skills/legal/dsar-form/SKILL.md
Drafts a GDPR- and CCPA-compliant Data Subject Access Request (DSAR) intake form for collecting requester information and processing privacy rights. Use when drafting DSAR forms, privacy rights request templates, or data subject rights workflows for EU/US-regulated organizations.
npx skillsauth add casemark/skills dsar-formInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Drafts a legally compliant DSAR intake form enabling individuals to exercise privacy rights under GDPR (Arts. 15–22) and CCPA (Cal. Civ. Code § 1798.100 et seq.).
Gather before drafting:
Draft the form in six sections in this order: Introduction, Requester Info, Request Details, Identity Verification, Declaration, Submission Instructions.
State in plain language:
| Field | Req | Notes | |---|---|---| | Full legal name | Yes | As on ID | | Email address | Yes | Primary contact | | Phone number | No | Optional | | Postal address | Yes | Written response option | | Date of birth | Yes | Identity verification | | Account/customer ID | No | If applicable | | Relationship to org | Yes | Customer / Employee / Former employee / Visitor / Representative | | Alternative names used | No | If interacted under different name |
For authorized representatives: require proof of authority (power of attorney, parental responsibility docs, or equivalent).
Request type (checkbox, select all that apply):
Scope fields:
| Field | Notes | |---|---| | Data description / categories sought | Encourage specificity; overly broad requests may need clarification | | Relevant time period | Date range if applicable | | Preferred response format | PDF / CSV / Secure portal / Encrypted email | | Additional context | Details to help locate records |
Include a note: rights may be limited where data is legally privileged, retention is required by law, or disclosure would adversely affect third-party rights.
Proportionate to data sensitivity (per ICO guidance):
Tier 1 — Standard requests:
Tier 2 — Sensitive data (GDPR Art. 9):
Verification documents: submit via encrypted email or secure portal. Used solely for DSAR processing, securely destroyed upon completion. Org may request additional verification if identity is reasonably uncertain.
Include declaration that the requester:
Add signature line, printed name, and date.
| Channel | Details | |---|---| | Email | [[email protected]] — subject: "DSAR Submission" | | Secure portal | [URL] | | Post | Data Protection Officer, [Address] |
| Regulation | Standard | Extension | Trigger | |---|---|---|---| | GDPR | 30 days | +60 days (90 total) | Complex or numerous requests | | CCPA/CPRA | 45 days | +45 days (90 total) | Reasonably necessary | | UK GDPR | 30 days | +60 days (90 total) | Same as GDPR |
Fees:
Key changes from the original:
tools
Audits the complete in-scope medical-record universe in a litigation matter and produces an attorney-facing, Bates-cited analysis of treatment gaps, missing records or providers, baseline coverage, material billing or production mismatches, and complaint evolution. Use when asked to find missing medical records, analyze treatment gaps or first-care timing, identify absent providers, assess whether a production is complete, or prepare a records-request target list. Use medical-record-chronology instead when the primary request is a chronological clinical narrative.
development
Drafts a legally compliant Private Placement Memorandum for Regulation D offerings (Rule 506(b)/506(c)), covering full disclosure framework including risk factors, capitalization, securities terms, use of proceeds, and investor qualification requirements. Enforces SEC anti-fraud compliance under Section 10(b)/Rule 10b-5, blue sky law considerations, and accredited investor verification under Rule 501. Use this skill when drafting PPMs, offering memorandums, Reg D disclosure documents, or private offering circulars for issuers raising capital from sophisticated investors. Also trigger when the user mentions private placement disclosure, offering memorandum, Reg D fundraising, or accredited investor verification. Even if the user just says "PPM" or "draft our offering memo," use this skill.
data-ai
Generates structured privacy and data protection law briefings across US, EU, UK, and other jurisdictions. Organizes by jurisdiction with compliance deadlines, enforcement actions, and legislative changes. Use when preparing privacy law briefings, compliance updates, regulatory change summaries, or data protection landscape reviews.
testing
Generates structured summaries of prior art references for patent prosecution, validity analysis, and freedom-to-operate assessments. Maps disclosures to claim elements with precise citations. Use when summarizing prior art, analyzing patent landscapes, mapping references to claims, or preparing office action responses.