workflow

DSAR Fulfillment (Access & Deletion Requests)

DSAR Fulfillment (Access & Deletion Requests) as a modular, decision-aware workflow that verifies identity, locates and reviews personal data, applies exemptions, and delivers the response inside the statutory deadline. The workflow runs against the EXISTING "DSAR / Data-Subject Request Handling" Process item (process_type: business_process) — enrich it, never recreate it: one workflow instance per inbound request, and the instance itself is the DSAR register entry (there is no native DSAR/privacy-request item type; the register is the set of these instances). In scope: a single inbound data-subject access or deletion request under GDPR, CCPA/CPRA, or HIPAA, with the statutory clock started at receipt, carried from identity verification through data compilation, exemption review, delivery, and archival, with any correction or portability elements handled inline. It consumes the inbound request and identity artifacts uploaded at the first step, the data map / record of processing activities, the exemption playbook and retention schedule (Policy items with the governing documents attached), and the processor register (Vendor items, category: data_processing). Named deliverables: the access disclosure set or deletion certificate, the exemption log and redlined package, the reasoned rejection notice on the failed-verification path, the delivery evidence and completion-metrics record, systemic-finding Issue items routed to the privacy program, and the archived DSAR case file — the exported workflow record. Out of scope: unrelated privacy processes such as breach notification and privacy impact assessments, which run as their own workflows; this workflow takes no upstream handoff and produces no downstream workflow handoff.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
reg
department
privacy
lineOfDefense
operate

Details

teams
  • privacy
domains
  • reg
standards
  • gdpr
  • ccpa
  • hipaa
sourceTemplateId
workflow-library:reg-dsar-fulfillment
releaseId
sha256:8226ebb5176ad52f52c7a5ab46e65466771eac32bed5bc7d88069b47d6aaef39
canonicalUrl
https://workflow-library.com/all/?w=reg-dsar-fulfillment
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-DATA-06
    • UC-DATA-08
    • UC-DATA-14
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:8226ebb5176ad52f52c7a5ab46e65466771eac32bed5bc7d88069b47d6aaef39

            Connections