Data Protection
Retention periods, anonymise (right to be forgotten), export user data, and privacy policy
Overview
The Data Protection tab provides GDPR-oriented tools for monitoring data retention, responding to subject access requests, and processing anonymisation (right to be forgotten) for eligible users. It is intended for authorised administrators who handle privacy operations — not everyday training administration.
Who can access this tab?
Data Protection settings require the canManageSystemSettings permission. Actions taken here are logged for audit purposes.
Warning
Compliance Status
The Compliance Status panel shows indicator lights for key controls:
- GDPR Compliant
- Data Retention Enforced
- Encryption Enabled
- Audit Logging Active
These indicators reflect platform configuration and operational status. They help you confirm controls are in place before an audit — they do not replace your organisation's own compliance assessment.
Data Retention Statistics
The dashboard shows counts for users (total, active, archived, anonymized) and data records such as audit logs and sessions, including how many records have passed their retention period.
| Retention period | Typical scope |
|---|---|
| User Data | Inactive user records eligible for cleanup |
| Audit Logs | System audit trail entries |
| Progress Data | Course completion and progress records |
| Session Data | Calendar session and attendance records |
| Notifications | Notification history |
| Temp Passwords | Temporary credential data |
Retention periods are shown in days on the Retention Periods (Days) panel. These are platform-defined defaults — contact TrainMeUK support if you need to discuss custom retention requirements for your contract.
Quick Actions
Three buttons in Quick Actions trigger operational retention processes:
| Action | Purpose |
|---|---|
| Enforce Retention Policies | Processes records that have exceeded their configured retention period |
| Clean Up Expired Data | Removes expired records identified by the retention system |
| Generate Compliance Report | Downloads an Excel GDPR compliance report for your records |
What these actions do not do
Retention enforcement and cleanup remove or anonymise data according to configured retention rules within the TrainMeUK platform. They do not guarantee immediate erasure from all backup systems, offline exports, or third-party integrations your organisation may operate separately. Allow reasonable time for scheduled backup rotation and document your internal process accordingly.
Anonymize User (Right to be Forgotten)
Use this workflow when you have a valid request to anonymise an inactive user's personal data. The system validates eligibility before allowing anonymisation.
Search for an inactive user
In Anonymize User (Right to be Forgotten), search by name or email. Only inactive or archived users appear — active users cannot be anonymised through this flow.
Review eligibility
Select the user and wait for validation. The page shows whether the user can be anonymized or explains why not (for example, active assignments or open compliance records).
Provide a reason and confirm
Enter a Reason for Anonymization (required for audit). Click Anonymize User when validation passes.
Warning
Export User Data
Use Export User Data to respond to subject access requests. You can search any user (not limited to inactive accounts) and download their data.
Search and select a user
Type a name or email in Search Users. Click the matching result to select them.
Choose format
Select JSON Format or CSV Format from the dropdown.
Export User Data
Click Export User Data. A file downloads to your browser. Export activity is recorded in Recent Activity on the dashboard.
Tip
Privacy Policy
The Privacy Policy panel shows the current policy version and last updated date. Click View Privacy Policy to open the published policy document.
Share this link with learners and staff when they ask where to read TrainMeUK's privacy information for your tenant.
Troubleshooting
User cannot be anonymized
Read the validation message — common reasons include the user still being active or having open records. Archive the user first if appropriate, then retry validation.
Export failed or is empty
Confirm you selected the correct user. If the problem persists, note the user ID and contact support with the approximate time of the attempt.
Retention counts still show expired records
Run Enforce Retention Policies or Clean Up Expired Data, then refresh the page. Large tenants may take a moment to process.
Related Guides
- Learner Verify — identity evidence retention and review
- Password Policy & MFA — security controls alongside data protection
- Exporting Reports — training data exports for operational reporting