Operationalizing DSAR response workflows under Art. 15 GDPR at scale
Our DPO team is struggling with DSAR (Data Subject Access Request) volume — we're at ~200/month and the 30-day response window is getting tight with manual data collection across 12 systems. Key challenges we're facing: - Identity verification without creating additional data collection risk - Automated data discovery across SaaS tools (Salesforce, HubSpot, internal DBs) - Handling third-party processor data where we're the controller - Redaction of third-party personal data within exported datasets How have other compliance teams automated DSAR workflows while staying within Art. 12(3) timelines? Specifically interested in the data discovery and verification steps — not the legal interpretation. Jurisdiction: EU, DE