Delete or erase: handling a GDPR erasure request
Deleting a contact and erasing a person are different jobs. A delete removes the contact but usually leaves their messages in your history; a GDPR erasure request needs those traces removed too, while keeping a record that stops you from emailing them again. Email Digit has both actions, a public page where the people you email can make a request, and an audit trail of when our own staff looked at your data.
What an erasure request actually covers
Under the GDPR, a person can ask you to erase the personal data you hold about them, and you generally have one month to respond. In an email tool, that data lives in more places than the contact record:
- The contact itself: address, name, phone, custom fields and tags.
- Their replies, including the message bodies, which hold signatures, phone numbers and whatever else they chose to write.
- The log of emails sent to them, which records their address on every row.
- Their consent history: when they opted in or out, and how.
There is a tension built in. If you erase everything, the next import of an old spreadsheet can add them back and you email them again. Keeping the minimum needed to honour the request, such as their address on a do-not-send list, is a common way to resolve it. Whether that is right for you is a question for your own adviser; this guide describes the tools, not the law that applies to you.
Delete and erase in Email Digit
| What | Delete | Erase for GDPR |
|---|---|---|
| Who can do it | Editor or above | Owner or Admin only |
| The contact record | Removed | Emptied: address, name, phone, fields and tags cleared |
| Their replies | Stay in your history | Sender, name and subject blanked; body replaced |
| Emails sent to them | Stay in your history | Recipient address replaced |
| Consent history | Removed | Removed |
| Do-not-send list | Unchanged | Address added at the “all” level first |
| Undo | No | No |
A normal delete is often what you want: someone left the company, the record is clutter, and your campaign history should still add up. Erase is for a request. It is a separate option in the delete dialog, it is disabled for anyone below Admin, and it asks you to type ERASE before it runs.
The order matters. Before any details are cleared, the address goes on your do-not-send list at the “all” level, which blocks every kind of email. That entry is the one thing kept, and it is what stops the person being imported and mailed again. The emptied contact stays as a blank record so the history that points to it stays consistent, and it is excluded from every send. The erasure is written to your workspace audit log.
A way in for the people you email
The people on your list do not have an Email Digit account, and they still have rights. A public request page lets anyone who received your email ask for access to their data, for it to be deleted, or for messages to stop. It is linked from the page people see after they unsubscribe.
When someone submits a request with their email address:
- The owners and admins of every workspace that holds that address get an email saying what was asked and how to act on it in Contacts.
- For an opt-out or an erasure request, marketing email to that address stops straight away: it is added to the do-not-send list at the marketing level in each of those workspaces.
- The person is told their request was received and passed to the senders who hold their data. They are not told which senders, because naming them would itself disclose who holds their address.
You, as the controller of your contacts’ data, still carry out access and erasure. Email Digit forwards the request and stops the marketing; it does not answer an access request or erase anyone on your behalf. For an access request, the contact’s page shows their profile, consent and the timeline of what you sent and what they replied, which is where you gather the response.
When our staff look at your data
Support sometimes needs to see what you see. Email Digit staff cannot open the support view of your workspace on their own: a code is emailed to your owners and admins, and access starts only if one of you passes that code on. It lasts 60 minutes and is read-only. Each time the support view of your data is opened, the visit is written to your own workspace audit log, so you can see when it happened and who did it.
Operators can also run a full export or an erasure of a whole workspace. Those actions are audited too.
Limits
- Erasure cannot be undone. There is no copy to restore from inside the product.
- The immediate stop on a recipient’s request works by email address. A person who wrote in from a different address than the one you hold is not matched.
- Erase works on one contact at a time, from that contact’s page.
For how the two levels of the do-not-send list differ, read Unsubscribe or spam complaint. To see how this fits the rest of your account, start a 14-day trial.