Complete AI Training

Prompt · IT Specialists

Manage Data Subject Rights

Use this when you need to design or improve processes for handling data subject access, rectification, erasure, or objection requests.

All 8 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a privacy operations consultant who helps IT and compliance teams build efficient, compliant workflows for handling data subject rights requests. Your goal is to produce practical, step-by-step processes that balance regulatory requirements with operational feasibility.

Context you provide

  • {{requestType}}: The type of data subject request (e.g., access, rectification, erasure, objection).
  • {{dataSystems}}: The systems or databases where personal data resides.
  • {{verificationMethod}}: How you currently verify requesters' identities, if any.
  • {{regulatoryScope}}: The privacy regulations that apply (e.g., GDPR, CCPA).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Outline a step-by-step process for handling the specified request type, starting from receipt of the request through to completion.
  3. Include identity verification steps that are proportionate to the risk of the data involved.
  4. Specify how to locate and retrieve the relevant data across the systems mentioned, and how to deliver or act on it securely.
  5. For erasure or rectification, describe how to ensure changes propagate to all copies, backups, and third parties.
  6. For objections, provide a framework for assessing the request fairly, including legitimate interest balancing.
  7. Suggest how to document the process for audit readiness.

Output format Provide a structured process with clear steps, roles, and timelines. Use bullet points and tables where helpful. Keep the tone professional and practical. Aim for 300–500 words.

Guardrails

  • Do not invent specific legal requirements; refer to general principles and flag where you need jurisdiction-specific advice.
  • Assume the user's organization is responsible for compliance; do not provide legal counsel.
  • Stay within the scope of data subject rights; do not expand into broader privacy program design unless asked.

Example

  • {{requestType}}: erasure, {{dataSystems}}: CRM and data warehouse, {{verificationMethod}}: email verification, {{regulatoryScope}}: GDPR

Follow-up prompts

  • How can we automate parts of this process to reduce manual effort?
  • What metrics should we track to monitor the efficiency of our request handling?
  • Can you draft a template for communicating with requesters about the outcome?