dsar-response

Draft GDPR-style DSAR response letters through a verification and exemption workflow.

Updated Dec 4, 2025
One-click install
npx skills add https://github.com/PolliticalSolutions/political-portal --skill dsar-response-polliticalsolutions
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dsar-response
Source: https://github.com/PolliticalSolutions/political-portal/tree/main/.claude/skills/privacy-legal/dsar-response
Command: npx skills add https://github.com/PolliticalSolutions/political-portal --skill dsar-response-polliticalsolutions

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps you handle a Data Subject Access Request (or related rights like deletion, portability, or correction) by guiding the end-to-end process of verification, locating data across systems, analyzing legal exemptions, and drafting regulator-ready response letters.

Core Features & Use Cases

  • Request classification and escalation: Determine which right(s) are being invoked and route for escalation when risk triggers apply (e.g., litigation hold, opposing counsel, regulator involvement).
  • Identity verification workflow: Calibrate verification steps to the request risk level, and pause/adjust if identity cannot be confirmed.
  • System-by-system data locating plan: Use a configured systems list to determine where data must be searched and what to include/exclude.
  • Exemption analysis for attorney review: Propose exemptions with explicit “requires attorney review” notes, and require documentation for any withholding.
  • Two-letter DSAR output: Draft a prompt acknowledgment letter and a separate substantive response letter without sending them.

Quick Start

Paste the incoming DSAR request content and ask the Skill to draft both the acknowledgment and substantive response letters for attorney review.

Frequently Asked Questions about dsar-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I draft a GDPR data subject access request response letter?

Draft a GDPR data subject access request response letter by classifying the invoked right, verifying identity, locating data across systems, analyzing exemptions, and generating acknowledgment plus substantive drafts for attorney review.

What is the process for handling a right to be forgotten request?

Handling a right to be forgotten request involves classifying the deletion right, calibrating identity verification to risk level, searching configured systems for data, proposing exemptions, and drafting substantive response letters without sending them.

What's the best way to manage DSAR deadlines and identity verification together?

Manage DSAR deadlines and identity verification by running a deadline-aware workflow that calibrates verification steps to request risk level, pausing or adjusting the process if identity cannot be confirmed before drafting responses.

Can I apply legal exemptions when drafting privacy request response letters?

Apply legal exemptions during privacy request response drafting by proposing applicable exemptions with explicit attorney review notes, requiring documentation for any withheld data before producing the substantive response letter.

How do I locate personal data across multiple systems for a portability request?

Locate personal data for portability requests by using a configured systems list to determine where data must be searched, identifying what to include or exclude from each system before drafting the response.

Does the DSAR drafting workflow flag requests that need escalation?

The DSAR drafting workflow flags requests for escalation when risk triggers apply, such as litigation hold, opposing counsel involvement, or regulator engagement, before proceeding with standard response drafting.