dsar-response

Draft non-sent DSAR response letters with exemption analysis and audit log.

Updated May 15, 2026
One-click install
npx skills add https://github.com/az9713/claude-for-legal-tutorial --skill dsar-response-az9713
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dsar-response
Source: https://github.com/az9713/claude-for-legal-tutorial/tree/main/privacy-legal/skills/dsar-response
Command: npx skills add https://github.com/az9713/claude-for-legal-tutorial --skill dsar-response-az9713

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps privacy teams handle a Data Subject Access Request (including deletion, portability, and correction requests) by walking through the end-to-end DSAR workflow and producing attorney-review-ready response drafts.

Core Features & Use Cases

  • Type the request and identify escalation triggers for unusual scope, litigation involvement, or regulator attention.
  • Verify the requester’s identity using the configured DSAR process posture to reduce misdelivery risk.
  • Locate data system-by-system using the preconfigured DSAR systems list, including handling processors and backup considerations.
  • Perform exemption analysis with citation discipline and explicit attorney review gates for anything that could be wrong or jurisdiction-specific.
  • Draft two letters—a prompt acknowledgment and a substantive response—without sending anything, plus a DSAR audit log checklist.

Quick Start

Paste the DSAR request (or the relevant email text) and ask the skill to draft the acknowledgment and substantive DSAR response letters for attorney review.

Frequently Asked Questions about dsar-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a DSAR response letter and when do I need to draft one?

A DSAR response letter addresses a Data Subject Access Request for access, deletion, portability, or correction. You need to draft one when a user submits a request or invokes right to be forgotten rules, requiring identity verification, exemption analysis, and substantive response generation.

How do I draft a privacy-compliant DSAR response with exemption analysis?

To draft a DSAR response, paste the request text to classify the right, verify identity, locate data system-by-system, and perform structured exemption reasoning with pinpoint citations. The workflow outputs non-sent acknowledgment and substantive letters plus an auditable DSAR log for attorney review.

Can I use an automated DSAR workflow for right to be forgotten requests across different jurisdictions?

Yes, the DSAR workflow locates applicable jurisdiction rules via a configured research connector. It applies structured exemption reasoning with explicit attorney review gates for jurisdiction-specific elements, ensuring right to be forgotten requests are handled compliantly before producing draft letters.

Does the DSAR drafting process handle data discovery across backup systems and processors?

DSAR data discovery uses a preconfigured systems list to locate data system-by-system, including handling processors and backup considerations. This structured data discovery ensures all relevant systems are checked and documented in the auditable DSAR log before drafting the substantive response.

What are the limitations of automated DSAR response drafting?

Automated DSAR drafting does not send letters directly; it outputs non-sent drafts plus an audit log checklist. It requires attorney review gates for anything potentially wrong or jurisdiction-specific, meaning legal professionals must validate exemption analysis and citations before final delivery.

Why does my DSAR workflow require identity verification before generating response letters?

Identity verification is required in the DSAR workflow to reduce misdelivery risk. Using the configured DSAR process posture, it confirms the requester's identity before data discovery and exemption analysis begin, ensuring compliant handling of access, deletion, portability, and correction requests.