Handle a Data Access or Deletion Request
When a subscriber invokes their rights under GDPR, CCPA, or a similar law, you may need to export the personal data you hold about them (a data access or subject access request) or permanently erase it (a deletion or right-to-be-forgotten request). This page walks an admin through fulfilling either request.
Before you begin
- Confirm the requester's identity and that they are the subscriber (or an authorized agent) before acting on any request.
- Note the applicable deadline — many regimes require a response within 30–45 days.
- Have the subscriber's email address or unique identifier ready to locate the correct record.
- Ensure you have an admin role with permission to view and remove subscriber data. (confirm the exact permission in your account)
- Decide the outcome up front: export (access) or erase (deletion). Deletion is irreversible.
Steps
- Search your audience for the subscriber using their email address or identifier to open the individual subscriber record.
- Review the record — profile fields, engagement history, and any list memberships — to confirm it is the right person.
- For an access request, export the subscriber's data (profile fields plus activity) and deliver it securely to the requester. (confirm the exact export option in your account)
- For a deletion request, remove or anonymize the subscriber record. Where offered, choose the option that also purges historical activity, not just list membership.
- Add the address to your account-wide suppression list so future imports cannot re-add the person after erasure.
- Log the request, the date, and the action taken for your own compliance records.
Result
The requester receives their data (access) or the subscriber's personal data is removed and suppressed from future sends (deletion). Searching the audience again should show no active record, and the address is retained only as a suppressed value.
Related
Canonical terms: Author, Edition, Folder (Project Folder), Broadcast. See the Glossary.