Skip to content

Glossary

Data subject request

Somebody asking to see, correct or delete what an organisation holds about them, which has to be answered within a deadline set by law.

In plain terms

Somebody writes in and asks what you hold about them, or asks you to correct or remove it. You have to answer, and there is a time limit. The difficulty is almost never willingness. It is that answering requires knowing where material about that person actually is, and in most organisations nobody has ever had to produce that list.

01

Why it matters

Because it is the moment an organisation finds out how many places its material lives, and it is a poor moment to find out. Every tool adopted without a central view adds somewhere to look, and AI tools add unusual ones: a conversation history, a search index built from documents, a transcript nobody classified. The request is the operational bill for choices made much earlier, and it arrives with a clock on it.

02

How it works

Answering is a search problem before it is anything else. The work is establishing everywhere material about one person might sit, which for most organisations spans several systems plus whatever individuals have kept locally. AI tools are frequently missing from that inventory entirely because nobody thinks of an assistant as somewhere data is held.

Conversation histories are the surprising place, and they are genuinely awkward. Somebody discussing a customer with an assistant has created a record about that person, held by a vendor, reachable by whoever holds the account. Whether it is findable at all depends on the tool, and whether anybody thinks to look depends on whether the inventory was written by somebody who had considered it.

Deletion is harder than storage in AI systems specifically. Removing a document from a source system does not necessarily remove it from a search index built earlier, from a copy pasted into a conversation, or from anywhere it was carried onward. What can actually be removed, and how completely, is worth understanding per tool rather than assuming.

The preparation that helps is unglamorous and cheap: knowing which tools hold material about people, who administers each, and what each can search and delete. That list takes an afternoon while nothing is happening, is impossible to assemble calmly under a deadline, and is the single thing that turns these requests from an emergency into a task.

Where an organisation looks, and where the material is

Where an organisation looks, and where the material isThe gap between these columns is not carelessness so much as a category error that is very easy to make. A CRM presents itself as a place data lives; an assistant presents itself as a thing you talk to, and the fact that the talking is retained is true, disclosed and entirely unmemorable. The same applies to a search index, which feels like a way of finding documents rather than a copy of them, and to a transcript, which feels like a convenience. Each was adopted for a reason unrelated to storage and each holds material about people. The repair is not a bigger process but a differently framed question, asked once a year: not which of our databases hold personal data, but which of our tools do. The second question catches everything the first one does and also catches the right-hand column.Where they lookThe CRM.The support system.Email.Also holding itAssistant conversationhistories.A search index built fromdocuments.Meeting transcripts nobodyclassified.The left column is what aninventory written five years agocontains. The right column iswhat the organisation adoptedsince, none of which anybodyadded to the list, because noneof it looks like a database.
The gap between these columns is not carelessness so much as a category error that is very easy to make. A CRM presents itself as a place data lives; an assistant presents itself as a thing you talk to, and the fact that the talking is retained is true, disclosed and entirely unmemorable. The same applies to a search index, which feels like a way of finding documents rather than a copy of them, and to a transcript, which feels like a convenience. Each was adopted for a reason unrelated to storage and each holds material about people. The repair is not a bigger process but a differently framed question, asked once a year: not which of our databases hold personal data, but which of our tools do. The second question catches everything the first one does and also catches the right-hand column.
03

Seen in the wild

  • Conversation histories in an assistant, where a colleague discussing a customer created a record about them nobody catalogued.

    ChatGPT
  • A search index built across internal systems, which may still surface material after the original document was removed.

    Glean
  • A CRM holding contact records, which is the obvious place to look and rarely the only one.

    Attio
04

Common misconceptions

People assume

We would just search our systems.

In fact

The systems are the easy half. The hard half is the material sitting in tools nobody counted as somewhere data is held: assistant histories, indexes built from documents, transcripts of meetings. Those are usually absent from an inventory because they were never thought of as storage.

People assume

Deleting from the source removes it.

In fact

Not necessarily. An index built earlier may still surface it, a copy may sit in a conversation, and material may have been carried onward. What can actually be removed and how completely differs by tool, which is why it is worth establishing before somebody asks rather than during.

05

Questions

What makes these hard to answer?
Knowing where to look. Willingness is rarely the problem and inventory almost always is, because every tool adopted separately adds a place, and AI tools add ones nobody classified as storage. The clock runs while that list is being assembled for the first time.
Do assistant conversations count?
A colleague discussing a person with an assistant has created a record about them held by a vendor, so it is at least a place worth being able to search. Whether and how it can be searched varies by tool and by plan, which is a question worth answering while nothing is urgent.
What preparation actually helps?
One list: which tools hold material about people, who administers each, and what each can search and delete. It takes an afternoon in calm conditions, cannot be produced calmly under a deadline, and is what turns these from an emergency into a task somebody works through.
06

Key takeaways

  • It is a search problem before it is anything else.
  • Assistant histories and search indexes are the places nobody inventoried.
  • Deleting from the source does not necessarily remove it everywhere.
  • One list of where material lives, made calmly, is the whole of the preparation.
08

Tools that use this

  • ChatGPT

    Histories holding records about people nobody catalogued.

  • Glean

    An index that may outlive the document it was built from.

  • Attio

    The obvious place to look, and rarely the only one.

Last checked July 2026

All glossary terms