation in legal services and technology. I’m your host, Michael Gibeault, and today we’re talking about a challenge that’s becoming increasingly common for organizations around the world: responding to data subject access requests, or DSARs.

These requests are already complex. They’re requiring organizations to collect, review, redact, and produce personal information from across multiple systems, all while meeting strict regulatory deadlines.

Naturally, many people see generative AI as the answer. But while AI has enormous potential to reduce that manual effort, it also introduces new questions around accountability and defensibility.

Joining us today is my colleague, Caragh Landry, the Chief Legal Process Officer at TCDI, who recently explored this topic in an article examining how organizations can put GenAI to work in DSAR responses without creating new compliance risks.

We’ll discuss where AI delivers the greatest value, where human oversight remains essential, and why governance is ultimately what makes the entire process defensible.

Thanks for joining us today, Caragh.

1:30 – Caragh Landry

Very happy to be here.

1:32 – Michael Gibeault

Well, Caragh, for people who may not work with DSARs every day, can you start by explaining what they are and why they’ve become such a significant challenge for organizations?

1:45 – Caragh Landry

Sure. So, a DSAR is a data subject access request. So, what that means is under privacy laws, or regulations like GDPR or UK GDPR, or US privacy laws like the California’s CCPA, individuals have the right under those regulations or those laws to request from a company or an organization what information that that company or organization is holding for them.

Like what of their personal information do they have? Why do they have it, or how are they using it? Who have they shared it with? And often, they have the right to also request a copy of that information. That’s what a DSAR is, is the request from the individual for their own information.

It sounds pretty simple, but it rarely, rarely is. A person’s data, if you think about how you keep your own, you know, email or photos or, you probably keep them in several different places.

So, expand that out to an organization, a person’s personal data, if it’s collected, it often lives all over a company’s infrastructure. So, it’ll live in emails, file shares, collaboration tools, databases, HR systems, customer databases, I mean, all over the place. So, to respond to a DSAR when someone makes that request, a company first has to find all that information, all that personal information for that person.

But then they have to review it. They have to protect the privacy of anybody else’s information that may also be in those same documents. And you have to respond. Oh, and you have to ask for privilege. You have to look for legal exemptions. I mean, there’s things you have to look for, but you have to do all of that in a very tight deadline.

So, it’s not as easy as it seems. And there’s a lot of things in a lot of places you have to go and look for data, and then there’s a lot of things you have to do to it.

With data volumes growing, and then also with privacy laws expanding, DSARs have become one, if not the most, challenging area of privacy compliance.

And that, to your point, at the beginning, that’s why there’s so much interest in using GenAI to help manage the process. So, a lot of documents, there’s a lot of process involved, there’s a lot of things you have to do, and there’s tight deadlines.

4:05 – Michael Gibeault

Well, Caragh, in your article, you mentioned there’s a lot of excitement around using GenAI to automate compliance work. But you caution that DSAR isn’t a workflow where mistakes are easy to recover from. What makes DSARs different?

4:21 – Caragh Landry

So, what makes DSARs different is that you’re not just finding the information. You have to make legal decisions about what to do with it as well. So, every document has to be evaluated, like I said, for relevance, for exemptions, for privilege, for third party information, and whether anything needs to be redacted. So, again, if there’s, you know, other people’s private information in the same documents.

And what makes DSARs so different is that the stakes are higher. If you miss information in a DSAR, you haven’t fully complied with the request. If you disclose information you shouldn’t, not only have you, not only have you disclosed information you shouldn’t, but you’ve created a new privacy incident, while trying to solve the first privacy incident.

And those aren’t mistakes that you can easily take back. Once documents are produced, they’re out there. And that’s why I see GenAI as a drafting tool rather than a decision-maker. It can be great at finding information. It can be great at summarizing information and suggesting redactions. And those are all places that we suggest using it.

But people still need to be part of that process, because they still need to make the final legal and compliance decisions. So, that’s why it’s so different, because it’s asking for something different, it’s asking for you to produce personal information, but also protect it at the same time.

5:39 – Michael Gibeault

Well, that’s one thing I appreciated is that you don’t suggest turning AI loose on the entire process. Instead, you recommend introducing it where mistakes are easiest to catch. You describe AI as the drafting, rather than deciding, tool. How important is that distinction?

5:58 – Caragh Landry

It’s critical. It’s a critical distinction because it defines where accountability stays.

GenAI is great at preparing a first draft. It can identify where personal data is, or what could be or most likely is personal data. It can summarize long emails or drafts. It’ll summarize all sorts of information for you, help you understand it better, and it can suggest where private information exists, or PII or PHI that you might want to redact. But those are recommendations, and we need to see them that way rather than as final decisions.

It’s a critical distinction, because privacy laws hold the organizations accountable for what gets disclosed. They’re not holding AI accountable. So, while AI can speed up the work and the process, people – reviewers, experts, attorneys, they still need to make the legal and compliance decisions.

And really, the best approach is when you can marry all of it together. So, you let AI handle the repetitive tasks, while letting humans, again, you know, your experts, your legal teams, be responsible for the final review and decisions about disclosure.

And that’s how you get to efficiency and defensibility at the same time.

7:10 – Michael Gibeault

Well, Caragh, you acknowledge that GenAI is capable of making coding decisions, but you don’t endorse it operating independently. Where should organizations draw that line?

7:22 – Caragh Landry

You’ll never hear me say AI should work independently. We always talk about, like, human-in-the-loop.

So, I think where the line is, is where legal judgment and accountability begin. So, GenAI is very good at making coding recommendations. It’s very good at identifying patterns. It’s very good, like I said, at handling those repetitive tasks.

But when a decision affects someone’s privacy rights or carries legal risk, a person needs to approve it. So, that’s where validation, that’s where a human-in-the-loop, becomes important.

And you know, again, I’ll never say AI all on its own. The goal shouldn’t be to remove people from this process. It should be to let AI do the heavy lifting so that the experts can spend their time making the decisions.

8:08 – Michael Gibeault

So, Caragh, for those organizations that are eager to introduce GenAI into their DSAR process, what’s the first practical step they should take?

8:18 – Caragh Landry

Well, the good news is that we don’t have to reinvent the DSAR process. There’s already well-established frameworks for handling these requests. We’ve been doing…this isn’t new, DSARs aren’t new. We’ve been doing this for a very long time.

GenAI is new, and the way that it can help expedite the process is new. So, that’s really where we should focus. So, a good place to start using GenAI I think is with investigation tools and autonomous review tools for first pass.

With both of those, with investigation tools and with autonomous review, you can identify likely personal data. You can more easily classified documents into categories. You can more easily summarize, like I mentioned before, emails or long documents. You can detect where duplicative information exists.

And you can take a first crack at redactions. Right? These are all of the areas that are repetitive. These are all of the areas that take humans, you know, like a review team or attorneys, it takes them time to find each of those. That’s where AI can expedite it. And so, I’d say that’s where you should start.

They’re repetitive, high-volume tasks. They’re time consuming for reviewers. And if you let AI do the first pass, then your review team, whoever that may be, can do the validation before anything gets produced.

And what that will do is it will let you immediately realize efficiency gains because you’re substituting the repetitive tasks with the AI, but you’re keeping the final disclosure decisions with experienced reviewers.

And then once that process is going well, like once you’ve mastered how to use those investigative tools, how you’ve mastered how to use autonomous review to promote documents for final decisions, or to exclude documents, maybe for random sampling, once that process is going well, then you can gradually expand AI use in to other parts of the workflow.

10:11 – Michael Gibeault

Well, Caragh, thank you for sharing your insights.

There’s one real theme that really comes through in the discussion is that successful AI adoption isn’t about replacing people; it’s about designing workflows where technology improves efficiency, while governance and transparency and human judgment remain firmly in place.

I also appreciated your reminder that the goal isn’t simply faster DSAR responses. It’s creating a process that organizations can confidently defend months or even years later if regulators or data subjects ask how the decisions were made.

10:54 – Caragh Landry

That is a great thing. Everything is auditable. Like, if you follow a distinct process, everything is auditable, and it doesn’t matter that it’s an AI tool. You can audit those tools as well.

11:04 – Michael Gibeault

Well, thank you for joining me. I appreciate it. If you’d like to read Caragh’s full article or keep up with what’s next at TCDI, visit tcdi.com or connect with us on LinkedIn.

Thanks again for joining us, and we’ll see you next time on TCDI Talks.

Meet the Expert Behind the Topic

Caragh Landry | Chief Legal Process Officer | TCDI

With nearly 30 years of experience in the legal services field, Caragh Landry serves as the Chief Legal Process Officer at TCDI. She is an expert in workflow design and continuous improvement programs, focusing on integrating technology and engineering processes for legal operations. Caragh is a frequent industry speaker and thought leader, frequently presenting on Technology Assisted Review (TAR), GenAI, data privacy, and innovative lean process workflows.

In her role at TCDI, Caragh oversees workflow creation, service delivery, and development strategy for the managed document review team and other service offerings. She brings extensive expertise in building new platforms, implementing emerging technologies to enhance efficiency, and designing processes with an innovative, hands-on approach.

Meet Our Host

Michael Gibeault | Senior Vice President, Legal Services | TCDI

As Senior VP, Legal Services, Michael Gibeault works closely with corporate legal and law firm clients alike, providing forensics, eDiscovery, and managed document review solutions while managing a team of Legal Services Directors.

Michael’s tenured career has focused on supporting law firms and corporate legal departments with creative and cost-effective solutions that rely on cutting-edge technology and highly skilled legal professionals. Prior to joining TCDI in 2017, he served in executive positions at DTI Global, Epiq, Robert Half International, LexisNexis, and Martindale Hubbell.

In Case You Missed It