When a Customer Asks You to Delete Their Data: How TempahKu Handles PDPA Requests

24 September 2026

When a Customer Asks You to Delete Their Data: How TempahKu Handles PDPA Requests

Salon Retno Beauty in Ampang gets a WhatsApp message from Yasmin, a regular customer: "Hi, can you delete my number from your booking system? I broke up with him and he keeps asking when I'm coming in." The owner isn't sure how — Yasmin's phone number isn't sitting in one row of one table. It's attached to a dozen old bookings, a few invoices, and staff notes about the treatments she likes.

In Klang, Auto Precision Workshop gets a different kind of request. Encik Farid just sold his car, and the new owner wants the full service history for a warranty claim. Farid has to open the booking list one entry at a time, note down the dates and work done, and retype it all into one long WhatsApp message — an hour of work for something that should be quick.

In Ipoh, Senyum Ceria Dental Clinic has a long-time patient, Puan Aishah, moving to Perth next month. She asks for a copy of her appointment history to hand to her new dentist there. The receptionist has no template to work from — she has to guess what to include, worried she'll leave something important out.

Three situations, three kinds of business, one same question: a customer asking for their own data — to see it, take it with them, or have it deleted — and the owner has no easy way to answer.

Why this keeps happening

First: one customer's data is scattered, not sitting in one row. The same phone number shows up in bookings, invoices, staff notes and customer tags. "Delete one record" means searching across several tables — easy to miss something when it's done by hand.

Second: Malaysia's Personal Data Protection Act (PDPA) gives customers this right, but few owners know there's supposed to be a formal process. Customers can ask for a copy of their data and ask for it to be deleted. But the law itself doesn't say how to confirm the person asking is actually who they say they are — and without that check, anyone could message claiming to be someone else.

Third: "delete" and "keep it for tax" pull in opposite directions. Deleting a customer record outright destroys the invoices attached to it — and tax law requires financial records to be kept for years. An owner trying to follow one rule can end up breaking another without realising it.

Fourth: handling it by hand leaves no trail. If Yasmin's request gets answered straight in WhatsApp, there's no record of when she asked, when it was confirmed, or who approved it — and that itself becomes a problem if the same question comes up again later.

What owners try instead

Most common: manual copy-paste from the booking or invoice list into Word or Excel, then sending it by email or WhatsApp — exactly what Encik Farid had to do. Fine for a one-off request, but slow, and easy to miss a row when the list is long.

Some try deleting the customer record outright from the customer list. That resolves the request, but creates a new problem — old invoices lose their reference, and records that are supposed to be kept for tax disappear along with them.

Others let written requests sit in an inbox with no formal process — no deadline to respond by, no way to verify who is actually asking, and easy to forget entirely.

The riskiest version: staying quiet and hoping the customer doesn't ask again. Not a solution, and not compliant with the right PDPA actually gives customers.

How a customer data request should work

First principle: customers download their own data, verified through their own phone. On their personal booking page, once their phone number is verified by OTP or PIN, there's a link to download their booking history as a JSON file — across every business they've ever booked with on TempahKu, not just one. The owner doesn't have to do anything; the customer does it themselves.

Second principle: a deletion request is confirmed before anything happens, never instant. When a customer asks for their data to be deleted, the system emails them a confirmation link, valid for 24 hours. Once confirmed, the request doesn't execute immediately — it goes into a review queue, and the TempahKu team approves or rejects it. Nothing is deleted before that approval.

Third principle: financial records get anonymised, not erased. Once approved, the customer's name, phone number, email and personal notes are stripped from bookings and invoices across every business involved — but the sales figures and the invoices themselves stay, with no way to trace them back to who the customer was. This is what resolves the conflict in cause three above: the business complies with both rules at once.

Fourth principle: the business gets told, but never the customer's name. Once a request is approved, the business involved is notified that a record has been anonymised — with no phone number or name in that notice itself, so the compliance process never becomes a way to leak a customer's identity.

Fifth principle: the customer can withdraw the request at any time before it's approved. If Yasmin taps the button in a moment of frustration, she can still cancel it before the TempahKu team gets to review it.

Sixth principle: owners can download their entire business's data in one action. In Settings, an owner or a manager with permission to manage settings can get a single JSON file containing the whole business's data — services, hours, bookings, customers, invoices, expenses, staff and payslips. This is the direct answer to Encik Farid's situation: not manual copying row by row, but one complete file in seconds. If the staff member downloading it doesn't have permission to see financial data or customer phone numbers, those parts stay hidden in the file too — the same permissions that apply on the dashboard apply to the export.

When it helps most

It matters most for businesses with a lot of walk-in customers, not a small handful of regulars the owner already knows by name. There, a request like "can I get my records" or "please delete me" comes from someone the owner genuinely doesn't recognise — and having a structured process matters more than trying to remember who they are.

It also helps businesses that have already had a request like this land on them and had to answer it ad hoc before. Now there's the same path every time, with a record of who asked, when it was confirmed, and when it was approved.

Honestly: if your business has only a handful of regulars and has never had a request like this, it isn't something you need to think about day to day — it's useful when the request actually arrives, not something to manage weekly. And the downloaded file is raw JSON data, not a polished report meant to be read directly — good for keeping on file or handing to whoever formally asked for it, not for a customer who just wants to glance at their booking list (a downloadable invoice PDF suits that better).

In short

A customer asking for their own data shouldn't leave an owner improvising every time it happens. TempahKu gives customers a verified way — through their own phone — to download or request deletion of their own data, a review step before anything is actually deleted so tax records stay protected, and a one-action export for owners to pull their whole business's data when they need it. If a customer has ever asked you a question like this and you had to handle it by hand, there's now a proper path for it.

Business tips, straight to your inbox

Customer stories & practical guides for Malaysian small businesses — about once a month, no spam.

Unsubscribe anytime. See our privacy policy.

14 days free

then from RM19/month

Try it now
Kembali ke laman utama