Question Clearly sourced

Expert knowledge for digital decisions

How to Respond to a GDPR Request from the CRM?

Short answer

Completely and usually within one month. A request means: all stored data about this person, purpose, origin, recipients, and planned storage duration. This also includes conversation notes and email threads – not just the master data. Those who compile this manually rarely meet the deadline.

What the Request Includes

According to Art. 15 GDPR:

  • All stored personal data
  • Purposes of processing
  • Categories of data
  • Recipients or categories of recipients
  • Planned storage duration
  • Origin of the data, if not collected from the person
  • Note on correction, deletion, complaint

What is Often Forgotten

  • Conversation notes – subjective assessments are also personal data
  • Email threads related to the contact
  • Log data such as openings of newsletters
  • Data in connected systems – newsletter tools, support, telephone systems

The last point is why responding to requests without preparation is so labor-intensive.

The Deadline

Usually one month from receipt (Art. 12 para. 3 GDPR), extendable by two months for complex requests – the extension must be communicated within the first month.

What Should Help Technically

A function in the CRM that compiles all data about a person from all connected areas into one document. In custom development, this can be built in from the start; in standard software, one should inquire about this before selection.

Caution with Notes

The request also includes what is written in free text fields. This is a good opportunity to clarify within the team what is noted there – and what is not.

This text does not replace legal advice.

Key facts

Deadline
Usually one month (Art. 12 para. 3 GDPR)
Also Includes
Conversation notes and connected systems

Sources

All external claims are backed by traceable sources.
  1. 01

Ready for your next project?

Free initial consultation - no sales pressure, just clear answers.

Request consultation