E-commerce

Customer support for GDPR requests: data access, deletion, and export

Customer support for GDPR requests: data access, deletion, and export

July 1, 2026

“Delete all my data immediately.” “I want a copy of everything you have on me.” “I requested erasure, but my account still exists.” Three tickets that customer service often handles as a simple unsubscription or a customer account request, with legal and relational risks.

The e-commerce GDPR requests support requires a distinct operational process: access (DSAR), erasure, rectification, portability, restriction, and objection. Legal deadline: one month, extendable to two months if complex. Each request must be identified, verified, processed across all systems, and documented.

This guide #383 covers the DSAR-FLOW framework, ticket typology, multi-tool discovery, and dsar_fcr KPIs. It is distinct from the GDPR chatbot (#142 area) (bot compliance, DPA, legal bases) and unsubscription (#381): here, customer service ops processing of data subject rights access, deletion, and export.

Summary

Why must customer service handle GDPR requests differently from classic tickets?

An e-commerce client GDPR request is not a WISMO ticket nor a newsletter unsubscription. It is the exercise of a legal right with a deadline, proof, and a multi-system scope.

Five risks without a DSAR process

  • Deadline exceeded: response beyond one month without justified extension

  • Partial erasure: Shopify deleted, Klaviyo or Gorgias forgotten

  • Confusion of rights: marketing unsub treated as total erasure

  • Over-collection of identity: systematic passport scan (sanctioned by CNIL)

  • CNIL complaint: dissatisfied customer escalates to the regulator

The EDPB recalls in 2025 that the right of access must receive real data, not a summary, and that the response must be given at the latest within one month, extendable by two months if complex, with notification to the requester (EDPB, guidelines on right of access 2025).

Angle #383 vs related content

DTC Example

Fashion brand on Shopify + Klaviyo + Gorgias, 18 GDPR requests/quarter before DSAR-FLOW. Average processing time 24 days, 2 partial erasures audited. After process: processing time 11 days, dsar_fcr 82%, zero CNIL complaints post-deployment.

Who is affected

Any store selling in the EU/EEA, even if the company is outside the EU. L1 support is often the first point of contact: it must route, not improvise the erasure.

Convert over 2,000 customers on average per month with Qstomy.

The world’s 1st Shopify AI dedicated to customer conversion

Empowering 200+ e-commerce merchants

Which GDPR rights do customers exercise through support?

Mapping e-commerce GDPR rights prevents handling an access request as an erasure request.

Seven rights and deadlines (Art. 15-22)

  • Access (Art. 15): copy of data + processing info. Deadline: 1 month.

  • Rectification (Art. 16): correct inaccurate data. Without undue delay.

  • Erasure (Art. 17): right to be forgotten if conditions are met. 1 month.

  • Restriction (Art. 18): freezing of processing, data preservation. 1 month.

  • Portability (Art. 20): structured JSON/CSV export based on consent or contract.

  • Objection (Art. 21): stop processing based on legitimate interest (e.g., direct marketing). 1 month.

  • Withdrawal of consent (Art. 7.3): linked to marketing preferences (#381/#382), not erasure.

The CNIL reminds that the controller must facilitate the exercise of rights and clearly inform about deadlines and any restrictions (CNIL, individuals' rights).

Ticket type → right matrix

"Send me all my data" → dsar_access. "Delete my account and my orders" → dsar_erasure (verify exemptions). "Correct my address in your database" → dsar_rectification. "JSON export to switch platforms" → dsar_portability.

Distinction between unsub vs erasure

"Stop promotional emails" = #381 or #382. "Delete all traces of me" = #383 dsar_erasure. GDPR-CLARIFY-01 macro if formulation is ambiguous.

E-commerce portability

Typical export: Shopify customer profile, order history, addresses, marketing consents, third-party anonymized Gorgias tickets. Machine-readable CSV or JSON format.

Which gdpr_* tickets should be mapped before the process?

Twelve GDPR support ticket typologies cover 95% of DTC requests.

Twelve gdpr_ticket typologies

  1. dsar_access_full: complete copy of personal data

  2. dsar_erasure_account: account deletion + associated data

  3. dsar_erasure_guest: deletion without Shopify account (email only)

  4. dsar_rectification: correct name, address, email

  5. dsar_portability: structured machine-readable export

  6. dsar_restriction: freezing marketing/analytics in case of dispute

  7. dsar_objection_marketing: objection to prospecting (similar to #381)

  8. gdpr_confusion_unsub: confuses unsubscription and deletion

  9. gdpr_third_party_request: spouse, lawyer, authorized representative

  10. gdpr_still_data_post_erasure: follow-up at D+30 regarding remaining data

  11. gdpr_chatbot_logs: chatbot conversation access/deletion

  12. gdpr_urgent_litigation: litigation threat + pre-procedure access request

Helpdesk tags

gdpr_dsar, gdpr_erasure, gdpr_access, gdpr_portability, gdpr_rectification, gdpr_handoff_dpo, gdpr_extension_2m, gdpr_refused_derogation. High priority on gdpr_urgent and gdpr_still_data.

Inbound channels

  • Email privacy@ or dpo@ (dedicated channel recommended by CNIL)

  • Web form /privacy-request

  • Support chat (bot routing → future #384)

  • Postal mail (rare for DTC, identical SLA)

12-month ticket mining

Keyword export: RGPD, GDPR, personal data, deletion, right to be forgotten, access, CNIL, delete my data. Quantify quarterly volume to right-size DPO/privacy support resources.

First response SLA

Acknowledgment of receipt within 48 business hours with case number DSAR-XXXX and estimated timeframe. No deletion processing before identity verification DF-3.

How to apply the DSAR-FLOW framework in nine steps?

The DSAR-FLOW framework structures every GDPR support request into nine reproducible and auditable steps.

Nine DSAR-FLOW steps

  1. DF-1 Intake: record receipt date, channel, request text, contact email

  2. DF-2 Classify right: access, erasure, rectification, portability, other

  3. DF-3 Verify identity: calibrated to risk, no over-collection

  4. DF-4 Discovery: multi-system search (section 6)

  5. DF-5 Analyze exemptions: legal retention obligations (section 7)

  6. DF-6 Execute: export, rectification, partial/total erasure

  7. DF-7 Document: log affected systems, date, agent, scope

  8. DF-8 Respond to customer: confirmation + attachments or reasoned refusal within 1 month

  9. DF-9 Close case: tag resolved, log retention 3 years for internal audit

DF-2 decision tree

Mixed formulation "delete and send copy beforehand" → process access first (DF-6 export), then erasure after customer confirmation or 7-day grace period offered.

2-month extension (Art. 12.3)

If complex discovery (10+ systems, B2B wholesale, multi-country): inform customer within 1 month with reasons and new deadline. Tag gdpr_extension_2m. Document in processing register.

Standard acknowledgment of receipt

"We have successfully received your [access/erasure] request on [date]. Reference DSAR-[ID]. Response within 30 days. If identity verification is required, here is the procedure."

Legal timestamping

The one-month period starts upon receipt, not at the end of reasonable identity verification (ECOSIRE, DSAR e-commerce). Parallelize identity verification and preliminary discovery.

DPO Escalation

dsar_erasure with dispute order, gdpr_urgent_litigation, contested exemption refusal: handoff gdpr_handoff_dpo before DF-6.

Which GDPR-* macros for support agents?

Standard GDPR-* agent macros standardize communication without legal promises outside the scope of the agent.

Ten GDPR macros

  • GDPR-ACK-01: acknowledgment of receipt + DSAR reference + 30-day deadline

  • GDPR-ID-01: proportionate identity verification request (section 5a)

  • GDPR-ACCESS-01: secure export delivery via link expiring in 7 days

  • GDPR-ERASE-01: erasure confirmation + legally retained scope

  • GDPR-ERASE-PARTIAL-01: reasoned partial refusal (accounting, dispute)

  • GDPR-CLARIFY-01: distinguish unsub (#381) vs erasure

  • GDPR-EXTEND-01: 2-month extension notification + reasons

  • GDPR-PORT-01: JSON/CSV export delivery for portability

  • GDPR-RECT-01: confirmation of rectification completed

  • GDPR-HANDOFF-01: transfer to DPO within 24 hours

Tone and L1 agent limits

L1 agents: intake, basic identity verification, discovery checklist, ACK and CLARIFY macros. No Art. 17 derogation refusals without DPO approval. No customer legal advice.

90-min agent training

Path: classify right, execute GDPR-CLARIFY, fill out discovery checklist, never delete Shopify customer without DF-5. 10-question quiz at the end of training.

Mandatory ticket documentation

Fields: dsar_id, right_type, identity_verified_date, systems_searched[], systems_modified[], derogation_applied, response_date, agent_id.

Secure export delivery

Password-encrypted ZIP sent separately by SMS or 7-day expiring link. Never attach full unencrypted data directly to an unencrypted ticket.

How to verify identity without over-collecting?

The DSAR identity verification must be proportionate to the risk. Systematic heavy over-collection = penalized practice.

Three levels of verification

  • Level 1 (low risk): access from account email + recent order number

  • Level 2 (standard): email OTP + confirmation of 2 profile fields (last name, delivery zip code)

  • Level 3 (high): total erasure + order history: OTP + ID document in case of reasonable doubt

The CNIL has penalized operators systematically requiring a passport scan for any DSAR, considered disproportionate (Zunapro, GDPR e-commerce France 2026).

Guest checkout case

No Shopify account: verification via email + order number + amount/date. See guest checkout support. If insufficient: Level 2 email OTP.

Third-party representative

Lawyer or spouse: written power of attorney or email from the account holder's address confirming the mandate. Otherwise, polite refusal with Art. 12 explanation.

Refusal of unproven identity

Macro GDPR-ID-01 prompts once. Without response within 14 days: suspend the file, inform the client. Do not process erasure without verification upon high-risk request.

Parallelization

While waiting for Level 3 verification, launch preliminary discovery (read-only) to meet the 1-month deadline.

Where to look for data: Shopify discovery, Klaviyo, and helpdesk?

The e-commerce DSAR discovery scans each system containing the requester's personal data.

Discovery Checklist (14 typical DTC systems)

  1. Shopify Customer: profile, addresses, orders, metafields

  2. Shopify Orders: lines, tokenized payment, notes

  3. Klaviyo Profile: email, segments, events, suppress status

  4. Alternative ESP: Shopify Email, Brevo if migrated

  5. SMS provider: Attentive, Postscript subscriber

  6. Helpdesk Gorgias/Zendesk: tickets, chats, attachments

  7. Chatbot Qstomy/other: conversation logs, session ID

  8. WhatsApp BSP: wa_id, history if WhatsApp support is used

  9. Reviews Judge.me/Yotpo: email-linked reviews

  10. Loyalty Smile/LoyaltyLion: points, history

  11. Analytics GA4: User-ID if enabled (limited, often aggregated)

  12. Payment Stripe/PayPal: PSP-side data (direct to a separate request if needed)

  13. ERP/3PL: shipments, if personal data is replicated

  14. Manual CSV Backups: marketing team exports (often forgotten)

Art. 15 Access Export

Compile: raw data + purposes + categories + recipients + retention periods + source. Redact third-party data (e.g., name of neighborhood parcel delivery person if visible).

Art. 17 Erasure by System

Shopify: anonymize customer or delete according to policy. Klaviyo: delete profile. Gorgias: anonymize ticket requester. Chatbot: purge session logs via vendor API.

Article 30 Register

Your processing register already lists these systems. Discovery = applying the register to an email. Update the register if a forgotten system is found.

Processors (Subprocessors)

Notify vendors if erasure is required on their end (DPA assistance clause Art. 28). Vendor delay is included in the 30-day DSAR timeline.

Notion Discovery Template

Table: system | admin contact | search method | data found Y/N | action access/erase | date | agent.

When to refuse or limit an erasure: Article 17 exemptions?

The right to erasure is not absolute. Customer Support must apply DF-5 before any Shopify delete.

Five frequent e-commerce derogations

  • Legal accounting obligation: invoices for 6 to 10 years depending on the country

  • Ongoing dispute: chargeback, contested return, open warranty

  • Exercise of legal right: ongoing consumer complaint

  • Public interest/archiving: rare for DTC, except in regulated sectors

  • Aggregated anonymized data: out of scope if truly anonymous

Standard partial erasure

Delete: marketing profile, chat logs, optional reviews. Retain: anonymized order (name → "Erased Customer", email hash), legal invoice. Macro GDPR-ERASE-PARTIAL-01 explains the scope to the customer.

Recent order without dispute

Profile erasure OK, minimal anonymized order retention for accounting. Document in DF-7.

Distinction between account vs data

Customer wants to "close account" without GDPR erasure: standard account process (#guest). GDPR erasure = wider scope discovery.

Reasoned refusal

Art. 12.4: inform of refusal, right to lodge a complaint with the CNIL, possibility of judicial remedy. DPO validation mandatory before sending GDPR-ERASE-PARTIAL-01.

Post-erasure still_data

gdrp_still_data_post_erasure ticket: re-discovery of forgotten system, apology + supplement within 72 hours.

Which DSAR SLAs and KPIs should be measured each quarter?

The support GDPR request KPIs prove operational discipline and prepare for a CNIL audit.

Eight key metrics

  • dsar_volume_quarterly: number of requests per right

  • dsar_median_days: days from receipt → response (target < 21)

  • dsar_sla_30d_rate: % of responses under 30 days (target 100%)

  • dsar_fcr: resolved without customer follow-up / total

  • dsar_partial_erasure_rate: partial erasures / total erasure

  • dsar_identity_reject_rate: cases suspended due to identity verification

  • dsar_still_data_rate: follow-ups post-erasure

  • gdpr_confusion_unsub_rate: rerouted to #381 (intake quality)

Recommended internal SLAs

  • Acknowledgment of receipt: 48 business hours (GDPR-ACK-01)

  • Identity verification follow-up: Day+7 if silent

  • Full discovery: Day+14 max

  • Final response: Day+28 max (margin before the legal 30 days)

  • DPO Handoff: within 24 hours if gdpr_urgent

Quarterly privacy + support ritual (60 min)

Review of volume, deadlines, still_data incidents, discovery checklist update, 1 test DSAR simulation. Share dashboard with management.

DTC SMB Benchmark

5 to 25 DSARs/quarter depending on size. dsar_median_days 10-15 post-process. Zero CNIL complaints related to delay if SLA is respected.

Training correlation

Spike in gdpr_confusion_unsub after hiring agents: reschedule 90 min DSAR-FLOW training.

Which edge cases and anti-patterns should be avoided?

Eight GDPR support edge cases and anti-patterns to document in the team playbook.

1. Unsubscribe vs erasure confusion

Customer says "delete my data" after email promo. GDPR-CLARIFY-01 before action. If unsubscribe is sufficient → route #381. If erasure confirmed → full DSAR-FLOW.

2. Request via public chatbot

Never execute erasure in the widget without the DF-3 process. Bot welcomes, creates DSAR ticket, directs to privacy@ email. Future #384 will automate triage.

3. Multi-accounts same person

2 emails, 1 customer: discovery on both profiles. Double merge or erasure documented.

4. Chatbot data + LLM vendor

Deletion of bot logs + deletion request at AI processor (DPA). CNIL 2025: rights on AI training data if applicable, timeframes may differ.

5. Active customer recurring subscription

Erasure = cancel subscription first. Link save subscription (#373) does not apply if GDPR request is confirmed.

6. Wholesale B2B contact

Professional + personal data: B2B contract scope may limit erasure of active reseller account.

7. Manifestly unfounded request

Art. 12.5: refusal or reasonable fee if repetitive abusive requests. DPO validates. Rare in DTC.

8. DSAR export leak

Unexpired export link sent to wrong email = breach incident. CNIL 72h incident procedure if risk.

Support Anti-patterns

  • Delete Shopify customer without Klaviyo/Gorgias discovery

  • Promising systematic 24h erasure

  • Passport scan for simple access

  • Ignoring chatbot logs in erasure

  • L1 agent refusing deviation without DPO

How does Qstomy receive GDPR requests without executing them on its own?

Qstomy welcomes GDPR requests via chat: structured intake, rights clarification, pre-filled DSAR ticket. It does not execute the deletion on its own (human/DPO validation required).

Qstomy GDPR intake capabilities

  • gdpr_detect_intent: access, erasure, rectification, portability

  • gdpr_clarify_unsub: distinguish #381 unsub vs Art. 17

  • gdpr_collect_dsar_fields: email, requested right, details

  • gdpr_create_ticket: DSAR-ID, gdpr_dsar tag, handoff privacy@

  • gdpr_ack_sla: 30-day response time message + reference file

  • gdpr_no_auto_delete: never delete without workflow DF-3 to DF-7

Completes bot compliance (#142) and paves the way for the future #384 GDPR bot triage advanced automation.

Quantified DTC scenario

Skincare brand, 22 GDPR requests/quarter via chat + email, 40% arrived via unstructured chat.

After Qstomy intake + DSAR-FLOW #383: gdpr_clarify_unsub 31% rerouted to #381 (time savings), dsar_ticket_complete_rate 94%, dsar_median_days 12 (vs 22), zero partial deletion audit errors.

Explore AI customer support, Shopify and request a demo.

Chat logs in discovery

DSAR erasure includes purging Qstomy sessions via API. Documented in DPA and record of processing activities.

What is the checklist for deploying DSAR-FLOW this week?

DSAR-FLOW Checklist (12 steps)

  1. Create privacy@ or dpo@ email + /privacy-request form

  2. Document DSAR-FLOW DF-1 to DF-9 in Notion

  3. Draft 10 GDPR-* macros + train agents for 90 mins

  4. Build discovery checklist 14 systems section 7

  5. Define 3 levels of proportionate identity verification

  6. Document Art. 17 exceptions with DPO

  7. Template for encrypted ZIP access export + expiring link

  8. Internal SLAs: D+2 ack, D+28 max response

  9. Quarterly dsar KPI dashboard

  10. Quarterly test DSAR simulation

  11. Update privacy policy (exercise of rights section)

  12. Align chat bot: intake only, no auto-delete

At a glance

  • #383 = GDPR support ops, not bot compliance (#142)

  • DSAR-FLOW: 9 steps intake → closure

  • 30-day legal deadline: parallelize verification and discovery

  • Multi-system discovery: Shopify, Klaviyo, Gorgias, bot

  • Erasure ≠ unsub: systematic GDPR-CLARIFY-01

FAQ

Difference with GDPR glossary?
Glossary = legal framework. #383 = operational access, deletion, export workflow for agents.

Can support delete data on their own?
L1 executes after DF-5 if the playbook is clear. Denials of exemption and dispute cases: DPO validation.

Customer requests erasure but order is in dispute?
GDPR-ERASE-PARTIAL-01: marketing profile + logs deleted, order kept anonymized until dispute resolution.

Relationship with bot #384?
#383 = human DSAR-FLOW process. #384 = AI automated triage and escalation.

Do we need a DPO?
Mandatory if core business = large-scale processing. Otherwise, an internal privacy point of contact is often sufficient for DTC SMEs. Legal advice recommended.

Go further

Simulate an access DSAR this week on a test profile: time the 14-system discovery, identify the forgotten link before a real customer does.

Share this guide #383 with support, DPO, and management: a documented DSAR-FLOW turns a GDPR obligation into a mastered, auditable customer relationship process.

Enzo

July 1, 2026

Convert over 2,000 customers on average per month with Qstomy.

The world’s 1st Shopify AI dedicated to customer conversion

Empowering 200+ e-commerce merchants

Subscribe to the newsletter and get a personalized e-book!

No-code solution, no technical knowledge required. AI trained on your e-shop and non-intrusive.

*Unsubscribe at any time. We do not send spam.

Subscribe to the newsletter and get a personalized e-book!

No-code solution, no technical knowledge required. AI trained on your e-shop and non-intrusive.

*Unsubscribe at any time. We do not send spam.