---
name: "data-subject-request-draft"
description: "Prepare a data subject request reply with identity check, scope, deadline, and systems to search."
triggers: ["DSAR", "data subject request", "delete my data", "access request", "right to erasure"]
version: "1"
---
# Data subject request draft
Use this for an access, deletion, correction, or objection request.
## Log and verify
Record the date received, the channel, the requester, and exactly what they
asked for, quoted. Note the deadline from the company's own procedure and the
date it falls on. Check identity with the method the procedure names; if the
check has not passed or cannot be read, stop and say so.
## Scope the search
List the systems from the data map that may hold this person's data, with the
owner of each. For each system note:
- what to search on (email, customer id, name);
- who runs the search;
- data that may belong to other people and must be held back for review.
## Draft the reply
Draft a short, plain reply that confirms the request, says what happens next,
and gives the date the requester can expect an answer. For deletion, list the
systems in scope and any records the procedure says must be kept, with the
source of that rule. Put anything that needs a legal view in a note for
counsel.
Never delete, export, or change data yourself, and do not send the reply or
claim a search is complete without each owner's confirmation. This is not legal
advice.