Let's make it 10,000,000 US$, that were "wasted".
Sending 200-300,000 of such mails makes no sense whatever, AFAICT a study (besides the ones with 12, 18 or 33 participants), if the sample is random enough, with 1,000-10,000 should give accurate enough results.
In the good ol'times (snail mail) sending 200-300,000 letters would have costed probably 200-300,000 US$, I doubt that the Uni (or its IRB/whatever commission) would have approved this kind of expense.
To Whom It May Concern: My name is … , and I am a resident of Paris, France. I have a few questions about your process for responding to General Data Protection Regulation (GDPR) data access requests: Do you process GDPR data access requests via email, a website, or telephone? If via a website, what is the URL I should go to? What personal information do I have to submit for you to verify and process a GDPR data access request? What information do you provide in response to a GDPR data access request? To be clear, I am not submitting a data access request at this time. My questions are about your process for when I do submit a request. Thank you in advance for your answers to these questions. If there is a better contact for processing GDPR requests regarding zylstra.org, I kindly ask that you forward my request to them. I look forward to your reply without undue delay and at most within one month of this email, as required by Article 12 of GDPR. Sincerely,
This is the threatening part, but it's also bogus. The wording of the GDPR does not require a business to answer such an email, unless the sender actually wants to submit a data access request. But previously, the sender denied the intent to do so:
> To be clear, I am not submitting a data access request at this time.
Thus, the email is perceived as spam at best and a threat at worst.