Handle erasure and access requests
Access requests under Article 15 and erasure requests under Article 17 are both one-month statutory obligations, and Arino One runs them as a single workflow across conversations, media, consent history and CDP attributes. The first two steps — verifying the requester and locating every linked record — are identical for both; only the final action differs.
Step by step
- Verify the requester. Confirm you are dealing with the actual data subject, typically by matching the request against a verified channel identifier already on file, or by asking a knowledge-based question if the request arrives through an unverified route (email to a general inbox, for instance).
- Locate every linked record. Search the CDP by phone number, email address and any social or channel identifier the contact has used, since a single person can appear as multiple loosely-linked records if they've messaged through more than one channel.
- Export or erase. For an access request, run the export, which compiles conversations, media, consent history and stored attributes into a package for the data subject. For an erasure request, run the erasure workflow, which deletes those same categories.
- Apply legal-hold exceptions. Billing records, invoices and other data you are required to keep under a separate legal obligation are excluded from deletion and flagged in the response as retained under that basis.
- Confirm and respond. Check the audit log entry created by the run — actor, timestamp, scope — then send your response to the data subject inside the one-month window, stating plainly what was done and what, if anything, was kept and why.
What erasure does and does not remove
| Category | Erased? | Note |
|---|---|---|
| Conversation transcripts | Yes | Removed across all channels linked to the contact |
| Media attachments and voice recordings | Yes | Removed alongside the conversation |
| Consent history | Yes | The consent record itself is deleted with the contact |
| CDP attributes and segment membership | Yes | Contact is removed from all segments |
| Billing and transaction records | No | Retained under a legal-obligation basis; state this in your response |
| Data independently held by Meta or Infobip outside your instance | No | Outside the scope of the in-instance workflow; may need a separate request |
Be explicit about the last two rows in your reply to the data subject — silently keeping data without saying so, even for a good legal reason, is itself a compliance gap.
How this differs by connection state
The erasure and export workflow itself is the same feature everywhere, since every client owns their own Infobip account and Meta assets directly. What changes with the $50/month Arino Core connection is whether Arino provides support and management while the client runs the workflow.
| Connection state | Who runs the workflow | Where the underlying data lives | Accountability |
|---|---|---|---|
| Connected ($50/month Arino Core connection) | Client, with Arino support and management | Client's own Infobip account and Meta assets | Client is Controller and runs the request directly; Arino is Processor for the connected instance but does not control the client's Infobip/Meta accounts |
| Unconnected | Client, entirely | Client's own accounts, self-configured | Client is Controller and solely responsible for running, evidencing and responding to the request |
In both cases, the client remains the Data Controller who must respond to the data subject within the statutory window; on a connected instance, Arino's role as Data Processor is limited to supporting the client's instruction within the Arino Core layer. Remember that any data the contact generated directly inside the client's own Infobip account or Meta Business Manager (outside what flows through Arino One) is the client's to locate and erase — Arino cannot act on accounts it does not operate.
Steps at a glance
- Verify the requester's identityConfirm the person making the request is the data subject (or their authorised representative) before taking any action on their record.
- Locate every linked recordSearch the CDP by phone number, email and any social/channel identifier to find all records linked to that person across channels.
- Choose export or erasureRun the export workflow to satisfy an access request, or the erasure workflow to delete conversations, media, consent history and CDP attributes for that contact.
- Apply legal-hold exceptionsExclude and clearly flag any records you are legally required to retain, such as billing or transaction data, rather than deleting them.
- Confirm the outcome and respondCheck the audit log entry for who ran the request, when, and what was affected, then reply to the data subject within the one-month statutory window, stating what was and was not removed and why.
Frequently asked
How long do we have to respond to an erasure request?
One calendar month from receipt under GDPR, extendable by a further two months for complex requests provided you inform the data subject of the extension and the reason within the first month.
Can we ever refuse an erasure request?
Yes, where another legal basis overrides it — for example a statutory obligation to retain billing or tax records, an active legal claim, or the data being needed to establish, exercise or defend a legal claim. State the basis clearly in your response rather than simply declining.
Does erasure remove data from WhatsApp/Meta and Infobip logs too?
The erasure workflow removes the contact's data from your instance — conversations, media, consent history and CDP attributes. Data held independently in Meta's or Infobip's own systems, such as delivery metadata retained under their own policies, sits outside what Arino One's workflow can act on and may need a separate request to the relevant provider.
What counts as sufficient identity verification before erasure?
Enough to be reasonably confident the requester is the data subject — commonly matching the contact channel they are messaging from (the verified phone number or email on file) against the request, or asking a knowledge-based question if the request arrives through an unverified channel.
Who is responsible if we get an erasure request wrong?
The client, as Data Controller, is accountable to the data subject and any regulator for the response. Arino, as Data Processor, is responsible for the workflow correctly executing what the client instructs it to do.
Is a subject access request the same workflow as erasure?
They share the first step — locating every linked record — but diverge after that: access requests run an export, erasure requests run deletion. Both produce an audit record for evidence.
Apply this to your own deployment
This guide describes decisions we make on live instances. Tell us your channels, systems and region and we will map it to an architecture outline, a provisioning plan and an indicative commercial model — usually within one business day.