DSAR response SLAs under GDPR — how do you handle peak volumes?
Jurisdiction: EU, DE Under GDPR Art. 12(3), DSAR responses are due within one month, extendable by two months for complex cases. Our team processes ~200/month normally, but after a data-breach announcement last quarter we hit 1,800 in two weeks. How are compliance teams operationally handling DSAR spikes without breaching the statutory deadline? Our current approach: - Automated identity verification (email-based challenge + optional ID upload) - Template responses for standard access requests (export of stored data categories) - Triage queue with manual escalation for complex cases (data shared with third parties, legal holds) Specifically interested in: - How you justify the Art. 12(3) extension to data subjects without triggering complaints - Whether you involve your DPO in every extended-case notification or delegate - Tools you use for data discovery across SaaS silos (Salesforce, HubSpot, Slack, etc.) This is peer experience sharing — not a request for legal advice.