dsar-response

Process Russian DSAR workflows with Federal Law 152-FZ compliance requirements.

17|4|Updated May 25, 2026
One-click install
npx skills add https://github.com/AlsKozlov/ru-legal --skill dsar-response-alskozlov
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dsar-response
Source: https://github.com/AlsKozlov/ru-legal/tree/main/packs/data-protection/skills/dsar-response
Command: npx skills add https://github.com/AlsKozlov/ru-legal --skill dsar-response-alskozlov

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Russian personal data operators face strict fines from RKN for mishandling data subject access requests (DSAR) under Federal Law 152-FZ, including missed deadlines, incorrect identity verification, incomplete responses, or accidental disclosure of third-party personal data.

Core Features & Use Cases

  • End-to-end DSAR workflow: Guides users through every step of processing a DSAR, from request type identification to final response sign-off and audit trail documentation.
  • Regulatory compliance built-in: Includes mandatory 152-FZ requirements, correct deadline calculations (30 days general, 10 working days for consent withdrawal, 7 working days for correction), exemption rules, and up-to-date RKN fine scales.
  • Real-world case patterns: Provides examples of common RKN violation patterns (late responses, unmotivated refusals, accidental data leaks) to help users avoid repeat mistakes.
  • Use case: A company receives a request from a customer to delete their personal data; use this skill to verify the requester's identity, locate all relevant data across company systems, assess applicable retention exemptions, draft a compliant response, and update the internal audit trail.

Quick Start

Use the dsar-response skill to process the pasted data subject personal data request from your user and draft a fully compliant 152-FZ response letter.

Frequently Asked Questions about dsar-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I process a data subject access request under Russian 152-FZ?

To process a data subject access request under 152-FZ, you must verify the requester's identity, locate data across systems, assess retention exemptions, and draft a compliant response letter with mandatory DPO sign-off and RKN audit trail documentation.

What are the RKN response deadlines for different DSAR types?

RKN response deadlines for DSARs under 152-FZ include 30 days for general requests, 10 working days for consent withdrawal, and 7 working days for data correction requests. Correct deadline calculation is required to avoid regulatory fines.

How do I verify identity and avoid third-party data leaks during a DSAR?

Verify identity and avoid third-party data leaks during a DSAR by applying strict identity verification protocols and cross-system data localization checks before drafting any substantive response, preventing accidental disclosure of third-party personal data.

When should I refuse a personal data deletion request under 152-FZ?

You should refuse a personal data deletion request under 152-FZ only when applicable retention exemptions apply. Perform an exemption assessment to ensure the refusal is legally motivated, as unmotivated refusals are common RKN violation patterns penalized by fines.

What are common RKN violation patterns for mishandling data subject requests?

Common RKN violation patterns for mishandling data subject requests include missed deadlines, incorrect identity verification, incomplete responses, unmotivated refusals, and accidental disclosure of third-party personal data. Avoiding these requires end-to-end compliant workflow management.

Can I use a DSAR workflow skill for Russian legal compliance if I am not a DPO?

You can use a DSAR workflow skill for Russian legal compliance even if you are not a DPO, as it guides you through regulatory requirements, exemption rules, and response drafting, but mandatory DPO sign-off is still required for final approval.