Why this needs a source card
Customer-data access questions can touch CRM notes, support tickets, invoices, recordings, forms, uploaded files, chat transcripts, email threads, and third-party AI tools. The risk is not only privacy; it is accidentally inventing what exists, exposing another customer's records, or promising a legal/compliance outcome before the right owner reviews it.
Copy/paste customer data access request card
| Field | What to capture | Review rule |
|---|---|---|
| Requester and verification status | Name, business/customer ID, contact method, account/order/project reference, and how the request was received. | Use the official customer record. Do not use AI to decide whether identity is verified. |
| Request scope | Exact wording of the request, date received, requested time period, data types requested, preferred delivery channel, and deadline owner. | Attach the original request before summarizing it. |
| Systems to check | CRM, helpdesk, billing, forms, email, calendar, call/meeting tools, chat widgets, file storage, e-signature, marketing tools, and AI vendors that may hold customer content. | List confirmed systems and missing-access systems separately. |
| Records found | Record type, source link/path, owner, last updated date, whether it includes third-party/private staff notes, and whether it needs redaction or exclusion review. | Never paste raw private records into an AI tool unless the approved AI/data policy allows it. |
| Risk and escalation | Legal/privacy reviewer, customer relationship owner, sensitive categories, third-party records, minors/health/financial details, dispute/chargeback risk, and vendor support questions. | Escalate uncertain, regulated, disputed, or sensitive records before drafting a final answer. |
| Approved response status | Acknowledgement sent, proof gathering in progress, waiting on reviewer/vendor, approved export, declined/limited with reason, or closed. | Record decision owner, date, evidence links, and next check date. |
Safe acknowledgement snippets
Initial acknowledgement: We received your request about the information associated with [account/order/project]. We are checking the relevant business systems and will respond through [official channel] after the request scope and account details are reviewed.
Missing verification note: Before we can continue, please use [official channel/process] so we can match this request to the correct customer record. We cannot provide or summarize account information from an unverified message.
Internal owner note: Customer data access request received on [date]. Please review identity/source proof, systems to check, sensitive records, third-party notes, AI/vendor data exposure, and approved response wording before any export or final reply.
AI review prompt
Act as a cautious operations assistant helping a small business organize a customer data access request for human review.
Use only the verified facts below. Do not decide legal obligations, verify identity, invent records, summarize raw private records, approve exports, promise completeness, recommend deletion, or draft a final customer response.
Verified facts:
- Original request text and date:
- Customer/account/order/project reference:
- Verification status and official channel:
- Requested scope and time period:
- Systems checked:
- Systems still missing:
- Record categories found:
- Sensitive/third-party/staff-note concerns:
- AI/vendor systems that may contain customer content:
- Owner/privacy reviewer:
- Due date and next step:
Return: 1) missing proof, 2) systems checklist, 3) risk flags, 4) reviewer questions, 5) safe internal summary, 6) customer-safe acknowledgement draft only, and 7) STOP AUTOMATION items.Weekly privacy-and-AI hygiene questions
- Which tools contain customer content that the team forgot to include in request reviews?
- Which AI tools should be kept out of raw customer-record review entirely?
- Which support, billing, or CRM fields need clearer owners before the next request arrives?
- Which request types need a written SOP, not another ad hoc AI summary?
Related free assets: Customer Data Deletion Request Checklist, Customer Data Redaction Checklist, and AI Customer Consent Record Checklist.
Disclosure: Horizon Flow is Andrew Burton's digital product catalog. This worksheet is useful without purchase; product links are labeled and UTM-tagged.
Product signal: if this customer-data access request checklist earns clicks, replies, or reuse, add a dedicated customer-data request SOP appendix to the paid Small Business AI Profit Kit covering access, deletion, correction, redaction, vendor checks, and owner/privacy review prompts.