All articles
Case study

Our First 'Delete Everything' Request Arrived on a Friday. Here's the Pack That Kept Us From Breaking the Law

PA
PromptDock AIVerified creator — vouched by Prompt Dock
Jun 22, 2026 · 8 min read
promptdock.ai/blog

The email arrived at 3:40pm on a Friday, which is of course exactly when these things arrive: 'I am writing to request the deletion of all personal data you hold about me under Article 17 of the GDPR.' We had a privacy policy. We did not have a process. We had a long weekend ahead of us and a 30-day legal clock that had just started ticking whether or not anyone on the team knew what to do next. Spoiler: nobody knew what to do next.

My instinct — and I suspect it's a common one — was to just delete the person's records, reply 'all done,' and get on with my weekend. That instinct, it turns out, would have put us in breach of a completely different law. The only thing that stopped me was a single warning baked into the prompt I reached for in mild panic.

From zero process to a full pack in two minutes

I ran the GDPR Data Subject Request Response Pack prompt with Grok 4.3 and set the request type to Erasure. I chose Grok deliberately: it's fast and punchy, and at 3:40 on a Friday I wanted complete, sober, no-nonsense deliverables in one shot, not a leisurely five-paragraph essay about the philosophy of data rights. Two minutes later I had four concrete things — an internal action checklist, an identity-verification email, an acknowledgement to send immediately, and a draft response letter. I fired off the acknowledgement within the hour, which is exactly the GDPR best practice, and forwarded the whole pack to our data-protection consultant so she'd start Monday with a head start instead of a blank page and a panicked Slack message.

The flag that saved us from a real, reportable mistake

The draft response letter carried a warning straight out of the prompt's rules: erasure requests are subject to legal exemptions, and we might be required to retain certain financial records under applicable law. We had fourteen months of transaction history for this user. Our DPO confirmed it — under financial regulations we were obligated to keep those records for seven years, full erasure request or not. If I'd followed my Friday-afternoon instinct and deleted everything, I would have broken a retention law in order to satisfy a deletion law. Instead, the response letter explained precisely what we deleted, what we kept, and exactly why — which is what Article 17 actually requires you to do.

What we built the following week

Our DPO made one substantive edit to the response letter and approved the rest. We hit the 30-day deadline with eight full days to spare, which felt frankly luxurious given how the Friday started. But the bigger outcome was realizing we needed a documented erasure process before the next request showed up, because in this business there is always a next request. We built one the following week, and the internal action checklist from the prompt became its literal backbone — verify identity, search these specific systems, check these exemptions, document everything, log the deadline.

The identity-verification step I nearly skipped

There's one deliverable in the pack I almost ignored, and it would have been a mistake. The identity-verification email felt like bureaucratic friction in the moment — the requester had emailed from the same address that was on their account, so surely that was enough? It is not enough, and the prompt was right to insist. Acting on a deletion request without verifying identity is its own risk: if someone spoofs or guesses an email and asks you to delete a real customer's data, you've just helped an attacker erase someone's account. The verification email the prompt drafted was short, professional, and not accusatory, and the requester replied within 48 hours without complaint. Friction that prevents you from deleting the wrong person's data on a stranger's say-so is not friction. It's the job.

The lesson I'd hand anyone: the dangerous move with a data request is acting fast and certain when the right answer is 'acknowledge fast, act carefully.' The exemption warnings in this prompt are the guardrail that kept our speed from quietly turning into a violation. Grab the GDPR Data Subject Request Response Pack prompt on Prompt Dock before your first Article 17 email lands, so you're not improvising compliance at 3:40 on a Friday. And while you're tightening things up, my Privacy Policy Section Generator with Reviewer Notes prompt is what I used afterward to make sure the policy promising these rights actually matched what our systems do.

The prompt behind this post
Free
GDPR Data Subject Request Response Pack

Generate the full pack for a GDPR data subject request — internal action checklist, identity-verification email, acknowledgement, and the final response letter — with exemption warnings baked in. A compliant-style template, not legal advice.

View promptGrok 4.3
Keep reading
Our Support Bot Confidently Made Up Enterprise Pricing — One System Prompt Fixed It

The agent wasn't hallucinating wildly, it was extrapolating plausibly. That's worse. Here's the exact system prompt that taught it to know its own limits.

Elite Prompting: Why Better Prompts Beat Random AI Instructions
I Designed Branded Wrapping Paper for My Candle Business for $28, Not $400

Packaging is part of my product, but a custom print run starts around $400. Print-on-demand plus one seamless-tile prompt got me there for the price of lunch.

Related prompts
Start in two minutes

Find a verified prompt for the job.