Customer data & GDPR
What you may store, how access and erasure requests work and when you need a processing agreement.
From inside a business, data protection looks like a collection of prohibitions. The reverse question is more useful, and it is the same in every market: what purpose are you holding this detail for, how long do you need it for that, and what happens afterwards? Anyone who can answer that per field has most of the work behind them — the rest is documentation.
The practical way in is therefore an inventory rather than a checklist. What is actually held: name and phone number, yes — but also the note about the last treatment, the photo, the allergy, the remark about an ex-partner. Health-related details, and anything someone would rather not see written down, are the sensitive category, and they arise in passing during the working day, not in the form.
Two situations turn theory into a real case. A subject access request — someone wants to know what you hold about them — can only be answered calmly if you know everywhere something sits: in the system, the calendar, the inbox, a colleague's phone. And a deletion policy is not a statement but a rule per data type, one that applies even when nobody remembers it.
As soon as a service provider processes data on your behalf — the software, the newsletter tool, the bookkeeper — an agreement comes into it. When one is needed and when it is not is a manageable question with a clear answer. The articles in this section work through the four topics one at a time; where a rule is named, it says which market it applies to.
Which customer data you may store — and which needs its own basis
Purpose, legal basis, deletion date: sort your customer file into three buckets in half an hour, and tell a health re...
A customer asks for access: what you must supply within a month
One month, extendable by two: what belongs in an access response under Article 15 GDPR, how to check identity and wha...
A deletion policy that works without a data protection officer
Data type, purpose, clock, trigger: a deletion policy without a data protection officer — and the answer for everythi...
Processing agreements: when you need one — and what it does not do
Software, newsletters, payroll: where processing hides in a small business, what Article 28 GDPR requires in the cont...