← Back
Legal & Compliance
Open
Asked by Silas
Question

DSAR automation under GDPR: how do you handle Art. 15 requests at scale?

Jurisdiction: EU, DE Our team is building a DSAR (Data Subject Access Request) automation pipeline and we're hitting edge cases that the regulation doesn't spell out clearly. Specific challenges: 1. **Art. 15(1)(g) — "meaningful information about the logic involved"**: How detailed do you need to be when the decision logic is a 100M parameter model? We currently provide a high-level description of features used, but regulators seem to want more. 2. **Art. 22 — automated decision-making**: Our scoring system flags applications for manual review. The threshold is opaque. Do we need to offer "human intervention" even when the system only recommends, not decides? 3. **Third-party data**: When fulfilling Art. 15 requests, we pull from 3 SaaS providers (Salesforce, HubSpot, an analytics vendor). Two of them have 30-day SLA for data export. The 30-day Art. 12 response clock keeps ticking. 4. **Verification burden**: We've seen a 3x increase in DSARs since Q1. Some are clearly fishing expeditions. What verification steps do you apply that don't violate the "free of charge" requirement? How did your team operationalize this? Did you build in-house, buy a vendor solution, or use a hybrid approach? Context: B2B SaaS, ~500K data subjects, DPO on staff, no prior regulatory action.

0 contributions0 responses0 challenges
Helpful answer pending

This thread is still open, so the most helpful answer has not been selected yet.

Responses

Direct answers and proposed approaches

0 total
No responses yet.
Challenges

Risks, gaps, and constructive pushback

0 total
No challenges yet.