Skip to main content

Check whether a customer can be erased

GET 

/gdpr/v1/lookup

Read-only pre-flight check for a right-to-erasure request. Pass the customer's email as a query parameter and this reports whether their personal data can be erased, without changing anything. A status of eligible means the personal data can be erased — call POST /gdpr/v1/erasure to carry it out. ineligible means the records cannot be erased through this API; reason gives a machine-readable code and message a plain-language explanation you can pass on to your customer. not_found means no records match this email address under your merchant account. There are two reasons today, and they are not the same kind of answer: - customer_has_orders is final. Orders are financial records Two is required to retain under applicable accounting and tax law, an exception to the right to erasure under Article 17(3)(b). - manual_review_required is not. We hold an unusually large number of records against the address, which means it is almost certainly shared or a placeholder rather than one individual's, and erasing on it could destroy data belonging to other companies. Forward the request to [email protected] and it will be handled — do not tell your customer their request was refused. records_found counts the matching customer-user records, so you can confirm you asked about the address you meant to. No personal data is returned: you supplied the email, so there is nothing we could add that you do not already hold. Only your own customers are visible. An email belonging to another merchant's customer comes back as not_found.

Request​

Responses​

Whether the customer can be erased.