Operations
Translating data subject rights and deletion into real operational processes
Deadlines can only be met when identification, search, decision, execution and evidence are prepared across systems and the people responsible.
9 minute read · Content as of 21.07.2026
Requests need an end-to-end process
A central intake alone is not enough. Responsibilities, identity verification, system searches, legal assessment, response and documentation must be connected in one deadline logic.
Deletion rules follow purpose and retention obligations
For each data category, you define when the purpose ends, which statutory retention obligations stand in the way, and how deletion or anonymisation is technically triggered and evidenced.
- Name system and data owners
- Define deadlines with a starting point, not just a duration
- Explicitly include backups and archives
- Regulate exceptions, restriction and the deletion log
Sources used
- General Data Protection Regulation (EU) 2016/679 · EU · check the consolidated version
- Short papers of the Datenschutzkonferenz · DSK
- Guidelines for Controllers and Processors · EDPB
- Privacy management, RoPA, DPIA and incident templates · KaitoSec