dsar-response

Drafts compliant Data Subject Access Request acknowledgment and substantive response letters.

Updated May 19, 2026
One-click install
npx skills add https://github.com/jrhueiueng/codex-for-legal --skill dsar-response-jrhueiueng
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dsar-response
Source: https://github.com/jrhueiueng/codex-for-legal/tree/main/plugins/jrhueiueng/codex-for-legal/skills/privacy-legal__dsar-response
Command: npx skills add https://github.com/jrhueiueng/codex-for-legal --skill dsar-response-jrhueiueng

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps you handle a Data Subject Access Request (or deletion/portability/correction request) by producing a regulator-ready, attorney-reviewable workflow and drafting the required acknowledgment and substantive response letters.

Core Features & Use Cases

  • DSAR intake and right classification: Determines which privacy right(s) the requester is invoking and checks escalation triggers (e.g., litigation posture, unusual scope, regulator involvement).
  • Configured DSAR process orchestration: Uses your practice-level CLAUDE.md DSAR process (systems list, identity verification method, SLA/clock expectations).
  • Jurisdiction-aware exemption analysis: Frames exemption research with citation and verification expectations, and flags uncertainty for attorney review.
  • Two-letter drafting: Generates a prompt acknowledgment letter plus the substantive response letter(s), without sending externally.

Quick Start

Run the dsar-response flow by issuing /privacy-legal:dsar-response and pasting the DSAR request email content for drafting.

Frequently Asked Questions about dsar-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I draft a compliant response to a Data Subject Access Request?

A DSAR response requires classifying the privacy right invoked, verifying requester identity, locating data across systems, applying jurisdiction-aware exemption analysis, and generating acknowledgment plus substantive response letters for attorney review.

What is the two-letter workflow for handling privacy requests?

The two-letter privacy request workflow generates a prompt acknowledgment letter upon DSAR intake, followed by a substantive response letter detailing access, deletion, portability, or correction outcomes without sending externally.

How does jurisdiction-aware exemption analysis work for DSAR responses?

Jurisdiction-aware exemption analysis frames legal exemption research with citation and verification expectations based on configured jurisdiction assumptions, flagging uncertainty for attorney review before finalizing the substantive DSAR response.

Can I use configured DSAR process assumptions for identity verification?

Yes, configured practice-level DSAR process assumptions including systems lists, identity verification methods, and SLA clock expectations orchestrate compliant handling of right to be forgotten and access requests.

When should I route DSAR escalations for attorney review?

Route DSAR escalations for attorney review when escalation triggers like litigation posture, unusual request scope, or regulator involvement are detected during intake and right classification.