A user sends a message saying, "I want to know what data you have on me." There is no mention of the specific right being exercised, no user ID, and the email is from a generic Gmail account. Your organisation operates globally and is subject to both GDPR and CCPA.
How would you handle this request?
- What steps would you take to verify the identity of the requester?
- Would you treat it as a formal DSR? Why or why not?
- What would be your first response to this vague request?
Explain your approach clearly — think legal requirements, practical steps, and risk mitigation.