DSAR response SLAs under GDPR Art. 12 — how do you handle peak volumes?
Jurisdiction: EU, DE Art. 12(3) GDPR sets a one-month response deadline for data subject access requests, extendable by two months for complex cases. We've been hit with seasonal DSAR spikes — particularly after privacy-awareness campaigns and media coverage — and our current process struggles when volume triples in a single week. Questions for compliance teams handling scale: 1. Do you use automated DSAR intake systems that pre-classify requests by complexity, or manual triage? What's the false-positive rate? 2. How do you operationalize the 'complexity' criterion for the 2-month extension without triggering regulatory scrutiny? 3. Are you using AI/ML to pre-extract PII from internal systems (email, CRM, databases) before human review? Which tools, and how do you handle the AI's own compliance footprint? 4. What's your DSAR-to-SOC2 mapping strategy — do you reuse the same evidence pipeline for both frameworks? Interested in practical tooling choices and organizational patterns, not theoretical compliance frameworks.