Route privacy requests with complete identity and scope
A controlled intake creates the right case, deadline, systems list, and legal review path.
The problem
Privacy requests arrive through multiple channels with missing jurisdiction, identity, system, and deadline context.
What you get
A working system with the steps, tools, checkpoints, and expected return made explicit.
- Setup
- 75 minutes
- Back each week
- 3 hours
- Difficulty
- assisted
Expected return
The working case
A planning estimate, not a guaranteed result. Measure the first four weeks against your own baseline.
144
hours returned per year
At 3 hours/week across 48 working weeks.
1
week to earn back setup
Compare the setup estimate with the weekly time returned.
Operating contract
Input
The source material, constraints, and examples a human would need to do this work well.
Checkpoint
A person reviews judgment calls, sensitive content, unfamiliar tools, and irreversible actions.
Success signal
Track time returned, corrections required, and exceptions. Keep it only if the measured result compounds.
Before you start
- ·A named privacy lead
- ·An approved source-of-truth and review template
The steps
- 01
Name privacy lead as the accountable owner and define the decision this workflow is allowed to support.
- 02
Collect the request, consented identity evidence, jurisdiction rules, and data-system inventory; preserve source links, timestamps, and access controls before any synthesis.
- 03
Produce a complete privacy-request case using the approved template. Never disclose, delete, or export personal data automatically.
Copy this prompt
Create a complete privacy-request case from the supplied evidence. Separate facts, assumptions, and missing inputs. Cite every material claim. Never disclose, delete, or export personal data automatically. Evidence: [approved inputs]
- 04
privacy lead reviews the draft, records the decision or next action, and corrects the source system before distribution.
What it runs on
Where this goes wrong
- Do not let the model act beyond never disclose, delete, or export personal data automatically.
- Keep sensitive fields out of unapproved tools and retain a human-readable evidence trail.
Definition of done
Run it for four weeks. Then make it earn its place.
- □ Baseline the manual time before launch.
- □ Keep a human approval step for consequential output.
- □ Record corrections and exceptions, not just successes.
- □ Expand, revise, or retire it after the first review.
Build the system around it
Related workflows
If this one stops working, tell us. Three reports in a month and it leaves the library until a person has looked at it again.