Trail Map โ€บ Use-Case Catalog โ€บ GDPR & Privacy
๐Ÿ”’ Admin & Extend ยท Module 24

GDPR & Privacy: Honoring a "Forget Me" Request

Sometimes a customer asks you to delete their personal data. How to do that the right way โ€” with a clear record of what happened โ€” in just a couple of clicks.

4
Tabs
~10 min
Time to Complete
80 pts
Available
1 Badge
Privacy Compliance Officer

Why "please delete my data" needs a real process

RK
Rahul Kapoor ยท Data Protection Officer

"A customer emailed us asking to erase their personal details. I need to know exactly what we changed, when, and who did it. Privacy law says I have to prove it happened โ€” not just say so."

You'll learn about a law called GDPR. It's short for General Data Protection Regulation, and it's a privacy law that protects people's personal data โ€” things like their name, email, or phone number.

GDPR gives people the right to ask a company to erase their personal data. If your company can't prove what it erased, and when, that's a real problem. Guessing, or editing a database by hand, isn't good enough.

๐Ÿ’ก
What you'll be able to do
Clear someone's personal data in one click, and keep a permanent record โ€” called an audit trail โ€” proving the request was honored.

Erasing personal data, the right way

Only an Admin can do this โ€” a user with full setup access to your CRM. There is no self-service "delete my account" button that customers can click themselves.

Instead, an Admin opens the person's Contact or Lead record (the CRM page that stores everything you know about that person). Then they choose "Erase PII (GDPR)" from the record's actions menu. PII stands for "personal information" โ€” things like someone's name, email, or phone number.

โš ๏ธ
This cannot be undone
Erasing replaces personal fields โ€” name, email, phone, address, and similar โ€” with the text [ERASED]. The record itself stays in place, along with its history of related activity. That's your proof for later. But the personal details are gone for good.

Every erasure is written to a log. Admins and Managers can check it any time at Setup โ†’ Data Quality โ†’ GDPR. The log shows which record, which fields, who asked for it, and when it happened.

1 Erase a test contact's personal data

Open the recordFind a Contact or Lead record that's safe to practice on โ€” not a real customer.
Choose "Erase PII (GDPR)"Open the record's actions menu and select "Erase PII (GDPR)". Only Admins see this option.
Confirm, then check the logConfirm "Yes, Erase PII". Then go to Setup โ†’ Data Quality โ†’ GDPR to see your request in the Erasure Request Log.

Day-to-day: when a request comes in

Confirm the request is realVerify the request actually came from the person on the record before erasing anything.
Erase it and log the confirmationRun the erasure, then reply to the customer confirming it's done โ€” you now have proof in the GDPR log if they or a regulator ever ask.

Day-to-day: compliance reviews

Pull the log on demandOpen Setup โ†’ Data Quality โ†’ GDPR any time a review or audit asks for proof of erasure requests handled.
๐ŸŽฏ
What to try next
Look at the Audit & Debug Logs trail โ€” the same permanent-record idea backs both features.

Test what you learned

1. Who can erase a customer's personal data on a Contact or Lead record?
Any user, as a self-service option
Only an Admin, from that record's actions menu
2. After erasure, what happens to the record?
The entire record disappears from the CRM
Personal fields show [ERASED]; the record and its history stay for audit purposes