An email arrives on a Tuesday afternoon. A customer wants to know what personal information your company holds about them, and they would like a copy. Maybe they also want it deleted. No lawyer’s letterhead, no threat, just a short, polite request landing in a shared inbox nobody owns. The usual reaction is a jolt of alarm followed by forwarding it to three people, none of whom respond.
We want to take the drama out of this, because handled calmly it is a routine customer service interaction with a paper trail. First, the necessary caveat: this is general information, not legal advice. Whether any privacy law applies to your business, what it requires, and what you may or may not delete are legal questions, and an attorney who knows your situation must confirm the answers. What we can offer is the operational shape of a good response.
The Request Is Not an Accusation
Start by adjusting the reflex. In our experience the overwhelming majority of these requests come from ordinary curiosity or housekeeping. Someone read an article. Someone is cleaning up after a breach at an unrelated company. Someone is moving and closing accounts. Very few come from people preparing to sue you, and treating every request as a threat produces the slow, defensive, lawyer-flavored response most likely to turn a curious customer into an annoyed one.
There is also a practical reason not to stonewall. The Office of the Texas Attorney General’s page on the Texas Data Privacy and Security Act explains that if a covered company denies a request, it must provide information on how to file a complaint with the Texas Attorney General. The path from a mishandled email to a regulator’s inbox is short and clearly signposted.
Verify Who Is Actually Asking
This is the step people skip, and the one that matters most. Think about what a data access request actually is: a stranger asking you to assemble everything you know about a specific person and send it somewhere. Do that without confirming identity and you have not complied with anything. You have run a very cooperative data breach.
The statute anticipates this. Texas House Bill 4, which created the Texas Data Privacy and Security Act, provides that a controller unable to authenticate a request may ask the consumer for additional information reasonably necessary to authenticate it. Verification is not an obstacle you invented. It is part of doing this correctly.
- Match the request to the record you already hold. If it arrives from the email address on file and matches account details you have, most of your verification is done.
- Ask for something only the real person would know. An invoice number, a service address, the date of a recent transaction. Proportionate, and easy for a genuine customer.
- Do not collect more than you need. Asking for a photo of a driver’s license to confirm an address you already have creates a new sensitive record you must now protect.
- Be suspicious of urgency and changed contact details. A request insisting on immediate delivery to a brand new address deserves a second look, the same instinct we described in our article on why phishing remains hard to block.
- Answer through a channel you trust. Reply to the address of record, or deliver through an authenticated portal. Strong authentication on your own accounts matters here too, which is the subject of our comparison of YubiKeys, passkeys, and MFA.
Where to Look, and What You Cannot Delete
If you have written out a data map, this part is a lookup. If not, this is the request that convinces you to build one, because the alternative is asking six people to search six systems from memory. Work down the list: email, file storage, accounting, the customer system, payroll if the person is a current or former employee, the industry application, and backups.
Deletion is where it gets complicated, and where we most want to hand you to an attorney. Some records you cannot delete on request because other obligations require keeping them: tax and accounting records, employment files, contractual commitments, industry requirements, and anything under a litigation hold. Privacy statutes also contain their own exemptions, and House Bill 4 lists exempt entity categories including state agencies, financial institutions covered by the Gramm-Leach-Bliley Act, entities covered by HIPAA, nonprofits, institutions of higher education, and utilities. Which exception applies to your business and to a specific record is a legal determination, not a judgment call for whoever opened the email.
The practical answer is usually partial. You delete what you can, keep what you must, and say so in writing. “We removed your marketing profile and contact record. We are required to retain the invoices from your project, and here is why” is a perfectly respectable response, and most customers accept it.
Answer in Writing, on a Clock
Two habits serve you well regardless of which law applies. Answer in writing, and answer on a schedule rather than when you get around to it.
The Texas Attorney General’s page states that covered businesses must respond without undue delay and no later than 45 days after receiving the request, with a possible 45-day extension where reasonably necessary. It also notes that covered companies must establish two or more secure and reliable methods for submitting requests, though a business operating exclusively online need only provide an email address. On appeals, House Bill 4 provides that a controller must respond not later than the 60th day after receiving one, and explain its decision in writing.
Whether or not those deadlines bind you, they are a reasonable standard to adopt voluntarily. Acknowledge within a couple of days. Give a real answer inside a month. Put it in writing so that six months later you can show what you did and when. The Attorney General’s page also states that a covered company must respond free of charge at least twice annually per consumer, a useful check on any impulse to bill for this.
Build the Process Before the First Request
Everything above is easier if it exists on paper before you need it. An afternoon covers most of it.
- Name an owner. One person receives these, tracks them, and owns the answer going out. Name a backup too.
- Create a monitored intake address. A dedicated mailbox beats a general contact form nobody checks on Fridays.
- Write the verification steps down. Decide in advance what you will ask for, so the answer does not vary by who is on duty.
- Keep the system checklist next to it. Your data map, turned into a list of places to look.
- Draft two template letters. One acknowledging receipt, one delivering the outcome. Have an attorney review them once. Reused language beats improvising.
- Log every request. Date received, who asked, how you verified, what you found, what you did, date answered. That log is your entire evidence file.
The Bottom Line
A customer asking what you hold about them is not a crisis. It is a question with an answer, and the businesses that handle it well are the ones that decided who answers and how before the question arrived. Verify the requester, look where your map tells you, delete what you can, keep what you must, explain it plainly in writing, and log the whole thing. Requirements shift, so review your process annually and confirm what currently applies.
Once more, plainly: this is general information, not legal advice, and none of it establishes an attorney-client relationship. Only a licensed attorney reviewing your business can tell you which obligations apply, what deadlines bind you, and what you must retain.
The operational side is where we come in: mapping where the data lives, setting up the intake mailbox and the log, making sure the search covers your backups, and confirming that deletion in one system does not leave copies in four others. We work with small and mid-sized businesses across Denton County and would gladly help you get this in place first. Contact us today.
Sources:
Comments are closed