Right to Erasure Workflow Design: Stop Hoping Vendors Deleted the Data
Data subject deletion requests must be fulfilled across every connected system inside tight deadlines. If your "forget me" process is still an email chain to five vendors, you are gambling with SLA risk and cannot prove deletion happened.
We design the automated erasure workflow that discovers, deletes, and documents the outcome.

Sound Familiar?
These are the exact issues Information Officers and ops leads bring us before the workflow is built:
- A "forget me" email lands and the Information Officer starts emailing five vendors by hand
- CRM soft-deletes the contact while the ESP, accounting tool, and shared drives still hold copies
- Identity is never verified properly, so the team either deletes the wrong person or stalls for days
- Legal-hold and statutory retention exceptions live in someone's head, not in the workflow
- When the Regulator or an EU buyer asks for proof, there is no evidence pack: only scattered emails
Urgency is rising: EY Law found 60% of organisations reporting more DSARs, the EDPB's 2025 Coordinated Enforcement Action put Article 17 under the microscope across 764 controllers, and EU customer contracts increasingly demand proof that data deletion happened, not just a polite acknowledgement email.
What the Erasure Workflow Actually Does
Request in → identity checked → systems cleared → evidence filed. No vendor email roulette.
Request Intake
Forget-me request opens a ticket with identity check and a live 30-day SLA clock
Discover Everywhere
CRM, ESP, accounting, and files searched for matching personal information in one pass
Apply Delete Rules
Soft-delete, hard-delete, or legal-hold retention runs per system with named reasons
Confirm and Evidence
Requester gets confirmation; the IO exports an Article 17 / POPIA evidence pack
Everything You Need for Reliable Data Deletion
Request Intake Queue
Email, web form, WhatsApp, and Form 2 style submissions open a tracked erasure ticket with a 30-day SLA clock the Information Officer can see.
Identity Verification
Confirm the requester is the data subject before any delete runs. Pause the clock when more proof is needed, then resume with a clear audit trail.
Cross-System Discovery
Locate matching records across CRM, email service provider, accounting, file stores, and connected apps from one search, not five vendor tickets.
Soft-Delete vs Hard-Delete Rules
Policy decides what is suppressed, anonymised, or permanently deleted per system, so ops never guess which button is lawful.
Legal-Hold Exceptions
Litigation, tax, and statutory retention blocks stop erasure automatically, with a written reason returned to the data subject inside the deadline.
Confirmation and Evidence Pack
Confirmation to the requester plus an immutable log of what was found, what was erased, what was retained, and which systems replied.
Systems We Wire into Erasure Cascades
From 22 Hours per Request to Under 2
How a 40-person SA exporter stopped emailing five vendors for every forget-me request and started shipping Article 17 evidence packs on time.
The Manual Process
- Information Officer emailed CRM admin, Mailchimp, Xero, and two file-share owners separately
- Average 22 hours of staff time per deletion request across discovery and chasing
- ESP still held two contacts after the CRM soft-delete, found only during a sample audit
- Two requests in one quarter breached the 30-day reply window
- No single evidence pack when an EU buyer asked how Article 17 was fulfilled
The Automated Process
- Intake form opens a ticket, verifies identity, and starts the SLA clock automatically
- Discovery runs across CRM, ESP, Xero, and shared drives in one pass
- Soft-delete, hard-delete, and legal-hold rules apply per system without ops guessing
- Requester confirmation and IO evidence pack generated on completion
- Zero missed 30-day SLAs in the first six months after go-live
Before vs After Data Deletion Automation
How It Works
From first conversation to a live erasure workflow in 3–5 weeks.
Map Your Deletion Paths
Where personal data lives today, how "forget me" requests arrive, and which systems still need a manual email.
Free Scoping Call
30-minute call with your Information Officer or ops lead to prioritise intake, discovery, legal holds, and evidence.
Build and Drill
We wire the erasure workflow across CRM, ESP, accounting, and files, then run sample deletions with your team.
Go Live and Prove It
Staff keep the same tools. Every request gets an SLA clock, exception rules, and an exportable evidence pack.
Frequently Asked Questions
How is a right to erasure workflow different from a full POPIA or GDPR programme?
A full programme covers lawful basis, consent, retention, and safeguards. This engagement is the operational "forget me" pipeline: intake, identity check, discovery across connected systems, soft-delete versus hard-delete rules, legal-hold exceptions, confirmation, and the evidence pack. If you already have policy documents but still email vendors by hand, this is the missing piece.
What deadlines apply under GDPR Article 17 and POPIA?
GDPR Article 17 requires erasure without undue delay, and controllers must respond within one month (extendable by two months for complex cases if you notify in time). POPIA section 24 deletion requests, under the amended Regulations, require written notice of the action taken within 30 days. Missing those windows is how complaints escalate to the Information Regulator or an EU supervisory authority.
What do incomplete erasures actually cost?
Manual fulfilment commonly burns 18 to 27 hours of staff time per request (industry practice reported by privacy operators and playbooks citing EY Law). Labour alone often lands around R20,000 to R33,000 per request at current rates. POPIA administrative fines reach R10 million. GDPR Article 83 caps for rights failures reach €20 million or 4% of worldwide turnover (about R380 million at roughly R19 per euro). Incomplete deletion also fails EU contract clauses that demand Article 17 evidence.
How do you handle soft-delete, hard-delete, and legal holds?
Each connected system gets an explicit rule: suppress and anonymise, hard-delete, or retain under a named legal hold. Holds for litigation, tax, or statutory retention block deletion automatically and write the reason into the evidence pack and the reply to the data subject. Ops no longer invents the answer under deadline pressure.
Which systems can the erasure workflow reach?
We typically cascade from the CRM into email platforms, accounting (Xero, Sage, and similar), shared drives, support tools, and other apps that hold customer personal information. If a vendor has no API, we still design a tracked manual step with a confirmation receipt so nothing falls off the list.
How much does a right to erasure workflow cost?
A focused intake-to-evidence workflow on an existing CRM and two or three connected systems typically starts around R45,000. Broader cascades with legal-hold rules, backup suppression lists, and Information Officer dashboards usually land between R65,000 and R120,000. Against R20,000-plus per manual request and R10 million POPIA exposure, most mid-market teams see payback inside a handful of requests or one avoided Regulator enquiry.
Stop Gambling on Vendor Email Chains
If your Information Officer still fulfils right to erasure requests by hoping five vendors reply in time, you are carrying SLA risk you can remove.
Tell us which systems hold customer personal information, how forget-me requests arrive today, and whether a Regulator enquiry or EU contract clause is the trigger. We will show you the workflow that discovers, deletes, and documents the outcome.