Home · Solutions · Legal & compliance
Solution · Legal & complianceEvery GDPR access and erasure request handled on a clock you can see
Data-subject requests answered in days, not at the deadline
Requests are logged, verified, searched across Microsoft 365 and your business systems and answered with an evidence trail; lawyers review and redact, robots do the collecting.
Executive summary
Stop answering GDPR requests by hand on day twenty-eight of a thirty-day clock.
We build a request lifecycle in two halves that stay apart: everything mechanical is automated, every judgement stays with a named person.
Requests are answered in the first days of the clock, not the last, so the two-month extension becomes an exception.
CRM and loyalty platform; ERP; HR system
Business problem
Privacy operations
Individuals may ask what a company holds about them, have it corrected, and have it deleted. For a consumer business those requests are not rare: they come from customers who read a press story, from former employees, and from claimants whose lawyer writes to twelve companies at once.
Personal data is scattered by design. Each system was bought for a different purpose and keyed differently: the loyalty platform knows a card number, the CRM an email address, the call archive a phone number, the HR system an employee ID. Answering a request therefore means finding one human being in nine systems that never agreed on who that person is.
The people doing that work are expensive and scarce. A privacy specialist is paid for judgement about disclosure, exemptions and third-party data, and spends most of each request exporting and reformatting instead.
At scale the failure mode is quiet. Requests get answered, mostly on time, but the standard drifts with whoever handled them, extensions become routine, and erasure runs only where the specialist knew to look. When a supervisory authority asks which systems were searched, the answer is reconstructed from email threads.
How it works today
What follows is what we usually find before any automation, whatever the industry.
- PersonThe request arrives by email, web form or scanned letter, and someone decides whether it is a formal request
- PersonIdentity is checked by emailing the requester for a document; the reply sits unread until somebody notices
- WaitingThe request queues behind higher-priority work, often consuming the first two weeks of the statutory clock
- PersonMailboxes, SharePoint and Teams are searched by hand, or IT is asked to run the search
- SystemThe CRM, loyalty platform, ERP and HR system are queried one at a time and pasted into a workbook
- PersonThird-party names and internal commercial notes are blacked out in a PDF editor, page by page
- Risk of errorFor erasure the record is deleted where the specialist knows to look; the database from an acquisition is missed
- WaitingThe response goes out close to the deadline and the register is updated afterwards, if there is time
Why the current process costs more than it appears
The most expensive part of this process has no cost line.
- Skilled hours go on clerical work. The part that genuinely needs a lawyer, deciding what may be disclosed and what must be withheld, is under an hour of a six-hour job.
- Completeness cannot be proved. Asked which systems were searched for a request closed in March, most organisations answer from memory rather than from a log written at the time.
- Erasure that misses a system creates a second incident. A record deleted in the CRM but alive in a marketing extract produces a campaign email, a furious customer and a complaint that writes itself.
- Extensions attract attention. Each letter invoking the two-month extension states in writing that the organisation could not answer in time, and a pattern of them reads as a capacity problem.
- Knowledge stays unwritten. Two colleagues know which table in the pre-2018 loyalty database holds transaction history, and when they are away the request waits.
Cost of inaction
The visible process keeps working: responses go out, mostly inside the month, and the register fills up. What accumulates underneath is harder to see. A rising share of requests closed with an extension letter, a redaction standard that varies with who was on duty, and a list of systems that drifts out of date with every platform change and every acquisition.
The real exposure is not the fine, it is the inability to demonstrate. A supervisory authority asks which systems were searched, how completeness was assured and how erasure was verified. Reconstructing that from mailbox archaeology takes weeks, and it takes them while the complaint is still open.
A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.
A retail loyalty-programme operator in Central Europe: 4 million customer records, 340 stores and an online shop, Microsoft 365 E3 with an E5 Compliance add-on, a CRM, an ERP, an HR system and two legacy databases from acquired chains.
260 data-subject requests a month; roughly 70% access, 25% erasure, the rest rectification and objection; about six hours of handling each, spread very unevenly.
Three specialists run every request by hand from a SharePoint list, with ad-hoc help from IT for mailbox searches and from HR for anything touching employees. A shared Excel file tracks deadlines.
Collection and formatting, not decision-making. The review that genuinely requires legal judgement is a small share of the six hours; the rest is finding, exporting and tidying.
A Microsoft Forms intake and a Microsoft Lists register start the statutory clock; Microsoft Purview eDiscovery searches Exchange Online, SharePoint and Microsoft Teams; UiPath robots query the CRM, ERP, HR system and legacy databases; a lawyer redacts and approves the assembled pack in Microsoft Teams; deletion runs as a controlled job recording a confirmation per system.
In the modelled case, specialist time per request falls to the review and redaction share, the median response moves from the fourth week to the first, and the register shows which systems were searched and when. The figures are a model, not a measurement.
Proposed solution
We build a request lifecycle in two halves that stay apart: everything mechanical is automated, every judgement stays with a named person. Requests enter through a Microsoft Forms page, the privacy mailbox or an agent acting for a caller, and each becomes an item in a Microsoft Lists register holding the receipt date, request type, search identifiers and due date. Nothing is collected until a person confirms the requester's identity.
Collection then runs as one orchestrated job. Microsoft Purview eDiscovery searches Exchange Online mailboxes, SharePoint sites and Microsoft Teams content for those identifiers. UiPath robots query what Purview cannot see: the CRM, the loyalty platform, the ERP, the HR system and the two legacy databases, through an API where one exists and through the application screen where none does. Every system returns data or a documented nil result, and both go into a draft pack on SharePoint under a coversheet naming each system, the query and the timestamp.
Review is human and deliberately so. The pack reaches a lawyer as an Action Center task inside Microsoft Teams; they redact third-party, privileged and commercial content, then approve or return it. Only after approval is the pack released through an authenticated channel. Erasure and rectification take the same route, then run as a write job that changes each system in turn and captures a confirmation. No model reads the data anywhere in the flow.
Microsoft Purview eDiscovery search and export across Exchange Online, SharePoint and Microsoft Teams; Microsoft Purview retention labels and disposition; Microsoft Forms; Microsoft Lists rules and reminders; Microsoft Teams Approvals app; UiPath Orchestrator queues, triggers, credential stores and audit; UiPath Action Center tasks inside Microsoft Teams; UiPath Integration Service connectors for Microsoft Outlook 365, Teams and OneDrive & SharePoint
The intake and identity-verification workflow, the register and its deadline model, the inventory of systems holding personal data with one query robot each, pack assembly, redaction and approval routing in Teams, the erasure job with per-system confirmations, and reporting that escalates before a deadline is at risk
CRM, ERP and HR queries through vendor APIs where available and UiPath UI automation where not; scoped read-only accounts against the two legacy databases; authenticated delivery of the pack
How the automated process works
- AutomationA submission from the form, the privacy mailbox or an agent creates a register item with receipt date, type, identifiers and due date
- PersonA specialist confirms the requester's identity and asks for further evidence where genuine doubt exists
- AutomationOrchestrator then releases the collection job and a Microsoft Purview eDiscovery search runs across Exchange Online, SharePoint and Microsoft Teams
- AutomationRobots query the CRM, ERP, HR system and the two legacy databases, writing each result or documented nil return to the record
- AutomationExtracts are deduplicated, normalised and assembled as a draft pack on SharePoint under a coversheet of every system searched
- PersonA lawyer opens the pack from an Action Center task in Teams, redacts third-party content, then approves or returns it
- AutomationThe approved pack goes out through the authenticated channel; for erasure, robots change each system in turn and capture a confirmation
- AutomationThe register closes the item, stores the evidence log and reports days-to-response and anything nearing its deadline in Teams
Human-in-the-loop model
Automation handles
- Register creation, deadline calculation from receipt, reminders and escalation
- Search and collection across Microsoft 365 and every system on the inventory, with a per-system log
- Deduplication, normalisation and assembly of the draft pack and its coversheet
- Execution of approved erasure and rectification, with a confirmation from each system
People decide
- Whether the request is valid, who the requester is, and whether more identity evidence is needed
- What is disclosed and what is redacted: third-party data, privilege, commercial confidentiality
- Whether an exemption or retention obligation blocks erasure, and how that is explained
- Whether to invoke the two-month extension, and the reasons put in writing
Before and after
Systems and integrations
Every entry can be checked in vendor documentation. The evidence class is stated next to each one.
Inputs
- intake form on Microsoft Forms
- privacy shared mailbox in Exchange Online
- scanned letters on SharePoint
- requests raised by contact-centre agents
Automation layer
- UiPath Orchestrator
- UiPath Robots
- UiPath Integration Service
- UiPath Action Center
- Microsoft Purview eDiscovery
Target systems
- CRM and loyalty platform
- ERP
- HR system
- two legacy customer databases
- SharePoint evidence archive
Human touchpoints: Action Center review tasks in Microsoft Teams; Microsoft Teams Approvals for erasure sign-off; the Microsoft Lists register
Technologies used
searches and exports one person's content from Exchange Online, SharePoint and Microsoft Teams
Aqueue each request, query the CRM, ERP, HR and legacy systems, retry, log and audit
Areads the privacy mailbox, updates the register, files the pack
Alegal review, redaction sign-off and exception decisions inside Teams
Athe register: type, receipt date, due date, identifiers, systems searched, status
Aintake from the website and from agents acting for a caller
Aworking area and evidence archive under restricted access and sensitivity labels
Aretention labels, disposition and the audit trail behind erasure evidence
AIllustrative economic model
The arithmetic is open, so it can be argued with.
Redaction and legal judgement sit inside the six hours, not on top of them; the ranges are typical rather than a measurement at a client. Six hours is a mid-range average across simple access requests and complex ones touching mail, chat, call recordings and legacy systems; €38 is a fully loaded hourly cost for a privacy specialist in Central Europe. The model shows skilled capacity tied up, not headcount removed.
Run the numbers on your data
An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.
Business benefits
- Requests are answered in the first days of the clock, not the last, so the two-month extension becomes an exception
- Specialist hours move from exporting and formatting to disclosure decisions and the wording of the response
- Every request carries a written record of which systems were searched, with what identifiers and when
- Erasure runs across every system on the inventory in one job, so deleted customers stop reappearing in campaigns
- A volume spike after a press story is absorbed by robots running longer, not by borrowing people from legal
- Requesters get the same response structure every time, which cuts follow-up questions and escalations
The management view
- The register shows the whole pipeline: received, in collection, in review, days remaining, and what is at risk
- Capacity planning becomes arithmetic rather than instinct, because volume, mix and handling time are measured
- The accountability obligation is answered with a log instead of a memo, per request and per system
- Departures from the privacy team stop being a compliance risk, because the queries live in the automation
Board-level KPIs
Security and governance
The automation holds exactly the rights it needs, and not one more.
- Robots read source systems through dedicated accounts limited to lookups on the tables the inventory names
- Write rights exist only inside the erasure job, and only for the fields it is permitted to change
- Secrets sit in a credential store rather than in workflow code, and every query is recorded against its request number
- Packs and evidence live in a restricted SharePoint area with sensitivity labels and a retention label that disposes on schedule
- Segregation of duties is explicit: whoever assembles a pack cannot approve it, and erasure needs a named reviewer
- Residency is fixed before the first search runs: Microsoft 365 content is read inside your tenant, and UiPath Automation Cloud carries the automation layer in its EU region
Why now
Article 12(3) of Regulation (EU) 2016/679 gives one month from receipt, extendable by two further months for complex requests and only with the reasons in writing; the deadline is the same whether the data sits in one system or nine
Request volumes rise with every publicised incident and every consumer-organisation campaign, and the loyalty database that makes the marketing work is exactly the asset people write in about
The building blocks are standard now: Purview eDiscovery searches Microsoft 365 natively, robots reach what it cannot see, and the modelled €59,280 a month of specialist time is what waiting costs
Relevant executive roles
The statutory deadline becomes a measured number, and completeness can be demonstrated rather than asserted
Legal hours go to disclosure decisions, not to exporting spreadsheets from systems the team never uses
One governed, logged way to find and delete a person's data, instead of ad-hoc queries by whoever knows the old database
Unanswered requests stop arriving as complaints, and agents can see status while the caller is on the line
Common questions and objections
The robot does less with the data than a person does: it runs a defined query, writes the result to a restricted location and logs both. Nothing is disclosed until a named reviewer approves it, and the log makes the handling easier to defend than a manual process nobody recorded.
Search and export across Exchange Online, SharePoint and Microsoft Teams, the core of a request, is available at E3. The Premium tier adds custodian management and review sets and needs E5 or the E5 Compliance add-on, so the licence decides depth, not whether you start.
That is where a robot earns its place. A read-only account running a query written and reviewed once is safer than an engineer improvising against production with two days left.
When this is not the right solution
- A handful of requests a month, where a checklist and a calendar reminder cost far less than an automated flow
- Nobody will own the inventory of systems holding personal data; the data map has to come first and is a separate piece of work
- Individuals cannot be identified reliably because the customer base is anonymous, in which case most requests end in a documented refusal
A question for the next management meeting
If a supervisory authority asked us today which systems we searched for our last twenty data-subject requests and how we verified that the data was deleted, how many days would it take us to answer?
Implementation approach
Delivery runs in stages, so it can be stopped at any point.
We deliver
- A data-map workshop that turns "where is personal data" into a named inventory of systems, owners and identifying keys
- The intake and identity-verification flow on Microsoft Forms, the privacy mailbox and the Microsoft Lists register
- Repeatable Microsoft Purview eDiscovery search templates for Exchange Online, SharePoint and Microsoft Teams
- Query robots for the CRM, ERP, HR system and legacy databases, including UI automation where no interface exists
- Pack assembly, the coversheet of systems searched, and the redaction and approval routing in Microsoft Teams
- The erasure and rectification job with per-system confirmations and the evidence log
- Register reporting, deadline alerts and a written runbook the privacy team owns
We need from you
- Twelve months of request history: volumes, types, handling time and the systems searched
- A named owner in legal or the data protection office, plus a technical owner per system
- Read accounts for every source system and a decision on who may approve an erasure
- Your current redaction standard and the response templates in use today
Stages
Data map
Name every system holding personal data, its keys, its owner and the query that finds one person
Design
Register model, deadline rules, identity checks, redaction standard, approvals, security
Build
eDiscovery templates, query robots, pack assembly, the Teams review step and the erasure job
Validation
Replay of closed requests through the automated flow against the manual result
Go-live
Access requests first, erasure second, with supervision on every case during hypercare
Optimisation
New systems added to the inventory, rules tuned, reporting extended
Departmental. Effort is driven by the number of systems holding personal data, whether they can be queried through an interface, and how confidently one person can be identified across them.
Collection and formatting are the six hours. The legal judgement is a small part.
Send us twelve months of request statistics and the list of systems holding customer and employee data. We come back with a system inventory, the automatable share of the collection work and a written assessment.
Map your personal-data systems with usThe neighbouring process usually has the same problem
Your counterparty file was true on the day you checked it. Sanctions and VAT status moved after that.
View solution Legal & complianceInformation requests answered inside the statutory clockRequests arrive on four channels, the clock starts on all of them, and the register is written afterwards.
View solution Management & planningThe document archive that files itselfYour documents sit on a network drive with no metadata, under retention rules nobody applies.
View solutionIndustries we deliver this in most oftenRetail & e‑commerceServices & ITFinance & insuranceShared services