Data Deletion Request Procedure

Ready to Edit

DATA DELETION REQUEST DECISION AND EXECUTION PROCEDURE

Organization: [________________________________]

Procedure owner: [________________________________]

Legal approver: [________________________________]

Request ID: [________________________________]

1. Purpose and Control Principle

This procedure provides a controlled record for:

  • determining whether a deletion request is covered;
  • identifying the data, entities, systems, and recipients in scope;
  • authenticating the requester when the approved rule requires it;
  • separating data approved for deletion from data approved for retention;
  • suspending deletion where a preservation or other approved override applies;
  • issuing and tracking internal and downstream deletion instructions;
  • testing the actual result; and
  • sending a source-aligned response.

A request does not authorize deletion by itself. A retention schedule, contract, business preference, or technical limitation does not defeat a request by itself. Legal must approve the rule and facts for each disposition.

2. Use Gate

Required decision Completion record
Request and affected individual identified [________________________________]
Governing entity and processing role identified [________________________________]
Jurisdiction and applicable framework confirmed [________________________________]
Current official source opened and saved [URL / version / effective date]
Covered individual, data, and right confirmed [________________________________]
Deadline trigger and calendar approved [________________________________]
Authentication and representative rules approved [________________________________]
Search population and identifiers approved [________________________________]
Preservation, exception, and retention sources reviewed [________________________________]
Processor, affiliate, and recipient duties approved [________________________________]
Backup, archive, replica, cache, and log treatment approved [________________________________]
Appeal and regulator-contact duties approved [________________________________]
Deletion plan and rollback risk approved [________________________________]
Final response legally approved [________________________________]

3. Request Intake

Field Entry
Date and time received / time zone [__/__/____ ____ TZ]
Request channel [________________________________]
Requester name and contact [________________________________]
Affected individual, if different [________________________________]
Claimed residence / jurisdiction [________________________________]
Relationship or claimed authority [________________________________]
Account, customer, worker, or other identifiers [________________________________]
Verbatim request [________________________________]
Data, product, account, or period specified [________________________________]
Related access, correction, opt-out, or appeal request [________________________________]
Duplicate or prior request IDs [________________________________]
Complaint, dispute, fraud, security, litigation, or hold indicator [________________________________]

4. Applicability and Rule Activation Record

Create one row for each framework that may independently govern the request. Do not blend rights, exceptions, deadlines, or appeal rules between rows.

Field Framework 1 Framework 2 Framework 3
Jurisdiction / authority [____________] [____________] [____________]
Official citation and URL [____________] [____________] [____________]
Source version / currency date [____________] [____________] [____________]
Effective date for this request [____________] [____________] [____________]
Covered entity / controller role [____________] [____________] [____________]
Covered individual [____________] [____________] [____________]
Covered data [____________] [____________] [____________]
Excluded data / relationship [____________] [____________] [____________]
Deletion right and scope [____________] [____________] [____________]
Request method valid [____________] [____________] [____________]
Authentication requirement [____________] [____________] [____________]
Representative / agent rule [____________] [____________] [____________]
Acknowledgment duty / trigger [____________] [____________] [____________]
Response period / trigger [____________] [____________] [____________]
Extension / notice [____________] [____________] [____________]
Deletion grounds or conditions [____________] [____________] [____________]
Exceptions / retention grounds [____________] [____________] [____________]
Downstream notification duty [____________] [____________] [____________]
Backup / archive treatment [____________] [____________] [____________]
Required response contents [____________] [____________] [____________]
Appeal / complaint process [____________] [____________] [____________]
Request-record retention [____________] [____________] [____________]
Counsel approval / date [____________] [____________] [____________]

4.1 Coverage Decision

☐ A deletion right applies.

☐ Multiple frameworks apply; each will be satisfied separately.

☐ No identified deletion right applies, but voluntary deletion is approved.

☐ No deletion will occur; the source-based decision is documented below.

Coverage analysis: [________________________________]

5. Deadline and Work Plan

Use the controlling source's trigger. Internal target dates must leave enough time for legal review and delivery but must not be presented as statutory unless the source says so.

Milestone Trigger Source or internal owner-approved target Due date / time zone Owner Completed
Receipt [Event] [Source] [__/__/____ ____ TZ] [Name] [____________]
Acknowledgment [Event] [Source / N/A] [__/__/____ ____ TZ] [Name] [____________]
Authentication communication [Event] [Source / internal] [__/__/____ ____ TZ] [Name] [____________]
Search completion [Event] [Internal] [__/__/____ ____ TZ] [Name] [____________]
Legal disposition approval [Event] [Internal] [__/__/____ ____ TZ] [Name] [____________]
Internal execution [Event] [Source / internal] [__/__/____ ____ TZ] [Name] [____________]
Downstream instruction [Event] [Source / contract] [__/__/____ ____ TZ] [Name] [____________]
Extension notice [Event] [Source / N/A] [__/__/____ ____ TZ] [Name] [____________]
Final response [Event] [Source] [__/__/____ ____ TZ] [Name] [____________]
Appeal response [Event] [Source / N/A] [__/__/____ ____ TZ] [Name] [____________]

Calendar convention and calculation evidence: [________________________________]

6. Authentication and Authority

Control Approved entry
Source of authentication rule [________________________________]
Sensitivity and consequence of requested deletion [________________________________]
Existing-account method, if permitted [________________________________]
Information already held that may be matched [________________________________]
Additional information permitted and necessary [________________________________]
Data that must not be requested [________________________________]
Failed-authentication consequence and notice [________________________________]
Verification-material security and disposal [________________________________]
Step Information or method Result Evidence location Reviewer / date
[____________] [____________] [Match / no match / inconclusive] [____________] [____________]
[____________] [____________] [Match / no match / inconclusive] [____________] [____________]

Final status: ☐ Authenticated ☐ Additional information requested ☐ Unable to authenticate ☐ Authentication not required under approved rule

6.1 Representative, Guardian, or Agent

Field Entry
Representative name and contact [________________________________]
Claimed authority [________________________________]
Governing source [________________________________]
Proof reviewed [________________________________]
Direct confirmation required / completed [________________________________]
Individual authentication required / completed [________________________________]
Scope and expiration of authority [________________________________]
Decision and reviewer [________________________________]

7. Data Map and Search Plan

7.1 Identity Resolution

Identifier Value / token Systems where used Collision or mismatch risk
Account / customer ID [____________] [____________] [____________]
Email / phone [____________] [____________] [____________]
Device / cookie / advertising ID [____________] [____________] [____________]
Employee / applicant / contractor ID [____________] [____________] [____________]
Vendor / partner ID [____________] [____________] [____________]
Other [____________] [____________] [____________]

7.2 Search Population

System, repository, or custodian Entity / owner Data and period Search method Result location Completed
Product / account systems [____________] [____________] [____________] [____________]
Customer support / communications [____________] [____________] [____________] [____________]
Marketing / analytics / advertising [____________] [____________] [____________] [____________]
Transactions / billing / fraud [____________] [____________] [____________] [____________]
Security / device / access logs [____________] [____________] [____________] [____________]
HR / applicant / benefits systems [____________] [____________] [____________] [____________]
Vendors / processors / affiliates [____________] [____________] [____________] [____________]
Files / email / collaboration [____________] [____________] [____________] [____________]
Archives / backups / replicas [____________] [____________] [____________] [____________]
Legal hold / investigation stores [____________] [____________] [____________] [____________]
Other [____________] [____________] [____________] [____________]

Search limitations and approved explanation: [________________________________]

8. Preservation and Conflict Check

Before deletion, Legal must check every potentially applicable preservation or retention source.

Source or matter Data affected Trigger / period Override or interaction with deletion Owner / approval
Litigation or legal hold [____________] [____________] [____________] [____________]
Investigation / audit / examination [____________] [____________] [____________] [____________]
Statute / regulation / order [____________] [____________] [____________] [____________]
Contract / program / license [____________] [____________] [____________] [____________]
Tax / accounting / insurance / claim [____________] [____________] [____________] [____________]
Security / fraud / abuse [____________] [____________] [____________] [____________]
Other [____________] [____________] [____________] [____________]

Conflict decision and source: [________________________________]

9. Item-Level Disposition Matrix

Do not apply a generic exception list. Approve each action against the activated source and facts.

Data set / record System / recipient Proposed action Source / ground Facts Duration or event Approver
[____________] [____________] [Delete / retain / restrict / de-identify / suppress / no data] [____________] [____________] [____________] [____________]
[____________] [____________] [Delete / retain / restrict / de-identify / suppress / no data] [____________] [____________] [____________] [____________]
[____________] [____________] [Delete / retain / restrict / de-identify / suppress / no data] [____________] [____________] [____________] [____________]

Checks:

  • ☐ Another person's data and shared accounts reviewed.
  • ☐ Privilege, confidentiality, trade-secret, security, fraud, and legal-claim issues reviewed.
  • ☐ Sector, employment, health, financial, education, child, and public-record regimes reviewed.
  • ☐ Minimum suppression data approved where needed to keep data deleted or an opt-out effective.
  • ☐ The response can accurately explain each retained category without exposing protected details.

10. Technical Execution Plan

10.1 Execution Ticket

Field Entry
Approved scope [________________________________]
Systems and environments [________________________________]
Records / fields / objects [________________________________]
Deletion, de-identification, restriction, or suppression method [________________________________]
Dependencies and downstream propagation [________________________________]
Rollback, integrity, and availability risk [________________________________]
Required approvals [________________________________]
Scheduled window [________________________________]
Executor and independent verifier [________________________________]

10.2 System Results

System Approved action Method / ticket Executed by / date Verification query or evidence Result
[____________] [____________] [____________] [____________] [____________] [Pass / exception / failed]
[____________] [____________] [____________] [____________] [____________] [Pass / exception / failed]

10.3 Backups, Archives, Replicas, Caches, and Logs

Do not claim immediate deletion or permanent inaccessibility without testing the actual system. Record the approved treatment for each technical copy.

Copy type / system Selective action feasible Approved treatment and source Natural expiry or review Restore handling Evidence
Backup [Yes / no / partial] [____________] [____________] [____________] [____________]
Archive [Yes / no / partial] [____________] [____________] [____________] [____________]
Replica / cache / index [Yes / no / partial] [____________] [____________] [____________] [____________]
Security / audit log [Yes / no / partial] [____________] [____________] [____________] [____________]
Other [Yes / no / partial] [____________] [____________] [____________] [____________]

11. Processor, Affiliate, and Recipient Instructions

Recipient Relationship / contract Data and action Legal / contractual source Due date Confirmation / exception
[____________] [____________] [____________] [____________] [____________] [____________]
[____________] [____________] [____________] [____________] [____________] [____________]

11.1 Instruction Module

[ORGANIZATION LETTERHEAD]

[DATE]

Re: Data Action Instruction [REQUEST ID / VENDOR TICKET]

To [RECIPIENT]:

Under [CONTRACT, INSTRUCTION RIGHT, OR APPLICABLE SOURCE], perform the following approved action for the identified records:

  • approved identifier or token: [________________________________];
  • data and systems in scope: [________________________________];
  • action: [DELETE / RESTRICT / DE-IDENTIFY / SUPPRESS / OTHER];
  • exclusions or retained data: [________________________________];
  • completion date derived from source or contract: [________________________________];
  • evidence required: [________________________________]; and
  • escalation contact: [________________________________].

Do not use the identifier or retained minimum data for another purpose unless separately authorized.

Authorized by: [NAME / ROLE]

12. Response Modules

12.1 Acknowledgment or Authentication Request

[ORGANIZATION LETTERHEAD]

[DATE]

Re: Deletion Request [REQUEST ID]

Dear [REQUESTER NAME]:

We received your request on [DATE AND TIME] concerning [SCOPE].

The request is being evaluated under [APPLICABLE SOURCE OR APPROVED VOLUNTARY PROCESS]. Our current response deadline is [DATE], calculated from [SOURCE-DEFINED TRIGGER].

☐ We have the information needed to continue.

☐ We need the following information that the approved authentication rule permits and requires: [________________________________].

This communication changes the response calculation only if [CONTROLLING SOURCE AND FACTS].

Sincerely,

[NAME / TITLE / ORGANIZATION]

12.2 Extension Notice

[ORGANIZATION LETTERHEAD]

[DATE]

Re: Extension for Deletion Request [REQUEST ID]

Dear [REQUESTER NAME]:

Under [CITATION OR APPROVED VOLUNTARY STANDARD], we are extending the response period from [ORIGINAL DATE] to [NEW DATE].

The extension is permitted because [SOURCE-ALIGNED REASON AND FACTS]. We provided this notice on [DATE] under the calculation recorded for this request.

Sincerely,

[NAME / TITLE / ORGANIZATION]

12.3 Completion, Partial Completion, or Refusal

[ORGANIZATION LETTERHEAD]

[DATE]

Re: Decision on Deletion Request [REQUEST ID]

Dear [REQUESTER NAME]:

We evaluated your request under [APPLICABLE SOURCE OR APPROVED VOLUNTARY PROCESS].

Requested data or action Decision Result Source / explanation
[____________] [Deleted / retained / restricted / no data / denied] [____________] [____________]
[____________] [Deleted / retained / restricted / no data / denied] [____________] [____________]

We sent applicable instructions to [PROCESSOR / AFFILIATE / RECIPIENT CATEGORIES] as required by [SOURCE OR CONTRACT].

The response does not claim deletion from any backup, archive, recipient, or system that has not been confirmed. Approved treatment for remaining technical copies or retained data is: [________________________________].

[IF REQUIRED: Appeal deadline, method, and regulator-contact information: [________________________________].]

Sincerely,

[NAME / TITLE / ORGANIZATION]

12.4 Appeal Decision

[ORGANIZATION LETTERHEAD]

[DATE]

Re: Appeal Decision [REQUEST ID]

Dear [REQUESTER NAME]:

We received your appeal on [DATE] and reviewed [ISSUES].

☐ The original decision is reversed as follows: [________________________________].

☐ The original decision is modified as follows: [________________________________].

☐ The original decision is upheld for these source-based reasons: [________________________________].

[IF REQUIRED: Regulator or complaint route: [________________________________].]

Sincerely,

[NAME / TITLE / ORGANIZATION]

13. Final Quality Control

  • ☐ The activated source version and effective date govern this request.
  • ☐ Every deadline uses the source-defined trigger, not a generic 45-day assumption.
  • ☐ Authentication did not stop or restart a clock unless the source permits it.
  • ☐ The data map covers each in-scope entity, system, processor, affiliate, and recipient.
  • ☐ Every deletion, retention, restriction, de-identification, or suppression decision has a source and facts.
  • ☐ No deletion occurred while an approved preservation conflict remained unresolved.
  • ☐ Execution evidence proves the claimed system result.
  • ☐ Backup, archive, replica, cache, index, and log language matches actual tested behavior.
  • ☐ Downstream instructions and confirmations are complete or accurately disclosed as pending.
  • ☐ Appeal and regulator-contact language appears only when required or voluntarily offered.
  • ☐ The response does not overstate deletion or conceal an approved exception.
  • ☐ Legal approved the final response and evidence package.

Final legal approval: [NAME / DATE]

Sent by / date / time zone: [________________________________]

Delivery evidence: [________________________________]

14. Request Record and Retention Decision

Record Repository Access restriction Approved retention source / period Disposal or review date
Original request [____________] [____________] [____________] [____________]
Authentication / authority evidence [____________] [____________] [____________] [____________]
Search and data-map evidence [____________] [____________] [____________] [____________]
Disposition and legal analysis [____________] [____________] [____________] [____________]
Execution tickets and validation [____________] [____________] [____________] [____________]
Recipient instructions / confirmations [____________] [____________] [____________] [____________]
Response and delivery evidence [____________] [____________] [____________] [____________]
Appeal record [____________] [____________] [____________] [____________]

No retention period is supplied by this template. Enter the approved source, trigger, period, hold override, access restriction, and disposal method for each record.

Metrics and Review

Metric Period Result Approved target / basis Owner
Requests received [____________] [____________] [____________] [____________]
Timely responses [____________] [____________] [____________] [____________]
Extensions [____________] [____________] [____________] [____________]
Partial or refused requests [____________] [____________] [____________] [____________]
Execution exceptions / failures [____________] [____________] [____________] [____________]
Processor confirmation rate [____________] [____________] [____________] [____________]
Appeals / complaints [____________] [____________] [____________] [____________]

Procedure review date and source-currency check: [________________________________]

Sources Reviewed for This Rebuild

These official sources were reviewed on 2026-08-15 to test the former universal deletion scope, deadline, exception, verification, appeal, and backup assumptions. Recheck the current version and applicability before use.

Ezel AI
Hi! Want this done for you? Tell me your situation and I'll fill in every section and tailor it to your state.
You get the finished Word & PDF in about 5 minutes. $99 one time for this document, or $249/mo for access to every document and every Ezel app. Want me to start?
AI Legal Assistant
Ezel AI
Hi! Want this done for you? Tell me your situation and I'll fill in every section and tailor it to your state.
You get the finished Word & PDF in about 5 minutes. $99 one time for this document, or $249/mo for access to every document and every Ezel app. Want me to start?

Insert Image

Insert Table

Watch Ezel in action (sample case)

All changes saved
Save
Export
Export as DOCX
Export as PDF
Generating PDF...
data_deletion_request_procedure_universal.pdf
Ready to export as PDF or Word
AI is editing...
Chat
Review

Get your finished document

Filled in for your situation. Drafting from scratch takes hours; finish yours in about 5 minutes for $99 one time.

  • Deep Legal Knowledge
    Understands case law, statutes, and legal doctrine.
  • Court-Ready Formatting
    Proper captions and local-rule compliance.
  • AI-Powered Editing
    Tailor every section to your case.
  • Export as PDF & Word
    Ready to file or send.
Secure checkout via Stripe
Need to customize this document?

About This Template

Compliance documents are what regulated businesses use to prove they follow the rules that apply to their industry, whether that is privacy, anti-money-laundering, consumer protection, or sector-specific requirements. Regulators look for consistent policies, up-to-date records, and clear evidence of employee training. The cost of getting compliance paperwork right is almost always smaller than the cost of an enforcement action, fine, or public disclosure.

Important Notice

This template is provided for informational purposes. It is not legal advice. We recommend having an attorney review any legal document before signing, especially for high-value or complex matters.

Checked against the law it cites

A reviewer verified this template's legal citations against the official source on 2026-08-15.

Legal authority: Applicable privacy, data-protection, sector, employment, consumer, contract, order, litigation-hold, and regulator sources: [INSERT CURRENT OFFICIAL CITATIONS BEFORE USE]

Last updated: 2026-08-15

Get your Data Deletion Request Procedure, done and ready to use

Fill it in for your situation, adjust it for your state, and download the finished Word and PDF. Let the AI do it in about 5 minutes, or finish it yourself in the editor. $99 one time, or go Pro for access to every document and every Ezel app.