How AI is reshaping privacy access requests

29 September 2026 Richard Massey

Generative AI has made it easier than ever for individuals to exercise their access rights under the Privacy Act 2020, creating new challenges for organisations subject to the Act.

While an individual can now use a large language model to draft a detailed privacy access request in minutes, the organisation on the receiving end may need weeks to prepare the response. That imbalance is attracting attention overseas and is increasingly being felt by New Zealand businesses.

This article outlines the framework for access requests under the Privacy Act, examines how AI is changing the landscape, and considers the mechanisms available to help manage the resulting compliance burden.

IPP 6 - the right of access

Under Information Privacy Principle 6 (IPP 6) of the Privacy Act, an individual is entitled to request confirmation of whether an organisation (or “agency” in the language of the Act) holds personal information about them, and to request access to that information.

Agencies must generally respond within 20 working days. There are various grounds for withholding information, including where disclosure would breach legal professional privilege or would involve the unwarranted disclosure of the affairs of another individual.

In practice, identifying relevant information, applying redactions, and assessing whether exceptions apply can be an onerous exercise - particularly where information is held across multiple systems. The Office of the Privacy Commissioner (OPC) has noted in guidance that wide-ranging requests for “all information” held about an individual can be “taxing for agencies to process” and that “often the information is not that helpful for the individual.”1

The impact of AI

As consumers become increasingly familiar with generative AI tools, agencies are increasingly receiving requests that appear to be generated by AI tools - often lengthy and legalistic in tone, drafted to pre-emptively avoid possible withholding grounds, and broadly expressed to capture every conceivable category of personal information. Responses to such requests may often trigger prolonged follow-up questions (sometimes instantaneously) or further access requests that the agency must then consider and address.

Similar trends have been noted in other jurisdictions where equivalent rights exist. The UK Information Commissioner’s Office published guidance in May 2026 noting that AI-generated requests for information “can be very long, repetitive and contain unrelated comments or misdirected demands”, and “can be written in a way which makes it harder to identify the information being requested.”2

Managing the compliance burden

AI does not change the underlying obligations to respond to access requests, but it does require agencies to be more deliberate about how they manage requests. The Privacy Act contains several limits and mechanisms that take on particular significance in this context.

  • First, it is important to highlight that the Privacy Act requires “reasonable assistance”3 in the context of an IPP 6 request, which is an appropriately contained standard. An agency may also refuse access if, despite “reasonable efforts” to locate it, the information cannot be found. These limits help to show that while genuine engagement with the requestor is required, the Privacy Act does not require an exhaustive search in every case.

  • Second, an agency does not have to provide access if the information is not held in a way that is “readily retrievable.” That may be relevant in the context of a wide-ranging access request covering various systems or sources. The OPC has advised: “A lot of information is technically 'retrievable', but this isn’t necessarily the same as being ‘readily’ retrievable. For instance, even if information has been deleted from a computer, it can often be retrieved. Doing so, though, is often difficult, is a specialist job, and can be very costly. The results may also be imperfect, particularly if the information has been deleted some time ago.”4

  • An agency may refuse access where a request is frivolous or vexatious, or where the information requested is trivial. This may be relevant where an AI-generated request seeks plainly irrelevant information or appears designed to obstruct an agency rather than to obtain information for a legitimate purpose. However, agencies should be cautious about relying on this provision. A request is not vexatious merely because it was AI-generated, broad in scope, inconvenient, or expensive to answer.

Can you charge for your costs?

The Privacy Act permits private sector agencies to impose a reasonable charge for making information available in compliance with an IPP 6 request. However, the OPC has traditionally taken a narrow view of imposing charges which it sees as “the exception, not the rule”, and advises that a reasonable charge will often be lower than an agency’s actual costs in responding to a request.

The Privacy Act also notes that the cost of labour and materials involved in making the information available is a relevant consideration. In this respect, the OPC recommends that while an agency can charge for providing personal information, including time spent locating the relevant information and redacting information, it cannot charge for assessing whether to provide it and whether withholding grounds apply.

The OPC has previously relied on the Ministry of Justice’s charging guidelines for the Official Information Act as a reference point. Those guidelines were issued in 2002 and provide relatively modest figures (e.g. charges of NZ$38 per half hour of staff time) but applying the guidance on an inflation-adjusted basis may offer a helpful starting point. As AI-generated requests become more elaborate and regular, charging may assume greater practical significance.

Could AI be part of the solution?

For complex access requests, manually reviewing all potentially responsive documents can be a very time-consuming exercise and businesses should consider how to leverage technology to ensure compliance. Just as AI contributes to the creation of new requests, it can also help to reduce the compliance burden - by assisting with identifying responsive documents, deduplicating material, classifying records, and assisting with redaction. While decisions about privilege, third-party privacy and other withholding grounds require careful legal judgment, technology can at least accelerate some of the more mechanical aspects of responding to access requests.

If your business is finding that access requests are consuming disproportionate time and resource, we can help. Bell Gully has established expertise in managing complex access requests under the Privacy Act, including using AI solutions as part of the review process and drawing on our deep understanding of regulatory guidance and relevant case law. We can also advise on cost recovery mechanisms, helping to ensure that any charges imposed are defensible and appropriately documented.

If you would like to discuss how we can assist with access requests or other aspects of your privacy risk management processes, please contact the authors below or your usual Bell Gully adviser.


1How should agencies deal with ‘empty-your-pocket’ requests?
2UK ICO, Freedom of Information (FOI) and Artificial Intelligence, May 2026.
3Section 42 of the Privacy Act 2020.
4What does readily retrievable mean?


Disclaimer: This publication is necessarily brief and general in nature. You should seek professional advice before taking any action in relation to the matters dealt with in this publication.