spectre

Spectre privacy tools

Manage GDPR erasure and privacy requests in one workspace.

Organise incoming privacy requests, review processing records, and keep decision and follow-up history with Spectre’s business privacy workspace.

Updated 2026-10-03 · Spectre editorial · General information, not legal advice.

Explore the business workspace

Give incoming privacy requests a clear workflow

An erasure request needs a responsible reviewer, a defined scope, and a record of the next action. Spectre's business workspace brings incoming privacy requests, review work, records of processing, and activity history together. Available capabilities depend on the plan and configuration.

Use the workspace to organise work around a request rather than rely on disconnected inbox messages. Your team remains responsible for checking the requester's identity where appropriate, assessing the applicable rules, and deciding what action to take.

Distinguish erasure requests from access requests

A person asking what information you hold is making a different request from a person asking you to delete it. A DSAR, or data subject access request, concerns access; an erasure request concerns deletion. Some messages ask for both. Record each requested action and have a reviewer confirm the scope before responding.

The Article 17 guide introduces the right to erasure. The deletion request template shows the information an individual might provide. Neither substitutes for the organisation's assessment.

Record decisions and follow-up work

For each request, establish who is reviewing it, which services or records are relevant, what has been decided, and which actions remain. Keep the response and the reasons for any retained records together with the request history. Where configured, Spectre offers additional processing-record, audit, log, and API workflows; check the business workspace for availability.

Erasure is not always absolute. Legal obligations and other exceptions can affect the outcome. Escalate uncertainty to the appropriate privacy or legal owner rather than treat generated text as approval to delete data.

Evaluate the workspace against a real request

Before adopting a workflow, walk through a representative case with your team:

  1. Identify how requests reach the organisation.
  2. Assign a reviewer and confirm the person's requested action.
  3. Locate the relevant systems and record owners.
  4. Document decisions, communications, and outstanding tasks.
  5. Check who can access the request history and how it is retained.

Read Spectre's data handling and security architecture as part of that evaluation. Spectre supports your privacy function; it is not legal advice or a replacement for a legally required Data Protection Officer.

Helping an individual clean up old accounts?

If you want to find your own forgotten accounts and send reviewed deletion requests, use the personal data removal workflow. The business workspace is intended for teams handling privacy work for an organisation.

Sources and further reading

Our editorial approach · About Spectre editorial