Confidential Dispatch

A DPDP data-deletion request, start to finish

1 min readUpdated 2026-07-21
Exercising rights

A data-deletion request, start to finish

When someone asks you to delete their data, five things have to happen — in order, and on the record. Here is the whole path.

Request receivedA message asking for deletion arriving into the inbox via the rights channel; the request line is highlighted.

Request received

Via the rights channel

Identity verifiedAn identity card with portrait and details, with a brass verification check above it.

Identity verified

Confirm who’s asking

AcknowledgedA calendar with a brass-ringed deadline and a within-window meter, acting inside the published 90-day window.

Acknowledged

Within a 90-day window

Deleted across systemsA document being dropped into a bin — the record deleted.

Delete everywhere

All systems & backups

ConfirmedA confirmation document carrying a prominent attested brass stamp; only legally-required data is retained.

Confirmed

Only legal retention

The duty at each stage
1

A reachable deletion channel

There is a real, published way to ask for deletion — the rights channel or the Grievance Officer — not a dead end.

2

Verify before you delete

Confirm the requester is who they say before acting, so you don’t erase or expose data on an unverified request.

3

Act within the window

Acknowledge the request and complete it inside your published timeline — at most 90 days.

4

Deleted across systems

Remove the data from live systems and processors, and schedule backups for deletion — not just the primary copy.

5

Confirm, keep only what’s required

Tell the requester it’s done, and retain only the residue the law specifically requires you to keep.

This is an illustration of the process, not legal advice.

Reviewed by Confidential Dispatch Editorial Team
Last updated 21 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →