Most requests under the data protection regulation do not arrive through a form on the website. They arrive as an email among other emails, or as a sentence in the chat: "I want you to delete everything you have about me". That makes customer service the function that meets them first, and therefore the one that decides whether the clock starts on time. This article goes through what counts as a request, which deadlines apply and where the limits are. It is not legal advice; check your routines with whoever is responsible for data protection at your company. The guidance cited is from the Swedish supervisory authority, and the rules it describes come from the GDPR itself, so the structure applies across the EU.
Which requests can arrive in customer service's channels?
Every data subject right can arrive anywhere, and customer service needs to recognise them. The Swedish Authority for Privacy Protection collects the rights and what they mean. In customer service's everyday work they look roughly like this:
| The customer writes | The right involved | What should happen |
|---|---|---|
| "What data do you have about me?" | Right of access | Compile the data and provide it |
| "Delete my account and everything you have" | Right to erasure | Assess whether an exception applies, answer with a decision |
| "You have the wrong address and wrong name" | Right to rectification | Correct it, and confirm that it is done |
| "Stop sending me your mailings" | Objection to direct marketing | Stop the mailings, always |
| "I want to move my data to another service" | Data portability | Provide it in a machine-readable format where the right applies |
| "Stop using my data until we have sorted this out" | Restriction of processing | Pause the processing during the assessment |
The fourth row is the most common and the simplest: an objection to direct marketing must always be followed, with no assessment. The others require judgement, and therefore a routine.
How do you know it is a request?
By the content, not the form. There is no requirement for the customer to use a particular form, write the word "GDPR" or cite an article. A sentence in the chat, a line in an ongoing ticket or a note at the end of a complaint can be a request, and the deadline then runs from when you received it.
That places three practical demands on customer service:
- Everyone must recognise the phrasings. "Delete my data", "what do you have about me", "stop contacting me", "your records about me are wrong". Put the list in the team's internal routine.
- The request must be tagged and handed over the same day. Give it a ticket type of its own so it can be tracked and counted, following the principles in the article on categorising tickets.
- The agent should not assess it alone. Customer service's job is to recognise the request, confirm receipt and hand it to whoever owns the question. Judging the exceptions is not an inbox decision.
A common grey area is the annoyed customer who writes "just delete me then" at the end of a complaint. Treat it as a request and ask back what the customer wants deleted, rather than interpreting it away.
How long do you have, and what does it cost?
One month, with the possibility of an extension, and the answer should as a main rule be free of charge. According to the authority's description of the deadlines, whoever processes the data must respond without undue delay and at the latest one month after the request was received. The deadline can be extended by two months if the request is complicated or if many requests have arrived at once, but then you must inform the person about the extension and the reason for it no later than one month after the request was received.
That detail is the one most often missed: the extension is not silent. If you miss informing them within one month, you have broken the deadline even if you answer in week six.
On fees, the authority writes that you have the right to exercise your rights free of charge, with certain exceptions where a fee may be charged. Assume the answer is free, and let someone other than customer service decide the few cases where it is not.
Can you require identification?
Only when it is needed, and never more data than necessary. In its guidance on identification, the authority writes that it is rarely necessary to require a person to show an identity document, since that can itself create a security risk, and that it should only be required if strictly necessary and supported by law. If there are reasonable grounds to doubt the identity, you may request further necessary information, but you may not collect more personal data than the identification requires.
The rule of thumb that follows: do not require stronger identification than you used when the customer relationship began. If you only have an email address, a request from that address is normally enough. If the customer has an account with a login, a logged-in session is the best identification. Asking a customer to email a photo of their driving licence to find out what data you hold is, in most cases, creating a risk rather than managing one.
Do you always have to erase?
No. The right to erasure applies under certain conditions, and there are exceptions. On its page about the right to erasure, the authority describes that data should for example be erased when it is no longer needed for the purpose it was collected for, or when someone objects to processing for direct marketing, but also that whoever processes the data may refuse erasure if the data is still needed to fulfil a legal obligation.
For an online retailer the most common example is accounting: a purchase held in the accounting records cannot be erased on request. That means the answer to the customer is rarely yes or no, but both: the account and the marketing history are removed, while the order and the invoice remain for as long as the law requires.
So write a standard answer that explains exactly that, in plain language, and have the data protection officer review it once. The format for such an answer, with the short decision first and the exceptions after, is described in the article on writing help articles.
What does customer service do when something has gone wrong?
Raises the alarm immediately, and does not assess it alone. Customer service is often the first to learn that the wrong person received a reply, that an attachment contained someone else's data or that a mailing went to the wrong list. That is a possible personal data breach, and according to the authority a notifiable breach must be reported within 72 hours of the organisation becoming aware of it.
72 hours is short, and the clock starts when someone in the organisation understands what has happened, not when the data protection officer reads their inbox on Monday. Customer service therefore needs three things: a named recipient, a route that works in the evenings and at weekends, and the message that it is better to raise the alarm once too often. The assessment of whether the breach is notifiable is made by whoever is responsible, not in the inbox. What otherwise applies when AI is used in customer service is covered in the article on GDPR and AI.
What to do
- Write a list of phrasings that should be read as a request, and go through it with the whole team.
- Create a ticket type of its own for data protection requests, so they can be counted and tracked against the deadline.
- Appoint a recipient and a deputy who take over the request the same day, and put the response time in the routine.
- Write four standard answers: confirmation of receipt, access, erasure with exceptions, and notice of extension with the reason.
- Decide the identification level per channel based on how the customer was identified in the first place, and write it down.
- Set up an alarm route for breaches with a name, a phone number and a clear instruction to rather raise the alarm once too often.
- Follow two numbers: requests per month and the share answered within one month.
Common questions
Does "delete my account" count as an erasure request?
Treat it as a request. There is no formal requirement, so a sentence in the chat or an email is enough, and the deadline starts when you have received it. Do ask back what the customer wants removed, since many mean they want to close the service rather than erase all history, but do that as part of handling the request and not as a way of postponing it.
Can we refer the customer to a form on the website?
You are welcome to offer a form, but you cannot require the customer to use it. The request is valid whatever the channel, and answering "fill in the form" without registering the request means the deadline runs anyway. The best setup is for customer service to register the request immediately while mentioning that the form exists if the customer wants to add details.
What do we answer when a customer asks whether the AI has stored their data?
Answer from what actually applies in your systems: where the data sits, how long it is kept and whether it is used to train models. That assumes you know, which is a reason to ask the supplier before a customer asks you. An answer saying "no, the AI stores nothing" without having checked is an answer you may have to take back.
Do we have to answer if we hold no data about the person?
Yes, you should answer then too, and say that you do not process any personal data about them. Silence is not an answer, and a lack of response is exactly what makes a customer turn to the supervisory authority. At the same time, be careful not to search more broadly than necessary to look for data; answer from the systems where you actually process customer data.
Sources
- De registrerades rättigheter — Swedish Authority for Privacy Protection, read 2026
- Tidsfrister — Swedish Authority for Privacy Protection, read 2026
- Vad kostar det att utöva mina rättigheter enligt GDPR? — Swedish Authority for Privacy Protection, read 2026
- Identifiering när den registrerade utövar sina rättigheter — Swedish Authority for Privacy Protection, read 2026
- Rätt till radering av dina personuppgifter — Swedish Authority for Privacy Protection, read 2026
- När ska vi anmäla personuppgiftsincidenten? — Swedish Authority for Privacy Protection, read 2026