Back to GDPR / Data Privacy Request Handling

Process Runbook / SOP

How the automation works day-to-day: what is automatic, what needs a human, how exceptions are handled, and who to contact.

4 pagesPDF · Operations
FS-DOC-03Operations

Process Runbook / SOP

GDPR / Data Privacy Request Handling

[YourCompany.com] · Legal / Operations Department · Prepared by FullSpec · [Today's Date]

This runbook is the day-to-day operating guide for your team's GDPR and data privacy request workflow. It covers how the automated process works, where your team's attention is genuinely required, what to do when something goes wrong, and how to keep the workflow healthy over time. The FullSpec team has built and configured the automation end to end. Your responsibility is the single human review step described in Section 02, and the exception handling described in Section 03.

01Process overview

When a data subject submits a right-of-access, erasure, or rectification request through the Typeform intake form, the automation immediately creates a case record in Notion, sends the requester a verification email, and timestamps the 30-day legal deadline. Once identity is confirmed by a team member in Notion, the Data Discovery Agent queries HubSpot for all records linked to the requester, compiles a structured draft response, and notifies the assigned reviewer via Slack. The reviewer checks the draft, approves it in Notion, and the system sends the response and closes the audit log automatically. No request can be sent without reviewer sign-off.

Process name
GDPR / Data Privacy Request Handling
Trigger
A data subject submits a privacy request (access, erasure, or rectification) via the Typeform intake form
Final output
An approved response sent to the requester via Gmail, with a fully closed and timestamped audit log in Notion
Agents running
Intake and Triage Agent; Data Discovery Agent
Tools involved
Typeform, Notion, Gmail, HubSpot, Slack
Weekly volume
Approximately 1 request per week (4 per month)
Human checkpoint
Reviewer approves the draft response package in Notion before any reply is sent to the requester
Process owner
Operations Manager
Process Runbook / SOPPage 1 of 4
FS-DOC-03Operations

02Step-by-step: what happens and who acts

What you actually need to do: There is one human step in this process. When you receive a Slack notification that a draft response is ready, open the linked Notion case record, read the compiled response package, and mark it as approved (or leave a comment requesting changes). The automation will not send anything until you have done this. Everything else, including intake logging, verification emails, data retrieval, and audit log closure, is handled automatically.
Step
What happens
Who acts
Type
1
The requester completes the Typeform intake form, selecting the request type (access, erasure, or rectification) and submitting their contact details. The form submission fires the workflow immediately.
Requester
Automated
2
The Intake and Triage Agent creates a structured case record in Notion containing the request type, requester name, submission date, and the calculated 30-day response deadline. This record is the single source of truth for the case.
Intake and Triage Agent
Automated
3
A templated identity verification email is sent to the requester via Gmail, asking for proof of identity and explaining what happens next. No manual drafting is required.
Intake and Triage Agent
Automated
4
When the requester replies with their ID documents, a team member reviews the documents and marks the identity field in the Notion case record as confirmed. This is the only manual step in the standard workflow.
Operations Manager
Human
5
Once the Notion record is marked as identity confirmed, the Data Discovery Agent queries HubSpot via its API and retrieves all records linked to the requester, including contact data, deal history, notes, and email history.
Data Discovery Agent
Automated
6
The Data Discovery Agent structures the retrieved records into a compliant draft response package and saves it directly into the Notion case record, flagging any sensitive or ambiguous data points for the reviewer.
Data Discovery Agent
Automated
7
A Slack message is sent to the assigned reviewer containing a direct link to the Notion draft and a prompt to approve or annotate before the deadline. The case remains on hold until approval is logged.
Data Discovery Agent
Automated
8
The reviewer opens the Notion case record, reviews the draft response and data package, and marks the case as approved. If changes are needed, they leave a comment in Notion and the Operations Manager amends the draft manually before re-approving.
Director / Legal Adviser
Human
9
After approval is logged in Notion, the automation sends the finalised response and any required data pack to the requester via Gmail and records the sent timestamp in the case record.
Automation
Automated
10
The Notion case record is updated with the completion date, reviewer name, and outcome, and the case is marked as closed. A full audit trail is preserved for regulator reference with no manual follow-up needed.
Automation
Automated
Process Runbook / SOPPage 2 of 4
FS-DOC-03Operations

03Handling exceptions

Situation
What the system does
What you do
The requester does not provide identity documents within 7 days
The automation sends a follow-up chase email to the requester via Gmail and adds a note to the Notion case record flagging the delay. The deadline clock continues to run.
If no ID is received after 14 days, contact the requester directly by phone or alternative email. Update the Notion case record with the outcome. If identity cannot be confirmed, log a refusal reason in Notion and close the case.
A duplicate request is submitted (same requester, same request type, case already open)
The automation creates a second Notion record. There is no automatic deduplication at this stage.
Open both Notion records, confirm they relate to the same case, and mark the duplicate as closed with a note referencing the original case ID. Reply to the duplicate submission email to let the requester know their original case is active.
HubSpot returns no records for the requester
The Data Discovery Agent logs a nil-return result in the Notion case record and still sends the Slack reviewer notification, noting that no data was found in HubSpot.
Review the case record and confirm whether the requester is genuinely not in HubSpot, or whether they may appear under a different email or name. Check any other connected data sources manually. Update the Notion record with your findings before approving the response.
The reviewer does not respond to the Slack notification within 48 hours
The automation does not escalate automatically. The case sits open in Notion with a pending approval status.
Check the Notion case record for the deadline date. If fewer than 5 days remain, escalate directly to the reviewer or their substitute by phone or email. You can approve the response yourself if you are also a named approver for the case.
Notion is unavailable (planned or unplanned outage)
The automation cannot create or update case records while Notion is offline. Typeform submissions may still arrive but will not be logged until the platform is restored.
Check your email for any Typeform submission notifications that arrived during the outage. Log them manually in Notion as soon as it is restored, setting the deadline date from the original submission timestamp. Notify FullSpec at support@gofullspec.com if the outage lasted more than 2 hours and you are unsure whether any records are missing.
Gmail is unavailable and automated emails cannot be sent
The automation will retry sending verification or response emails up to three times at 15-minute intervals. If all retries fail, the Notion case record is flagged with a send-failure status.
Check the Notion case record for any send-failure flags. Send the verification or response email manually from your Gmail account, copying the standard template text. Update the Notion case record to confirm the email was sent and record the sent timestamp.

04Who to contact and when

Fill in the team rows below once your contacts are confirmed. Keep this table updated whenever a role changes so that exception handling is never delayed by uncertainty about who to call.

Role
Name
How to reach them
Process owner (Operations Manager)
[Your name]
[Your email / Slack handle]
Primary reviewer (Director)
[Rep name]
[Rep email / Slack handle]
Legal adviser
[Rep name]
[Rep email / phone]
Backup approver (if primary reviewer is unavailable)
[Rep name]
[Rep email / Slack handle]
FullSpec builder
FullSpec team
support@gofullspec.com
FullSpec support (technical issues, automation errors, change requests)
FullSpec support
support@gofullspec.com
Contact FullSpec at support@gofullspec.com for any of the following: the automation stops triggering on new Typeform submissions, Notion records are not being created, HubSpot data is not appearing in the draft response, or you need to update the intake form, email templates, or reviewer routing. Do not attempt to reconfigure the automation connections yourself, as incorrect changes can break the audit trail.
Process Runbook / SOPPage 3 of 4
FS-DOC-03Operations

05Ongoing maintenance

When
What to do
Who
Whenever a new data source is added (e.g. a new CRM, support tool, or billing platform)
Notify FullSpec at support@gofullspec.com so the new system can be connected to the Data Discovery Agent. Do not assume the automation will find data in tools it has not been configured to query. Until connected, those systems must be checked manually for each request.
Operations Manager + FullSpec
Whenever your identity verification or response email templates need updating
Send the revised template text to FullSpec at support@gofullspec.com. Do not edit the Gmail templates directly inside the automation platform, as changes made outside the configured workflow may not save correctly.
Operations Manager + FullSpec
Monthly spot-check (first week of each month)
Open the Notion case log and review all requests closed in the previous month. Confirm each record has a response date, reviewer name, and closed status. Flag any incomplete records to FullSpec for investigation.
Operations Manager
Monthly error-log review
Check the Notion case records for any send-failure flags, nil-return HubSpot results, or cases still marked as pending approval after 5 or more days. Investigate each one and update the record with a resolution note.
Operations Manager
Whenever a team member changes role, leaves, or a new reviewer is added
Update the contact table in Section 04 of this runbook immediately. Notify FullSpec so the Slack reviewer notification and approval routing can be updated to reflect the new team structure.
Operations Manager + FullSpec
Quarterly volume review (every 3 months)
Compare actual request volume against the assumed baseline of 4 requests per month. If volume has increased significantly, review whether the current automation tier and tooling costs remain appropriate and discuss capacity with FullSpec.
Operations Manager
The single most common maintenance issue for this process is reviewer routing becoming out of date after a team change. If the Slack notification is pointing to someone who has left or changed role, draft responses sit unreviewed and the 30-day deadline continues to run. Update the reviewer assignment in the automation immediately whenever a personnel change occurs, and confirm the new reviewer has access to the relevant Notion workspace.
Process Runbook / SOPPage 4 of 4

More documents for this process

Every document generated for GDPR / Data Privacy Request Handling.

Launch Plan
Operations · Owner
View
ROI and Business Case
Finance · Owner
View
Developer Handover Pack
Technical · Developer
View
Integration and API Spec
Technical · Developer
View
Test and QA Plan
Quality · Developer
View