dsar-response

Drafts compliant Data Subject Access Request acknowledgment and substantive response letters.

Updated May 19, 2026
One-click install
npx skills add https://github.com/jrhueiueng/codex-for-legal --skill dsar-response-jrhueiueng
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: dsar-response
Source: https://github.com/jrhueiueng/codex-for-legal/tree/main/plugins/jrhueiueng/codex-for-legal/skills/privacy-legal__dsar-response
Command: npx skills add https://github.com/jrhueiueng/codex-for-legal --skill dsar-response-jrhueiueng

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps you handle a Data Subject Access Request (or deletion/portability/correction request) by producing a regulator-ready, attorney-reviewable workflow and drafting the required acknowledgment and substantive response letters.

Core Features & Use Cases

  • DSAR intake and right classification: Determines which privacy right(s) the requester is invoking and checks escalation triggers (e.g., litigation posture, unusual scope, regulator involvement).
  • Configured DSAR process orchestration: Uses your practice-level CLAUDE.md DSAR process (systems list, identity verification method, SLA/clock expectations).
  • Jurisdiction-aware exemption analysis: Frames exemption research with citation and verification expectations, and flags uncertainty for attorney review.
  • Two-letter drafting: Generates a prompt acknowledgment letter plus the substantive response letter(s), without sending externally.

Quick Start

Run the dsar-response flow by issuing /privacy-legal:dsar-response and pasting the DSAR request email content for drafting.

Frequently Asked Questions about dsar-response

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I draft a compliant response to a Data Subject Access Request?▼

A DSAR response requires classifying the privacy right invoked, verifying requester identity, locating data across systems, applying jurisdiction-aware exemption analysis, and generating acknowledgment plus substantive response letters for attorney review.

What is the two-letter workflow for handling privacy requests?▼

The two-letter privacy request workflow generates a prompt acknowledgment letter upon DSAR intake, followed by a substantive response letter detailing access, deletion, portability, or correction outcomes without sending externally.

How does jurisdiction-aware exemption analysis work for DSAR responses?▼

Jurisdiction-aware exemption analysis frames legal exemption research with citation and verification expectations based on configured jurisdiction assumptions, flagging uncertainty for attorney review before finalizing the substantive DSAR response.

Can I use configured DSAR process assumptions for identity verification?▼

Yes, configured practice-level DSAR process assumptions including systems lists, identity verification methods, and SLA clock expectations orchestrate compliant handling of right to be forgotten and access requests.

When should I route DSAR escalations for attorney review?▼

Route DSAR escalations for attorney review when escalation triggers like litigation posture, unusual request scope, or regulator involvement are detected during intake and right classification.