{"id":7261,"date":"2025-03-24T09:19:45","date_gmt":"2025-03-24T08:19:45","guid":{"rendered":"https:\/\/lawwwing.com\/?p=7261"},"modified":"2025-04-07T16:32:33","modified_gmt":"2025-04-07T15:32:33","slug":"what-do-customer-asks-you-delete-their-data","status":"publish","type":"post","link":"https:\/\/lawwwing.com\/en\/what-do-customer-asks-you-delete-their-data\/","title":{"rendered":"What to do when a customer requests data deletion?"},"content":{"rendered":"\n<p><\/p>\n\n\n\n<p>In the digital age, we are aware of the value of our personal data. Data privacy is a topic of great importance today, yet many users are still unaware of the rights they have regarding data protection.<\/p>\n\n\n\n<p>One of the most relevant rights is the<strong> right to erasure<\/strong>, also known as the <strong>\u201cright to be forgotten.\u201d<\/strong><\/p>\n\n\n\n<p>If you have a business or manage a company that handles personal data, sooner or later you might receive a request from a customer asking you to delete their information. What should you do in this situation? Are you required to delete the data in all cases? Are there any exceptions? In this article, we will try to answer all these questions so you can comply with the regulations and respond appropriately to these requests.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The right to erasure according to the GDPR<\/h2>\n\n\n\n<p>Data erasure is a process aimed at <strong>permanently deleting <\/strong>personal data held by a company. The goal is to ensure that <strong>personal data<\/strong> is not kept longer than necessary and is handled in accordance with data protection laws.<\/p>\n\n\n\n<p>In Europe, <strong><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/ES\/TXT\/?uri=CELEX%3A32016R0679\" target=\"_blank\" rel=\"noreferrer noopener\">Article 17 of the General Data Protection Regulation (GDPR)<\/a> <\/strong>gives users the right to request the deletion of their personal data whenever certain circumstances are met.<\/p>\n\n\n\n<p>But what exactly is this right? This right allows:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Individuals to request the deletion of their personal data when it is no longer necessary for the <strong>purpose<\/strong> for which it was collected.<\/li>\n\n\n\n<li>When they have <strong>withdrawn <\/strong>their consent.<\/li>\n\n\n\n<li>When its processing is <strong>unlawful<\/strong>, among other reasons.<\/li>\n<\/ul>\n\n\n\n<p>However, while the <strong>right to erasure<\/strong> is fundamental, it is not an absolute right, and data cannot always be deleted. There are some situations where companies are not obligated to delete a customer's data, even if requested.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Do you always have to delete a customer\u2019s data?<\/h2>\n\n\n\n<p>There are several reasons why a company may refuse a data deletion request.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>One of the most common is when the data is necessary to comply with<strong> a legal obligation<\/strong>. For example, <strong>invoices and accounting documents<\/strong> must be kept for a specific period established by <strong>tax law<\/strong> (4 years).<\/li>\n\n\n\n<li>Other situations include when the data is necessary for <strong>legal claims<\/strong> if the company is involved in a lawsuit or anticipates one.<\/li>\n\n\n\n<li>The right to erasure does not apply when data processing is <strong>necessary for reasons of public interest:<\/strong> scientific, statistical, or historical research.<\/li>\n<\/ul>\n\n\n\n<p>If your company receives a data deletion request, but the data falls under any of these exceptions, it is important to inform the customer clearly and transparently why it is not possible to delete the data at that time.<\/p>\n\n\n\n<p>Your obligation will be to convert that data into<strong> blocked data<\/strong> until the retention period ends for one of the aforementioned reasons.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" width=\"880\" height=\"495\" src=\"https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/03\/6c212355-d1e9-4010-817b-863f2102f6c6_16-9-aspect-ratio_default_0.jpg\" alt=\"\" class=\"wp-image-7252\" style=\"width:590px\" srcset=\"https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/03\/6c212355-d1e9-4010-817b-863f2102f6c6_16-9-aspect-ratio_default_0.jpg 880w, https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/03\/6c212355-d1e9-4010-817b-863f2102f6c6_16-9-aspect-ratio_default_0-300x169.jpg 300w, https:\/\/lawwwing.com\/wp-content\/uploads\/2025\/03\/6c212355-d1e9-4010-817b-863f2102f6c6_16-9-aspect-ratio_default_0-768x432.jpg 768w\" sizes=\"(max-width: 880px) 100vw, 880px\" \/><\/figure>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Steps to handle a data delation request<\/h2>\n\n\n\n<p>If a customer requests the deletion of their data, the first thing you must do is <strong>verify their identity<\/strong>. This is important to prevent unauthorized individuals from requesting the deletion of someone else's information.<\/p>\n\n\n\n<p>By the way, don\u2019t go asking for their <strong>ID directly<\/strong>! Your obligation is to verify the identity of the person wishing to exercise a right, but you <strong>should not request invasive personal data<\/strong> (such as a photocopy of their ID) when you can verify their identity through simpler means.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>For example, you can ask them to provide their phone number or the last digits of their ID; but only if these are details you have stored in your database and can use to verify that the person is who they claim to be.<\/li>\n<\/ul>\n\n\n\n<p>Once you've confirmed their identity, you need to review the request and <strong>decide if the data can be deleted or if there's a legal reason to keep it<\/strong>. If the request is valid, you must delete it from all systems where it is stored and ensure it is no longer processed in the future.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/lawwwing.com\/en\/what-is-gdpr-and-how-does-it-affect-your-website\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>GDPR<\/strong><\/a> establishes that companies have a period of <strong>one month<\/strong> to respond to customers\u2019 requests related to their data protection rights. In cases where the request is complex, the period can be extended to<strong> two months<\/strong>, and the customer must be<strong> informed about the extension and the reasons for the delay.<\/strong><\/p>\n\n\n\n<p>After deleting the data, you must confirm to the customer that their request has been fulfilled. If it is not possible to delete the data due to legal exceptions, you must explain the reasons and the period during which the information will remain stored.<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Best practices to avoid issues with data management<\/h2>\n\n\n\n<p>To avoid future problems, follow these recommendations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Clearly inform your customers about how their <strong>data will be used<\/strong> in your<strong> privacy policy.<\/strong><\/li>\n\n\n\n<li>Implement <strong>internal procedures<\/strong> to handle users\u2019 rights requests.<\/li>\n\n\n\n<li><strong>Minimize the collection of personal data:<\/strong> the fewer data you store, the lower the risk.<\/li>\n\n\n\n<li><strong>Keep records<\/strong> of deletion requests and how you have handled them.<\/li>\n<\/ul>\n\n\n\n<p>Did you know that at <strong><a href=\"https:\/\/lawwwing.com\/en\/dsar-exercise\/?_gl=1*1brzrff*_up*MQ..*_ga*NjY5Mjg5ODQ2LjE3NDQwMzg5OTc.*_ga_PVQTMLESR8*MTc0NDAzODk5Ni4xLjAuMTc0NDAzODk5Ni4wLjAuMA..\" target=\"_blank\" rel=\"noreferrer noopener\">Lawwwing<\/a><\/strong>, we help you manage your customers\u2019 rights requests? Properly handling personal data deletion requests is essential to comply with the GDPR and LOPDGDD. <strong>Lawwwing<\/strong>, the comprehensive platform to comply with digital regulations and ensure your website meets all legal requirements.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-1 wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-background wp-element-button\" style=\"background-color:#5533ff\"><strong>Get it free<\/strong><\/a><\/div>\n<\/div>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Data erasure is a process aimed at permanently deleting personal data held by a company.<\/p>\n","protected":false},"author":9,"featured_media":7285,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"footnotes":""},"categories":[364,216,210,345,209,243,201,211,202],"tags":[360,372,425,382,371],"class_list":["post-7261","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-2025-3","category-consent","category-data-protection","category-datos-personales-en","category-gdpr-en","category-online-privacy-en","category-privacy-en","category-privacy-policy-en","category-rgpd-en","tag-2025-2","tag-consent","tag-datos-personales","tag-gdpr","tag-privacy"],"acf":[],"_links":{"self":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/7261","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/comments?post=7261"}],"version-history":[{"count":6,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/7261\/revisions"}],"predecessor-version":[{"id":7649,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/posts\/7261\/revisions\/7649"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media\/7285"}],"wp:attachment":[{"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/media?parent=7261"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/categories?post=7261"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lawwwing.com\/en\/wp-json\/wp\/v2\/tags?post=7261"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}