Handle erasure and access requests

ComplianceDraft — not publishedUpdated 2026-07-26

Access and erasure requests are one-month obligations. The console runs both as a single workflow across conversations, media, consent history and CDP attributes.

  1. Verify the requester's identity.
  2. Locate every record linked to the data subject across identifiers.
  3. Run the export (access) or the erasure workflow (deletion).
  4. Confirm the audit record — who, when and what was affected.

What erasure does not remove

Records you are legally required to keep, such as billing and transaction data, are retained under the legal-obligation basis and reported as such in the response. Say so explicitly in your reply to the data subject.

Steps at a glance

  1. Verify the requesterConfirm the identity of the data subject before acting on the request.
  2. Locate the recordSearch the CDP by phone, email or social identifier to find every linked record.
  3. Export or eraseRun the export for an access request, or the erasure workflow to delete across conversations, media and consent history.
  4. Record the outcomeThe audit log captures who ran the request, when, and what was affected.
Next step

Bring this to your enterprise stack

See how a dedicated Arino One instance — deployed in your region (EU, NA or APAC) — would sit inside your operation. Architecture, DPA, and rollout plan walked through live.