One of us was a DPO at a Danish public-sector agency. A former employee asked, under Article 15, for every photo on file. Standard request. The answer should have taken a day.
It took twenty-three. Six systems, two cloud drives, a SharePoint older than the GDPR itself. Spreadsheets, screenshots, second-guessing. The PDF that finally went out was almost certainly incomplete. Nobody could prove otherwise — including the regulator.
We looked for the tool. The market had two flavours: enterprise face-recognition platforms designed for surveillance, and consumer photo apps designed for grandparents. Nothing in between for a compliance officer with a 30-day clock and seven systems to search.
So we built it.