This happens more often than you think
A customer emails you: “Please delete all my information.” Maybe they stopped shopping with you, maybe they just prefer to keep their data footprint small. Either way, don’t panic — this is one of the most common requests under GDPR, and handling it well takes minutes, not days.
This is known as the right to erasure, sometimes called “the right to be forgotten” (Article 17) — one of eight rights GDPR gives every individual. It’s also the one small businesses run into most often, which is why it gets its own deep dive here. Every business that holds customer data — a mailing list, a booking system, a loyalty programme — needs to know what to do when this request lands in their inbox.
Step 1: Confirm it’s really them
Before doing anything, make sure the request actually comes from the person whose data it is. A quick reply asking them to confirm via the email or account associated with their record is usually enough. You’re not required to demand ID for a simple request, but you do need reasonable confidence it isn’t someone else trying to delete another person’s records.
Step 2: Check whether you actually have to delete everything
This is where most business owners get nervous, and it’s usually unnecessary. The right to erasure isn’t absolute — Article 17(3) lists specific exceptions where you can, or must, keep data instead of deleting it, and Article 17(1) only requires erasure in the first place if the data is genuinely no longer needed. The most relevant for a typical business:
- You’re legally required to (e.g. invoices and tax records typically must be kept for several years under Cyprus tax law)
- You need it to fulfil an existing contract (an order still being delivered)
- You need it to establish or defend a legal claim
The flip side of this same rule is the lawful basis for how long you keep anything in the first place. GDPR’s storage limitation principle says you shouldn’t hold personal data longer than you actually need it for the purpose you collected it — so “we might need it someday” isn’t a valid reason to keep something indefinitely, but “our tax law requires 6 years” is. In practice, this means you can usually delete someone from your marketing list and CRM immediately, while still legally retaining their invoice history in your accounting records for exactly as long as the law requires, and no longer. That’s completely normal and doesn’t mean you failed the request — you just explain it.
Step 3: Actually locate and delete the data
This is the part people underestimate. Customer data is rarely in one place. Check:
- Your CRM or customer database
- Your email marketing tool (Mailchimp, etc.)
- Your point-of-sale or booking system
- Spreadsheets or shared drives
- Any backups (you don’t need to hunt through years-old backups, but note where they’re covered by your retention policy)
Delete or anonymise the data in each of these. If a system doesn’t have a delete function, removing identifying details (name, email, phone) while keeping anonymised transaction data is usually enough.
Step 4: Reply to the customer
You have one month to respond under GDPR (Article 12(3)). A short, clear reply works best:
“We’ve deleted your personal information from our marketing and customer systems. We’re required to retain your invoice records for [X] years for tax purposes, after which they’ll also be removed.”
That’s it. Most customers just want confirmation it was actioned — they’re not expecting a legal essay.
Common mistakes to avoid
- Ignoring the request or going silent — this is the fastest way to turn a simple request into a complaint to the Commissioner.
- Deleting everything, including records you’re legally required to keep — this can create its own compliance problem.
- Forgetting a system — the marketing list is easy to remember; the old spreadsheet on someone’s desktop isn’t.
Quick checklist
- Confirm the request is genuine
- Check what you’re legally allowed or required to keep — this comes down to your lawful basis for that data
- Search every system where the data lives, not just the obvious one
- Delete or anonymise
- Reply within one month, in plain language
Handled this way, a deletion request isn’t something to dread — it’s a five-minute task that shows customers you take their data seriously.
Facing a deletion request and not sure what you can keep? Let’s Talk GDPR.
Related reading
References
- GDPR Article 12(3) — timescale for responding to requests.
- GDPR Article 17 — right to erasure; Article 17(3) — exceptions to erasure.
- GDPR Article 5(1)(e) — storage limitation principle.
- Cyprus tax record-keeping requirement — 6 years (Assessment and Collection of Taxes Law; current as of August 2026, with a public-consultation proposal to extend to 8 years not yet in force).