GDPR Documents: Your Right to be Informed and Erased
github.com
github.com
With that in mind, a big blast is also easy to filter out.
Perhaps, instead of sending them all at once, you sent a random number from 1 to 100 per day, every day, indefinitely. No way to filter out the bogus requests, forced work for the company, and unknown consequences of having these people emailed about their private information usage. Chaotic good or chaotic evil? I have my opinion.
IANAL.
For example source of particular data point that I have not given myself (like phone number, etc.), and that is not publicly available.
Most of the answers to questions in the access request are usually available on the comapny's website already. And if you send generic sounding e-mail, you'll get a generic reply to read the privacy policy.
I wish the idea that all cookies require disclosure would die. Cookies don't require disclosure per-se. Stalking and tracking, regardless of method (whether it's a cookie, a token in the URL, in local storage, browser fingerprinting, etc) requires consent - cookies for functional purposes (hint: stalking doesn't count) don't require consent.
Also, as a non-EU resident, do I have any ability to make such a request? I suppose the answer is 'no' from a strictly legal standpoint, but is it possible in practice? Or will the company require a comprehensive verification process that precludes such illegitimate requests.
What we plan now is to finalize erase request, start translations into the most of European languages as well as create some static page for generating those PDFs via entering data via form ... (list of authorities to report would be also great - because, from my experience, most of the results of the request were fails (from the company side))