Home · Solutions · Legal & compliance

Solution · Legal & compliance

Every GDPR access and erasure request handled on a clock you can see

Data-subject requests answered in days, not at the deadline

Requests are logged, verified, searched across Microsoft 365 and your business systems and answered with an evidence trail; lawyers review and redact, robots do the collecting.

DepartmentalMicrosoft TeamsHuman in the loopDeterministic automation
260data-subject requests a month reach this illustrative loyalty operator. Each one starts a hand-search of mailboxes, the CRM, HR files and two legacy databases.

Executive summary

Challenge

Stop answering GDPR requests by hand on day twenty-eight of a thirty-day clock.

What changes

We build a request lifecycle in two halves that stay apart: everything mechanical is automated, every judgement stays with a named person.

Business value

Requests are answered in the first days of the clock, not the last, so the two-month extension becomes an exception.

Systems involved

CRM and loyalty platform; ERP; HR system

Business problem

Privacy operations

Individuals may ask what a company holds about them, have it corrected, and have it deleted. For a consumer business those requests are not rare: they come from customers who read a press story, from former employees, and from claimants whose lawyer writes to twelve companies at once.

Personal data is scattered by design. Each system was bought for a different purpose and keyed differently: the loyalty platform knows a card number, the CRM an email address, the call archive a phone number, the HR system an employee ID. Answering a request therefore means finding one human being in nine systems that never agreed on who that person is.

The people doing that work are expensive and scarce. A privacy specialist is paid for judgement about disclosure, exemptions and third-party data, and spends most of each request exporting and reformatting instead.

At scale the failure mode is quiet. Requests get answered, mostly on time, but the standard drifts with whoever handled them, extensions become routine, and erasure runs only where the specialist knew to look. When a supervisory authority asks which systems were searched, the answer is reconstructed from email threads.

How it works today

What follows is what we usually find before any automation, whatever the industry.

  1. PersonThe request arrives by email, web form or scanned letter, and someone decides whether it is a formal request
  2. PersonIdentity is checked by emailing the requester for a document; the reply sits unread until somebody notices
  3. WaitingThe request queues behind higher-priority work, often consuming the first two weeks of the statutory clock
  4. PersonMailboxes, SharePoint and Teams are searched by hand, or IT is asked to run the search
  5. SystemThe CRM, loyalty platform, ERP and HR system are queried one at a time and pasted into a workbook
  6. PersonThird-party names and internal commercial notes are blacked out in a PDF editor, page by page
  7. Risk of errorFor erasure the record is deleted where the specialist knows to look; the database from an acquisition is missed
  8. WaitingThe response goes out close to the deadline and the register is updated afterwards, if there is time
PersonWaitingSystemRisk of error

Why the current process costs more than it appears

The most expensive part of this process has no cost line.

  • Skilled hours go on clerical work. The part that genuinely needs a lawyer, deciding what may be disclosed and what must be withheld, is under an hour of a six-hour job.
  • Completeness cannot be proved. Asked which systems were searched for a request closed in March, most organisations answer from memory rather than from a log written at the time.
  • Erasure that misses a system creates a second incident. A record deleted in the CRM but alive in a marketing extract produces a campaign email, a furious customer and a complaint that writes itself.
  • Extensions attract attention. Each letter invoking the two-month extension states in writing that the organisation could not answer in time, and a pattern of them reads as a capacity problem.
  • Knowledge stays unwritten. Two colleagues know which table in the pre-2018 loyalty database holds transaction history, and when they are away the request waits.

Cost of inaction

Twelve months of hand-assembled response packs≈ €711,360
The same effort across a three-year retention cycle≈ €2,133,000
If loyalty growth lifts requests to 340 a month≈ €930,000

The visible process keeps working: responses go out, mostly inside the month, and the register fills up. What accumulates underneath is harder to see. A rising share of requests closed with an extension letter, a redaction standard that varies with who was on duty, and a list of systems that drifts out of date with every platform change and every acquisition.

The real exposure is not the fine, it is the inability to demonstrate. A supervisory authority asks which systems were searched, how completeness was assured and how erasure was verified. Reconstructing that from mailbox archaeology takes weeks, and it takes them while the complaint is still open.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

A retail loyalty-programme operator in Central Europe: 4 million customer records, 340 stores and an online shop, Microsoft 365 E3 with an E5 Compliance add-on, a CRM, an ERP, an HR system and two legacy databases from acquired chains.

Volume

260 data-subject requests a month; roughly 70% access, 25% erasure, the rest rectification and objection; about six hours of handling each, spread very unevenly.

Current process

Three specialists run every request by hand from a SharePoint list, with ad-hoc help from IT for mailbox searches and from HR for anything touching employees. A shared Excel file tracks deadlines.

Bottleneck

Collection and formatting, not decision-making. The review that genuinely requires legal judgement is a small share of the six hours; the rest is finding, exporting and tidying.

Solution

A Microsoft Forms intake and a Microsoft Lists register start the statutory clock; Microsoft Purview eDiscovery searches Exchange Online, SharePoint and Microsoft Teams; UiPath robots query the CRM, ERP, HR system and legacy databases; a lawyer redacts and approves the assembled pack in Microsoft Teams; deletion runs as a controlled job recording a confirmation per system.

Potential outcome

In the modelled case, specialist time per request falls to the review and redaction share, the median response moves from the fourth week to the first, and the register shows which systems were searched and when. The figures are a model, not a measurement.

Proposed solution

We build a request lifecycle in two halves that stay apart: everything mechanical is automated, every judgement stays with a named person. Requests enter through a Microsoft Forms page, the privacy mailbox or an agent acting for a caller, and each becomes an item in a Microsoft Lists register holding the receipt date, request type, search identifiers and due date. Nothing is collected until a person confirms the requester's identity.

Collection then runs as one orchestrated job. Microsoft Purview eDiscovery searches Exchange Online mailboxes, SharePoint sites and Microsoft Teams content for those identifiers. UiPath robots query what Purview cannot see: the CRM, the loyalty platform, the ERP, the HR system and the two legacy databases, through an API where one exists and through the application screen where none does. Every system returns data or a documented nil result, and both go into a draft pack on SharePoint under a coversheet naming each system, the query and the timestamp.

Review is human and deliberately so. The pack reaches a lawyer as an Action Center task inside Microsoft Teams; they redact third-party, privileged and commercial content, then approve or return it. Only after approval is the pack released through an authenticated channel. Erasure and rectification take the same route, then run as a write job that changes each system in turn and captures a confirmation. No model reads the data anywhere in the flow.

Native capabilities used

Microsoft Purview eDiscovery search and export across Exchange Online, SharePoint and Microsoft Teams; Microsoft Purview retention labels and disposition; Microsoft Forms; Microsoft Lists rules and reminders; Microsoft Teams Approvals app; UiPath Orchestrator queues, triggers, credential stores and audit; UiPath Action Center tasks inside Microsoft Teams; UiPath Integration Service connectors for Microsoft Outlook 365, Teams and OneDrive & SharePoint

What we build

The intake and identity-verification workflow, the register and its deadline model, the inventory of systems holding personal data with one query robot each, pack assembly, redaction and approval routing in Teams, the erasure job with per-system confirmations, and reporting that escalates before a deadline is at risk

Custom integration

CRM, ERP and HR queries through vendor APIs where available and UiPath UI automation where not; scoped read-only accounts against the two legacy databases; authenticated delivery of the pack

How the automated process works

  1. AutomationA submission from the form, the privacy mailbox or an agent creates a register item with receipt date, type, identifiers and due date
  2. PersonA specialist confirms the requester's identity and asks for further evidence where genuine doubt exists
  3. AutomationOrchestrator then releases the collection job and a Microsoft Purview eDiscovery search runs across Exchange Online, SharePoint and Microsoft Teams
  4. AutomationRobots query the CRM, ERP, HR system and the two legacy databases, writing each result or documented nil return to the record
  5. AutomationExtracts are deduplicated, normalised and assembled as a draft pack on SharePoint under a coversheet of every system searched
  6. PersonA lawyer opens the pack from an Action Center task in Teams, redacts third-party content, then approves or returns it
  7. AutomationThe approved pack goes out through the authenticated channel; for erasure, robots change each system in turn and capture a confirmation
  8. AutomationThe register closes the item, stores the evidence log and reports days-to-response and anything nearing its deadline in Teams
AutomationPerson

Human-in-the-loop model

Automation handles

  • Register creation, deadline calculation from receipt, reminders and escalation
  • Search and collection across Microsoft 365 and every system on the inventory, with a per-system log
  • Deduplication, normalisation and assembly of the draft pack and its coversheet
  • Execution of approved erasure and rectification, with a confirmation from each system

People decide

  • Whether the request is valid, who the requester is, and whether more identity evidence is needed
  • What is disclosed and what is redacted: third-party data, privilege, commercial confidentiality
  • Whether an exemption or retention obligation blocks erasure, and how that is explained
  • Whether to invoke the two-month extension, and the reasons put in writing

Before and after

BeforeAfter
Specialist time per requestabout six hoursreview and redaction only, modelled at one to one and a half hours
Response point in the statutory monthweek fourthe first week
Systems searchedthose the handler remembersevery system on the inventory, each logged
Evidence of the searchemail threads and screenshotsa per-request log with identifiers and timestamps
Erasure confirmed per systemrarely recordeda confirmation captured from each system

Systems and integrations

Every entry can be checked in vendor documentation. The evidence class is stated next to each one.

Inputs

  • intake form on Microsoft Forms
  • privacy shared mailbox in Exchange Online
  • scanned letters on SharePoint
  • requests raised by contact-centre agents

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath Integration Service
  • UiPath Action Center
  • Microsoft Purview eDiscovery

Target systems

  • CRM and loyalty platform
  • ERP
  • HR system
  • two legacy customer databases
  • SharePoint evidence archive

Human touchpoints: Action Center review tasks in Microsoft Teams; Microsoft Teams Approvals for erasure sign-off; the Microsoft Lists register

intake form on Microsoft FormsUiPath OrchestratorUiPath RobotsCRMAction Center review tasks in Microsoft Teams

Technologies used

Microsoft Purview eDiscovery

searches and exports one person's content from Exchange Online, SharePoint and Microsoft Teams

A
UiPath Robots + Orchestrator

queue each request, query the CRM, ERP, HR and legacy systems, retry, log and audit

A
UiPath Integration Service (Microsoft Outlook 365, Teams, OneDrive & SharePoint connectors)

reads the privacy mailbox, updates the register, files the pack

A
UiPath Action Center tasks in Microsoft Teams

legal review, redaction sign-off and exception decisions inside Teams

A
Microsoft Lists

the register: type, receipt date, due date, identifiers, systems searched, status

A
Microsoft Forms

intake from the website and from agents acting for a caller

A
Microsoft SharePoint

working area and evidence archive under restricted access and sensitivity labels

A
Microsoft Purview retention and records management

retention labels, disposition and the audit trail behind erasure evidence

A
Averified product capability (vendor documentation)

Illustrative economic model

The arithmetic is open, so it can be argued with.

Illustrative model
260 requests a month × 360 minutes of manual handling= 1,560 h / month
1,560 h × €38 fully loaded hourly cost= €59,280 / month
× 12 months≈ €711,360 / year
Annual specialist capacity tied up in request handling (illustrative)≈ €711,360

Redaction and legal judgement sit inside the six hours, not on top of them; the ranges are typical rather than a measurement at a client. Six hours is a mid-range average across simple access requests and complex ones touching mail, chat, call recordings and legacy systems; €38 is a fully loaded hourly cost for a privacy specialist in Central Europe. The model shows skilled capacity tied up, not headcount removed.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • Requests are answered in the first days of the clock, not the last, so the two-month extension becomes an exception
  • Specialist hours move from exporting and formatting to disclosure decisions and the wording of the response
  • Every request carries a written record of which systems were searched, with what identifiers and when
  • Erasure runs across every system on the inventory in one job, so deleted customers stop reappearing in campaigns
  • A volume spike after a press story is absorbed by robots running longer, not by borrowing people from legal
  • Requesters get the same response structure every time, which cuts follow-up questions and escalations

The management view

  • The register shows the whole pipeline: received, in collection, in review, days remaining, and what is at risk
  • Capacity planning becomes arithmetic rather than instinct, because volume, mix and handling time are measured
  • The accountability obligation is answered with a log instead of a memo, per request and per system
  • Departures from the privacy team stop being a compliance risk, because the queries live in the automation

Board-level KPIs

median days to responseshare closed without an extensionrequests overduesystems covered by the automated searcherasure confirmations per request

Security and governance

The automation holds exactly the rights it needs, and not one more.

  • Robots read source systems through dedicated accounts limited to lookups on the tables the inventory names
  • Write rights exist only inside the erasure job, and only for the fields it is permitted to change
  • Secrets sit in a credential store rather than in workflow code, and every query is recorded against its request number
  • Packs and evidence live in a restricted SharePoint area with sensitivity labels and a retention label that disposes on schedule
  • Segregation of duties is explicit: whoever assembles a pack cannot approve it, and erasure needs a named reviewer
  • Residency is fixed before the first search runs: Microsoft 365 content is read inside your tenant, and UiPath Automation Cloud carries the automation layer in its EU region

Why now

01

Article 12(3) of Regulation (EU) 2016/679 gives one month from receipt, extendable by two further months for complex requests and only with the reasons in writing; the deadline is the same whether the data sits in one system or nine

02

Request volumes rise with every publicised incident and every consumer-organisation campaign, and the loyalty database that makes the marketing work is exactly the asset people write in about

03

The building blocks are standard now: Purview eDiscovery searches Microsoft 365 natively, robots reach what it cannot see, and the modelled €59,280 a month of specialist time is what waiting costs

Relevant executive roles

Data Protection Officer

The statutory deadline becomes a measured number, and completeness can be demonstrated rather than asserted

General Counsel

Legal hours go to disclosure decisions, not to exporting spreadsheets from systems the team never uses

CIO

One governed, logged way to find and delete a person's data, instead of ad-hoc queries by whoever knows the old database

Customer Service Director

Unanswered requests stop arriving as complaints, and agents can see status while the caller is on the line

Common questions and objections

Would a regulator really accept a robot handling personal data?

The robot does less with the data than a person does: it runs a defined query, writes the result to a restricted location and logs both. Nothing is disclosed until a named reviewer approves it, and the log makes the handling easier to defend than a manual process nobody recorded.

We are on Microsoft 365 E3, so Purview eDiscovery is out of reach.

Search and export across Exchange Online, SharePoint and Microsoft Teams, the core of a request, is available at E3. The Premium tier adds custodian management and review sets and needs E5 or the E5 Compliance add-on, so the licence decides depth, not whether you start.

Our legacy databases have no interface and nobody wants to touch them.

That is where a robot earns its place. A read-only account running a query written and reviewed once is safer than an engineer improvising against production with two days left.

When this is not the right solution

  • A handful of requests a month, where a checklist and a calendar reminder cost far less than an automated flow
  • Nobody will own the inventory of systems holding personal data; the data map has to come first and is a separate piece of work
  • Individuals cannot be identified reliably because the customer base is anonymous, in which case most requests end in a documented refusal

A question for the next management meeting

If a supervisory authority asked us today which systems we searched for our last twenty data-subject requests and how we verified that the data was deleted, how many days would it take us to answer?

Implementation approach

Delivery runs in stages, so it can be stopped at any point.

We deliver

  • A data-map workshop that turns "where is personal data" into a named inventory of systems, owners and identifying keys
  • The intake and identity-verification flow on Microsoft Forms, the privacy mailbox and the Microsoft Lists register
  • Repeatable Microsoft Purview eDiscovery search templates for Exchange Online, SharePoint and Microsoft Teams
  • Query robots for the CRM, ERP, HR system and legacy databases, including UI automation where no interface exists
  • Pack assembly, the coversheet of systems searched, and the redaction and approval routing in Microsoft Teams
  • The erasure and rectification job with per-system confirmations and the evidence log
  • Register reporting, deadline alerts and a written runbook the privacy team owns

We need from you

  • Twelve months of request history: volumes, types, handling time and the systems searched
  • A named owner in legal or the data protection office, plus a technical owner per system
  • Read accounts for every source system and a decision on who may approve an erasure
  • Your current redaction standard and the response templates in use today

Stages

Data map

Name every system holding personal data, its keys, its owner and the query that finds one person

Design

Register model, deadline rules, identity checks, redaction standard, approvals, security

Build

eDiscovery templates, query robots, pack assembly, the Teams review step and the erasure job

Validation

Replay of closed requests through the automated flow against the manual result

Go-live

Access requests first, erasure second, with supervision on every case during hypercare

Optimisation

New systems added to the inventory, rules tuned, reporting extended

Departmental. Effort is driven by the number of systems holding personal data, whether they can be queried through an interface, and how confidently one person can be identified across them.