The templates
Each one copies with its subject line. The parts in brackets are the parts to change; the date and the list of what you keep are the parts to get exactly right.
Subject: Re: [their subject line]
Subject: Re: [their subject line]
Subject: Your data has been deleted
Subject: Re: [their subject line]
Subject: Re: [their subject line]
Subject: Re: [their subject line]
Subject: Re: [their subject line]
Subject lines for a deletion request reply
Keep the thread. The request, your acknowledgement and your confirmation in one place is also your record that it was handled. If you start a new email, say plainly what it is about; this is not the place for a clever subject line.
- Re: [their subject line] (reply in their thread, so request and answer stay together)
- Your data deletion request: done by [date]
- Please confirm your data deletion request
- Your data has been deleted
- About your data deletion request
What to get right
- Recognise it when it arrives. “Please remove me from everything” is a deletion request, even without the words GDPR or erasure.
- Acknowledge the same week. The deletion can take longer; the reply with a date takes a minute. A request left unanswered for weeks is how a routine email becomes a complaint to a regulator.
- List every place their data lives before you promise anything: your mailbox, licence system, payment processor, mailing list tool, analytics, crash reports and backups. The one you forget is the one that emails them next month.
- Verify with what you already have. A reply from the account address or an order number. Not a passport scan.
- Be specific about what you keep. “Some data may be retained” invites a second email. “Invoices, for six years, because tax law requires it” does not. (Use your own country’s period.)
- Do not ask them to justify it. A question to clarify what they want deleted is fine. A deletion request is not a negotiation, and not a retention opportunity.
Where a customer’s support history lives with Moorline
A deletion request is only as complete as your list of places the customer’s data might be, and support is usually the longest part of that list: every email they sent, every reply, every note. With a hosted help desk there is also a copy on the vendor’s servers to deal with.
Moorline works from the mailbox you already have and keeps its conversations in one database file on your Mac, with rolling local backups. No Moorline server holds your conversations. Moorline has no GDPR feature: it will not find, export or erase a customer’s data for you, and its Stripe view is read-only, so it cannot delete a customer in Stripe either. What it does is treat the request like any other conversation with two facts to settle, the deletion done and the customer told, and keep it on your list until both are true. That model is explained in how to never forget to reply to a customer, and a deletion request, with a legal deadline behind it, is the case where it matters most.
Questions people ask
How long do I have to respond to a GDPR deletion request?
Under the GDPR and the UK GDPR, usually one month from the day you receive it. That can be extended by up to two further months where a request is complex or you have received a number of them, but you have to tell the person within the first month and explain why. Other privacy laws set their own deadlines. This is general guidance, not legal advice.
Do I have to delete invoices when a customer asks me to delete their data?
Usually not. The right to erasure does not apply to data you must keep to meet a legal obligation, and accounting and tax rules in most countries require businesses to keep invoices for several years. Keep only what the law requires, for as long as it requires, use it for nothing else, and tell the customer that is what you are doing.
Can I ask for proof of identity before deleting someone’s data?
Yes, if you have reasonable doubt that the request comes from the person the data is about, for example when it arrives from an unfamiliar address. Ask for the least you need: a reply from the address on the account, or an order number, is usually enough. Asking for a passport scan in order to delete someone’s data means collecting more of it.
Can I refuse a data deletion request?
In some cases: where the law requires you to keep the data, where you need it for a legal claim, where you cannot verify who is asking, or where a request is manifestly unfounded or excessive. You still have to reply within the deadline, give your reason, and tell the person they can complain to a data protection authority. Deletion being inconvenient is not one of the exceptions.
Does the GDPR apply to a small software company outside the EU?
It can. The GDPR generally applies to businesses outside the EU that offer products to people in the EU, whatever their size, and the UK GDPR works the same way for people in the UK. If you sell software to customers in Europe, the safe assumption is that deletion requests from them need a proper answer. This is general guidance, not legal advice.