Data security
How do you handle customer data deletion requests?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
Delete customer data within a committed timeframe upon request, covering primary stores, backups (as they age out), and derived data. Provide confirmation of deletion and document the process in your data-processing agreement.What the security reviewer is checking
Deletion answers fail on the details, and reviewers know exactly which ones to probe: whether deletion covers all data locations (production, backups, logs, caches, analytics derivatives, and vector or search indexes), the timeline for each, how deletion propagates to subprocessors, and what written confirmation the customer receives. The backup question is the classic trap — honest answers explain that data is removed from production immediately and ages out of encrypted backups on a defined retention cycle, rather than claiming instant universal erasure. Reviewers also verify alignment with GDPR and CCPA timelines and check that the process works at both granularities: individual data-subject requests and full account offboarding.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.Deletion requests are handled through a documented process at two granularities. For individual data-subject requests under GDPR or CCPA, customer administrators can delete specific records directly in the product, or submit a request to our support team, which we fulfill within 30 days with written confirmation. For account termination, we delete all customer data from production systems within 30 days of the effective date, covering databases, object storage, search and vector indexes, and caches; a deletion certificate is issued on completion. Data in encrypted backups is not selectively editable and instead expires through the backup retention cycle, with all backups containing the data aged out within 35 days of the production deletion — after which no copy exists in any system we control. Deletion instructions are propagated to subprocessors under our data processing agreements, which bind them to equivalent timelines. Operational logs referencing customer identifiers expire under their own retention schedule, and the entire workflow is tracked in our compliance system for auditability.
Evidence reviewers expect you to attach
- Data retention and deletion policy with per-store timelines
- Sample deletion certificate or confirmation template
- DPA clauses covering deletion and subprocessor obligations
- Backup retention configuration evidence supporting the expiry window
Follow-up questions reviewers ask next
- How long until data is gone from backups, not just production?
- Does deletion cover derived data — search indexes, embeddings, and analytics?
- How is deletion propagated to and confirmed by your subprocessors?
- Can we get a deletion certificate for our auditors?
- Can we export all our data before initiating deletion?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated data security questions
Do you encrypt data at rest and in transit?Do you maintain an inventory of all customer data?What is your data backup and recovery process?How do you secure data in development environments?Do you have a privacy policy that covers customer data usage?Where is customer data stored geographically?
Browse the full security questionnaire question library