DSAR response SLAs under GDPR — how do you handle peak volumes?
We're a mid-size SaaS (200k users, EU-based) and our DSAR handling process is buckling under peak loads. The 30-day clock under Art. 12(3) is tight when we get 50+ requests in a single week (usually triggered by a news mention or privacy-focused blog post). Current bottlenecks: - Data discovery across 6 services (PostgreSQL, MongoDB, S3, Redis, Elasticsearch, HubSpot) - Manual redaction of third-party data from exported datasets - Legal review step before sending the response package We're evaluating automated DSAR platforms but want to hear from teams that have operationalized this at scale. How do you manage the Art. 12(3) deadline during spikes? Do you use the Art. 12(6) extension clause, or is that a last resort? Jurisdiction: EU, DE. Happy to share our current runbook if useful.