=� Data Subject Request Templates
Overview
Data subject request (DSR) templates ensure consistent, timely, and compliant responses to individual rights requests. Healthcare Manufaktur's DSR templates cover all major data subject rights across multiple jurisdictions with healthcare-specific considerations.
🌍� Request Response Templates
Access Request Response Template
Timeline: 30 days (GDPR), varies by jurisdiction Use Case: Providing copies of personal data to individuals
SUBJECT: Response to Your Data Access Request - Reference: [ID]
Dear [Individual Name],
Thank you for your request to access your personal data. We are pleased to provide the following information:
## YOUR PERSONAL DATA
Attached you will find:
- [List of data categories provided]
- [Date ranges of data included]
- [Format explanation (PDF/Excel/etc.)]
## DATA SOURCES
Your data was collected from:
- [Direct collection from you]
- [Healthcare providers and referrals]
- [Insurance and billing systems]
- [Medical devices and monitoring]
## DATA SHARING
We have shared your data with:
- [Healthcare providers and specialists]
- [Insurance companies for authorization]
- [Laboratory and diagnostic services]
- [Regulatory authorities as required]
## RETENTION PERIODS
- Medical records: [X years per legal requirement]
- Billing information: [X years per regulation]
- Insurance data: [X years per policy]
## YOUR RIGHTS
You have the right to:
- Request correction of inaccurate data
- Request deletion (subject to legal retention)
- Restrict processing in certain circumstances
- Object to processing based on legitimate interests
- Data portability for certain data
If you have questions or wish to exercise other rights, please contact us.
Best regards,
[Privacy Team]
Healthcare Manufaktur
Deletion Request Response Templates
Deletion Granted Template
SUBJECT: Confirmation of Data Deletion - Reference: [ID]
Dear [Individual Name],
We have processed your request to delete your personal data.
## DELETED DATA
We have permanently deleted:
- [Specific data categories]
- [Date ranges affected]
- [Systems and backups included]
## RETAINED DATA
Some data remains due to:
- Legal retention requirements ([specific law])
- Ongoing medical care necessity
- Insurance claim processing
- Regulatory compliance obligations
## THIRD PARTY NOTIFICATION
We have notified the following recipients:
- [List of notified parties]
- [Notification dates]
Deletion completed on: [Date]
Deletion Declined Template
SUBJECT: Response to Data Deletion Request - Reference: [ID]
Dear [Individual Name],
We cannot fully comply with your deletion request for the following reasons:
## LEGAL RETENTION REQUIREMENTS
- Medical records must be retained for [X years] per [applicable law]
- Financial records required for [X years] per [regulation]
- Insurance documentation per contractual obligations
## ONGOING HEALTHCARE NEEDS
- Active treatment requires data retention
- Emergency medical information for patient safety
- Prescription and allergy alerts
## ALTERNATIVE OPTIONS
We can offer:
- Restriction of processing (data marked as not for use)
- Anonymization where legally permissible
- Access restriction to essential personnel only
Please let us know if you would like to pursue these alternatives.
Rectification Request Templates
Standard Correction Confirmation
SUBJECT: Data Correction Completed - Reference: [ID]
Dear [Individual Name],
We have reviewed and updated your personal information as requested.
## CORRECTIONS MADE
- [Specific field]: Changed from "[old value]" to "[new value]"
- [Date of correction]
- [Verification process used]
## THIRD PARTY NOTIFICATIONS
We have informed:
- [Healthcare providers]
- [Insurance companies]
- [Other relevant parties]
Your updated information is now active in our systems.
Portability Request Template
SUBJECT: Your Data Export - Reference: [ID]
Dear [Individual Name],
Attached is your personal data in a structured, machine-readable format.
## FILE CONTENTS
- [Data categories included]
- [File format explanation]
- [Date range of data]
- [Instructions for use]
## TECHNICAL NOTES
- Files are in [format] for easy import
- Healthcare data follows [standard] format
- Password protection: [if applicable]
## TRANSFER ASSISTANCE
If you need help transferring this data to another provider, please contact us.
=' Process Management Templates
Initial Acknowledgment Template
SUBJECT: Data Subject Request Received - Reference: [Auto-Generated ID]
Dear [Individual Name],
We have received your request regarding your personal data on [Date].
## NEXT STEPS
- Identity verification (if required)
- Request processing within [X] days
- Response via your preferred communication method
## REFERENCE NUMBER
Your request reference: [ID]
## CONTACT INFORMATION
Questions? Contact our Privacy Team:
[Contact details]
Identity Verification Template
SUBJECT: Identity Verification Required - Request: [ID]
Dear [Individual Name],
To protect your privacy, we need to verify your identity before processing your request.
## REQUIRED DOCUMENTS
Please provide ONE of the following:
- Government-issued photo ID
- Patient ID number and date of birth
- Recent medical record number
## SUBMISSION OPTIONS
- Secure patient portal upload
- Encrypted email to [email]
- Mail to [address]
Once verified, we will process your request within [X] days.
🌍
Jurisdictional Adaptations
GDPR-Specific Elements
- 30-day response timeline
- Right to complain to supervisory authority
- DPO contact information
- Specific legal basis citations
- Cross-border processing disclosures
US State Law Variations
- California CPRA: 45-day response timeline
- Virginia VCDPA: Appeal process information
- State-specific verification requirements
- Attorney General complaint procedures
- Business contact information
Healthcare-Specific Considerations
- Medical record retention requirements
- Patient safety implications
- Healthcare provider coordination
- Professional licensing obligations
- Insurance and billing complications
These DSR templates must be customized for specific cases and reviewed by legal counsel. For DSR processing support, contact: dsr-support@healthcare-manufaktur.com
Last Updated: January 2025