Skip to content
← All work

Privacy · Compliance · Operations

Building our GDPR management system

Worked with the team to build our GDPR management system: prioritised responses to data requests, and an account deletion flow that reaches every system holding user data, from our own database to MoEngage and partners.

Context

A large, global user base meant personal data lived in many places: our own database, MoEngage for email and push, and partner systems.

The challenge

Every data request needed the right response at the right time, and "delete my account" had to mean deleted everywhere, not just in the app.

What I did

I worked with the team to design how data requests are logged, triaged and prioritised, so each type of request gets the correct response, in the right order.

The biggest piece was account deletion. We built a flow that runs across our own database, MoEngage and partner systems, so a deletion request reaches everywhere a user's data is held.

What we built

  • 01

    Request management

    One place to log and track every data request from users, from first contact through to resolution.

  • 02

    Prioritised responses

    Requests triaged by type and urgency, so each one gets the right response, in the right order, within its deadline.

  • 03

    Deletion across every system

    An account deletion flow that removes a user's data from our own database, MoEngage and partner systems, not just the app.

Results

We now have one consistent process for handling GDPR requests, and account deletions that reach every system holding a user's data, including MoEngage and our partners.

Trust isn't only earned in campaigns. Respecting someone's data, right down to deleting it properly, is part of the relationship.
  • GDPR
  • Privacy
  • Operations
  • Cross-team