You send a cold email campaign. Six months later, someone from that list emails you back asking to be removed. Simple enough - you delete them from your system. But then you get a formal GDPR request demanding you prove you've deleted all their data, including email addresses, click tracking, open tracking, and bounce records. You realize you have no idea where all their information actually lives.
The GDPR Right to Be Forgotten (Article 17) is one of those regulations that sounds straightforward until you actually have to implement it across a cold email operation. And if you're running campaigns at any scale - even 2-3 campaigns a month - you need a system for this. Not because it's complicated legally, but because it gets messy operationally fast.
Here's what actually matters, and what you should build.
What the Right to Be Forgotten Actually Means for Cold Email
The Right to Be Forgotten means when someone asks you to delete their data, you have to delete it - completely. Not anonymize it, not archive it. Delete it. This includes:
- Their email address from your contact lists
- Their name and any identifying information you captured
- Engagement data (opens, clicks, bounces) connected to their account
- Any records in your CRM or email platform that link back to them
- Backup files or historical records that contain their information
The legal threshold is straightforward: you have 30 days to respond, and you should delete everything. The operational problem is that your contact data touches multiple systems - your email platform (lemlist, Instantly, etc.), your CRM, your backup storage, your lead list tool. If you're not tracking where someone's information actually lives, you'll miss something and create a compliance liability.
One clarification: the Right to Be Forgotten doesn't apply the same way to everyone in your database. You can legally keep sending cold emails to people if you have a lawful basis (like legitimate interest in B2B). But once someone explicitly asks to be removed, you have to honor that request and delete everything.
The Practical System: Where Data Lives and How to Remove It
Build a removal request log. This is a simple spreadsheet or database record that captures three things: the person's email, the date of the request, and the systems where you need to remove them. Here's what that looks like:
- Email address: [email protected]
- Request date: 2024-11-15
- Systems to clean: lemlist, HubSpot, backup storage, analytics dashboard
Then create a removal checklist. For every system you use, document the actual steps to delete someone's data completely. Here's what that includes for a typical cold email operation:
Email Platform (lemlist, Instantly, etc.)
Remove the contact from every active and paused campaign. Search their email address across all campaigns - don't just assume they're only in one. If your platform has a global unsubscribe feature, use it. Then verify the deletion in the campaign reports (their opens/clicks should disappear or show as [deleted]).
CRM (HubSpot, Pipedrive, etc.)
Delete their contact record entirely. This removes their email, any notes your team added, any deal records associated with them. If your CRM has an