E-commerce
July 1, 2026
“Delete all my data immediately.” “I want a copy of everything you have on me.” “I requested erasure, but my account still exists.” Three tickets that customer service often handles as a simple unsubscription or a customer account request, with legal and relational risks.
The e-commerce GDPR requests support requires a distinct operational process: access (DSAR), erasure, rectification, portability, restriction, and objection. Legal deadline: one month, extendable to two months if complex. Each request must be identified, verified, processed across all systems, and documented.
This guide #383 covers the DSAR-FLOW framework, ticket typology, multi-tool discovery, and dsar_fcr KPIs. It is distinct from the GDPR chatbot (#142 area) (bot compliance, DPA, legal bases) and unsubscription (#381): here, customer service ops processing of data subject rights access, deletion, and export.
Summary
Why must customer service handle GDPR requests differently from classic tickets?
An e-commerce client GDPR request is not a WISMO ticket nor a newsletter unsubscription. It is the exercise of a legal right with a deadline, proof, and a multi-system scope.
Five risks without a DSAR process
Deadline exceeded: response beyond one month without justified extension
Partial erasure: Shopify deleted, Klaviyo or Gorgias forgotten
Confusion of rights: marketing unsub treated as total erasure
Over-collection of identity: systematic passport scan (sanctioned by CNIL)
CNIL complaint: dissatisfied customer escalates to the regulator
The EDPB recalls in 2025 that the right of access must receive real data, not a summary, and that the response must be given at the latest within one month, extendable by two months if complex, with notification to the requester (EDPB, guidelines on right of access 2025).
Angle #383 vs related content
Chatbot GDPR (#142): DPA, legal bases, bot retention. #383 = execution of rights on the agent side.
Unsubscribe (#381): UNSUB-FLOW marketing email. Distinct from Art. 17 erasure.
Bot preferences (#382): PREF-FLOW channel consent. Handoff gdpr_erasure to #383.
Future GDPR Bot (#384): AI triage. #383 = human process + discovery ops.
Glossary: GDPR sheet legal framework, not CS workflow.
DTC Example
Fashion brand on Shopify + Klaviyo + Gorgias, 18 GDPR requests/quarter before DSAR-FLOW. Average processing time 24 days, 2 partial erasures audited. After process: processing time 11 days, dsar_fcr 82%, zero CNIL complaints post-deployment.
Who is affected
Any store selling in the EU/EEA, even if the company is outside the EU. L1 support is often the first point of contact: it must route, not improvise the erasure.

Convert over 2,000 customers on average per month with Qstomy.
The world’s 1st Shopify AI dedicated to customer conversion



Empowering 200+ e-commerce merchants
Which GDPR rights do customers exercise through support?
Mapping e-commerce GDPR rights prevents handling an access request as an erasure request.
Seven rights and deadlines (Art. 15-22)
Access (Art. 15): copy of data + processing info. Deadline: 1 month.
Rectification (Art. 16): correct inaccurate data. Without undue delay.
Erasure (Art. 17): right to be forgotten if conditions are met. 1 month.
Restriction (Art. 18): freezing of processing, data preservation. 1 month.
Portability (Art. 20): structured JSON/CSV export based on consent or contract.
Objection (Art. 21): stop processing based on legitimate interest (e.g., direct marketing). 1 month.
Withdrawal of consent (Art. 7.3): linked to marketing preferences (#381/#382), not erasure.
The CNIL reminds that the controller must facilitate the exercise of rights and clearly inform about deadlines and any restrictions (CNIL, individuals' rights).
Ticket type → right matrix
"Send me all my data" → dsar_access. "Delete my account and my orders" → dsar_erasure (verify exemptions). "Correct my address in your database" → dsar_rectification. "JSON export to switch platforms" → dsar_portability.
Distinction between unsub vs erasure
"Stop promotional emails" = #381 or #382. "Delete all traces of me" = #383 dsar_erasure. GDPR-CLARIFY-01 macro if formulation is ambiguous.
E-commerce portability
Typical export: Shopify customer profile, order history, addresses, marketing consents, third-party anonymized Gorgias tickets. Machine-readable CSV or JSON format.
Which gdpr_* tickets should be mapped before the process?
Twelve GDPR support ticket typologies cover 95% of DTC requests.
Twelve gdpr_ticket typologies
dsar_access_full: complete copy of personal data
dsar_erasure_account: account deletion + associated data
dsar_erasure_guest: deletion without Shopify account (email only)
dsar_rectification: correct name, address, email
dsar_portability: structured machine-readable export
dsar_restriction: freezing marketing/analytics in case of dispute
dsar_objection_marketing: objection to prospecting (similar to #381)
gdpr_confusion_unsub: confuses unsubscription and deletion
gdpr_third_party_request: spouse, lawyer, authorized representative
gdpr_still_data_post_erasure: follow-up at D+30 regarding remaining data
gdpr_chatbot_logs: chatbot conversation access/deletion
gdpr_urgent_litigation: litigation threat + pre-procedure access request
Helpdesk tags
gdpr_dsar, gdpr_erasure, gdpr_access, gdpr_portability, gdpr_rectification, gdpr_handoff_dpo, gdpr_extension_2m, gdpr_refused_derogation. High priority on gdpr_urgent and gdpr_still_data.
Inbound channels
Email privacy@ or dpo@ (dedicated channel recommended by CNIL)
Web form /privacy-request
Support chat (bot routing → future #384)
Postal mail (rare for DTC, identical SLA)
12-month ticket mining
Keyword export: RGPD, GDPR, personal data, deletion, right to be forgotten, access, CNIL, delete my data. Quantify quarterly volume to right-size DPO/privacy support resources.
First response SLA
Acknowledgment of receipt within 48 business hours with case number DSAR-XXXX and estimated timeframe. No deletion processing before identity verification DF-3.
How to apply the DSAR-FLOW framework in nine steps?
The DSAR-FLOW framework structures every GDPR support request into nine reproducible and auditable steps.
Nine DSAR-FLOW steps
DF-1 Intake: record receipt date, channel, request text, contact email
DF-2 Classify right: access, erasure, rectification, portability, other
DF-3 Verify identity: calibrated to risk, no over-collection
DF-4 Discovery: multi-system search (section 6)
DF-5 Analyze exemptions: legal retention obligations (section 7)
DF-6 Execute: export, rectification, partial/total erasure
DF-7 Document: log affected systems, date, agent, scope
DF-8 Respond to customer: confirmation + attachments or reasoned refusal within 1 month
DF-9 Close case: tag resolved, log retention 3 years for internal audit
DF-2 decision tree
Mixed formulation "delete and send copy beforehand" → process access first (DF-6 export), then erasure after customer confirmation or 7-day grace period offered.
2-month extension (Art. 12.3)
If complex discovery (10+ systems, B2B wholesale, multi-country): inform customer within 1 month with reasons and new deadline. Tag gdpr_extension_2m. Document in processing register.
Standard acknowledgment of receipt
"We have successfully received your [access/erasure] request on [date]. Reference DSAR-[ID]. Response within 30 days. If identity verification is required, here is the procedure."
Legal timestamping
The one-month period starts upon receipt, not at the end of reasonable identity verification (ECOSIRE, DSAR e-commerce). Parallelize identity verification and preliminary discovery.
DPO Escalation
dsar_erasure with dispute order, gdpr_urgent_litigation, contested exemption refusal: handoff gdpr_handoff_dpo before DF-6.
Which GDPR-* macros for support agents?
Standard GDPR-* agent macros standardize communication without legal promises outside the scope of the agent.
Ten GDPR macros
GDPR-ACK-01: acknowledgment of receipt + DSAR reference + 30-day deadline
GDPR-ID-01: proportionate identity verification request (section 5a)
GDPR-ACCESS-01: secure export delivery via link expiring in 7 days
GDPR-ERASE-01: erasure confirmation + legally retained scope
GDPR-ERASE-PARTIAL-01: reasoned partial refusal (accounting, dispute)
GDPR-CLARIFY-01: distinguish unsub (#381) vs erasure
GDPR-EXTEND-01: 2-month extension notification + reasons
GDPR-PORT-01: JSON/CSV export delivery for portability
GDPR-RECT-01: confirmation of rectification completed
GDPR-HANDOFF-01: transfer to DPO within 24 hours
Tone and L1 agent limits
L1 agents: intake, basic identity verification, discovery checklist, ACK and CLARIFY macros. No Art. 17 derogation refusals without DPO approval. No customer legal advice.
90-min agent training
Path: classify right, execute GDPR-CLARIFY, fill out discovery checklist, never delete Shopify customer without DF-5. 10-question quiz at the end of training.
Mandatory ticket documentation
Fields: dsar_id, right_type, identity_verified_date, systems_searched[], systems_modified[], derogation_applied, response_date, agent_id.
Secure export delivery
Password-encrypted ZIP sent separately by SMS or 7-day expiring link. Never attach full unencrypted data directly to an unencrypted ticket.
How to verify identity without over-collecting?
The DSAR identity verification must be proportionate to the risk. Systematic heavy over-collection = penalized practice.
Three levels of verification
Level 1 (low risk): access from account email + recent order number
Level 2 (standard): email OTP + confirmation of 2 profile fields (last name, delivery zip code)
Level 3 (high): total erasure + order history: OTP + ID document in case of reasonable doubt
The CNIL has penalized operators systematically requiring a passport scan for any DSAR, considered disproportionate (Zunapro, GDPR e-commerce France 2026).
Guest checkout case
No Shopify account: verification via email + order number + amount/date. See guest checkout support. If insufficient: Level 2 email OTP.
Third-party representative
Lawyer or spouse: written power of attorney or email from the account holder's address confirming the mandate. Otherwise, polite refusal with Art. 12 explanation.
Refusal of unproven identity
Macro GDPR-ID-01 prompts once. Without response within 14 days: suspend the file, inform the client. Do not process erasure without verification upon high-risk request.
Parallelization
While waiting for Level 3 verification, launch preliminary discovery (read-only) to meet the 1-month deadline.
Where to look for data: Shopify discovery, Klaviyo, and helpdesk?
The e-commerce DSAR discovery scans each system containing the requester's personal data.
Discovery Checklist (14 typical DTC systems)
Shopify Customer: profile, addresses, orders, metafields
Shopify Orders: lines, tokenized payment, notes
Klaviyo Profile: email, segments, events, suppress status
Alternative ESP: Shopify Email, Brevo if migrated
SMS provider: Attentive, Postscript subscriber
Helpdesk Gorgias/Zendesk: tickets, chats, attachments
Chatbot Qstomy/other: conversation logs, session ID
WhatsApp BSP: wa_id, history if WhatsApp support is used
Reviews Judge.me/Yotpo: email-linked reviews
Loyalty Smile/LoyaltyLion: points, history
Analytics GA4: User-ID if enabled (limited, often aggregated)
Payment Stripe/PayPal: PSP-side data (direct to a separate request if needed)
ERP/3PL: shipments, if personal data is replicated
Manual CSV Backups: marketing team exports (often forgotten)
Art. 15 Access Export
Compile: raw data + purposes + categories + recipients + retention periods + source. Redact third-party data (e.g., name of neighborhood parcel delivery person if visible).
Art. 17 Erasure by System
Shopify: anonymize customer or delete according to policy. Klaviyo: delete profile. Gorgias: anonymize ticket requester. Chatbot: purge session logs via vendor API.
Article 30 Register
Your processing register already lists these systems. Discovery = applying the register to an email. Update the register if a forgotten system is found.
Processors (Subprocessors)
Notify vendors if erasure is required on their end (DPA assistance clause Art. 28). Vendor delay is included in the 30-day DSAR timeline.
Notion Discovery Template
Table: system | admin contact | search method | data found Y/N | action access/erase | date | agent.
When to refuse or limit an erasure: Article 17 exemptions?
The right to erasure is not absolute. Customer Support must apply DF-5 before any Shopify delete.
Five frequent e-commerce derogations
Legal accounting obligation: invoices for 6 to 10 years depending on the country
Ongoing dispute: chargeback, contested return, open warranty
Exercise of legal right: ongoing consumer complaint
Public interest/archiving: rare for DTC, except in regulated sectors
Aggregated anonymized data: out of scope if truly anonymous
Standard partial erasure
Delete: marketing profile, chat logs, optional reviews. Retain: anonymized order (name → "Erased Customer", email hash), legal invoice. Macro GDPR-ERASE-PARTIAL-01 explains the scope to the customer.
Recent order without dispute
Profile erasure OK, minimal anonymized order retention for accounting. Document in DF-7.
Distinction between account vs data
Customer wants to "close account" without GDPR erasure: standard account process (#guest). GDPR erasure = wider scope discovery.
Reasoned refusal
Art. 12.4: inform of refusal, right to lodge a complaint with the CNIL, possibility of judicial remedy. DPO validation mandatory before sending GDPR-ERASE-PARTIAL-01.
Post-erasure still_data
gdrp_still_data_post_erasure ticket: re-discovery of forgotten system, apology + supplement within 72 hours.
Which DSAR SLAs and KPIs should be measured each quarter?
The support GDPR request KPIs prove operational discipline and prepare for a CNIL audit.
Eight key metrics
dsar_volume_quarterly: number of requests per right
dsar_median_days: days from receipt → response (target < 21)
dsar_sla_30d_rate: % of responses under 30 days (target 100%)
dsar_fcr: resolved without customer follow-up / total
dsar_partial_erasure_rate: partial erasures / total erasure
dsar_identity_reject_rate: cases suspended due to identity verification
dsar_still_data_rate: follow-ups post-erasure
gdpr_confusion_unsub_rate: rerouted to #381 (intake quality)
Recommended internal SLAs
Acknowledgment of receipt: 48 business hours (GDPR-ACK-01)
Identity verification follow-up: Day+7 if silent
Full discovery: Day+14 max
Final response: Day+28 max (margin before the legal 30 days)
DPO Handoff: within 24 hours if gdpr_urgent
Quarterly privacy + support ritual (60 min)
Review of volume, deadlines, still_data incidents, discovery checklist update, 1 test DSAR simulation. Share dashboard with management.
DTC SMB Benchmark
5 to 25 DSARs/quarter depending on size. dsar_median_days 10-15 post-process. Zero CNIL complaints related to delay if SLA is respected.
Training correlation
Spike in gdpr_confusion_unsub after hiring agents: reschedule 90 min DSAR-FLOW training.
Which edge cases and anti-patterns should be avoided?
Eight GDPR support edge cases and anti-patterns to document in the team playbook.
1. Unsubscribe vs erasure confusion
Customer says "delete my data" after email promo. GDPR-CLARIFY-01 before action. If unsubscribe is sufficient → route #381. If erasure confirmed → full DSAR-FLOW.
2. Request via public chatbot
Never execute erasure in the widget without the DF-3 process. Bot welcomes, creates DSAR ticket, directs to privacy@ email. Future #384 will automate triage.
3. Multi-accounts same person
2 emails, 1 customer: discovery on both profiles. Double merge or erasure documented.
4. Chatbot data + LLM vendor
Deletion of bot logs + deletion request at AI processor (DPA). CNIL 2025: rights on AI training data if applicable, timeframes may differ.
5. Active customer recurring subscription
Erasure = cancel subscription first. Link save subscription (#373) does not apply if GDPR request is confirmed.
6. Wholesale B2B contact
Professional + personal data: B2B contract scope may limit erasure of active reseller account.
7. Manifestly unfounded request
Art. 12.5: refusal or reasonable fee if repetitive abusive requests. DPO validates. Rare in DTC.
8. DSAR export leak
Unexpired export link sent to wrong email = breach incident. CNIL 72h incident procedure if risk.
Support Anti-patterns
Delete Shopify customer without Klaviyo/Gorgias discovery
Promising systematic 24h erasure
Passport scan for simple access
Ignoring chatbot logs in erasure
L1 agent refusing deviation without DPO
How does Qstomy receive GDPR requests without executing them on its own?
Qstomy welcomes GDPR requests via chat: structured intake, rights clarification, pre-filled DSAR ticket. It does not execute the deletion on its own (human/DPO validation required).
Qstomy GDPR intake capabilities
gdpr_detect_intent: access, erasure, rectification, portability
gdpr_clarify_unsub: distinguish #381 unsub vs Art. 17
gdpr_collect_dsar_fields: email, requested right, details
gdpr_create_ticket: DSAR-ID, gdpr_dsar tag, handoff privacy@
gdpr_ack_sla: 30-day response time message + reference file
gdpr_no_auto_delete: never delete without workflow DF-3 to DF-7
Completes bot compliance (#142) and paves the way for the future #384 GDPR bot triage advanced automation.
Quantified DTC scenario
Skincare brand, 22 GDPR requests/quarter via chat + email, 40% arrived via unstructured chat.
After Qstomy intake + DSAR-FLOW #383: gdpr_clarify_unsub 31% rerouted to #381 (time savings), dsar_ticket_complete_rate 94%, dsar_median_days 12 (vs 22), zero partial deletion audit errors.
Explore AI customer support, Shopify and request a demo.
Chat logs in discovery
DSAR erasure includes purging Qstomy sessions via API. Documented in DPA and record of processing activities.
What is the checklist for deploying DSAR-FLOW this week?
DSAR-FLOW Checklist (12 steps)
Create privacy@ or dpo@ email + /privacy-request form
Document DSAR-FLOW DF-1 to DF-9 in Notion
Draft 10 GDPR-* macros + train agents for 90 mins
Build discovery checklist 14 systems section 7
Define 3 levels of proportionate identity verification
Document Art. 17 exceptions with DPO
Template for encrypted ZIP access export + expiring link
Internal SLAs: D+2 ack, D+28 max response
Quarterly dsar KPI dashboard
Quarterly test DSAR simulation
Update privacy policy (exercise of rights section)
Align chat bot: intake only, no auto-delete
At a glance
#383 = GDPR support ops, not bot compliance (#142)
DSAR-FLOW: 9 steps intake → closure
30-day legal deadline: parallelize verification and discovery
Multi-system discovery: Shopify, Klaviyo, Gorgias, bot
Erasure ≠ unsub: systematic GDPR-CLARIFY-01
FAQ
Difference with GDPR glossary?
Glossary = legal framework. #383 = operational access, deletion, export workflow for agents.
Can support delete data on their own?
L1 executes after DF-5 if the playbook is clear. Denials of exemption and dispute cases: DPO validation.
Customer requests erasure but order is in dispute?
GDPR-ERASE-PARTIAL-01: marketing profile + logs deleted, order kept anonymized until dispute resolution.
Relationship with bot #384?
#383 = human DSAR-FLOW process. #384 = AI automated triage and escalation.
Do we need a DPO?
Mandatory if core business = large-scale processing. Otherwise, an internal privacy point of contact is often sufficient for DTC SMEs. Legal advice recommended.
Go further
Simulate an access DSAR this week on a test profile: time the 14-system discovery, identify the forgotten link before a real customer does.
Share this guide #383 with support, DPO, and management: a documented DSAR-FLOW turns a GDPR obligation into a mastered, auditable customer relationship process.

Enzo
July 1, 2026


