Consent requests and data deletion

Collect withdrawal requests and review deletion across configured Snowflake tables.

Manage a deletion request from intake through verification. Requests can be entered manually or collected from a consent table. An administrator reviews the matching records and confirms each deletion.

EmbrasureGovernance DeletionExample
DELETION REQUEST

Consent withdrawn

Request 1042 · Manual confirmation required

Subject
member_1042
Warehouse
Snowflake
Status
Awaiting confirmation
Configured tableIdentifierMatching rows
clinical.recordsmember_id24
clinical.featuresmember_id8
clinical.model_inputsmember_id1

No records have been deleted. An administrator must confirm this request.

  1. 01Collect
  2. 02Preview
  3. 03Confirm
  4. 04Verify
Illustrative request with sample counts. Only explicitly configured Snowflake tables are in scope.

Before you begin

In Governance → Deletion, an administrator selects the Snowflake tables and the subject identifier column in each. The same identifier must identify the person in every selected table. Only these configured tables are included.

Request lifecycle

Collect

Enter a subject identifier or select a pending request from consent-table watching.

Preview

Review the configured tables and matching row counts. No records are deleted at this stage.

Confirm

The administrator who created the preview confirms the exact subject identifier. Embrasure rechecks the scope and counts, then deletes and verifies that no matching rows remain within the transaction.

Review the result

Inspect the request history and receipt for the outcome. Failed or uncertain requests remain visible for follow-up.

Every deletion requires confirmation. Consent-table watching creates requests for review; it never deletes data automatically.

Automatic request intake

Configure a current-consent table on the same Snowflake connection. Select the person and status columns and the withdrawal value. You can also specify a purpose filter and an expiry timestamp.

The watcher checks on a nominal hourly cadence. It deduplicates active requests and cancels pending requests when it observes renewed consent. Review scan failures in the UI; a failed scan is not evidence that no requests are outstanding.

Supported scope

This workflow deletes matching rows from the configured Snowflake base tables. It does not remove unconfigured copies, S3 objects, backups, or trained models, prevent future ingestion, or send confirmation emails.

Use data policies to record the broader requirements and track the engineering work needed around this operation. Request receipts describe the work performed within the configured scope; they do not certify compliance.