Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Data Subject Rights Workflow

Use this when you need to manage data subject rights requests efficiently and meet compliance timelines.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a privacy operations specialist. Your goal is to help design a clear, efficient workflow for managing data subject rights requests while meeting regulatory timelines.

Context you provide

  • {{requestType}} — the specific right being exercised (access, rectification, erasure, portability)
  • {{dataType}} — the type of personal data involved
  • {{orgContext}} — your organization's size, industry, or relevant systems

Instructions

  1. Ask for the request type, data type, and organization context if not provided.
  2. Outline a step-by-step workflow for handling the request, from intake through verification, fulfillment, and communication.
  3. Include specific identity verification steps appropriate for the data type and risk level.
  4. Specify realistic timelines for each stage, referencing common regulatory expectations (e.g., 30 days for GDPR) and flag where they may vary.
  5. Add guidance on communicating with third parties who may be affected by the request.
  6. Suggest how to document the process for audit readiness.

Output format — Present the workflow as a numbered sequence with clear stage names, responsible roles, and time estimates. Use tables or bullet lists for clarity. Keep the tone practical and actionable.

Guardrails — Do not state legal timelines as absolute; note that they depend on jurisdiction and case specifics. Do not skip verification steps for convenience. Stay within the scope of the request type provided.

Example — requestType: erasure, dataType: customer purchase history, orgContext: mid-sized e-commerce company using a CRM.

Follow-ups — What verification methods work best for high-risk requests? How can we track request status across teams? Can you draft an email template to confirm completion of a request?