1. Assign an authorized cycle owner
Define who retrieves portal-controlled information, who prepares matches, who executes deletions and who closes exceptions.
2. Freeze the internal record population
Record the systems and snapshot date used for the cycle. Do not mix later records into an untracked population.
3. Use the minimum matching data
Apply the approved hashed, tokenized or otherwise minimized identifiers needed for the workflow. Avoid broad exports by default.
4. Separate match confidence from action
A possible match is not automatically a deletion instruction. Define deterministic, review and inconclusive outcomes.
5. Route system actions
Send supported deletion or suppression instructions to the relevant system owners and track completion.
6. Control exceptions
Record records that cannot be matched, deleted, verified or completed by the internal deadline, including the assigned owner.
7. Close with evidence
Retain cycle dates, population counts, mapping version, worklists, completion acknowledgments, unresolved items and management sign-off.
Release test
Before the artifact is released, ask four questions: Can every material value be traced to a source? Are unresolved facts still visible? Was the exact release candidate rechecked? Does the final claim stay inside the evidence?
Questions teams ask
The safer boundary is usually customer-controlled portal access and a separate controlled processing workflow.
No. It can reduce exposure, but design, access, retention and linkage risks still require control.
A stable responsibility matrix, data-minimized input contract, exception taxonomy and evidence packet.