dsar-response

Generate DSAR confirmation and substantive response drafts with exemption reasoning.

183|37|Updated May 15, 2026
One-click install
npx skills add https://github.com/zhou210712/claude-for-legal-ZH --skill dsar-response-zhou210712
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dsar-response
Source: https://github.com/zhou210712/claude-for-legal-ZH/tree/main/privacy-legal/skills/dsar-response
Command: npx skills add https://github.com/zhou210712/claude-for-legal-ZH --skill dsar-response-zhou210712

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps privacy teams process personal data subject rights (DSAR) requests by guiding classification, identity verification, system-wide data locating, exemption analysis, and drafting both a confirmation letter and a substantive response.

Core Features & Use Cases

  • DSAR workflow guidance: Follows a structured process to categorize the request (access, copy/portability, deletion/account closure, correction, explanation, and related restrictions) and routes any upgrade triggers.
  • Identity verification and data-location planning: Uses the plugin’s DSAR process configuration and system inventory to ensure the requestor is verified and the relevant data sources are identified before drafting.
  • Exemption-aware drafting support: Produces response drafts that separately cover what will be provided or withheld, with exemption rationale marked for lawyer review.
  • Two-letter drafting: Generates an internal-review draft for an acknowledgment/confirmation letter and a separate substantive response letter within the required timelines.
  • Audit-ready recording: Ensures the process records key DSAR events such as receipt date, verification date, response date, provided/deleted items, and asserted exemptions.

Quick Start

Run /privacy-legal:dsar-response and paste the DSAR request email content (e.g., the subject access or deletion request details).

Frequently Asked Questions about dsar-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I draft a data subject access request response that includes identity verification and exemption analysis?

To draft a DSAR response, you must first classify the request type, verify the subject's identity, traverse your system inventory for data localization, and analyze applicable exemptions before generating reviewable confirmation and substantive response letters.

What is the process for handling privacy rights requests for data deletion and account closure?

Handling privacy rights requests involves categorizing the deletion or account closure demand, confirming identity verification requirements, locating data across systems, and drafting a substantive response letter with exemption rationale marked for lawyer review.

How do I manage cross-system data localization when responding to a data portability request?

Managing cross-system data localization for portability requests requires traversing a configured system inventory to identify all relevant data sources before drafting the response, ensuring all data subjects' requested information is located and accounted for.

Can I automate DSAR timing control and escalation triggers for subject access requests?

You can manage DSAR timing control and escalation triggers by following structured workflow guidance that categorizes the request and routes upgrade triggers, ensuring response drafts are produced within required timelines without sending them directly.

What do I need to configure before creating audit-ready records for personal data subject rights requests?

Before creating audit-ready records for DSARs, you need to load DSAR process instructions into your configuration and set up a system inventory to ensure receipt dates, verification dates, response dates, provided items, and asserted exemptions are accurately recorded.

Why are two separate letters generated when responding to privacy rights requests?

Two distinct letters are generated to separate the internal-review acknowledgment confirmation from the substantive response, ensuring that disclosed information and withheld exemption rationales are clearly marked for lawyer review within required timelines.