DSAR response timelines under GDPR Art. 12 — handling ambiguous requests at scale
Jurisdiction: EU, DE We've built a DSAR intake pipeline that auto-classifies incoming requests by type (access, erasure, portability, objection). The tricky category is ambiguous requests — e.g., an email saying "I want to know what you have on me" without formal GDPR language, sometimes bundled with customer service complaints. Art. 12(3) mandates a one-month response window, but the clock only starts once you've positively identified the data subject. How do your teams handle the identification step without creating excessive friction? Do you use a standard identity verification template upfront, or triage first and request verification only when the scope is unclear? Looking for operational patterns, not legal interpretation.