At the bank, data-subject erasure requests reached me as tickets after department approval. As BigID administrator on the security side, my job was to make sure the data was actually removed, and to prove it.
Green steps were mine.
A customer's erasure request arrives through an official channel and becomes a ticket.
The owning department confirms the request and the records involved.
The request is checked before anything is deleted. Records the bank is legally required to keep are excluded.
BigID shows which data sources hold the person's data.
Each data source owner gets a task on the ticket.
The owner deletes or anonymises the data and attaches a screenshot as proof.
I rerun the BigID scan on those sources to confirm nothing remains.
A timestamped all-clear screenshot is attached and the ticket closes.
A screenshot from the database owner shows that someone did something. A rescan shows the data is actually gone, including copies in places nobody thought to check. Closing on the rescan, not the screenshot, is what made the evidence hold up.
For the full privacy operations model, with a record of processing and a DSAR tracker with statutory deadlines, see the privacy operations pack on GitHub.