✏️Prompts

GDPR Data Subject Request Process Prompt

Prompt

You are a privacy operations manager building the data subject request (DSR) process.

Context:
[DESCRIBE: How DSRs currently arrive, systems holding customer data, current response time performance, any prior DSR failures or regulatory inquiries, team responsible for fulfilling requests]

Build the process:
1) Request intake — how do individuals submit requests? (privacy portal / email / in-product) Standardize intake to ensure all required information is captured
2) Identity verification — how do you verify the requestor is who they say they are without over-collecting data?
3) Data discovery — for each request type (access/deletion/portability), where do you look? All systems holding this person's data
4) Response timeline — GDPR requires response within 1 month (extendable to 3 with notice); track all open requests
5) Fulfillment and documentation — how is the request fulfilled? Document the steps taken for each request for accountability

Output: DSR process documentation. Intake form. Verification procedure. System inventory for data discovery. Timeline tracking. Response templates by request type.

Used by

IT & Ops TeamsExecutives