Privacy Request Playbook
Privacy requests need identity verification, careful scoping, and no invention of legal positions. This skill structures operations; it is not a substitute for counsel or your company's policy.
Workflow
- Classify request: access, export, delete, correct, restrict, object, appeal.
- Verify identity using approved channels only.
- Scope systems of record (app DB, logs, backups, vendors, support tools).
- Apply legal holds / exceptions per policy (do not invent).
- Execute export/delete with audit trail; minimize data in replies.
- Respond with clear timelines and what was done / not done.
- Record ticket fields for compliance evidence.
Output format
## Privacy request intake
**Type:** …
**Verification status:** …
**Systems in scope:** …
**Exceptions / holds:** (only if policy provided)
## Internal run steps
1. …
## Customer-facing reply draft
…
## Open questions for policy/legal
…
Rules
- Never invent legal deadlines or rights language; use user-provided policy.
- Do not export other users' data or employee PII by mistake.
- Prefer secure delivery for exports (link expiry, auth).
- Deletion vs anonymization: follow policy; mention backups retention honestly if policy says so.
- Security incidents masquerading as privacy tickets → security path.
- Mark uncertainty; escalate rather than guess.
Edge cases
- Vague "delete everything": clarify products/accounts.
- Third-party subprocessors: note vendor coordination when policy requires.
- Child accounts / guardians: extra verification sensitivity.