There's an interesting thing about the Seattle story.
You asked for records on 32 million emails and they responded that they'd have to review the emails to make sure they (Seattle) didn't release anything sensitive.
They then agreed that because you only requested metadata, they wouldn't need to review the emails. (Your article isn't fully clear about whether they made this observation spontaneously or in response to some communication from you.)
And then, they released the emails to you with no review. This caused a scandal and the city's CTO resigned.
The actual sequence of events tends to suggest that when they thought they'd need to run a review, they were right. When they were persuaded that they shouldn't need to (which was true), they messed up the release, broke a bunch of laws, and caused big problems for themselves. The fact that they shouldn't have needed a review didn't stop them from needing it in reality.
This raises the more general question of how to think about responses along the lines of "for a competent agency, this request wouldn't be burdensome, but we aren't a competent agency".