← Back to blog

The $1,524 GDPR Tax: Why DSAR Fulfilment Belongs in Your Platform, Not Your Spreadsheet

Stefan Gimeson··5 min read

A single GDPR Data Subject Access Request — a DSAR — costs the average company around $1,524 to fulfil manually (Gartner via K2view; the figure has ticked upward from the earlier $1,406 estimate as scope and staff cost have grown). Someone exports a CSV, searches the support tool, digs through application logs, stitches it together, and hopes nothing was missed. Eight to twelve hours per request. And volume is up more than 70% since 2021, with DataGrail's 2024 Data Privacy Trends report clocking a 246% jump in two years.

That's the operational tax most teams quietly pay — and the one we kept seeing small EU teams treat as a fire drill. Discovered two weeks before launch, hand-rolled into a spreadsheet, left to rot. So we built the answer into the platform.

Compliance, by construction

Every Eurobase project ships with a Compliance tab. Three surfaces, all wired up the moment your project exists. No add-on SKU, no separate dashboard, no integration to configure.

Data Export — GDPR Article 15 + 20

One click exports a full project, or scoped to a single user across every table they have touched. The platform understands the relationships — the user's rows in your tables, their auth identities, their files in storage, their entries in audit logs — and produces a structured, portable dump that satisfies both the right of access (Art. 15) and the right to data portability (Art. 20).

Or stay out of the loop entirely: end-users self-serve through the SDK with eb.auth.exportMyData(), rate-limited and audited. A $1,500 cost centre becomes a function call.

DPA Report — Article 30 Record of Processing Activities

Every controller has to keep a RoPA. The bigger question, though, isn't "can I get my data?" — it's "who can compel access to it?". 61% of Western European CIOs told Gartner they plan to move to local providers; EU sovereign-cloud adoption jumped from 30% to 40% in a single year per IDC. Microsoft's French executive told the French Senate, under oath, that they cannot guarantee EU data stays out of the reach of the US CLOUD Act.

Eurobase generates the RoPA from your project's actual configuration and the sub-processors actually in use — each entry flagged with region, encryption, and CLOUD Act exposure. For Eurobase itself, that exposure flag reads zero. By construction: EU-incorporated, EU-hosted (Scaleway, France), no US-controlled parent.

Audit Log

Append-only. Schema changes, RLS policy toggles, key rotations, vault reads and writes, role changes, DSAR exports — each entry stamped with timestamp, actor, IP, and target. Useful for the next security review. Also useful for the "who dropped that table at 3am?" conversation.

It's the same log we use ourselves for incident triage. We didn't bolt one on for compliance theatre; we exposed the one that was already there.

None of this is new regulation

Article 15 was published in 2016. Article 30 has been mandatory for almost every controller since 2018. The CLOUD Act passed the US Congress in March 2018. The only thing that's changed is the volume — 246% in two years — and the increasing willingness of regulators to actually enforce the response timelines.

The only question worth asking is whether you hand-roll the response the fortnight before launch, or whether your platform just does it.

Sovereign by construction, documented by default

This is what we mean when we say Eurobase is GDPR-native. Not a privacy policy on the marketing site. Not an "enterprise tier" upcharge. The articles of the regulation map directly to surfaces of the product — and they're on every project from day one, including the free tier.

If you're a developer, founder, or CTO who's been quietly dreading what your DSAR response looks like under load — that's the cost centre we made into a function call. Sign up — the Compliance tab is on your first project.