First of all, where are you located? Can this be enforced at all? What would happen if you just ignored?
Second, don’t you have a month to respond?
Third, aren’t you allowed to charge a reasonable fee? I suspect 99% of these requests go away if you charge $50, which seems reasonable if it takes someone more than 15 mins to respond.
Fourth, how do you validate the identity of the requester? Email addresses can be spoofed, so that’s not sufficient. Can you make them jump through another hoop to prove who they are?
I think my approach (if I wasn’t going to just ignore) would be to to spend the next month to prepare a form letter to match theirs that’s as vague and non-specific as the law allows, and then just be able to plug in a few pieces of info for that specific user, if needed. And then I’d charge them a fee AND make them verify their identity somehow. I think 99.99% of them would go away. And yes, they’ll file complaints. Which puts me right back at: if I wasn’t in the EU, I’d just ignore this and point them to my privacy policy.