Notifications
Clear all
Topic starter
16/07/2026 5:00 pm
Just went through our annual GDPR review. Our process for handling right to be forgotten requests is a joke.
We have a spreadsheet mapping data subjects to systems. Then we manually log into each one—CRM, marketing platform, support ticket system, analytics—to delete records. It takes days and relies on people remembering every single system. Missed one last time and it was a compliance finding.
Is everyone else doing it this way? I'm sourcing a potential automation tool but the RFP process is heavy. Looking for practical steps, not theory. What's your actual workflow?