Mohsin Anwar Sharif

From a deletion request to proof it is gone

At the bank, data-subject erasure requests reached me as tickets after department approval. As BigID administrator on the security side, my job was to make sure the data was actually removed, and to prove it.

The flow

Green steps were mine.

  1. Request logged

    Service desk

    A customer's erasure request arrives through an official channel and becomes a ticket.

  2. Department approval

    Business owner

    The owning department confirms the request and the records involved.

  3. Compliance review

    Compliance and privacy

    The request is checked before anything is deleted. Records the bank is legally required to keep are excluded.

  4. Locate the data

    BigID admin: my part

    BigID shows which data sources hold the person's data.

  5. Assign deletion

    BigID admin: my part

    Each data source owner gets a task on the ticket.

  6. Delete and prove

    Database owner

    The owner deletes or anonymises the data and attaches a screenshot as proof.

  7. Verify by rescan

    BigID admin: my part

    I rerun the BigID scan on those sources to confirm nothing remains.

  8. Close with evidence

    BigID admin: my part

    A timestamped all-clear screenshot is attached and the ticket closes.

Why the rescan matters

A screenshot from the database owner shows that someone did something. A rescan shows the data is actually gone, including copies in places nobody thought to check. Closing on the rescan, not the screenshot, is what made the evidence hold up.

For the full privacy operations model, with a record of processing and a DSAR tracker with statutory deadlines, see the privacy operations pack on GitHub.