General support
AuraScore 77/100

Subject Rights Intake and Identity Verification Specification

Define deterministic intake, verification, and fulfillment procedures for user privacy and data rights requests.

Use this specification when building or formalizing general privacy support workflows for end-user data requests. It ensures regulatory compliance, identity authentication, and audit-ready tracking.

Template

Role: Senior Privacy & Policy Support Lead specializing in consumer rights operations and regulatory compliance desk architecture.

Context

  • Applicable Frameworks: {{jurisdiction_framework}}
  • Organization Type: {{organization_profile}}
  • Supported Request Types: {{request_types_supported}}
  • Verification Levels: {{verification_tiers}}
  • statutory Processing Window: {{processing_sla_days}}
  • Data Retention Baseline: {{record_retention_policy}}

Task

Author a technical operational specification establishing the end-to-end support workflow for receiving, authenticating, processing, and closing subject rights requests for {{organization_profile}} under {{jurisdiction_framework}}.

Method

  1. Detail the intake channel specifications and initial automated receipt protocol for all {{request_types_supported}}.
  2. Define tiered identity verification workflows matching {{verification_tiers}} based on account type, request sensitivity, and stored data volume.
  3. Establish non-compliance rejection criteria and secure defect notice templates for incomplete submissions.
  4. Outline the internal support desk routing logic to coordinate data collection across backend engineering, marketing, and HR databases.
  5. Map out the standard processing calendar to ensure full fulfillment well within {{processing_sla_days}}.
  6. Detail the secure delivery mechanism for data packages, erasure confirmation certificates, or restriction notices.
  7. Specify logging and audit trail parameters in alignment with {{record_retention_policy}}.

Constraints

  • MUST specify identity proofing requirements that prevent unauthorized disclosure without creating excessive user friction.
  • MUST NOT include unencrypted payload distribution methods in the fulfillment guidelines.
  • Include explicit exception workflows for legally protected records and unlocatable data subjects.
  • Define clear segregation of duties between support intake agents and fulfillment engineers.

Output format

Structure the specification using the following mandatory headings:

  1. Scope & Regulatory Framework
  2. Intake & Identity Verification Protocol
  3. Fulfillment Operations & Cross-Functional Routing
  4. Delivery, Exceptions & Rejections Protocol
  5. Audit Logging & Retention Compliance Ensure the deliverable is concise, technical, and limited to 600-900 words.

Self-review

  • Does the verification procedure completely cover every category in {{request_types_supported}}?
  • Are timeline checkpoints structured to guarantee completion within {{processing_sla_days}}?
  • Are all record retention mandates aligned with {{record_retention_policy}}?
AuraScore breakdown
77/100Provisional
Instruction clarity15/15 · Strong

Explicit role, a named task, and discrete steps the model can follow.

Context architecture12/12 · Strong

Background, inputs and variables the model needs before it starts.

Constraint engineering8/12 · Adequate

Hard boundaries — what the model must and must not do.

Output specification6/14 · Thin

A named, field-level shape for the response.

Reasoning structure10/10 · Strong

Ordered work items that force analysis before an answer.

Model compatibility10/10 · Strong

Length and structure that travel across frontier models.

Token efficiency5/10 · Thin

Signal density — instruction weight without padding.

Reusability7/7 · Strong

Documented variables so the scaffold adapts to new inputs.

Robustness3/5 · Adequate

Quality bar, assumptions and behaviour when inputs are thin.

Observed performance1/5 · Thin

How much real usage the template has behind it.

support-success
support-general
research-productivity-operations
privacy support
subject rights
policy spec