Support

Respond to a GDPR data deletion request

A scenario prompt for handling a right-to-erasure request correctly, including the parts of a customer's data you legally can't delete.

Works with Claude / GPT980 uses 4.3

The prompt

support-gdpr-data-deletion-request
An EU customer emails your support inbox:

"Under GDPR, I am requesting that you delete all my personal data from your
systems immediately, including my account, order history, and any marketing
lists."

ACCOUNT CONTEXT: [active license expires in 8 months, 2 completed orders,
subscribed to the marketing newsletter, no open disputes or fraud flags]

Write the reply, as the support lead who handles data requests.

Requirements:
- Confirm you're processing this as an Article 17 request and give a concrete
  timeframe (your actual policy, commonly within 30 days).
- Be specific about what will be deleted (account profile, marketing list
  subscription) versus what must legally be retained and for how long (invoice
  and transaction records, often required for tax law, typically 6-10 years
  depending on jurisdiction), and say plainly that this isn't optional on your
  end either.
- If they have an active paid license, note what deletion means for that license,
  it will stop working once the account is deleted, so they aren't surprised
  later. Don't try to talk them out of the request.
- Give a single point of contact or reference number for follow-up, not a generic
  "let us know if you have questions."
- Keep it factual and free of legal disclaimers copy-pasted from a lawyer.

Replace the ACCOUNT CONTEXT block with the real account details before running
this.

The part that trips people up is treating this as all-or-nothing: tax and invoicing law usually forces you to keep transaction records even while deleting the rest of the profile.

Pro tip: say that limitation plainly upfront, a customer who finds an old invoice later assumes you didn’t actually honor the request.