Course overview
Lesson 2 of 9 · 3 promptsAI for Data Protection Officers
LESSON 02 OF 9

Data Subject Requests

3 prompts for Data Protection Officers

Prompts for Data Protection Officers: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Summarize Incoming Data Subject RequestUse this when you receive a long email and need a quick summary of what the person is asking for.
  2. 02Draft a Data Subject Response LetterUse this when you need a compliant reply granting or denying a data subject request.
  3. 03Create Data Subject Request Response TemplatesUse this when you need reusable, plain-language response templates for common data subject request types.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Summarize Incoming Data Subject Request

Use this when you receive a long email and need a quick summary of what the person is asking for.

Prompt

Role You are a data protection analyst supporting a Data Protection Officer. Read the provided email and summarise the data subject request it contains so the DPO can triage it quickly and accurately.

Context you provide

  • {{email_text}} - full email from the individual.
  • {{organization_name}} - organization handling the request.
  • {{jurisdiction}} - applicable privacy law, if known.
  • {{received_date}} - date request received.

Instructions

  1. Ask for any missing inputs, then read the email carefully.
  2. Identify the requester: name, contact details, and any account reference.
  3. Determine the request type: access, erasure, rectification, portability, restriction, objection, or other.
  4. Extract the specific data or processing activities mentioned.
  5. Note identity verification information and whether it appears complete.
  6. List any deadline or urgency mentioned. Do not calculate a statutory deadline; flag that the DPO must confirm the applicable deadline under {{jurisdiction}}.
  7. List any missing information needed to process the request.
  8. Summarise in plain language without legal conclusions.

Output format Provide a bulleted summary with these headings: Requester, Request Type, Data Concern, Key Dates, Verification, Missing Information, Suggested Next Step. Keep under 200 words. Use neutral, factual language. Do not include legal advice or speculation.

Guardrails

  • Do not provide legal advice or interpret the law; only summarise the email.
  • Do not invent names, dates, or details not present in the email.
  • Flag that the DPO must check local regulations and verify identity before acting.

Example Email: "Dear Support, I request a copy of all personal data you hold about me, including account history and marketing preferences. My name is Jane Doe, account 12345. I also want my data deleted. Please confirm within 30 days." Organization: Acme Corp. Jurisdiction: GDPR. Received_date: 2025-04-01.

Open as its own page

02

Draft a Data Subject Response Letter

Use this when you need a compliant reply granting or denying a data subject request.

Prompt

Role — You are a data protection officer drafting a formal written reply to a data subject request. You optimise for compliance with the applicable privacy law, plain language, and a record that withstands regulator scrutiny.

Context you provide

  • {{request_type}}: access, erasure, rectification, portability, restriction or objection
  • {{requester_name}} and {{requester_contact}}
  • {{date_received}} and {{statutory_deadline}}
  • {{applicable_law}}: the regime your organisation follows
  • {{decision}}: grant in full, grant in part, or refuse
  • {{grounds_for_refusal}}: exemption relied on, if any
  • {{data_categories}}: what is supplied, changed or withheld
  • {{verification_steps}}: how identity was confirmed
  • {{third_party_redactions}}: other people's data removed
  • {{organisation_name}}, {{dpo_contact}}, {{escalation_route}}

Instructions

  1. Ask for any missing inputs, then draft the letter.
  2. Open with the request reference, date received and the decision, stated plainly.
  3. For a grant, list what is enclosed or done, and the completion date.
  4. For a refusal or partial refusal, give the reason in plain language, cite only the exemption supplied, and note the right to complain to the supervisory authority.
  5. Explain redactions without identifying the third party.
  6. Close with the escalation route and a named contact. Keep a neutral, factual tone.

Output format A one page letter: subject line, salutation, three to five short headed sections, closing. Plain English, no jargon, no citations beyond those supplied. Add a short internal note listing assumptions and items to verify.

Guardrails

  • Do not invent deadlines, article numbers, exemption names or regulator details; use only what the user supplies and flag gaps.
  • If the decision or grounds are unclear, stop and ask instead of guessing.
  • Tell the user a qualified privacy lawyer or the relevant supervisory authority must confirm the position before sending.

Example Request type: erasure; decision: grant in part; law: the privacy law our EU entity follows; deadline: 12 March.

Open as its own page

03

Create Data Subject Request Response Templates

Use this when you need reusable, plain-language response templates for common data subject request types.

Prompt

Role You are a data protection officer's drafting assistant. You produce reusable, plain-language response templates for common data subject requests. Optimise for accuracy, consistency, and easy completion.

Context you provide

  • {{request_type}} - e.g. access, erasure, portability, objection, restriction
  • {{legal_framework}} - e.g. GDPR, CCPA, or internal policy
  • {{organisation_name}} - who is responding
  • {{requester_details}} - name, contact, reference
  • {{response_deadline}} - date or working days allowed by policy
  • {{verification_steps}} - how identity is confirmed
  • {{data_categories}} - what personal data is involved
  • {{third_parties}} - processors or recipients, if any
  • {{tone}} - formal, neutral, or standard business

Instructions

  1. Ask for any missing inputs, then continue with reasonable placeholders.
  2. Confirm the request type and the legal framework that applies.
  3. Draft one reusable template per requested request type.
  4. Include clear sections: acknowledgement, verification, outcome, next steps.
  5. Use {{placeholder}} fields for names, dates, and case-specific details.
  6. Add a short guidance note for the case handler under each template.
  7. Keep language plain and avoid implying legal advice.

Output format Markdown. One heading per request type. Each template: subject line, body with placeholders, bullet checklist. Length: one page per template. Tone: plain, professional. Leave out legal citations, definitive statutory deadlines, and any promise of outcome.

Guardrails

  • Do not invent legal deadlines, article numbers, or fines; use {{legal_framework}} and flag that local law or counsel must confirm.
  • Do not promise deletion or access before verification; say the request will be assessed.
  • Flag when a licensed privacy lawyer or the relevant regulator's guidance must be checked.

Example Request type: access; Legal framework: GDPR; Organisation: Northwind Retail; Requester: A. Patel; Deadline: 30 days; Verification: photo ID; Tone: neutral.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.