Earlier quoted context omitted.
I think I can count on one hand the number of right-to-be-forgotten requests the team I work with has ever received in the last three years (with 15x the users). We've had a couple more subject access requests than that, but we'd already shipped pretty comprehensive self-service tools for retrieving data that met the vast majority of our user's needs. This doesn't seem like an unreasonable thing to expect a service t…
Unsure of how you extrapolated the total number of users from my previous statements. We were a B2B SaaS where our customers each served 10,000s of end users, who also had access to our platform with their data stored within. In aggregate we’re talking 25mm+ total users in my case. At the time, being that the DPO role was new we didn’t know how many requests to expect. And while the law may allow for 30 days, our cus…
Doesn't that make you a data processor rather than a data controller - i.e. not at all your problem for your end user's end users?