I had to get historical bills from a terrible cellphone provider in Canada (Wind mobile, now Freedom mobile, now owned by Shaw communications) a little while back.
Their customer support process was useless (they'll send historical bills to third party organisations for stuff like background checks, but they're afraid that consumers will use the bills to prove that they're misapplying charges). Thinking I'd just just have to navigate their customer service departments, I started recording the calls (legal in my jurisdiction).
After several conversations with friendly but incredibly unhelpful CSRs (thanks to corporate policy), I started to look at other ways that I could get my info. I issued a formal request for all of my personal data under Canadian federal and provincial privacy laws (PIPEDA). Their legal department claimed that I issued the request incorrectly ("by email"), so I responded by citing the relevant clauses (never mind that there was a paper version that I sent at the same time). Then they made a couple of other similar claims (that PIPEDA doesn't apply to them, my reply was that telcos are specifically named).
Seeing that they were drawing things out, I started to respond with expansions to my request (asking for potentially damaging things like a list of who they intentionally or unintentionally disclosed my personal information to), and threatening to report the issue to the Privacy Commissioner of Canada.
Some combination here seemed to do the trick, someone from their corporate security department reached out to me by email, and had the authority and power to give me my data. They ended up charging me an exorbitant amount for the original request's export (and never actually fully complied with my request for disclosures), but I ended up getting what I wanted.
I now take the opportunity to share my experience whenever possible, and figure that these types of stories being out there (along with the potential customers they lose) will provide the financial incentive for them to change their processes long-term.
TL;DR: CS process first, then recording, then escalating the request slowly using privacy laws to your advantage, then expanding on the request to give them time pressure (that eventually you'll request data they legally have to provide but practically can't), then providing pressure to respond by threatening to take it to a federal regulatory body.