Skip to content
Help
Go to Learnient(opens in a new tab)

How purging, anonymising and legal holds work

This is the full behaviour behind Archiving, anonymising and purging people. Read it before you answer an erasure request, because the three actions differ in what they leave behind and only one of them is reversible.

Learnient separates who somebody was from what they did. Closing somebody down is a choice about which of those two you are removing.

  • Archiving removes neither. It closes every route in and leaves the record intact.
  • Anonymising removes who they were and keeps what they did.
  • Purging removes both.

Everything below follows from that.

Anonymising is only offered on somebody already archived, and it runs in a fixed order: certificates are transformed into retained-set proof, free text is redacted, and the identity is replaced with a tombstone.

The order matters. Anything that has to survive is rewritten into a form that does not identify anybody before the identity is removed, so nothing depends on a record that is about to stop existing.

Free-text redaction is the part worth understanding. Structured fields are easy to clear; the risk is somebody’s name sitting in a comment or an answer. That text is redacted rather than left, which is why anonymising is not simply blanking a few columns.

Passkeys and two-factor enrolments go with the identity.

Purging removes the person and the history they own.

Records that exist because of somebody are deleted outright. Records they merely wrote have their authorship cleared, so the record survives with no author.

That distinction is the whole design. A course somebody authored is not their personal data and does not disappear with them; their own attempts, engagements, assessments, attestations and training records are, and do.

Certificates are handled first and separately. Where a certificate has to be retained, proof of it is written before the certificate itself is deleted, so the evidence that somebody qualified survives the removal of who they were. Certificates with no retention requirement are deleted with the person.

The confirmation tells you how many certificates were kept this way.

Competency sign-offs from a post-course process follow the same rule as certificates. Where certificates are retained, a pseudonymised proof of each sign-off is written first — the course, the date observed and that a qualified signatory signed it off — and the sign-off forms, evidence and signatures go with the person. A person under a legal hold cannot be purged, so their sign-off records, evidence included, stay intact however long the hold lasts.

A purge is refused until you say what happens to any reports, dashboards or schedules the person owns: transfer or delete. A transfer with no named recipient comes to the administrator running the purge.

This is easy to click past and hard to undo. A schedule that keeps sending every Monday now sends as you.

A purge of somebody with no history runs immediately. A purge of anybody else is queued and runs 72 hours after it is confirmed.

The delay exists so that a purge can be taken back. During it the person shows as having a purge scheduled, their menu offers Cancel purge, and Pending purges lists everybody waiting. Nothing else changes: they are still archived, still not signing in, still visible.

Once the window closes there is no recovery path anywhere in the product.

A hold is placed over a scope rather than a person, and while it is active it suspends policy-driven retention actions and refuses manual anonymise and purge for everybody it covers.

Two behaviours surprise people.

A hold cancels a queued purge rather than freezing it. If somebody’s purge is waiting out its 72 hours and a hold lands on them, the queue is cancelled. Releasing the hold later does not resume it, and the purge has to be started again.

A department hold pins its members at the moment it is placed. Membership is resolved once, from the organisation history, and written down. Somebody who joins that department afterwards is not covered. Somebody who leaves it stays covered until the hold is released.

So a hold is a snapshot of people, not a standing rule about a department. If the department changes and the matter still applies, the hold needs placing again.

Answer an erasure request with anonymise where the training record has to survive, which is the usual answer for compliance training somebody has completed. Use purge where the record itself must go.

Archive first either way. It is reversible, it stops access immediately, and it is the precondition for anonymising.

Before you start either, check that nothing is on hold, and check what the person owns. The two things that most often go wrong are a purge cancelled silently by a hold, and a schedule that quietly changes hands.