Expert knowledge for digital decisions
How to Respond to a GDPR Request from the CRM?
Short answer
What the Request Includes
According to Art. 15 GDPR:
- All stored personal data
- Purposes of processing
- Categories of data
- Recipients or categories of recipients
- Planned storage duration
- Origin of the data, if not collected from the person
- Note on correction, deletion, complaint
What is Often Forgotten
- Conversation notes – subjective assessments are also personal data
- Email threads related to the contact
- Log data such as openings of newsletters
- Data in connected systems – newsletter tools, support, telephone systems
The last point is why responding to requests without preparation is so labor-intensive.
The Deadline
Usually one month from receipt (Art. 12 para. 3 GDPR), extendable by two months for complex requests – the extension must be communicated within the first month.
What Should Help Technically
A function in the CRM that compiles all data about a person from all connected areas into one document. In custom development, this can be built in from the start; in standard software, one should inquire about this before selection.
Caution with Notes
The request also includes what is written in free text fields. This is a good opportunity to clarify within the team what is noted there – and what is not.
This text does not replace legal advice.
Key facts
- Deadline
- Usually one month (Art. 12 para. 3 GDPR)
- Also Includes
- Conversation notes and connected systems
Sources
All external claims are backed by traceable sources.- 01