One day you receive an email with the subject line “Delete all my data, now!”. What do you do next? Call your go-to person for legal questions?
You don’t need a legal team to respond to requests like this—you just need a process to know what to do and when you actually need external help. I will explain the main points and give you some useful tips on how to handle and understand these requests without any issues. By the end of this article, you will have a good understanding of how to handle simple data subject requests. Let’s imagine you are running an e-commerce business or an early-stage startup.
How do you identify data subject requests?
We are not going down the rabbit hole here; let’s keep it simple for the sake of clarity. You are most likely to see these main types:
- Right of Access (DSAR): “Send me all the data you have on me.” Sometimes this is phrased as simply wanting a copy of all the personal information you hold about them. You are expected to hand over a copy of that data.
- Right to Erasure (“Right to be Forgotten”): “Delete my account and purchase history.” Again, sometimes they want everything wiped. If you use contractors or third-party platforms to process data (including mailing lists, forums, or CMS tools), this includes removing their data from those places as well.
- Right to Rectification: “Update my personal details.” Sometimes customers notice their address is wrong, or their last name changes after marriage. Most of the time, this is just a simple correction of details.
- Right to Object / Opt-out: “Stop using my email for marketing.” People subscribe to all sorts of things, and their interests change over time. You must respect this right and stop sending marketing emails when requested.
…and also, any combination of the above, such as: “What information do you have on me? I don’t want to get any more of your emails!” (which is an access request combined with a marketing opt-out). It is also common for people to ask for their data to be deleted and then, a few weeks later, file an access request just to see if you actually fulfilled their deletion request.
At this point, I want to highlight some very common mistakes and misunderstandings around these requests.
First, the request doesn’t always spell out its legal name—and according to the GDPR, it does not need to. If a customer sends a long email and somewhere inside it they mention “…and remove all my information,” you are expected to treat it as a formal request. Sometimes people use generic templates they found on the internet that don’t make much sense, using strange wording or referencing inaccurate things. That doesn’t matter. Even if they cite an unrelated law, if you can understand their overall intent, you must handle it as a valid GDPR request. The request does not even need to mention “GDPR” or include any other ‘magic’ words to be legally binding.
Second, a request can arrive in any shape or form. It can be a phone call, a text message, an email, or a message sent through the customer support bot on your website. Contrary to common belief, you cannot force your customers to use one specific channel. You can ask them to send an email to a designated address, but they are not obliged to follow that instruction. The same applies to online forms and portal logins—while forcing them through a form would make your life easier, their request remains valid regardless of the medium they choose to use.
Now, let’s discuss the time limit to respond
If you don’t know what to look for, you might not even realize you’ve received a request—meanwhile, the clock is already ticking.
- You have one calendar month to fulfill the request. In practice, this is commonly understood as 30 days from the date you receive it.
- You should not charge for anything related to fulfilling the request. There are rare exceptions when requests are manifestly unfounded or excessive, but this is not something you should rely on 99.9% of the time. So, we will not discuss it further here.
- You may encounter situations where you need more than one month if you receive an exceptionally complex request. You can extend your response time by two additional months (one time only), but be aware that citing a lack of staff or saying “it takes too much time” are not valid reasons. The request itself must be inherently complex. Think of extensions as being meant for edge cases, like needing to redact thousands of pages or long video footage.
- A short note on redaction: A person is entitled to their own information, but you cannot provide personal information belonging to someone else. In many cases, redaction is required so you don’t commit a data breach yourself while answering a request.
Practical tips for handling requests
Aside from having a clear process and educating your team, here are a few extra tips for a smooth workflow:
- Know where your data is stored, what tools you use, and how you can locate customers across your systems. If you have customer profiles, make sure you gather all information connected to them. For example, if you know a customer used a different email address in the past (and you have a record of it), you need to dig up that related information as well. In practice, people often forget that the scope of GDPR covers the entire person, not just a single data point like their current email address.
- Educate your customer-facing employees so they know how to spot a data subject request and what to do with it. Ideally, you should appoint someone in your organization to track these and ensure their completion. That way, frontline staff can simply forward incoming requests to the right person. All support staff need to know is how to spot a request, what details to note down (like the exact time it was received), and where to send it internally. It’s simple and should be covered in your routine privacy training.
- Watch out for bad actors. At the same time, don’t forget that malicious actors sometimes try to get hold of other people’s information. You must make sure that data held on one person never ends up in the hands of someone else.
- Automate where you can. Depending on your size, you can try to automate parts of the process with dedicated privacy tools, but keep in mind that you still need structured data and human oversight to spot and validate requests properly.
I promised not to go down the rabbit hole, so here is an actionable process you can customize for your needs:
Step-by-Step Response Process
You received a request and you understand what they want—so, what do you do now?
- Step 1: Verify Identity: You have to confirm that the request is coming from the actual account holder. In most cases, you can do this by sending back a quick confirmation. Ask for details you already have on file to verify them—like their name, email, phone number, or delivery address. If the request comes directly from the email address on file and the details match, it’s clear. If it arrives from a completely different address, you may need to ask for extra verification.Stick to information you already hold. If you never collected a government ID number before, you do not need it now to validate who they are. Avoid asking for sensitive documents unless absolutely necessary. This is why companies like to push users to log into their accounts to submit requests—logging in acts as immediate proof of identity. If you would normally trust it’s the right person for a regular customer service issue, that same level of validation is usually sufficient here.
- Step 2: Map and Audit the Data: This simply means checking your systems (like your order handling system or CRM) using the information you have on the person. Double-check that the records match—for instance, making sure an order belongs to that specific individual, as multiple family members might share an email address.
- Step 3: Handle Exceptions: This mostly comes up with deletion requests. There will be cases where you cannot fully wipe a customer’s data due to tax laws, legal obligations, or active service requirements (like a product warranty—if you have no record of the order, you can’t honor the warranty). If you must refuse to delete certain data, provide a clear explanation to the customer (e.g., explaining that you are legally required to keep sales invoices for tax audit purposes for X years).If your business is growing, make sure you establish a clear data retention policy that outlines what data is kept, for how long, and why. This makes explaining exceptions much easier.
- Step 4: Prepare and Send the Response: Gather the documents and put them into a clean, easily readable format. Draft a response letter (using a standard template) answering any specific questions they asked.Deliver the response securely. Sending raw files or sensitive documents via plain email might not be secure enough. However, if you are simply sending a confirmation that their data has been deleted, a plain email is perfectly fine.
- Step 5: Log the Case: You are required to keep internal records of data requests in case a privacy regulator asks you to demonstrate compliance. Keep a secure log containing the case details, dates, and actions taken. This is also helpful if the same person files another request later on, so you can see your previous history with them. Finally, don’t forget to send a final email confirming to the user that their requested action has been completed.
Need a Hand Setting This Up?
This is a simple, high-level overview of what data subject requests look like and the crucial steps you need to take to comply. If a request looks unusually complex or comes from a former employee, make sure to consult a professional before responding.
Above all, ensure you have an internal system in place to spot these requests the moment they arrive so your 30-day clock doesn’t run out!
If you have any questions, feel free to contact us—we can help you build a smooth process, educate your team, or audit your current privacy setup.
FAQ
1. What do I do if a former employee or customer threatens a GDPR fine to negotiate a refund?
Separately process their data request and handle the commercial dispute—never combine them or offer to ignore GDPR in exchange for settling. Regulators penalize “blackmail” tactics lightly, but heavily fine businesses that fail to respond within 30 days due to an ongoing argument.
2. Do we have to delete data stored in offsite system backups and disaster recovery?
No, provided you put those backups out of active reach. You do not need to immediately restore and edit historical backups; simply mark the user as deleted in your live database so that if a backup is ever restored, their data is immediately re-purposed or purged.
3. Can an ex-employee request internal Slack messages, Teams chats, or emails mentioning them?
Yes, but only messages where they are the subject or sender, not every internal discussion. Before releasing internal communications, you must redact all opinions, performance reviews, or personal details belonging to other colleagues to prevent committing a separate privacy breach.
4. How do I verify a customer’s identity if they no longer have access to their original email address?
Do not ask for government IDs or passports if you never stored them before. Instead, verify them using “knowledge-based” matching: ask them to confirm specific past transaction details only the real owner would know, such as a specific order number, date of purchase, or the last four digits of the payment card used.
5. Can a lawyer, relative, or claims agency submit a GDPR request on behalf of a customer?
Yes, individuals are legally allowed to designate a representative. However, do not hand over any data immediately. You must request written proof of authority (such as a signed Letter of Authority or Power of Attorney) confirming the representative is authorized to act on the customer’s behalf. If they cannot provide signed authorization, you must refuse the disclosure to avoid committing a data breach.