Customer data deletion requests for small teams

The scariest email a small business can receive is short: "Under GDPR/CCPA I'm requesting that you delete all personal data you hold about me." Nothing is broken, nobody is angry — and yet most small teams freeze, because nobody knows whether deleting is required, allowed, or even possible across the nine systems that hold the customer's name. The deadline pressure is real (typically one month under GDPR, 45 days under CCPA), the penalty for a sloppy response is real, and — the part nobody advertises — fake deletion requests are also a social-engineering play.

This checklist turns the panic into a sequence: acknowledge, verify, inventory, delete what's deletable, keep what the law makes you keep, tell the processors, and close in writing. It costs one afternoon to prepare and about two hours per real request after that.

1. First 48 hours: acknowledge, then verify — in that order

Two moves, and the order matters:

The verification step costs one email. Skipping it is how a routine compliance request becomes the first hour of a data breach.

2. Build the inventory: where the data actually lives

The request says "all personal data." Reality is a map of copies. Before deleting anything, list where the person exists:

If you can't produce this inventory in under an hour, that's the finding: the SaaS sprawl audit (one hour, one owner per tool) is the fix, and it's cheaper to do before the request than during it.

3. Delete what's deletable — and know what you must keep

Here's the part that surprises people: the right to erasure is not a right to erase your accounting records. Split the inventory into two piles:

4. The processor relay: your vendors hold most of the data

A small team's honest inventory says the quiet part out loud: you don't hold most of the data — your SaaS vendors do. The deletion isn't done until it's done there:

5. What "deleted" means when you have backups

Nobody can surgically remove a person from last Tuesday's backup, and no regulator expects them to. What's expected is a defensible answer:

6. Close in writing: the confirmation that ends the clock

The request is complete when the requester knows it is. The closing letter is short:

7. Make it a procedure, not an improvisation

One request handled well is luck; three handled well is a process. After the first real request, spend thirty minutes making it repeatable: