Data subject request pack
Builds a traceable work pack for a data-subject access, correction, or deletion request, including search log, record inventory, redaction reasons, exceptions, and response draft. Use for DSARs, privacy rights requests, access requests, deletion reviews, or personal-data search packs.
Published Aug 21, 2026 · Updated Aug 26, 2026
Requirements
Add the company-specific reference document or policy to the corpus. Define required statuses, severity or priority values and escalation roles.
Skill document
The full SKILL.md your agent reads and follows.
Data subject request pack
Purpose
Turn a rights request and the supplied workspace records into an auditable inventory of personal-data hits, exemptions or redactions, deletion constraints, and a draft response.
Scope
Cover the request wording, identity and scope supplied for the run, data-system inventory, customer and employee records, support tickets, contracts, communications, retention policy, and prior response template.
Excluded: identity verification outside the supplied evidence, legal conclusions about local law, executing deletion, and sending the response.
Data basis
- Request document with requester name, identifiers, right invoked, date, and requested period.
- Record tables and documents containing names, email addresses, account IDs, ticket IDs, contracts, and correspondence.
- Retention schedule, privacy policy, redaction guidance, and response template.
Result
A search log, personal-data inventory, redaction/deletion decision table, and response draft with every inclusion and exclusion tied to a record or document citation.
Quality criteria
- Every declared search location has a searched/not-searchable status and reason.
- Every hit records data subject, source, record ID, data category, action, and citation.
- Third-party content, privileged material, and retention holds are not silently removed.
- The draft response reports unresolved searches and does not claim deletion occurred.
- Scope ambiguity is preserved as a question or exception.
Instructions
Search exact identifiers first, then document aliases supplied in the request; record the query term and result count. Distinguish the requester’s data from another person’s data in the same record. Apply only the supplied retention and redaction rules. For deletion, label each record “candidate for deletion”, “retain”, or “needs legal review” and name the rule or hold. Cite page, section, row, or record ID for every decision.
Adapt before use
- Add the company data map, retention schedule, redaction policy, and response template.
- Define approved identifiers, search locations, rights terminology, and escalation roles.
- Set the request date, response deadline, and local-law review boundary in the run input.
Related skills
- Claim chronology builder
Builds a dated chronology from claim notices, correspondence, contracts, invoices, incident records, and evidence logs, preserving source citations and disputed dates. Use for insurance claims, commercial disputes, incident files, demand packages, litigation chronologies, and internal fact reviews.
- Compliance training refresh
Updates compliance training modules against revised policies, identifies changed learner obligations, and creates source-linked lesson text, scenario questions, and an answer key. Use for annual compliance refreshes, policy changes, code-of-conduct training, and controlled learning-content updates.
- Contract obligation register
Extracts dated and recurring duties from signed contracts into an obligation register with parties, triggers, notice windows, service levels, payment terms, evidence, and owners. Use for contract lifecycle management, renewal tracking, vendor obligations, or inherited agreement cleanup.
- Contract playbook review
Reviews a commercial contract against a company playbook, records missing or non-standard clauses with exact citations, and proposes fallback positions. Use for procurement, sales, SaaS, services, and contract redline preparation.