Understand the ask.
Bring incoming requests into a review workflow. Confirm whether the person is asking for access, erasure, an objection, or several actions.
Define the scopeGDPR erasure & privacy requests
Behind every request is a person. Bring your team’s review work, decisions, and follow-up together in one thoughtful workspace.
Human review at the centre. A clearer path from inbox to response.
Confirm the scope, document the decision, and keep the next action visible.
Less scattered work. More clarity.
Keep the people, the request, and the reasoning connected.
Bring incoming requests into a review workflow. Confirm whether the person is asking for access, erasure, an objection, or several actions.
Define the scopeIdentify relevant records, involve the right reviewer, and document the reasons for the decision. Your team remains responsible for the assessment.
Keep decisions togetherKeep communications and outstanding work with the request history, so the team can follow up with context rather than start again.
Walk through a real caseExplore the workspace, then evaluate it against your team’s own workflow.
An erasure request needs a responsible reviewer, a defined scope, and a record of the next action. Spectre's business workspace brings incoming privacy requests, review work, records of processing, and activity history together. Available capabilities depend on the plan and configuration.
Use the workspace to organise work around a request rather than rely on disconnected inbox messages. Your team remains responsible for checking the requester's identity where appropriate, assessing the applicable rules, and deciding what action to take.
A person asking what information you hold is making a different request from a person asking you to delete it. A DSAR, or data subject access request, concerns access; an erasure request concerns deletion. Some messages ask for both. Record each requested action and have a reviewer confirm the scope before responding.
The Article 17 guide introduces the right to erasure. The deletion request template shows the information an individual might provide. Neither substitutes for the organisation's assessment.
For each request, establish who is reviewing it, which services or records are relevant, what has been decided, and which actions remain. Keep the response and the reasons for any retained records together with the request history. Where configured, Spectre offers additional processing-record, audit, log, and API workflows; check the business workspace for availability.
Erasure is not always absolute. Legal obligations and other exceptions can affect the outcome. Escalate uncertainty to the appropriate privacy or legal owner rather than treat generated text as approval to delete data.
Before adopting a workflow, walk through a representative case with your team:
Read Spectre's data handling and security architecture as part of that evaluation. Spectre supports your privacy function; it is not legal advice or a replacement for a legally required Data Protection Officer.
If you want to find your own forgotten accounts and send reviewed deletion requests, use the personal data removal workflow. The business workspace is intended for teams handling privacy work for an organisation.