Establish first what you actually hold, which is the part that makes this difficult in practice rather than in principle. Customer data spreads: the primary record in your customer system, copies in email threads, exports in spreadsheets, entries in your accounting software, and backups of all of them. A deletion addressing only the first has not achieved much, and knowing where data goes is the harder half of the task.

Verify who is asking before deleting anything, since acting on an unverified request is its own risk. A message claiming to be from a customer, asking you to remove their record, could be somebody else attempting to disrupt your relationship with them. Reasonable verification means confirming through a channel already associated with the account rather than the one the request arrived through.

Know the exceptions, because some records must be kept regardless of a request. Transaction records needed for tax purposes, anything subject to a legal obligation or an ongoing dispute, and information required to complete something they asked for. A deletion request does not override those, and the correct response is to delete what you can and explain plainly what you must retain and for how long.

Respond within a defined period rather than when convenient. Several regimes specify a window, typically measured in weeks rather than months, and even where no rule applies a prompt response is what prevents an ordinary request becoming a complaint. Acknowledging receipt immediately and confirming completion afterward is the pattern.

Remove them from your marketing lists as a separate step, because deleting a customer record frequently leaves the email platform untouched. Somebody who asked to be forgotten and then receives your newsletter has had the request ignored in the most visible way possible, and that is the version of this failure that becomes a complaint.

Keep a minimal record of the request itself, which sounds contradictory and is standard practice. The date, what was asked, what you deleted, and what you retained with the reason. That note demonstrates compliance and it should contain the minimum necessary rather than a copy of what you deleted.

Tell your suppliers where they hold the data on your behalf. Your email platform, your booking system, and your accounting software may each hold a copy, and a deletion that stops at your own systems is incomplete. Established providers have a process for this and it usually takes one message.

Then treat the request as a prompt to check your retention generally, because a business that holds data it cannot justify will receive these requests as an interruption rather than a routine matter. Deciding in advance how long you keep things is what makes each individual request straightforward. This is general information rather than legal advice, and obligations differ by where your customers are.

Confirm completion in writing rather than only performing it, since the customer has no way of knowing what happened inside your systems. A short message stating what was deleted, what was retained, and why closes the request properly and demonstrates that it was handled.

Handle it yourself rather than delegating a first request, because the process reveals where your data actually lives and that knowledge is worth having. Once you have done it once, writing down the steps means anybody can follow them afterward.

Treat a request as a signal about your practices rather than only as a task, since customers rarely ask unless something prompted them. Frequently the prompt is a message they did not expect to receive, and that is worth understanding independently of the deletion itself.