Loading...
Loading...
Walk through a Data Subject Access Request (or deletion, portability, correction request) and draft the response — verify identity, locate data system-by-system, assess exemptions, draft the acknowledgment and substantive response letters. Use when a DSAR comes in, the user pastes an access/deletion/portability/correction request, or says "DSAR came in", "access request", "right to be forgotten", or "someone wants their data".
npx skill4agent add anthropics/claude-for-legal dsar-response~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md/privacy-legal:dsar-response
[paste the request email]## Matter workspacesEnabled✗/privacy-legal:matter-workspace switch <slug>practice-levelmatter.md~/.claude/plugins/config/claude-for-legal/privacy-legal/matters/<matter-slug>/Cross-matter contexton~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md## DSAR processNo silent supplement. If a research query to the configured legal research tool returns few or no results for the jurisdiction's rights, exemptions, or deadlines, report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: "The search returned [N] results from [tool]. Coverage appears thin for [regime / right]. Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be taggedand should be checked against a primary source before relying, or (4) flag as unverified and stop. Which would you like?" A lawyer decides whether to accept lower-confidence sources.[web search — verify]Source attribution tiering. Tag every citation with its source. For model-knowledge citations, use one of three tiers rather than a single blanket "verify" tag:
— stable, well-known statutory and regulatory references unlikely to have changed (e.g., GDPR Art. 33, CCPA § 1798.100, FTC Act § 5, 45-day CCPA response window under § 1798.130(a)(2) as a concept). Still verify before filing, but lower priority.[settled] — model-knowledge citations that are real but should be verified: specific implementing regulations, agency guidance, case holdings, thresholds, effective dates, post-2023 amendments.[verify] — pinpoint citations (specific subsection letters, volume/page numbers, paragraph numbers, regulatory subpart references) carry the highest fabrication risk and should ALWAYS be verified against a primary source.[verify-pinpoint]Tool-retrieved citations keep their source tag (,[Westlaw], or the MCP tool name); web-search citations remain[issuing authority site]; user-supplied citations remain[web search — verify]. The tiering surfaces the real verification work — a reader who verifies everything verifies nothing. Never strip or collapse the tags.[user provided]
~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.mdWe were unable to verify that this request came from the individual whose data
is at issue. To proceed, please [verification step]. We cannot provide personal
data in response to a request we cannot verify.~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md| System | Queried? | Data found? | What |
|---|---|---|---|
| Production database | |||
| Analytics (e.g., Mixpanel, Amplitude) | |||
| Support tickets (e.g., Zendesk) | |||
| CRM (e.g., Salesforce, HubSpot) | |||
| Email marketing (e.g., Marketo) | |||
| Logs | |||
| Backups | (note: usually exempt from deletion — see below) | ||
| Third-party processors | (they may need to be notified for deletion) |
Research-connector pre-flight. Before emitting either letter or the internal exemption analysis, check whether a legal research connector is reachable for this session — Westlaw, an EUR-Lex / regulator-site connector, or any firm-configured research MCP. Collect this into the reviewer note per CLAUDE.md— the reviewer note sits on the INTERNAL exemption-analysis and cover memo, NOT on the outward-facing DSAR letters to the data subject. If no connector returns results in Step 1 (right classification), Step 4 (exemption analysis), or the Deadline management research step (or none is configured at run time), record it in the Sources: line of the internal reviewer note — e.g.,## Outputs. Per-citationnot connected — cites from training knowledge; claimed exemptions, response deadlines, and extension mechanisms are especially fabrication-prone, verify before asserting any exemption to a data subject or regulatortags remain inline. Do not emit a standalone banner above the output.[model knowledge — verify]
## Who's using this~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.mdSending a DSAR response has legal consequences — the content, the exemptions claimed, and the omissions are all reviewable by a regulator, and misstatements become enforcement exposure. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:[Generate a 1-page summary: data subject, right invoked, applicable regime(s), what was located across the systems list, what is being withheld and under which exemption, identity verification posture, response deadline, and the three things to ask the attorney before the letter goes out.]If you need to find a licensed attorney, solicitor, barrister, or other authorised legal professional in your jurisdiction: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).
Note: Both DSAR letters are externally-facing deliverables sent to the data subject. Do not include the work-product header from~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.mdon either letter. Internal notes, logs, and exemption analyses that accompany the letters are attorney work product — keep those separate and prepend the work-product header per## Outputs~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md(which differs by user role — see## Outputs).## Who's using this
Before sending either letter: This is a draft for attorney review, not a response to send. Sending commits the controller to a position, may waive exemptions, and may start a regulator's clock. A licensed attorney reviews, edits, and approves before either letter goes to the data subject. Do not send unreviewed.
Subject: We received your privacy request — [Company] — [date]
Dear [Name],
We received your [access / deletion / portability / correction] request on [date received].
**Your request, as we understand it:** [one-sentence restatement — e.g., "a copy of all personal data we hold associated with your account, along with the categories of third parties with whom we share it, and deletion of your account after we provide the copy."]
**What happens next:**
- Our target date for the substantive response is [date — no later than the regime's statutory deadline; use internal SLA if tighter]. [If identity verification is outstanding: "We need [specific verification step] before we can proceed — see below."]
- If we need more time because the request is complex or we receive other requests from you at the same time, we will tell you before the initial deadline and explain why. [If the regime allows an extension, cite the controlling provision.]
- No fee applies to this request. [Or: the fee applies only if the regime permits it and the request is manifestly unfounded or excessive — cite the provision.]
[If identity verification is outstanding:]
**To verify your identity,** please [specific verification step — e.g., reply to this email from the address on file with the last 4 digits of the payment method we have on file]. This does not pause our deadline; we continue to work in parallel.
If you have questions, contact [privacy contact].
[Sender]Subject: Your Data Access Request — [Company] — [date]
We received your request on [date] for a copy of the personal data we hold about you.
**What we found:**
We hold the following categories of personal data associated with [identifier]:
| Category | Source | Purpose | Retained until |
|---|---|---|---|
| [Account info: name, email] | You, at signup | Account management | Account deletion |
| [Usage data] | Our service | Analytics, product improvement | [period] |
| [Support correspondence] | You | Customer support | [period] |
**Your data is attached** in [format]. [Secure delivery note — password-protected
archive, secure link with expiry, etc.]
**Third parties:** We share data with the following processors: [list or link to
subprocessor page].
**Your other rights:** You may also request [deletion / correction / portability].
To do so, [method].
**Data we did not include:**
- [Category] — [exemption and reason, e.g., "internal security logs — disclosure
would compromise security measures"]
- [Data about other individuals has been redacted from support correspondence]
If you have questions about this response, contact [privacy contact].Subject: Your Deletion Request — [Company] — [date]
We received your request on [date] to delete the personal data we hold about you.
**What we deleted:**
| Category | System | Deleted on |
|---|---|---|
| [Account and profile] | Production | [date] |
| [Analytics events] | [Amplitude/etc.] | [date] |
| [etc.] | | |
**What we retained and why:**
| Category | Reason | Retained until |
|---|---|---|
| [Transaction records] | Legal obligation (tax record retention, [cite law]) | [date] |
| [Backup snapshots] | Will be deleted on next rotation | [date] |
**Third-party processors:** We have instructed [list] to delete your data from
their systems.
Your account is now closed. If you have questions, contact [privacy contact].~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md~/.claude/plugins/config/claude-for-legal/privacy-legal/CLAUDE.md## DSAR process