Back to GDPR / Data Privacy Request Handling

Launch Plan

What FullSpec will build for you, what happens at each stage, and what your automation looks like once live.

4 pagesPDF · Operations
FS-DOC-01Operations

Launch Plan

GDPR / Data Privacy Request Handling

[YourCompany.com] · Legal Department · Prepared by FullSpec · [Today's Date]

This Launch Plan sets out exactly what is being built, how FullSpec will build and deliver it, what you need to provide, and what to expect once the automation is live. It is written for the business owner and process lead, not a technical audience. FullSpec handles every aspect of the build, testing, and go-live. Your role is to provide access to your existing tools and confirm one configuration decision before work begins.

01What you're launching

You are launching an automated GDPR and data privacy request handling workflow. Right now, each Subject Access Request, erasure request, or rectification request that lands in your inbox triggers a long chain of manual steps: acknowledging by email, logging in Notion, chasing identity documents, hunting data across HubSpot and other tools, compiling a response, routing it for review, and finally updating the audit trail. The entire sequence can consume four to six hours per request and relies on calendar reminders to avoid missing the 30-day legal deadline. This automation replaces seven of those ten steps with two purpose-built agents, leaving your team responsible only for reviewing and approving the draft response before it is sent.

Process
GDPR / Data Privacy Request Handling
Trigger
A data subject submits a privacy request (access, erasure, or rectification) via the Typeform intake form
Final output
An approved response sent to the requester via Gmail, with a closed and fully populated Notion audit record
Agents being built
2 agents: Intake and Triage Agent, Data Discovery Agent
Tools involved
Typeform, HubSpot, Notion, Gmail, Slack
Volume
Approximately 4 requests per month
Launch PlanPage 1 of 4
FS-DOC-01Operations

02How the build works

FullSpec delivers this automation in four sequential stages: Connect, Build, Test, and Launch. Each stage has a defined set of actions for the FullSpec team and a small set of inputs required from you. Nothing moves from one stage to the next until the prior stage is complete and confirmed. The total delivery window is four weeks from the close of Connect, and your participation at key moments keeps that timeline on track.

Complexity level: Moderate. Estimated delivery: 4 weeks (approximately 20 business days). The delivery clock starts at the close of Connect, not payment. If credentials or confirmations are delayed, the delivery window moves accordingly.
1
Connect
Business days 1 to 3
Who
Actions
FullSpec
Schedules and leads the Connect call. Confirms the intake channels to be replaced, reviews which systems hold personal data beyond HubSpot, agrees on the request types covered at launch, and documents the configuration decision that must be confirmed before build begins.
You
Attend the Connect call (typically 45 to 60 minutes). Provide or arrange access credentials for Typeform, HubSpot, Notion, Gmail, and Slack. Confirm the one configuration decision (see Section 03). Sign off on scope before the clock starts.
2
Build
Business days 4 to 15
Who
Actions
FullSpec
Configures the Typeform intake form and connects it to the automation platform. Builds the Intake and Triage Agent: Notion case record creation, deadline calculation, and automated Gmail verification email. Then builds the Data Discovery Agent: HubSpot API connection, data retrieval and structuring logic, Notion draft response template, and Slack reviewer notification. Sets up the approval gate so no response is ever sent without sign-off.
You
Remain available to answer questions about your HubSpot data structure or Notion workspace layout. Respond to any clarification requests within one business day to avoid delays. No technical action is required from you during the build phase.
3
Test
Business days 16 to 19
Who
Actions
FullSpec
Runs the complete workflow against at least three request types (Subject Access Request, erasure, and rectification) using test records. Verifies that the Notion audit log is fully and accurately populated, confirms the reviewer approval gate blocks sends correctly, and documents all test outcomes.
You
Review the test results shared by FullSpec. Confirm that the Notion case records, Gmail emails, and Slack notifications look correct to your team. Raise any concerns before sign-off so they can be resolved before go-live.
4
Launch
Business days 19 to 20
Who
Actions
FullSpec
Switches the Typeform intake form live as the primary channel for all incoming privacy requests. Delivers the Runbook and supporting documentation. Monitors the first live runs and confirms the workflow is behaving as expected.
You
Brief your operations and legal team members on the new intake channel. Update any external-facing privacy notices or contact pages to direct requesters to the Typeform link. Stop accepting requests by email as the primary channel once the form is live.
Launch PlanPage 2 of 4
FS-DOC-01Operations

03What FullSpec needs from you

FullSpec needs only access to your existing tools. No technical knowledge is required from you or your team. Everything listed below is standard account-level access that you already have. FullSpec will guide you through how to share each credential securely if you are unsure.

Tool
What we need
When
Typeform
Admin access to create and publish forms, plus the API key from your Typeform account settings
Before Connect closes
HubSpot
A private app API key with read access to Contacts, Deals, Notes, and Email history
Before Connect closes
Notion
Workspace admin or full-member access so FullSpec can create the case database and configure templates
Before Connect closes
Gmail
A shared or role-based Gmail address (for example, privacy@[YourCompany.com]) for sending verification and response emails, with OAuth access authorised
Before Connect closes
Slack
Permission to add an app integration to your workspace and the name of the channel or user to receive reviewer notifications
Before Connect closes
One decision to confirm before Connect closes: which named person or role receives the Slack reviewer notification and holds sign-off authority for draft responses? This determines how the approval gate is configured. If sign-off is shared between multiple people (for example, an Operations Manager and a Legal Adviser), confirm the order of escalation now. This cannot be changed mid-build without adding time to the delivery window.

04Your role once live

Role
Ongoing responsibilities
What you no longer touch
You (business owner / Operations Manager)
Review Slack notifications when a draft response is ready. Open the Notion case record, check the compiled data package, and approve or annotate before sending. Handle any exception cases flagged by the workflow (for example, identity documents that are unclear or incomplete). Update your privacy notice if request types change.
Manually acknowledging requests by email. Logging requests in a tracker. Sending identity verification emails. Hunting data across HubSpot and other tools. Chasing reviewers by calendar reminder. Updating the audit log after each case closes.
FullSpec
Monitors the automation for errors or failed runs. Applies fixes if a tool API changes or a connection drops. Provides ongoing support via support@gofullspec.com. Updates the workflow if your request types or tool stack changes.
Not applicable. FullSpec does not handle request content, approve responses, or make compliance decisions on your behalf.
Launch PlanPage 3 of 4
FS-DOC-01Operations

05What success looks like

Timeframe
What to expect
Sign of success
Week 1
The first live requests arrive through the Typeform form. The Intake and Triage Agent logs each one in Notion automatically and sends the identity verification email within seconds of submission. Your team receives Slack notifications when a draft is ready for review rather than having to remember to check an inbox.
At least one end-to-end request is completed without any manual logging or email drafting. The Notion audit record is fully populated from the moment the form is submitted.
Month 1
The workflow is handling all standard request types: access, erasure, and rectification. Your team's time per request has dropped to review-only, approximately 45 to 60 minutes rather than four to six hours. Slack notifications are reliably reaching the right reviewer and approvals are being recorded in Notion.
Zero missed deadlines. Every case closed within the 30-day window. Audit logs complete for all cases processed through the new workflow. Manual hours per week reduced from 3.5 hours to approximately 30 minutes.
Month 3
The automation is fully embedded in your operations. Your team no longer thinks about the mechanics of compliance handling. The Notion database gives you a clean, regulator-ready audit trail covering every request since go-live. Annual staff cost attributable to this process has fallen from approximately $13,650 to approximately $1,950.
175 hours saved on an annualised basis. Deadline compliance rate at 100%. If a regulator requests evidence of your privacy handling process, you can produce a complete log in minutes, not days.

Next step: confirm your Connect session date with the FullSpec team at support@gofullspec.com. Have your tool access credentials ready and come prepared to confirm the reviewer sign-off arrangement. Once Connect closes, the four-week delivery clock starts and FullSpec takes it from there.

Launch PlanPage 4 of 4

More documents for this process

Every document generated for GDPR / Data Privacy Request Handling.

ROI and Business Case
Finance · Owner
View
Process Runbook / SOP
Operations · Owner
View
Developer Handover Pack
Technical · Developer
View
Integration and API Spec
Technical · Developer
View
Test and QA Plan
Quality · Developer
View