Right, but nothing stops companies from refusing SARs on baloney grounds. Complain to a DPA? They tell you to go through ADR or outright ignore you. Complain to Ombudsman? They'll tell you the same. (In my experience, the Dutch do this)
Company ignores ADR? Sure, now you can go through the legal route and spend copious amounts of money all because a multi billion dollar company knows the game and how to navigate the bureaucratic mess better than you.
This. In reality, GDPR isn't preventative, nor punitive enough for any meaningful user protection. We get cookie banners everywhere and user data harvesting companies happily pay the negligible fines
Yep, this is how they do it. The domain registrar netcup did something like this to me.I went through their parent company (?) too, without success. They will put forth any reason to not have to delete your data. I suspect, that they either are trying to reduce work for themselves, or their platform is so crap internally, that they would have to get someone coding to delete the data.