Privacy Request Packets for DSAR and Consumer Rights
A privacy-request agent should verify identity, locate systems, and assemble an export or denial packet. It should not release a copy or delete records on its own.
Direct Answer
Assemble a verified packet. Do not auto-release the copy.
Privacy request packets help a privacy operations team finish a data-subject or consumer rights request by verifying the requester, locating the systems that hold the person, collecting a reviewable export, and routing exceptions. The agent prepares the work. A named privacy owner decides whether to disclose, deny, extend, or delete.
The clocks are unforgiving and they are not the same. The European Commission states that controllers must reply to GDPR rights requests without undue delay and, in principle, within one month of receipt. California's CCPA materials give consumers a right to know and require businesses to verify identity before disclosing specific pieces of personal information. An agent that speeds collection without protecting verification is a faster way to send the wrong person's file.
Our bias is to start with access and know requests that already have a system map. Deletion, correction, and authorized-agent cases can wait until the export packet is boring.
Current Queue
Most teams still hunt inboxes and hope the identity check was enough.
A marketplace privacy inbox receives an email that says 'send me everything you have.' Someone forwards it to engineering. Engineering searches the warehouse, the support tool, the payments vendor, and a leftover marketing list. Legal asks whether the requester was verified. The one-month or 45-day clock is already running.
The expensive part is not writing the cover letter. It is proving who the requester is, which systems are in scope, what must be withheld because it identifies someone else, and what cannot be found.
An email address is not verification
GDPR Article 12(6) allows additional information only when there is reasonable doubt. CCPA regulations require a higher bar before releasing specific pieces. The packet should record which bar applied and what was matched.
A warehouse dump is not an access copy
EDPB Guidelines 01/2022 describe access as confirmation, the data, and information about the processing. A raw extract that includes other customers fails the third-party-rights limit.
A missed system is a missed request
Support tickets, payment processors, device logs, and a retailer return portal are often out of the first search and still in scope.
Marketplace Packet
A consumer-marketplace access request needs six fields the reviewer can defend.
Use a privacy operations desk at a consumer marketplace. The systems of record are the identity store, the order and returns platform, the support desk, the payments processor, the marketing list, and the privacy-request tracker. The agent may inventory sources and draft the export. It should not email the ZIP file.
Request class and clock
GDPR access, CCPA request to know categories, CCPA specific pieces, deletion, or correction. Store the received timestamp and the due date for that class.
Verification record
What was matched, the certainty level required, whether an authorized agent presented written permission, and why a request was denied when identity could not be verified.
System inventory
Each store searched, the query used, the owner, and whether the search returned data, no-data, or blocked access.
Withhold and redact log
Other customers in a shared ticket, payment-account secrets, and employee notes that are not the requester's personal data.
Proposed package
The consumer-facing copy plus the Article 15 or CCPA notice information: purposes, categories, recipients, and retention.
Decision and extension
Disclose, disclose-in-part, deny, or extend. GDPR allows a two-month extension for complex cases if the requester is told within the first month. That notice is a workflow step, not a footnote.
Build Order
Map systems and verification before connecting an export tool.
The first implementation is a source map and a verification playbook. If the team cannot list the systems that hold marketplace personal data, the agent will search the two tools someone remembered and call the request done.
Compliance evidence collection at https://solzero.com/blog/compliance-evidence-agents-for-audit-prep is a cousin, not a substitute. Audit packets prove a control existed. Privacy packets prove a specific person's data was found, withheld, or not held.
Build the system map
Identity, orders, returns, support, payments, marketing, device logs, and vendors that process the same consumer.
Write verification lanes
Account-holder login, non-account matching, authorized-agent proof, and the deny path when certainty is not met.
Draft before transmit
Use the approval-packet pattern at https://solzero.com/blog/approval-packets-for-human-in-the-loop-agents so a privacy owner sees the copy, the redactions, and the due date in one place.
Keep deletion on a later lane
Access teaches the map. Deletion adds legal exceptions, backup windows, and vendor cascade. Do not combine them in the first agent.
Hard Stops
Identity doubt and third-party data are stop conditions, not prompt hints.
The European Commission's individual-rights pages and EDPB Guidelines 01/2022 both treat access as facilitative and bounded. The requester should not have to justify the ask. The controller still must protect other people's rights and may refuse manifestly unfounded or excessive requests if it can prove that character.
Those boundaries belong in the workflow. A model that 'does its best' with a thin identity match is the failure we watch for.
No export without a recorded verification decision
The tool that attaches the file should require the privacy owner's disclose action, not a completed search.
No default government-ID harvest
Additional identity data should follow reasonable doubt, not a standing demand for a passport image on every ticket.
No silent vendor omissions
If the payments processor cannot return a copy in time, the packet should show the gap and the follow-up, not a clean empty section.
Scoreboard
Measure on-time, complete, and correctly withheld packages.
The agent is working when privacy owners send fewer reconstructed exports and miss fewer clocks. Useful measures include time from receipt to verification decision, systems searched versus systems on the map, on-time close rate by request class, reviewer redactions per package, denials for failed verification, and extensions sent inside the required window.
Do not treat tickets closed as the win. A closed ticket that omitted the support desk or attached another customer's refund note is a rights failure.
The SolZero take is that privacy-request agents are deadline-and-identity work. If the inbox already misses clocks because people are hunting systems, start at https://solzero.com/#how-it-works.
FAQ
The first automation question privacy owners ask.
Should the agent email the export when the search looks complete?
No. Completeness and identity are separate decisions. Let the agent assemble the package and the withhold log. A named privacy owner releases the copy after verification and third-party review.
Further reading