Skip to document
erudeon/ops
confidentialoperations/sops/handling-a-gdpr-request.md

SOP: Handling a GDPR request

Owner
Bence
Updated
20 August 2026
Review
quarterly
History(1)SourceLast changed 20 August 2026 by Bence

This SOP is thin on purpose. What the app does, and every field it touches, is in erudeon/passtheyear/docs/COMPLIANCE.md. This page is the human process around it: the clock, who answers, and what must not happen.

Purpose

Answer a member exercising their rights, correctly and in time.

Scope

Access, export, rectification, erasure and objection, from students and Flow members alike. erudeon is the data controller for both.

The clock

One month from receipt. It can be extended by two further months for genuinely complex requests, but the extension has to be communicated within the first month. The clock starts when the request arrives, not when somebody notices it.

RACI

Step Responsible Accountable Consulted Informed
Acknowledge Bence Bence
Verify identity Bence Bence
Execute Bence Bence
Confirm to the member Bence Bence

Steps

1. Acknowledge and start the clock

  • Who: Bence
  • When: same day where possible
  • How: reply confirming receipt and the date. Record the date somewhere durable.
  • Output: the member knows they have been heard, and the deadline is fixed

2. Verify who is asking

  • Who: Bence
  • When: before anything is exported or deleted
  • How: the request must come from, or be provable against, the account's own verified email.
  • Output: confidence you are not handing one person another person's data

This step is the one that goes wrong. An export sent to the wrong person is itself a personal data breach, and it is a worse outcome than answering late.

3. Execute

  • Who: Bence
  • When: within the month
  • How: the app's own export and erasure paths. See docs/COMPLIANCE.md for what each one covers, what is pseudonymised rather than deleted, and what is retained under a legal obligation.
  • Output: the request carried out

4. Confirm

  • Who: Bence
  • When: on completion
  • How: tell the member plainly what was done, and what was kept and why.
  • Output: a closed request

Exceptions

Situation What to do
Erasure would delete an invoice Invoices are retained seven years under Dutch law. Erase the rest, keep the accounting record, and say so
The request is vague Ask one clarifying question. The clock keeps running
Identity cannot be verified Do not act. Explain why and what would satisfy you
The request arrives via a channel nobody watches Fix the channel. A right delayed by an unread inbox is still a breach of the deadline

What must never happen

Do not record any part of the request, or the person's details, in this repository. That is the rule this whole repository is built around, and a GDPR request is exactly the place it would be tempting to break it.

  • erudeon/passtheyear/docs/COMPLIANCE.md — the PII map, retention, what erasure covers
  • ../../legal/processing-register.md — the Article 30 record