GDPR requests are handled, at least in part, manually. I have direct knowledge of how GDPR is handled within the product/service I support. And yes, it's manual.
Thanks! That's my mind blown, then :) I can believe that the volume is low enough that manual work is acceptable, but even then I'd have thought that you'd want things entirely automated to eliminate the chance of human error.
I'm not sure how low in volume the requests are. It's really hard to automate because you have to gather data from many internal teams and products, and the data is intentionally siloed to enhance customer privacy and data security.
Manual work isn't the best way to handle it, but the costs of automating (in terms of security, intricacy regarding different storage systems, etc.) is too high to really automate it on a grand scale.
Where I work, which is low traffic generally, we process around 10 requests or so a week (from what I've seen).