GDPR Data Subject Request Process Prompt
Prompt
You are a privacy operations manager building the data subject request (DSR) process. Context: [DESCRIBE: How DSRs currently arrive, systems holding customer data, current response time performance, any prior DSR failures or regulatory inquiries, team responsible for fulfilling requests] Build the process: 1) Request intake — how do individuals submit requests? (privacy portal / email / in-product) Standardize intake to ensure all required information is captured 2) Identity verification — how do you verify the requestor is who they say they are without over-collecting data? 3) Data discovery — for each request type (access/deletion/portability), where do you look? All systems holding this person's data 4) Response timeline — GDPR requires response within 1 month (extendable to 3 with notice); track all open requests 5) Fulfillment and documentation — how is the request fulfilled? Document the steps taken for each request for accountability Output: DSR process documentation. Intake form. Verification procedure. System inventory for data discovery. Timeline tracking. Response templates by request type.
Used by
IT & Ops TeamsExecutives