Blog · Your Data, Your Rights · 23 September 2026 · 6 min read

A Customer Asks You to Delete Their Data. Now What?

A customer emails asking you to delete their data. Here is the four step process, the response template, and the deadline worth treating as fixed.

A guest emails your hotel two days after checkout and asks you to delete everything you have on them: booking history, phone number, the WhatsApp thread from their stay, even the call recording from when they complained about the air conditioning. Oman's Personal Data Protection Law gives them that right. It also gives your front desk a real process to follow, and a deadline you cannot treat as optional.

Verify who is actually asking

Before anyone touches a record, confirm the request really comes from the person it names. Someone could email pretending to be a former guest or patient, and correcting or deleting the wrong file is a mistake of its own. Match the request against something you already hold: the phone number on the booking, the last four digits of an invoice, the email address already on file. Don't ask for a fresh copy of an ID card just to check, that only creates a new pile of sensitive data you now have to protect.

Find every place the data lives

Once you know who is asking, the harder part starts. A hotel might hold a guest's name in the booking system, the loyalty app, the WhatsApp Business archive, the email marketing tool and a folder of recorded calls. A polyclinic might hold the same person across the appointment system, the lab portal and the billing software. If nobody has ever written down which system holds what, this single step can eat an entire afternoon, and that afternoon is exactly what five minutes of preparation can save, as you'll see later in this piece.

A customer's request to delete their data is not a favor you grant. It is a right the law already gives them.

Delete, or explain, which one and why

Not everything can go, and that's fine to say out loud. The law lets customers ask for their data to be corrected or deleted, but other rules can require you to keep certain records anyway. Tax rules ask most businesses to keep signed invoices for years. Safety and clinical rules ask health providers to keep parts of a patient file long after a visit ends. When you can't delete something, say so plainly and name the reason. Going quiet is what turns a routine request into a complaint.

  • Usually safe to delete: marketing list entries, loyalty profiles no longer active, and WhatsApp threads with no live booking attached.
  • Usually kept regardless: signed invoices, safety or incident reports, and anything tied to an open complaint or legal claim.

Write down what you did

Whatever you decide, put it in writing, even briefly: a line in a register, a shared drive, or a ticketing system, noting who asked, when, what you found, what you deleted and what you kept, and why. Starting the request as a ticket the moment it lands rather than a note on paper means the same record that tracks a complaint or a booking change can carry the deadline with it too.

The law's Executive Regulation, the detailed rulebook that explains how to apply it, sets 45 days as the standard window to respond to a request like this. Treat that as the outer limit, not the target: if the answer is simple, five days is better than 45, and the customer notices the difference.

What a five-minute plan saves you

Hamed manages the front office for a small hotel group in Muscat. When a guest asked to have her profile deleted after a September stay, his team spent close to two hours hunting across five systems before they could answer her. The fix wasn't complicated: a one-page list of every system that might hold a customer's data, kept current and checked in minutes, not hours.

StepWithout a data mapWith a five-minute data map
Verify identity10 minutes2 minutes
Search the booking system20 minutes3 minutes
Search the loyalty app or CRM20 minutes3 minutes
Search the WhatsApp Business archive25 minutes3 minutes
Search the call recording archive30 minutes4 minutes
Decide and write the response20 minutes10 minutes
Total staff timeabout 2 hours 5 minutesabout 25 minutes

At a front office supervisor's loaded cost of about OMR 3.500 an hour, that gap is roughly OMR 7.300 spent hunting through five systems against about OMR 1.500 spent looking something up you already indexed. Multiply that by however many requests a busy season brings, and the data map pays for the hour it took to build within the first two or three requests. Miss the window entirely instead, and a customer can complain to the ministry that oversees the law, which can issue a warning or a fine of up to OMR 2,000 per violation once it investigates, quite apart from what an unhappy guest tells the next ten people who ask about your hotel.

A request without a deadline attached to it just becomes next week's problem.
Zainab, call-desk coordinator, a polyclinic group in Muscat · composite voice

Five minutes of preparation turns a two-hour scramble into a 25-minute lookup.

The response you can copy

Keep a short template ready so nobody starts from a blank page under deadline pressure. Adjust the brackets, keep the order:

  1. Subject: We received your data request on [date].
  2. Thank you for reaching out. We received your request on [date] and will respond within 45 days at the latest, sooner if we can.
  3. To confirm this is really you, we matched your request against [the phone number or reference already on your account].
  4. We found your data in the following systems: [list them].
  5. Here is what we have deleted, and what we must keep and why: [name the reason, for example tax or safety record keeping rules].
  6. We have logged this request under reference [number], on [date].

What this means for you

If you run the desk that answers these emails, build the data map before the next request arrives, not while you are answering one. Write the 45 day window into whatever system already tracks your complaints or bookings, so it does not depend on one person remembering. If you are the customer sending that email, you do not need to explain why you want your data gone, and a business that stalls without a reason is the one worth pushing back on. An earlier piece on this blog covers what you are entitled to ask a business to show you about your own data.

Does a business have to delete everything a customer asks for?

No. The law allows correction and deletion, but other rules, like tax record keeping, can require you to keep certain documents anyway. Explain what you kept and why.

How fast do we have to respond?

The law's Executive Regulation sets 45 days as the standard window. Treat that as the outer limit, not the target.

What if we cannot tell the request is genuinely from that customer?

Ask for something already on file, like the phone number or booking reference tied to their account, instead of collecting a fresh ID copy just to check.

What happens if we miss the window entirely?

The customer can complain to the ministry that oversees the law, which can issue a warning or a fine of up to OMR 2,000 per violation once it investigates.

The bottom line

A deletion or correction request is routine once you have a process: verify, locate, decide and record, inside 45 days at the latest. Build the data map before the email arrives, and a scramble that used to take two hours becomes a 25-minute lookup, with a paper trail that protects your business if anyone ever asks.

Sources checked for this article

Practical information, not legal advice. Rules and dates were checked on 23 September 2026; verify current official positions before acting.

Personal Data Protection Lawdata deletion requestcustomer data rightsMTCIT compliancefront office operationscall center complianceconsumer privacy

Put an end to hold music and IVR menus

Your first 100 minutes of customer conversations are free, and your customer data stays inside Oman.

Oman Personal Data Protection Law compliant · Data never leaves the Sultanate