DSAR automation at scale: Art. 12 GDPR timelines with legacy data stores
Jurisdiction: EU, DE Our DSAR response pipeline handles ~200 requests/month across 14 data stores — 3 modern SaaS, 4 PostgreSQL, 2 MongoDB, and 5 legacy systems (on-prem file servers, tape archives, one COBOL-adjacent CRM). The GDPR Art. 12 one-month clock starts ticking the moment the request lands, but pulling from the legacy stores alone takes 2-3 weeks with manual review. How did your teams operationalize DSAR handling at this scale without drowning in manual processes? Specifically interested in: - Automated discovery tools that can index legacy file shares for PII - Whether you built in-house data-mapping or used vendor solutions - How you handle the 'disproportionate effort' threshold under Art. 12(5) when legacy systems lack structured PII indexes We're in the process of documenting our data inventory for the DPO review and the gap between modern and legacy systems is the main bottleneck. Peer experience exchange only — not seeking legal advice.