Agent skill

Dsar Processing

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response…

Apache-2.0Auto-check passedLegal & Compliance

Install Dsar Processing

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill dsar-processing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills dsar-processing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/dsar-processing .claude/skills/dsar-processing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dsar-processing
GitHub stars
295
Token cost
~2.7k tokens
SKILL.md length
1,458 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response…

  • Works in 9 steps: Receive and Log the Request → Verify the Identity of the Requester → Assess the Request Scope → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Legal Foundation, DSAR Processing Workflow and Fee and Refusal Provisions, plus 1 more section
  • Runs Python scripts from its folder

What it does

Dsar Processing is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response formatting, exemptions, and fee provisions. Activate when handling DSAR, access request, subject access, Art. 15, or SAR queries.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the dsar-processing skill to guide AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including…”
  • “/dsar-processing”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Receive and Log the Request
  2. Verify the Identity of the Requester
  3. Assess the Request Scope
  4. Calculate the Response Deadline
  5. Apply Exemptions Under Art. 15(4)
  6. Compile the Response
  7. Quality Assurance Review
  8. Deliver the Response
  9. Post-Response Actions

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dsar Processing loads about 2.7k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 1,458 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,458 words, ~2,688 tokens.

Download SKILL.mdSave it as .claude/skills/dsar-processing/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
dsar-processing
description
Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response formatting, exemptions, and fee provisions. Activate when handling DSAR, access request, subject access, Art. 15, or SAR queries.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-subject-rights
metadata.tags
dsar, gdpr-article-15, access-request, subject-access-right, data-subject-rights

Processing Data Subject Access Requests

Overview

A Data Subject Access Request (DSAR) is the right of an individual under GDPR Article 15 to obtain confirmation of whether their personal data is being processed, and if so, to access that data along with supplementary information. This skill provides a complete operational workflow for receiving, validating, processing, and responding to DSARs within the legally mandated timeframe.

GDPR Article 15 — Right of Access by the Data Subject
  1. Art. 15(1) — The data subject has the right to obtain from the controller confirmation as to whether personal data concerning them is being processed, and where that is the case, access to the personal data and the following information:

    • (a) the purposes of the processing
    • (b) the categories of personal data concerned
    • (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations
    • (d) where possible, the envisaged period for which the personal data will be stored, or if not possible, the criteria used to determine that period
    • (e) the existence of the right to request rectification, erasure, restriction, or to object to processing
    • (f) the right to lodge a complaint with a supervisory authority
    • (g) where the personal data are not collected from the data subject, any available information as to their source
    • (h) the existence of automated decision-making, including profiling, referred to in Art. 22(1) and (4), and meaningful information about the logic involved, significance, and envisaged consequences
  2. Art. 15(3) — The controller shall provide a copy of the personal data undergoing processing. For additional copies, the controller may charge a reasonable fee based on administrative costs.

  3. Art. 15(4) — The right to obtain a copy shall not adversely affect the rights and freedoms of others.

GDPR Article 12 — Transparent Communication
  • Art. 12(3) — Response deadline: without undue delay and in any event within one month of receipt. That period may be extended by two further months where necessary, taking into account the complexity and number of requests. The controller shall inform the data subject of any such extension within one month of receipt, together with the reasons for the delay.
  • Art. 12(5) — Where requests are manifestly unfounded or excessive (particularly due to repetitive character), the controller may either charge a reasonable fee or refuse to act. The controller bears the burden of demonstrating the manifestly unfounded or excessive character.

DSAR Processing Workflow

Step 1: Receive and Log the Request
  1. Record the request in the DSAR tracking register with a unique reference number (format: DSAR-YYYY-NNNN).
  2. Capture the channel of receipt (email, web form, postal mail, telephone, in-person).
  3. Timestamp the receipt to the minute using UTC.
  4. Assign the request to the designated DSAR processing team member.
  5. Send an acknowledgement to the data subject within 3 business days confirming receipt and reference number.
Step 2: Verify the Identity of the Requester
  1. Low-risk verification (request received from a verified account, e.g., logged-in customer portal): Confirm account ownership via existing authentication.
  2. Medium-risk verification (request received via email matching records): Request two of the following — date of birth, account number, postal code associated with the account, last four digits of payment method.
  3. High-risk verification (request from unrecognised channel or on behalf of another person): Require government-issued photo ID plus one additional identifier. For third-party requests (e.g., solicitor acting on behalf), require written authorisation signed by the data subject plus proof of identity for both the representative and the data subject.
  4. If identity cannot be verified, inform the requester within 10 business days that additional proof is required. The 30-day response clock pauses until verification is complete per EDPB Guidelines 01/2022 paragraph 64.
Step 3: Assess the Request Scope
  1. Determine whether the request covers all personal data or a specific subset.
  2. Identify all data processing systems where the subject's data may reside:
    • CRM systems (e.g., Salesforce, HubSpot)
    • HR/payroll systems (for employee DSARs)
    • Marketing automation platforms
    • Customer support ticket systems
    • Analytics and logging platforms
    • Backup and archival systems
    • Third-party processor systems
  3. Document any data that falls under exemptions (see Step 5).
  4. Where the controller processes a large quantity of data, request that the data subject specify the information or processing activities to which the request relates, per Recital 63.
Step 4: Calculate the Response Deadline
  1. Standard deadline: 30 calendar days from the day after receipt of the request (or from the day after identity verification is completed, if verification was required).
  2. Extension: Where the request is complex or where there are numerous requests, extend by up to two additional months (total maximum: 90 calendar days). Notify the data subject of the extension and reasons within the initial 30-day period.
  3. Weekend/holiday rule: If the deadline falls on a weekend or public holiday in the controller's jurisdiction, the deadline moves to the next business day per Regulation (EEC, Euratom) No 1182/71.
Show full SKILL.md (636 more words)Show less
Step 5: Apply Exemptions Under Art. 15(4)

Review whether any of the following exemptions apply:

  1. Rights and freedoms of others — Art. 15(4): Redact or withhold data where disclosure would adversely affect the rights and freedoms of other individuals (e.g., third-party personal data, trade secrets of third parties).
  2. Legal privilege — Data protected by legal professional privilege or litigation privilege.
  3. Confidential references — References given in confidence for education, training, or employment purposes (applicable under UK GDPR supplementary provisions).
  4. Management forecasting — Data processed for management forecasting or planning where disclosure would prejudice the business (applicable under certain Member State derogations).
  5. Negotiations — Data consisting of records of intentions in relation to negotiations with the data subject where disclosure would prejudice those negotiations.

Document each exemption applied with specific justification.

Step 6: Compile the Response
  1. Gather all personal data from identified systems.
  2. Organise data by category:
    • Identity data (name, date of birth, contact details)
    • Financial data (transaction records, payment methods)
    • Technical data (IP addresses, device identifiers, cookies)
    • Usage data (service interaction records, preferences)
    • Communications data (support tickets, correspondence)
    • Profiling data (segments, scores, automated decisions)
  3. Prepare the supplementary information required under Art. 15(1)(a)-(h).
  4. Apply redactions for exempted data with clear notation that redactions have been made and the legal basis for each.
  5. Format the response in a commonly used electronic format (PDF for the cover letter, structured data in CSV/JSON where applicable).
Step 7: Quality Assurance Review
  1. Verify completeness: all identified systems have been queried and results compiled.
  2. Verify accuracy: spot-check data against source systems.
  3. Verify redactions: confirm each redaction is legally justified and documented.
  4. Verify the response addresses all elements of Art. 15(1)(a)-(h).
  5. Obtain sign-off from the Data Protection Officer or designated privacy lead.
Step 8: Deliver the Response
  1. Transmit the response via a secure channel:
    • Encrypted email (TLS 1.2+ in transit, AES-256 encrypted attachment)
    • Secure download portal with time-limited access link (72-hour expiry)
    • Registered postal mail with delivery confirmation (for non-electronic requests)
  2. Record the delivery date, method, and confirmation of receipt.
  3. Update the DSAR register with the closure date and outcome.
Step 9: Post-Response Actions
  1. Retain the DSAR processing record (request, internal notes, redaction justifications, copy of response) for a minimum of 3 years to demonstrate compliance.
  2. If the data subject is dissatisfied, inform them of their right to lodge a complaint with the relevant supervisory authority under Art. 77.
  3. Feed any systemic issues identified during the DSAR process into the organisation's data governance improvement programme.

Fee and Refusal Provisions

Reasonable Fee (Art. 12(5)(a))

A controller may charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested where:

  • The request is manifestly unfounded (e.g., the requester has explicitly stated they intend to cause disruption), or
  • The request is excessive (e.g., the same individual submits a fourth identical DSAR within a 12-month period without any change in processing activities).

The fee at Meridian Analytics Ltd is calculated as: GBP 10.00 base fee + GBP 0.10 per page exceeding 500 pages of output.

Refusal to Act (Art. 12(5)(b))

The controller may refuse to act on the request where it is manifestly unfounded or excessive, but must:

  1. Inform the data subject of the reasons for refusal.
  2. Inform the data subject of their right to lodge a complaint with the supervisory authority.
  3. Inform the data subject of their right to seek a judicial remedy.
  4. Document the refusal decision and its justification.

EDPB Guidance References

  • EDPB Guidelines 01/2022 on data subject rights — Right of access: Clarifies scope, means of access, third-party data handling, and relationship with other GDPR rights.
  • EDPB Guidelines on Transparency (WP260 rev.01): Provides guidance on the Art. 12 requirements for concise, transparent, intelligible, and easily accessible communication.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/dsar-processing of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Dsar Processing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dsar Processing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dsar Processing this skillmukul975/Privacy-Data-Protection-Skills295—~2.7kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms586—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated 2 days ago
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    586 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    939 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    939 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    149 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Questions about Dsar Processing

What does Dsar Processing do?

Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response…. Dsar Processing is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides AI agents through the complete GDPR Data Subject Access Request (DSAR) workflow under Article 15, including identity verification, 30-day deadline calculation with extensions, response formatting, exemptions, and fee provisions.

When should I use Dsar Processing?

Dsar Processing fits situations like: tasks that involve Privacy and GDPR.

How do I install Dsar Processing in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill dsar-processing -a claude-code`. Or copy the skill folder (skills/privacy/dsar-processing in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/dsar-processing in your project. Claude Code loads it when a task matches its description.

How do I install Dsar Processing in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill dsar-processing -a codex`. Or copy the skill folder (skills/privacy/dsar-processing in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/dsar-processing in your project. Codex loads it when a task matches its description.

Can I use Dsar Processing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill dsar-processing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dsar-processing, .gemini/skills/dsar-processing, .github/skills/dsar-processing and .opencode/skills/dsar-processing in your project.

What does Dsar Processing need to run?

Going by SKILL.md and its folder, Dsar Processing needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Dsar Processing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dsar Processing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dsar Processing use?

Dsar Processing is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dsar Processing use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Dsar Processing?

Skills that share tags, products or a category with Dsar Processing: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 586 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dsar Processing?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.