Data Subject Access Request (DSAR) Response Drafter
When an access, deletion or correction request arrives and you need a verified, sourced response package and deadline tracker, especially for requests from employees or adverse parties.
Privacy requests have become routine for many organizations, and each one carries a statutory clock, a verification problem and judgment calls about what must be disclosed or deleted. A request from a former employee or a counterparty in a dispute is a different animal: it can function as early discovery, and a careless response can disclose privileged material or destroy data subject to a hold.
This prompt takes the request exactly as received and the system search results for that person, then builds the full response package. Claude quotes what the requester asked for, proposes a proportionate verification step, tabulates the data by category and source using only the inventory you pasted, runs an exemption and redaction checklist with each exemption left as a bracketed provision, sets up a deadline tracker, and drafts a plain-language letter. If the context suggests the request is a discovery tool, it says so and explains why.
Claude cannot confirm what is actually stored in your systems, whether a hold is in place, or which exemptions apply in your jurisdiction. Counsel must verify the governing law, calculate the deadline, decide each exemption and redaction, and approve the letter. The output is a draft for attorney review.
The Prompt
I am responding on behalf of [ORGANIZATION] to the privacy request below. Request type as we understand it: [ACCESS / DELETION / CORRECTION / OTHER]. Laws that may apply: [GDPR / UK GDPR / US STATE PRIVACY LAW(S) / OTHER]. Date received: [DATE]. Identity verification status: [VERIFIED / NOT YET VERIFIED / METHOD USED]. Known relationship with the requester: [CUSTOMER / EMPLOYEE / FORMER EMPLOYEE / OTHER]. Any open dispute or litigation with the requester: [YES, DESCRIBE / NO / UNKNOWN]. <request> [PASTE THE REQUEST EXACTLY AS RECEIVED, INCLUDING ANY FOLLOW-UP MESSAGES] </request> <data_inventory> [PASTE SYSTEM SEARCH RESULTS OR DATA MAP ENTRIES FOR THIS PERSON: SYSTEM, DATA CATEGORIES, SOURCE, PURPOSE, RECIPIENTS, RETENTION] </data_inventory> Produce: 1. Request analysis: what the requester is asking for, quoted, and any ambiguity to clarify. 2. Identity verification step: what is still needed, proportionate to the data involved, without asking for more data than necessary. 3. Data summary table: Category | Source | Purpose | Recipients | Retention, using only the inventory. 4. Exemption and redaction checklist: third-party data, privileged material, data relating to other employees, trade secrets, manifestly unfounded or excessive requests, and legal-hold conflicts. For each, state whether it may apply on these facts and cite it as [APPLICABLE PROVISION]. Do not state that an exemption applies. 5. Deadline tracker: received date, verification date, response due [DEADLINE UNDER APPLICABLE LAW], any extension and notice requirement [CONFIRM]. 6. Pre-litigation flag: if the request or context suggests it is being used to obtain discovery, say why, quote the language, and list points for counsel. 7. A draft response letter in plain language. Flag gaps in the inventory. This is a draft for attorney review before sending.
Example Output
A request analysis, identity step, data summary table, exemption checklist with bracketed provisions, a deadline tracker, any pre-litigation flags and a plain-language draft response letter.
Illustrative example — names, figures, and facts are fictional.
DSAR RESPONSE PACKAGE (DRAFT FOR ATTORNEY REVIEW)
Organization: Marrow & Pike Home Goods | Requester: former employee J. Castellanos
1. REQUEST ANALYSIS
Quoted: "Send me every email, Slack message and performance note that mentions me, and delete my file after." Two requests: access and deletion. Ambiguity: "every email" may include messages that mainly concern other people.
2. IDENTITY VERIFICATION
Requester wrote from a personal email not on file. Proposed step: confirm two data points already held (employee ID, last work location). Do not request a copy of government ID unless proportionate [CONFIRM].
3. DATA SUMMARY
Category | Source | Purpose | Recipients | Retention
HR file | HRIS | Employment administration | Payroll vendor | [PER POLICY]
Email mentions | Mail system | Business communications | Internal | [PER POLICY]
Performance notes | Review tool | Performance management | Manager, HR | [PER POLICY]
4. EXEMPTION AND REDACTION CHECKLIST
Third-party data in emails: may apply [APPLICABLE PROVISION]
Privileged material (emails with counsel, March 2026): may apply [APPLICABLE PROVISION]
Legal hold: inventory notes "hold: Castellanos matter." Deletion request conflicts. Do not delete.
5. DEADLINE TRACKER
Received: Sept 3 | Verified: [DATE] | Due: [DEADLINE UNDER APPLICABLE LAW] | Extension: [CONFIRM]
6. PRE-LITIGATION FLAG
Hold reference plus the scope of the request ("every Slack message") suggest discovery use. Recommend litigation counsel review before production.
7. DRAFT LETTER (EXCERPT)
"Dear Ms. Castellanos, we received your request on September 3. Before we respond, we need to confirm your identity..."
Gaps: Slack search results not included in inventory.Tips
- •Paste the request verbatim. Requesters often combine access, deletion and objection in one message, and the quoted analysis catches each one.
- •Check for a litigation hold before acting on any deletion request; the checklist flags it, but only you can confirm the hold.
- •Calculate the response deadline yourself from the governing law and the received date. Claude leaves it bracketed on purpose.
- •Treat requests from current or former employees, or anyone in a dispute, as potential discovery and involve litigation counsel early.
- •The letter is a draft for attorney review. Verify every cited provision and redaction decision before sending.
Frequently Asked Questions
Why does the prompt leave the response deadline as a placeholder?
Response periods, extension rules and the event that starts the clock differ between laws and can change. Rather than risk a wrong date, the prompt has Claude build the tracker and leave the deadline bracketed so you insert the figure after checking the governing statute or regulation. That keeps the calendar entry tied to a verified source.
How should I handle a DSAR from someone who is suing us?
Treat it as both a privacy request and a litigation event. The prompt flags pre-litigation indicators, but the response strategy belongs to counsel: coordinate with litigation counsel, check holds, review for privilege, and make sure the response is consistent with your discovery positions. Do not let a routine privacy workflow produce documents without that review.
Can Claude search our systems for the requester's data?
Not in this workflow. You run the searches and paste the results into the data inventory section. Claude works only from what you paste, which is why it flags gaps such as a system that was not searched. A response is only as complete as the searches behind it.
Related Prompts
Get New Prompts Like This Every Week
Join the free Claude for Lawyers newsletter — weekly prompts, tutorials, and practice-specific guides.