TL;DR: Data subject requests are shifting from simple access lookups to deletion-heavy, cross-platform workflows that must reach cloud, SaaS, collaboration tools, and AI systems, according to BigID. The governing issue is no longer response intent but discovery, scope, and defensible execution across fragmented personal data estates.
NHIMG editorial — based on content published by BigID: How Data Subject Requests Have Changed
By the numbers:
- 36% of consumers had exercised their data subject access rights, up from 28% the year before.
- 46% of consumers aged 25 to 34 had exercised these rights, compared with just 16% of those 65 and older.
- 60% of organizations reported an increase in DSARs year over year, according to EY Law survey data cited by BigID.
Questions worth separating out
Q: How should organisations handle deletion requests across cloud, SaaS, and AI systems?
A: Treat deletion as a distributed workflow, not a manual case.
Q: Why do employee data subject requests create higher legal risk?
A: Employee requests often arrive alongside disputes, termination issues, or counsel involvement, which raises the need for precise search boundaries and stronger evidence.
Q: What breaks when privacy teams rely on manual DSR workflows?
A: Manual workflows break when request volume rises, data is scattered across systems, and search quality depends on individual knowledge.
Practitioner guidance
- Map personal data to identity and system ownership Build an inventory that ties data stores to accountable owners, system types, and search paths across cloud, SaaS, collaboration tools, and AI systems.
- Automate deletion and opt-out workflows Use workflow controls that execute across source systems, downstream recipients, and audit logging so the same request is handled consistently at scale.
- Include unstructured and AI content in discovery scope Expand search logic to email, chat, shared drives, recordings, prompts, and outputs so personal data is not missed outside databases.
What's in the full article
BigID's full article covers the operational detail this post intentionally leaves for the source:
- Cisco consumer survey breakdowns that show how request behaviour differs by age group and why demand is rising.
- California Delete Act DROP operational requirements, including cascading deletion, suppression, and downstream service-provider handling.
- Employee DSAR handling considerations tied to disputes, retention, and legal review under tighter evidence expectations.
- Practical examples of how discovery, classification, and fulfilment workflows are structured across complex environments.
👉 Read BigID's analysis of how data subject requests have become harder to fulfill →
Data subject requests are getting harder to fulfill manually?
Explore further
Discovery is now the control plane for privacy execution. The article shows that DSR failure is less about intent and more about incomplete discovery across modern data estates. Once personal data sits in collaboration suites, AI systems, and distributed SaaS, the programme depends on identity-aware classification and inventory discipline, not manual case handling. That aligns closely with the same visibility problem seen in NHI governance. If you cannot locate what exists, you cannot govern what it can do. Practitioner conclusion: build discovery as a control, not as a support function.
A question worth separating out:
Q: Which controls help prove that a data subject request was handled properly?
A: Strong proof comes from end-to-end logging, clear ownership, repeatable search criteria, and policy-based workflow execution. Organisations should be able to show what was searched, what was removed, what was exempted, and why. Without that evidence chain, even a completed request can remain vulnerable to complaint or challenge.
👉 Read our full editorial: Data subject requests are outgrowing manual privacy workflows