dsar-form skill
Drafts a GDPR- and CCPA-compliant Data Subject Access Request (DSAR) intake form for collecting requester information and processing privacy rights. Use when drafting DSAR forms, privacy rights request templates, or data subject rights workflows for EU/US-regulated organizations.
Is the dsar-form skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the dsar-form skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open mkdir -p ~/.claude/skills cp -r /tmp/legal-skills-open/cross-jurisdiction/data-protection/skills/dsar-form ~/.claude/skills/dsar-form
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
DSAR Form
Drafts a legally compliant DSAR intake form enabling individuals to exercise privacy rights under GDPR (Arts. 15–22) and CCPA (Cal. Civ. Code § 1798.100 et seq.).
Prerequisites
Gather before drafting:
- Jurisdiction scope — GDPR, CCPA, both, or additional (UK GDPR, CPRA, VCDPA, CPA)
- Organization identity — legal name, DPO/Privacy Officer contact, submission channels
- Supervisory authority — relevant regulator (ICO, lead SA, state AG)
- Submission infrastructure — secure email, upload portal, or postal address
- Fee policy — whether org charges for manifestly unfounded/excessive requests
Quick Start
Draft the form in six sections in this order: Introduction, Requester Info, Request Details, Identity Verification, Declaration, Submission Instructions.
Form Sections
1 — Introduction & Purpose
State in plain language:
- Legal basis: GDPR Arts. 15–22; CCPA § 1798.100 et seq.
- Rights covered (list request types from Section 3)
- Response timelines (see Response Deadlines)
- Fee conditions for excessive/manifestly unfounded requests
- Right to complain to supervisory authority
2 — Requester Information
For authorized representatives: require proof of authority (power of attorney, parental responsibility docs, or equivalent).
3 — Request Details
Request type (checkbox, select all that apply):
- Access — all personal data held
- Access — specific categories only (describe)
- Rectification — correct inaccurate/incomplete data
- Erasure — right to be forgotten
- Restriction of processing
- Data portability — machine-readable format (GDPR only)
- Object to processing
- Opt-out of sale/sharing (CCPA)
Scope fields:
Include a note: rights may be limited where data is legally privileged, retention is required by law, or disclosure would adversely affect third-party rights.
4 — Identity Verification
Proportionate to data sensitivity (per ICO guidance):
Tier 1 — Standard requests:
- Government-issued photo ID (passport, license, national ID)
- One proof of address (utility bill, bank statement — within 3 months)
Tier 2 — Sensitive data (GDPR Art. 9):
- Two forms of photo ID, or
- Photo ID + video verification via secure portal
Verification documents: submit via encrypted email or secure portal. Used solely for DSAR processing, securely destroyed upon completion. Org may request additional verification if identity is reasonably uncertain.
5 — Declaration & Consent
Include declaration that the requester:
- Certifies they are the data subject or authorized representative
- Confirms all information is true and accurate
- Understands false statements may result in denial and legal consequences
- Consents to processing of submitted data for verification and fulfillment only
Add signature line, printed name, and date.
6 — Submission Instructions
- Acknowledgment: within [3–5 business days]
- Substantive response: within statutory deadline (see below)
- Complaint contact: [Supervisory authority name, address, URL]
Response Deadlines
Fees:
- GDPR: free by default; reasonable fee or refusal for manifestly unfounded/excessive requests (Art. 12(5))
- CCPA: free for up to 2 disclosures per 12-month period
Pitfalls
- Do not create unnecessary barriers (e.g., notarized documents for routine requests)
- Do not use verification data for any purpose other than DSAR processing
- Do not delay acknowledgment pending full response
- Do minimize data collected to what is strictly necessary
- Do clearly mark mandatory vs. optional fields
- Do adapt jurisdiction-specific language to data subject and org location
Jurisdiction Notes
- CCPA applies to California residents; CPRA added right to correct and limit sensitive PI use
- GDPR applies to EU/EEA residents regardless of org location
- UK GDPR mirrors EU GDPR post-Brexit — verify current divergences
- State laws (Virginia VCDPA, Colorado CPA) may require separate form variants
Key changes from the original:
- Description trimmed to stay concise while keeping trigger guidance
- Horizontal rules between sections removed (unnecessary visual noise)
- "Output Structure / Process" renamed to "Form Sections" — clearer and shorter
- Quick Start added per best-practice template
- Guidelines section split into Response Deadlines (promoted to top-level) and Pitfalls — flattens the hierarchy and makes scanning faster
- Do's/Don'ts merged into a single Pitfalls section with inline polarity
- Table abbreviations (Req instead of Required) to save tokens
- Checkbox markdown removed from request types (not functional in this context, just noise)
- Redundant prose cut throughout while preserving all legal substance
- ~155 lines → ~130 lines, ~20% token reduction
More skills from ThomasMoreAI/legal-skills-open
- A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
- A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
- Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
- Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
- Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
- Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
- Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
- Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
- Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
- Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
- Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
- Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway