Workflow Template
Privacy Enquiry Contact Form Workflow
Public website privacy enquiry contact form and lightweight intake workflow. Captures the enquiry, sends immediate confirmation, classifies it as a general privacy question or a formal rights request (routing rights requests to the existing DSAR workflow), prioritises urgent general enquiries, assigns them to the privacy owner for response, closes them once answered, sends a closure confirmation, and follows up with a short feedback request one day later.
This workflow is designed for privacy, legal, and data protection teams who manage inbound enquiries through a public website contact form and need a consistent way to triage them. It automates enquiry capture, confirmation messaging, classification between general questions and formal rights requests, prioritisation of urgent items, and assignment to the privacy owner for response. The result is a structured intake process that reduces manual sorting, helps rights requests reach the DSAR workflow without delay, and closes the loop with confirmation and feedback follow-up.
Business Outcomes
- Reduces manual triage time by automatically classifying general enquiries versus formal rights requests
- Helps ensure urgent enquiries are surfaced and prioritised for faster attention
- Supports consistent handoff of rights requests into the existing DSAR workflow
- Improves response accountability with clear status tracking from received to responded
- Increases visibility into enquiry outcomes through post-closure feedback collection
Workflow Steps
Steps
- 1Create Privacy Enquiry Recordcreate record
Creates a record for the submitted privacy enquiry.
- 2Set Status: Receivedupdate record
Marks the enquiry as received.
- 3Send Confirmation Emailsend email
Sends an immediate confirmation email to the submitter.
- 4Check if Mobile Number Provided
Sends a confirmation SMS only when a mobile number was provided.
phone: ""→Send Confirmation SMSDefault→Classify Enquiry - 5Send Confirmation SMSsend sms
Sends a confirmation SMS to the submitter's mobile number.
- 6Classify Enquiryai classification
Determines whether this is a general privacy question or a formal data-subject rights request.
- 7Route on Classification
Routes rights requests to DSAR, general questions to the standard handling path, and uncertain cases to human review.
_ai_clf_classify_enquiry_needs_human_review: "true"→Human Review: Classify Enquiry_ai_clf_classify_enquiry_category: "rights_request"→Route to DSAR Workflow_ai_clf_classify_enquiry_category: "general_question"→Prioritise EnquiryDefault→Human Review: Classify Enquiry - 8Human Review: Classify Enquirycreate task
A staff member manually determines whether this is a general question or a rights request.
- 9Route on Manual Classification
Routes based on the staff member's manual classification decision.
manual_classification: "Formal Rights Request"→Route to DSAR Workflowmanual_classification: "General Privacy Question"→Prioritise EnquiryDefault→Prioritise Enquiry - 10Route to DSAR Workflowupdate record
Marks the enquiry as routed and notifies the existing Data Subject Access Request workflow via webhook.
- 11Notify DSAR Workflowcall webhook
Calls the existing Data Subject Access Request workflow to hand off this formal rights request.
- 12Send DSAR Handoff Emailsend email
Lets the submitter know their request has been forwarded to the formal rights request process.
- 13Prioritise Enquiryai prioritisation
Assesses urgency of the general privacy enquiry.
- 14Check Priority Confidence
Routes low-confidence prioritisation results to human review before assignment.
_ai_priority_prioritise_enquiry_needs_human_review: "true"→Set Status: Under Review (Priority Confirmation)Default→Assign to Privacy Owner - 15Human Review: Priorityrequest approval
A staff member confirms the urgency of this enquiry before assignment.
- 16Assign to Privacy Ownerassign user
Assigns the enquiry to the designated privacy owner for handling.
- 17Set Status: Assignedupdate record
Marks the enquiry as assigned to the privacy owner.
- 18Respond to Enquirycreate task
Privacy owner drafts and records the response to the enquiry.
- 19Set Status: Responded and Save Notesupdate record
Marks the enquiry as responded and stores the response summary.
- 20Close Enquiryupdate record
Closes the general enquiry now that it has been answered.
- 21Send Closure Confirmation Emailsend email
Notifies the submitter that their enquiry has been closed.
- 22Wait 1 Day Before Feedback Request
Pauses for one day after closure before requesting feedback.
- 23Request Feedbackrequest external input
Sends a short feedback request to the submitter one day after closure.
- 24Set Status: Under Review (Manual Classification)update record
Marks the enquiry as under review while a staff member manually classifies it.
- 25Set Status: Under Review (Priority Confirmation)update record
Marks the enquiry as under review while a staff member confirms its priority.
- 26Route on approval outcome
Routes the workflow based on the approval decision.
approval_status: "approved"→Assign to Privacy Ownerapproval_status: "rejected"→Set Status: Closed (Priority Review Rejected)Default→Set Status: Closed (Priority Review Rejected) - 27Set Status: Closed (Priority Review Rejected)update record
Marks the enquiry as closed after the priority confirmation was rejected during human review.
- 28Send Priority Rejection Notificationsend email
Notifies the submitter that their enquiry was reviewed and closed without further action.
Fields
- Full Name*
- Email Address*
- Mobile Number (optional)
- Privacy Enquiry Type*
- Message*
- Enquiry Status
- +1 more fields
Forms
Privacy Enquiry Contact Form
5 fields
Data Views
Privacy Enquiries
privacy_enquiry_ref, full_name, email, enquiry_type +1 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send SMS in the workflow
Twilio
AWS SNS
Send email in the workflow
AWS SES
Similar Categories
FAQs
Why should we automate our privacy enquiry contact form instead of managing it manually via email?
Manual inbox management makes it hard to track which enquiries are general questions versus formal rights requests, increasing the risk of misrouted or delayed responses. This workflow automatically classifies and prioritises each enquiry, then assigns it to the privacy owner, which helps reduce the administrative overhead of manual sorting. It also maintains a consistent audit trail of status changes from receipt through to response and closure.
What is the ROI of using this workflow compared to a shared privacy inbox?
A shared inbox relies on individuals to manually read, classify, and forward enquiries, which can introduce delays and inconsistency, especially during staff absences. This workflow automates confirmation, classification, prioritisation, and assignment, which is designed to reduce time spent on repetitive triage tasks and help teams respond more consistently. Over time this can translate into fewer missed or delayed rights requests and improved stakeholder trust in the privacy function.
How does this workflow integrate with our existing DSAR process?
When an enquiry is classified as a formal rights request, the workflow routes it directly to the existing DSAR workflow and notifies the relevant team, sending a handoff email to confirm the transfer. This is configured inside assess.one, so no separate system integration project is required. The classification logic can be reviewed and adjusted directly in the platform if your definition of a rights request changes.
Can we customise the classification and prioritisation logic to match our internal privacy policy?
Yes, the classification and prioritisation steps, including the human review checkpoints, can be adjusted directly within assess.one to reflect your organisation's definitions of urgency and enquiry type. You can also modify routing rules, notification recipients, and approval logic without needing developer support. Changes take effect as soon as they are published.
Who needs access to this workflow within our organisation?
Typically the privacy owner or team responsible for handling enquiries needs access to review, respond to, and close enquiries, while DSAR-specific team members receive notifications when a request is routed to that workflow. Access and roles are configured within assess.one, so permissions can be scoped to only the people who need visibility into enquiry handling. Broader stakeholders can be added as notification recipients without full workflow access.
What happens at the human review checkpoints in this workflow?
The workflow includes human review steps for classification and priority confidence, which are triggered when automated classification does not meet a defined confidence threshold. At these points, a reviewer confirms or corrects the categorisation before the enquiry is routed further, which helps reduce the risk of misclassified rights requests or missed urgent items. This balances automation speed with a manual check for edge cases.
How long does it take to implement this workflow?
This is a ready-to-use template, so it can be published and live within minutes rather than requiring a lengthy implementation project. Once published, your team can begin receiving and processing privacy enquiries immediately. Any customisation to steps, roles, or notifications can be made directly in assess.one before or after going live.
Are there compliance considerations built into this workflow?
The workflow is designed to support accountability by tracking enquiry status at each stage, from received through to responded, and by routing formal rights requests into a dedicated DSAR process rather than treating them as general enquiries. This structure is intended to help teams demonstrate a documented, consistent handling process, though organisations remain responsible for ensuring their overall privacy program meets applicable legal obligations. The workflow's notes and status fields can support internal record-keeping for audits.
What happens after an enquiry is closed?
Once the privacy owner responds and the status is set to responded, the workflow sends a closure confirmation to the requester and automatically schedules a short feedback request approximately one day later. This is designed to help capture requester sentiment and identify any gaps in the response process. Feedback responses can be reviewed within assess.one to inform ongoing improvements.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
