GDPR and recipient permissions

Handle a recipient's data deletion request

The quick answer

Identify and verify the recipient's request through the privacy process, review your controller responsibilities and retention duties, and communicate the result accurately. Suppression and permanent deletion serve different purposes.

Submit or handle a privacy request

  1. Identify the request

    State whether the request is for access, correction, deletion, objection, tracking opt-out, or a report of abuse.

  2. Use the privacy request page

    Submit through the published privacy-request route. Complete the verification flow for the address involved.

  3. Provide enough context

    Give the sender, message date/subject, and requested outcome when relevant. Share only the minimum context needed.

  4. Review the response

    The responsible controller and service will handle the verified request according to applicable duties and any legitimate retention requirements.

Open privacy requestsRead the complete product guide