Start with scope and verification
Before assigning deletion work, the team should understand who is asking, what relationship the request concerns, and whether the requester is verified for the action.
- Confirm the request type and requester relationship.
- Use verification review before changing account data.
- Document unclear scope or representative requests.
| Step | Evidence | Decision owner |
|---|---|---|
| Find | Systems and matched records | System owner confirms search |
| Review | Retention, exception, and dependency notes | Authorised reviewer decides treatment |
| Act and confirm | Change result, failure, or retained item | Case owner checks completion |
Assign system-specific tasks
Deletion work can cross product, support, billing, analytics, and operational systems. Tasks should identify the system owner and the evidence needed for review.
- Use the system list to assign work to the right owner.
- Create repeatable task templates for common systems.
- Track completion and exceptions against the case.
Review before confirming
Final response should be reviewed before the requester is told what happened. The case should show what was completed, what could not be completed, and who approved the response.
- Keep response language consistent but human-reviewed.
- Make the response specific to the actions and outcomes the team has reviewed.
- Attach closure notes to the case history.
Example: product, support, and billing hold records
The case owner assigns separate reviews to the teams responsible for those systems. Each team records what it found and the outcome of its work, including anything referred for further review.
- Define the account identifiers and systems in scope before anyone takes action.
- Ask each owner to distinguish completed work from unresolved questions.
- Have the final reviewer reconcile the results before saying what was deleted.
Define completion for each system task
A task called "delete customer" is too vague to support a careful review. Write down the system, the approved scope, and the result the owner must report.
- Specify who can authorize the action and who will carry it out.
- Record failures, dependent systems, or retained records for the appropriate reviewer.
- Keep the final confirmation limited to actions the team can substantiate.
Sources
Sources checked September 20, 2026. These primary and regulator materials support the legal-rule summaries above; check the current rules that apply to your organization.
- EU General Data Protection Regulation, Articles 12 and 15 — Primary text for access rights, transparent communication, identity questions, and response timing.
- California Attorney General: California Consumer Privacy Act — Official overview of consumer rights, designated request methods, verification, and 45-calendar-day responses.
Common questions
What makes deletion requests hard to manage?
They often require identity verification, multiple system owners, retention review, exceptions, and careful response approval.
Should engineering own every deletion request?
Engineering may own system tasks, but the overall request workflow usually needs legal, compliance, operations, or support ownership.
How should exceptions be handled?
Exceptions should be reviewed by the appropriate human owner and documented in the case record.
Run privacy requests in one controlled workflow
Privacy Requests helps teams manage intake, verification, tasks, response preparation, secure delivery, and audit history without a broad enterprise suite.
Start free