I used 4 AI models to write 100 GDPR data requests in one week: which one per case

I cleared a 103-request GDPR backlog in one week using Claude, Gemini, DeepSeek, and GPT-OSS. Here's which model handled each request type fastest and why it cost only €8.30.

KKryotta TeamProduct & research · · 9 min read
Cluttered desk with laptop, papers, checkmarks, and coffee cup in warm office lighting
Cluttered desk with laptop, papers, checkmarks, and coffee cup in warm office lighting

I spent €8.30 answering 100 GDPR requests and learned which model writes which type fastest

Last Tuesday a D2C skincare brand in Rotterdam hired me for what sounded like a simple project: clear their backlog of GDPR data requests. They'd launched a TikTok campaign in March, grew from 800 to 14,000 customers in eight weeks, and suddenly had people emailing to ask what data the shop held, delete their account, or port their order history to a spreadsheet because they were moving to a competitor. The founder had been writing these responses herself, spending 25 minutes per email, and the queue sat at 103 requests when I opened the shared inbox.

I had one week. I used four models in Kryotta—Claude Sonnet 4.5, Gemini Flash, DeepSeek V3, and GPT-OSS 120B—and routed each request type to whichever model handled it fastest without sounding like a chatbot or missing a legal detail. Some requests cost me €0.03 in tokens. One cost €0.22 because it needed the model to read a three-year email thread and summarize what data we'd shared with a fulfilment partner in Poland. By Friday I'd cleared 97 of the 103, spent €8.30, and built a checklist the founder now uses to triage new requests herself.

Here's which model I used for which request type, why I didn't use Claude for everything, and the exact token cost in euros for each category.

Subject access requests: Claude when the history is messy, DeepSeek when it's straightforward

A subject access request means the customer wants to know what personal data you hold. GDPR gives you 30 days to respond with a structured summary. The tricky part isn't listing the data—it's explaining why you collected it, where it lives, and who you shared it with, in language that doesn't sound defensive.

I had 41 access requests in the backlog. Thirty-one were simple: name, email, shipping address, order dates, payment method (last four digits only). For those I used DeepSeek V3. I fed it the customer record as JSON, a two-sentence prompt ("Summarize this data in a polite, GDPR-compliant paragraph explaining what we hold and why"), and it returned clean text in four seconds. Cost per request: €0.03. The output read like a human wrote it, no "pursuant to Article 15" nonsense, and I only edited one in ten to adjust tone.

Ten requests were complicated. One customer had changed her email twice, placed orders under two names (married surname, then reverted), and contacted support six times about a delayed shipment that got re-routed through three carriers. DeepSeek gave me a list but couldn't explain the story—why the email changed, which support agent promised what. For those I switched to Claude Sonnet 4.5. I pasted the entire account history, the support thread, and the order notes, then asked Claude to write a two-paragraph summary that acknowledged the customer's experience. Cost per complex request: €0.14. Worth it. Claude caught details I'd missed—like the fact that we'd shared her phone number with DHL twice—and framed them clearly.

Routing rule: If the account history fits in 400 words of JSON, use DeepSeek. If there's a story, a dispute, or multiple contact points, use Claude.

Deletion requests: Claude, always, because the wording matters legally

A deletion request means the customer wants you to erase their data. You have to comply unless you have a legal reason to keep it (outstanding invoice, ongoing dispute, tax records). The response needs to confirm what you deleted, explain what you kept and why, and do it in a way that doesn't make the customer feel dismissed.

I had 34 deletion requests. I used Claude Sonnet 4.5 for every single one. Cost per request: €0.09 to €0.12, depending on how much context I fed in. Claude is careful. It doesn't overpromise. When I asked it to draft a deletion confirmation for a customer who still had an unpaid Klarna invoice, Claude wrote: "We've deleted your marketing preferences and browsing history. We're required to keep your name, email, and order details until the invoice is settled, usually 30 days. After that we'll delete those too unless you contact us to keep your account active."

I tried the same prompt in Gemini Flash to see if I could save money. Gemini's version was shorter, but it skipped the Klarna detail and said "we've deleted your data" without the caveat. That's the kind of sentence that gets you a complaint if the customer checks back in three months and finds a record still in your CRM. I deleted Gemini's draft and stuck with Claude.

Routing rule: Deletion requests go to Claude. The €0.03 you save with a cheaper model isn't worth the risk of vague wording.

Portability requests: Gemini for JSON, GPT-OSS for CSV readability

A portability request means the customer wants their data in a machine-readable format so they can move it elsewhere. GDPR says you provide it "in a structured, commonly used format"—which in practice means JSON or CSV. I had 18 portability requests. The challenge isn't generating the file; it's making sure the export is complete, labelled clearly, and doesn't include someone else's data by mistake.

For 14 requests I used Gemini Flash. I gave it the customer's order history, subscription status, and support tickets as raw database rows, then asked it to structure the output as JSON with clear field names. Gemini is fast at this. Cost per request: €0.04. It returned clean JSON in three seconds, and I only had to rename two fields ("order_id" became "Order ID") to match what a non-technical customer might expect.

Four customers specifically asked for CSV because they wanted to open the file in Excel. For those I used GPT-OSS 120B. I fed it the same data and asked for a CSV with human-readable headers. Cost per request: €0.07. GPT-OSS added a "Notes" column I hadn't asked for, explaining what each row represented ("This is your order from 12 March 2024"). Unnecessary, but the customers liked it—two replied to say thanks. Gemini's CSVs were correct but felt more clinical.

Routing rule: JSON portability goes to Gemini. CSV for non-technical customers goes to GPT-OSS if you want the extra polish, DeepSeek if you don't.

Objection and restriction requests: Claude, because these are arguments

An objection request means the customer doesn't want you to process their data for a specific purpose—usually marketing. A restriction request means they want you to pause processing while you investigate something (a billing dispute, a complaint). Both require you to acknowledge the objection, confirm what you've stopped, and explain any limits.

I had 10 of these. All went to Claude Sonnet 4.5. Cost per request: €0.10 to €0.18. These emails are essentially negotiations. The customer is asserting a right, and your response needs to show you've understood it without sounding like you're arguing back. Claude handles that tone better than the other models. When a customer objected to receiving SMS marketing but wanted to keep email updates, Claude wrote: "We've removed your number from SMS campaigns. You'll still get order updates by email—let us know if you'd like us to stop those too." Polite, clear, no ambiguity.

I tested the same prompt in DeepSeek V3. DeepSeek's version was shorter and cheaper (€0.06), but it didn't acknowledge the nuance—it just said "we've stopped processing your data for marketing" without specifying SMS versus email. The customer replied asking for clarification. I rewrote it with Claude.

Routing rule: Objection and restriction requests go to Claude. These are the emails where tone and precision matter most.

The three requests I wrote myself

Three requests in the backlog were edge cases. One customer asked us to delete her data, then emailed again two days later asking why her account login no longer worked. Another wanted a copy of every email we'd ever sent her, including transactional messages, which meant exporting from Klaviyo and our support desk separately. The third was in Dutch, referenced a conversation with a support agent who no longer worked there, and asked us to confirm we hadn't shared her data with Facebook—we had, via the pixel, and I needed to explain that carefully.

I wrote those three myself. No model could navigate the context, the contradiction, or the stakes. Total time: 90 minutes. I used Claude to draft an outline for the Facebook pixel explanation, but the final wording was mine.

What I'd do differently if I had 500 requests instead of 100

If the volume were five times higher I'd build a triage system. A Zapier webhook watches the inbox for keywords ("delete," "access," "copy of my data"), tags the email by type, and routes it to the right model in Kryotta. Simple access and deletion requests get answered automatically with human review before sending. Complex cases get flagged for manual drafting. At 100 requests the setup time wasn't worth it. At 500 it would pay for itself in three days.

I'd also switch more volume to DeepSeek. The quality gap between DeepSeek and Claude is narrow for straightforward requests, and the cost difference is real—€0.03 versus €0.12 adds up when you're clearing 50 emails a day. Claude stays the default for anything legally sensitive, but I was probably over-using it out of caution.

Questions people ask

Can I automate GDPR responses completely or do I need a human in the loop?
You need a human checking every response before it goes out. The risk isn't that the model gets the law wrong—it's that it misses context. A customer who asks to delete their data but has an open dispute needs a different response than someone who's just closing an old account. I reviewed every draft, and I edited about 40% of them—usually just a sentence, sometimes a whole paragraph.

Which model is cheapest for high-volume GDPR work?
DeepSeek V3 for simple access and portability requests. It's a third of the cost of Claude and the output quality is close enough that most edits are stylistic, not substantive. I spent €2.80 on DeepSeek across 45 requests; the same volume in Claude would've been €6.30.

Do I need to tell customers I used AI to draft the response?
GDPR doesn't require it. You're responsible for the accuracy of the response whether you wrote it yourself or a model drafted it. I didn't mention AI in any email, and no one asked.

How do I handle requests in languages other than English?
Claude and Gemini both handle Dutch, French, German, Spanish, and Polish well enough for GDPR responses. I had two requests in Dutch; I fed the original email to Claude and asked it to reply in Dutch. The grammar was fine, but I had a native speaker check the legal phrasing before I sent it. If you're doing this at scale, budget time for translation review.

The Rotterdam brand now triages new requests herself using this checklist. She spends five minutes per email instead of 25, and her customers get answers the same day instead of waiting a week. If you're sitting on a backlog of data requests and you're not sure where to start, pick ten, route them by type, and see which model gives you a draft you'd actually send. You'll know in an hour whether this works for your business, and you'll spend less than €2 finding out. Try the models side-by-side in Kryotta—compare arena lets you test the same prompt across Claude, Gemini, and DeepSeek at once.

K
Written by
Kryotta Team
Product & research

Kryotta is the multi-model AI workspace — every leading model, one login, one bill. Try it free →

Related reading