AskBiz
Help Centre
Compliance & Audit·2 min read·Updated 21 May 2026

Processing GDPR Deletion Requests

How to handle customer requests to delete their personal data from your system.

Receiving a deletion request#

Under GDPR, customers have the right to request deletion of their personal data. When you receive a request — by email, in person, or through any channel — you have 30 days to comply. Log the request immediately in POS > Customers > GDPR > Log Request with the date received, the customer identity, and the channel through which the request was made.

Processing the deletion#

Find the customer in your database. Click GDPR > Delete Data. The system removes all personal identifiers — name, phone number, email address, and notes. Transaction records are anonymised: the sale amount, date, and products remain but the customer link is severed. This preserves your financial records for tax purposes while removing personal data.

Confirmation and logging#

After deletion, the system generates a confirmation record with a timestamp and the processing staff member. Send confirmation to the customer that their data has been deleted. The deletion itself is logged in the compliance audit trail — recording that a deletion occurred, when, and by whom, without storing the deleted data.

Frequently Asked Questions

Was this article helpful?

Still stuck? Email our support team.