Processing GDPR Deletion Requests
How to handle customer requests to delete their personal data from your system.
Receiving a deletion request#
Under GDPR, customers have the right to request deletion of their personal data. When you receive a request โ by email, in person, or through any channel โ you have 30 days to comply. Log the request immediately in POS > Customers > GDPR > Log Request with the date received, the customer identity, and the channel through which the request was made.
Processing the deletion#
Find the customer in your database. Click GDPR > Delete Data. The system removes all personal identifiers โ name, phone number, email address, and notes. Transaction records are anonymised: the sale amount, date, and products remain but the customer link is severed. This preserves your financial records for tax purposes while removing personal data.
Confirmation and logging#
After deletion, the system generates a confirmation record with a timestamp and the processing staff member. Send confirmation to the customer that their data has been deleted. The deletion itself is logged in the compliance audit trail โ recording that a deletion occurred, when, and by whom, without storing the deleted data.
Frequently Asked Questions
Was this article helpful?
Still stuck? Email our support team.