Skip to content
Back to skills

Subject Access Requests

ASecurity

Answer a request for a copy of someone's data completely, on time, and without exposing anyone else. Use when building an export path or responding to an access request.

  • 7 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 5, 2026
ai-agentsgitdatabase

Security analysis

A100/100

Scanned September 5, 2026

npx -y skills add Amey-Thakur/AI-SKILLS --skill subject-access-requests --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Subject Access Requests?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Subject Access Requests
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/amey-thakur-subject-access-requests/badge)](https://www.skillsdirectory.com/skills/amey-thakur-subject-access-requests)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: subject-access-requests
description: Answer a request for a copy of someone's data completely, on time, and without exposing anyone else. Use when building an export path or responding to an access request.
---

# Subject access requests

An access request asks a simple question that most systems answer
badly: what do you hold about me. Answering means finding every store,
assembling it in a form a person can read, and removing other people
who appear in the same records.

## Method

1. **Verify identity proportionately.** Enough to be confident, not so
   much that you collect new sensitive data to satisfy a request. An
   authenticated session is usually the strongest and cheapest proof.
2. **Search every store the map lists.** Primary database, warehouse,
   logs, support tickets, email, and vendors all hold personal data,
   and an export covering only the main database is incomplete (see
   data-lineage, right-to-erasure).
3. **Return something a person can actually read.** A machine dump with
   internal codes technically complies and practically fails; include
   labels, dates, and a short explanation of each section.
4. **Redact third parties.** Records mentioning other people, internal
   authors, or another customer's data must be removed or masked,
   because an access right is not a right to someone else's data.
5. **Automate the common path.** A self-serve export in the product
   handles most requests instantly and reduces the manual work to the
   unusual cases, which is where the deadline risk lives.
6. **Track the clock and the completeness.** Requests have statutory
   deadlines, so record when each arrived, what was searched, and when
   it was answered (see audit-logging).

## Boundaries

- Access rights differ by jurisdiction in scope, deadline, and
  exemptions, so the legal parameters are not an engineering choice.
- Some material is legitimately withheld, including trade secrets and
  other people's data, and deciding that is a review step rather than
  an automated one.
- An export is a snapshot; it does not commit you to keeping the data
  longer than your retention policy allows.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…