Playbook, online course
Delete everything, except the thing that proves I did it
This request arrives with a condition attached that the person has not noticed is a condition. They want their account gone and their certificate to still mean something, and a certificate only means something while the issuer can confirm it was issued. That tension has to be published rather than explained one message at a time.
Why this is not the general answer
The handling pattern for data deletion requests holds across every trade. What follows is the part that does not.
- The certificate is the whole difficulty. A credential is worth what the issuer can still confirm, so a register of who completed what usually has to survive a deletion, and a learner deserves to know that before they ask for erasure rather than after.
- Deleting the account ends lifetime access permanently and there is no route back into the same enrolment, which makes this the one deletion request that destroys something the person actually paid for.
- A course community holds posts written under somebody's name and answered by other learners, so removing an author leaves conversations that no longer make sense, and your position on those threads is separate from your position on the account.
- Where an employer bought the place, the completion record is something the employer expects to keep for its own training file while the learner treats it as personal, and both of those expectations have to be written down rather than settled per request.
How it arrives
- delete my account but let me keep my certificate
- how long do you keep my results after i finish
- can you take my posts out of the course forum
- my employer paid can they see how far i got
- if i delete my account do i lose lifetime access
- who checks my certificate is real if i delete everything
What has to be indexed for this to work
| What survives a deletion, and why each item does | The certificate register, anything needed for tax or accounting on the sale, and whatever a payment record obliges you to keep. Give the reason next to each one, because a list of exceptions with no reasons reads as a provider keeping whatever it likes. |
|---|---|
| The retention period for progress and assessment results | How long results are held after completion, and what event the period runs from. A learner asking this is usually deciding whether to keep the account open, and a period with no starting event answers nothing. |
| Your position on community posts, written separately | Whether posts are removed, anonymised or left in place, and what happens to replies underneath them. Treating this as part of the account answer produces a wrong answer either way, and forum threads are the part other learners notice. |
| What an employer who bought the place is told | Whether completion, progress or results are shared back, and what learners are told about that when they enrol. If those two documents disagree, this request is where the disagreement surfaces, in writing, from somebody who is unhappy. |
The reply
Two parts to this. Deleting the account closes access to the course permanently, and because access was sold as lifetime there is no way back into the same enrolment afterwards, which is worth being certain about [1]. A record that a certificate was issued is normally kept even after a deletion, because a certificate nobody can confirm is not worth holding, and our privacy notice sets out exactly what stays and why [2]. Community posts are handled separately and that position is on the same page. I cannot delete anything, confirm what is held about you or check a record. Leave your name, an email and what you are asking for, and it reaches the person who handles these.
The warning about lifetime access comes first because it is the irreversible part and the person may not have thought about it. The certificate answer gives the reason rather than the rule, since the reason is the thing that makes it acceptable. And it separates the community from the account, which is the split most of these requests actually contain.
Where it stops
The trigger. Any request phrased as deletion, erasure, or a copy of what is held, and any question about what an employer has been told about a learner.
This is a request rather than a question and it needs the person who handles them. Leave your name, the email you enrolled with and what you are asking to have removed, and you will get a reply within the period in our privacy notice.
It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.
Never say this here
Out of bounds
- Never confirm that anything has been deleted, anonymised or scheduled for removal, because nothing here changes a record.
- Never state a retention period that is not in your own published notice, particularly for certificates and assessment results.
- Never confirm whether a named person enrolled, completed or was issued anything.
- Never tell a learner that deleting their account will keep their certificate valid, unless your own notice says exactly that.
Questions
- Should the certificate exception really be on the sales page?
- Near it. A learner who finds out at the point of asking treats it as a provider keeping data it was asked to remove. A learner who read it at enrolment treats it as the reason the certificate is worth having, which is the same fact received completely differently.
- Can it remove somebody from the mailing list at least?
- No. It changes nothing anywhere, including preferences, so even the smallest request here ends as a message to your inbox. The details are stored as well as emailed, which matters most for the requests that carry a statutory clock.
- Employers ask us for their staff's results. Is that a deletion question?
- It becomes one. The learner who finds out afterwards asks for their record to be removed, and by then you are arguing about something that should have been a sentence at enrolment. Publish what a sponsor is told, and say it where the learner sees it.
Keep reading
- Everything for a online courseWhat is included, how long access lasts, refund and cooling off rights, and the honest limit that it cannot see a learner's own progress.
- Handling data deletion requests in generalA deletion request is a request with a clock on it, not a question. The characteristic failure is silence, so it always has to reach a person.
- The request is nearly always captions, and the answer is per moduleMost accessibility requests here are about captions on older modules. What to publish about what is captioned and what is machine generated.
- Paid on a Sunday night, and now whatWhere to start, how much of a week it needs, and getting live session times into a calendar in the right time zone.
- Asked before buying, and a wrong answer becomes a refundA tablet at home, a locked down work laptop, a phone on a commute. What to publish before purchase rather than after the refund window.
Try it on your own material
Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.