{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:8226ebb5176ad52f52c7a5ab46e65466771eac32bed5bc7d88069b47d6aaef39","slug":"reg-dsar-fulfillment","url":"/assets/agent_workflow-reg-dsar-fulfillment-60b0f02d.67def2a4e745e6e9.json"},"kind":"record","record":{"attributes":{"department":"privacy","domain":"reg","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=reg-dsar-fulfillment","description":"DSAR Fulfillment (Access & Deletion Requests) as a modular, decision-aware workflow that verifies identity, locates and reviews personal data, applies exemptions, and delivers the response inside the statutory deadline. The workflow runs against the EXISTING \"DSAR / Data-Subject Request Handling\" Process item (process_type: business_process) — enrich it, never recreate it: one workflow instance per inbound request, and the instance itself is the DSAR register entry (there is no native DSAR/privacy-request item type; the register is the set of these instances). In scope: a single inbound data-subject access or deletion request under GDPR, CCPA/CPRA, or HIPAA, with the statutory clock started at receipt, carried from identity verification through data compilation, exemption review, delivery, and archival, with any correction or portability elements handled inline. It consumes the inbound request and identity artifacts uploaded at the first step, the data map / record of processing activities, the exemption playbook and retention schedule (Policy items with the governing documents attached), and the processor register (Vendor items, category: data_processing). Named deliverables: the access disclosure set or deletion certificate, the exemption log and redlined package, the reasoned rejection notice on the failed-verification path, the delivery evidence and completion-metrics record, systemic-finding Issue items routed to the privacy program, and the archived DSAR case file — the exported workflow record. Out of scope: unrelated privacy processes such as breach notification and privacy impact assessments, which run as their own workflows; this workflow takes no upstream handoff and produces no downstream workflow handoff.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=reg-dsar-fulfillment","capabilities":[],"controls":["UC-DATA-06","UC-DATA-08","UC-DATA-14"],"domains":["reg"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:8226ebb5176ad52f52c7a5ab46e65466771eac32bed5bc7d88069b47d6aaef39","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:reg-dsar-fulfillment","standards":["gdpr","ccpa","hipaa"],"teams":["privacy"]},"id":"wf:R7","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AR7","slug":"reg-dsar-fulfillment","sourceIds":["ccpa","gdpr","hipaa","soc2"],"sourceUrl":null,"title":"DSAR Fulfillment (Access & Deletion Requests)","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0397d83c942955bc563ce4621fb8047bb032df2964e3023994df0f935d05b448","properties":{},"sourceDetailPath":"/data/v1/records/wf-r7-2fc6568b.json","sourceId":"wf:R7","targetDetailPath":"/data/v1/records/uc-uc-data-06-14975c65.json","targetId":"uc:UC-DATA-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0fc80560685af378c2311919123351d81ec079e3addb8bc6572c8c30c70c7fc8","properties":{},"sourceDetailPath":"/data/v1/records/wf-r7-2fc6568b.json","sourceId":"wf:R7","targetDetailPath":"/data/v1/records/uc-uc-data-14-2c0be84c.json","targetId":"uc:UC-DATA-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea7b0f02af40eff5e0f538783b7ce78a185f3b1ca45a83e4c65e6f9d8510efdc","properties":{},"sourceDetailPath":"/data/v1/records/wf-r7-2fc6568b.json","sourceId":"wf:R7","targetDetailPath":"/data/v1/records/uc-uc-data-08-794007b4.json","targetId":"uc:UC-DATA-08","type":"operates"}],"schemaVersion":1}
