Consent that is actually recorded,
deletion that actually happens
A privacy policy that promises deletion on request is only honest if deletion actually happens, end to end, across every table and backup that holds the data. We build consent tracking per purpose, a working export and deletion flow, and retention rules enforced automatically, so a data request is a feature, not a scramble through the database.
What it is
GDPR consent and data lifecycle management covers three connected pieces: recording what a person actually agreed to, by purpose, not one blanket checkbox; honoring a request to see, export or delete their data, across every system that holds it, not just the obvious one; and enforcing retention rules so data does not sit indefinitely past the point you said you would keep it. Each piece sounds simple in a policy document and is genuinely hard to get right across a real system with a database, a CRM, email tools and backups all holding pieces of the same person’s data.
When you need it (and when you do not)
You need this if you process personal data of people in the EU or UK, which in practice covers most products with any European users or clients, regardless of where your business is based. It matters most once you have enough data spread across enough systems (a CRM, a marketing tool, a product database) that a request to delete someone’s data cannot be handled by one person manually checking a few tables.
You do not need a heavy system if you are very early and hold minimal personal data in one place; a documented manual process can cover a handful of requests a year. It becomes worth automating once request volume, system count, or your own risk tolerance makes a manual process unreliable.
How we build it
We start with a data map: where personal data actually lives across your systems, your product database, your CRM, your email tool, any analytics platform, because a request-handling flow is only as good as its knowledge of where to look. Consent is recorded per purpose (marketing emails, analytics, a specific processing activity), timestamped, and stored so withdrawal of one purpose does not accidentally revoke another. An export flow pulls a person’s data into a readable format on request, and a deletion flow removes or anonymizes it across every system the data map identified, logged so you have evidence the request was actually fulfilled, not just acknowledged.
Retention rules run as a scheduled job rather than a calendar reminder: data past its agreed retention window is flagged for review or removed automatically, depending on what you decide is appropriate for that data type. Where full deletion is not realistic, certain records with a legal retention requirement, for instance, we build anonymization instead and document why deletion does not apply.
What to watch
The hardest part of this work is usually not code, it is finding every place personal data actually ends up, including places nobody remembers adding, a spreadsheet export, a third-party tool’s own copy. We treat the data map as a living document that needs revisiting as you add new tools, not a one-time exercise. Legal questions, lawful basis for processing, cross-border transfer rules, are real and are outside what a development engagement covers; we flag where you need a lawyer rather than guessing at legal interpretation ourselves.
Price and timeline
| Option | Price | What it covers | Timeline |
|---|---|---|---|
| MVP | from $1,000 | Data map, per-purpose consent recording, manual-trigger export and deletion | 1 to 3 weeks |
| Production | from $2,800 | Automated retention enforcement, multi-system deletion, consent withdrawal flow | 3 to 5 weeks |
Related
This pairs with audit log and compliance trail for the record of how requests were handled, and with age verification and KYC flows where identity and consent intersect. It sits inside development and setup-integrations. The lead-data handling here matches the Bali real estate CRM and the candidate-data flow in the staffing agency recruitment bot.
Ready to find out where your personal data actually lives? Get in touch and we will map it with you.
FAQ
How much does GDPR consent and lifecycle work cost?
From $1,000 to map your data, build consent recording and a working export/deletion flow for one system; multiple systems or complex retention rules add time.
How long does it take?
1 to 3 weeks, most of which is mapping where personal data actually lives before building the request-handling flow.
Does this make us fully GDPR compliant?
It covers the technical core, consent, access, deletion, retention, but full compliance also involves legal review of your policies and lawful basis for processing, which is outside development work and worth a lawyer's review.
What happens to data in backups when someone requests deletion?
We document a realistic policy: backups typically age out and are not retroactively edited, which is standard practice, but the live system and any reasonably reachable backup are handled according to the retention window we agree with you.
Can consent be withdrawn after the fact?
Yes, withdrawal is built as a real action that stops the specific processing it covered, not just a flag that gets ignored by the rest of the system.