Skip to main content

Data deletion request response templates: how to answer a GDPR erasure request

Seven replies for a customer who asks you to delete their data, from the first acknowledgement to the confirmation, including what you are allowed to keep. Practical guidance for small software businesses, not legal advice.

The templates

Each one copies with its subject line. The parts in brackets are the parts to change; the date and the list of what you keep are the parts to get exactly right.

Acknowledging the request, with a date

Subject: Re: [their subject line]

Hi [Name], Thanks for your email. I have received your request to delete your personal data, and I will have it done by [date, no later than one month from when your request arrived]. That will cover [your account, your support emails with me, your licence record and your mailing list entry]. Two things to know before then: 1. Deleting your account [deactivates your licence / ends your access], and it cannot be undone. 2. I am required to keep some records, such as invoices, for tax purposes. I will list exactly what when I confirm. I will email you once it is done. [Your name]
Verifying identity, when it comes from another address

Subject: Re: [their subject line]

Hi [Name], Thanks for your request. Before I delete anything, I need to be sure it comes from the account holder, because this address is not the one I have for the account you mentioned. The simplest way: reply from the address you used to [buy Product / sign up], or send me the order number from your receipt. This is only to stop someone else deleting your account. As soon as I hear back, I will go ahead and have it done by [date]. [Your name]
Confirming the deletion is complete

Subject: Your data has been deleted

Hi [Name], This is to confirm that I have deleted your personal data from [Product], as you asked on [date]. That covers [your account, your support conversations, your licence record and your mailing list entry]. What remains, and why: - [Invoices for your purchases, which I must keep for number years for tax purposes.] - [Payment records held by Stripe / Paddle / Apple, which they keep under their own legal obligations.] - [Backups, which are overwritten automatically within number days and are never restored for any other purpose.] Unless you write to me again, this is the last email you will get from me. Thank you for having used [Product]. [Your name]
Explaining what you have to keep

Subject: Re: [their subject line]

Hi [Name], I have deleted [your account, your support emails and your mailing list entry]. There are a few things I am not able to delete, and I want to be clear about what and why: - Invoices and payment records: accounting and tax rules in [country] require me to keep these for [number] years. They contain [your name, billing address and what you paid] and are used for nothing except my accounts. - Records held by [Stripe / Paddle / Apple]: I never stored your card details. [Payment processor] keeps its own records under its own legal obligations, and you can contact them directly at [their privacy contact]. - A note of this request: [your email address and the date], kept only so I can show your request was handled and make sure you are never added to the mailing list again. When the retention period ends, the invoices will be deleted too. If you have any questions about this, reply here. [Your name]
Declining, or declining in part, with the reason

Subject: Re: [their subject line]

Hi [Name], Thanks for your request. I have [deleted your account and support history / looked into it carefully], but I cannot delete [the specific data] at the moment, and I want to explain why. [The reason, specifically, for example: there is an open dispute on your payment from date, and I need to keep the records related to it until it is resolved. Once it is closed, I will delete them and let you know.] If you disagree, you have the right to complain to [the ICO in the UK / the data protection authority where you live], and to seek a remedy through the courts. [Your name]
The request that is really a cancellation

Subject: Re: [their subject line]

Hi [Name], I have cancelled your subscription, so you will not be charged again. [Your access continues until date.] You also asked me to delete your account, and I will do that by [date]. So you know what it means: [your licence, settings and support history] will be gone, and I will not be able to restore them if you come back. If you only meant to stop the subscription and would like to keep your account, reply before then and I will leave it as it is. Otherwise, there is nothing more you need to do. [Your name]
The short version, when there was little to delete

Subject: Re: [their subject line]

Hi [Name], Done. I have deleted [your email address from the mailing list / your trial account], which was all I had. You will not hear from me again. [Your name]

Subject lines for a deletion request reply

Keep the thread. The request, your acknowledgement and your confirmation in one place is also your record that it was handled. If you start a new email, say plainly what it is about; this is not the place for a clever subject line.

  • Re: [their subject line] (reply in their thread, so request and answer stay together)
  • Your data deletion request: done by [date]
  • Please confirm your data deletion request
  • Your data has been deleted
  • About your data deletion request

What to get right

  • Recognise it when it arrives. “Please remove me from everything” is a deletion request, even without the words GDPR or erasure.
  • Acknowledge the same week. The deletion can take longer; the reply with a date takes a minute. A request left unanswered for weeks is how a routine email becomes a complaint to a regulator.
  • List every place their data lives before you promise anything: your mailbox, licence system, payment processor, mailing list tool, analytics, crash reports and backups. The one you forget is the one that emails them next month.
  • Verify with what you already have. A reply from the account address or an order number. Not a passport scan.
  • Be specific about what you keep. “Some data may be retained” invites a second email. “Invoices, for six years, because tax law requires it” does not. (Use your own country’s period.)
  • Do not ask them to justify it. A question to clarify what they want deleted is fine. A deletion request is not a negotiation, and not a retention opportunity.

Where a customer’s support history lives with Moorline

A deletion request is only as complete as your list of places the customer’s data might be, and support is usually the longest part of that list: every email they sent, every reply, every note. With a hosted help desk there is also a copy on the vendor’s servers to deal with.

Moorline works from the mailbox you already have and keeps its conversations in one database file on your Mac, with rolling local backups. No Moorline server holds your conversations. Moorline has no GDPR feature: it will not find, export or erase a customer’s data for you, and its Stripe view is read-only, so it cannot delete a customer in Stripe either. What it does is treat the request like any other conversation with two facts to settle, the deletion done and the customer told, and keep it on your list until both are true. That model is explained in how to never forget to reply to a customer, and a deletion request, with a legal deadline behind it, is the case where it matters most.

Questions people ask

How long do I have to respond to a GDPR deletion request?

Under the GDPR and the UK GDPR, usually one month from the day you receive it. That can be extended by up to two further months where a request is complex or you have received a number of them, but you have to tell the person within the first month and explain why. Other privacy laws set their own deadlines. This is general guidance, not legal advice.

Do I have to delete invoices when a customer asks me to delete their data?

Usually not. The right to erasure does not apply to data you must keep to meet a legal obligation, and accounting and tax rules in most countries require businesses to keep invoices for several years. Keep only what the law requires, for as long as it requires, use it for nothing else, and tell the customer that is what you are doing.

Can I ask for proof of identity before deleting someone’s data?

Yes, if you have reasonable doubt that the request comes from the person the data is about, for example when it arrives from an unfamiliar address. Ask for the least you need: a reply from the address on the account, or an order number, is usually enough. Asking for a passport scan in order to delete someone’s data means collecting more of it.

Can I refuse a data deletion request?

In some cases: where the law requires you to keep the data, where you need it for a legal claim, where you cannot verify who is asking, or where a request is manifestly unfounded or excessive. You still have to reply within the deadline, give your reason, and tell the person they can complain to a data protection authority. Deletion being inconvenient is not one of the exceptions.

Does the GDPR apply to a small software company outside the EU?

It can. The GDPR generally applies to businesses outside the EU that offer products to people in the EU, whatever their size, and the UK GDPR works the same way for people in the UK. If you sell software to customers in Europe, the safe assumption is that deletion requests from them need a proper answer. This is general guidance, not legal advice.