Subject Rights Intake and Identity Verification Specification
Define deterministic intake, verification, and fulfillment procedures for user privacy and data rights requests.
Use this specification when building or formalizing general privacy support workflows for end-user data requests. It ensures regulatory compliance, identity authentication, and audit-ready tracking.
Role: Senior Privacy & Policy Support Lead specializing in consumer rights operations and regulatory compliance desk architecture.
Context
- Applicable Frameworks: {{jurisdiction_framework}}
- Organization Type: {{organization_profile}}
- Supported Request Types: {{request_types_supported}}
- Verification Levels: {{verification_tiers}}
- statutory Processing Window: {{processing_sla_days}}
- Data Retention Baseline: {{record_retention_policy}}
Task
Author a technical operational specification establishing the end-to-end support workflow for receiving, authenticating, processing, and closing subject rights requests for {{organization_profile}} under {{jurisdiction_framework}}.
Method
- Detail the intake channel specifications and initial automated receipt protocol for all {{request_types_supported}}.
- Define tiered identity verification workflows matching {{verification_tiers}} based on account type, request sensitivity, and stored data volume.
- Establish non-compliance rejection criteria and secure defect notice templates for incomplete submissions.
- Outline the internal support desk routing logic to coordinate data collection across backend engineering, marketing, and HR databases.
- Map out the standard processing calendar to ensure full fulfillment well within {{processing_sla_days}}.
- Detail the secure delivery mechanism for data packages, erasure confirmation certificates, or restriction notices.
- Specify logging and audit trail parameters in alignment with {{record_retention_policy}}.
Constraints
- MUST specify identity proofing requirements that prevent unauthorized disclosure without creating excessive user friction.
- MUST NOT include unencrypted payload distribution methods in the fulfillment guidelines.
- Include explicit exception workflows for legally protected records and unlocatable data subjects.
- Define clear segregation of duties between support intake agents and fulfillment engineers.
Output format
Structure the specification using the following mandatory headings:
- Scope & Regulatory Framework
- Intake & Identity Verification Protocol
- Fulfillment Operations & Cross-Functional Routing
- Delivery, Exceptions & Rejections Protocol
- Audit Logging & Retention Compliance Ensure the deliverable is concise, technical, and limited to 600-900 words.
Self-review
- Does the verification procedure completely cover every category in {{request_types_supported}}?
- Are timeline checkpoints structured to guarantee completion within {{processing_sla_days}}?
- Are all record retention mandates aligned with {{record_retention_policy}}?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.