Anonymising Users (GDPR Compliance)

Anonymising Users (GDPR Compliance)

Overview

Anonymising a user permanently removes their personal identifiable information from Learn Amp while preserving their activity data for reporting purposes. This feature supports GDPR compliance and "right to be forgotten" requests.

Anonymisation is a one-way process that cannot be undone. Once anonymised, a user's name, email, and other personal details are replaced with anonymous identifiers.

💡 A note on naming: in company settings this feature is labelled pseudonymisation rather than anonymisation. They refer to the same thing in Learn Amp, so if you are looking for the setting, look for Data protection and Automatic pseudonymisation.


Pre-requisites

Role Requirements

Role

Capabilities

Role

Capabilities

Admin

Can anonymise deactivated users within their company

Owner

Full access to anonymise any deactivated user, and the only role that can change the automatic setting

Requirements

  • The user must be deactivated before they can be anonymised

  • Anonymisation cannot be reversed – ensure this is the correct action before proceeding


Quick Start Guide

  1. From the sidebar, click People

  2. Select Individuals

  3. Click the Status filter and select Deactivated

  4. Find the user you want to anonymise

  5. Click the three dots (⋮) next to their name

  6. Select Anonymise user

  7. Confirm when prompted

⚠️ Warning: This action cannot be undone. The user's personal information will be permanently removed.


What Happens When You Anonymise

Removed Permanently

  • Name – Replaced with "Anonymous User [ID]"

  • Email address – Replaced with an anonymised email

  • Job title – Removed

  • Bio – Removed

  • Profile picture – Removed

  • Any personal identifiers – Removed from all records

Preserved (Anonymised)

  • Activity completion records (shown as "Anonymous User")

  • Quiz and assessment attempts

  • Survey responses (already anonymous, remain unchanged)

  • Content they created (creator shown as "Anonymous User")

  • Historical reports and analytics data


Anonymisation vs Deactivation vs Deletion

Action

Personal Data

Activity Data

Reversible

Use Case

Action

Personal Data

Activity Data

Reversible

Use Case

Deactivate

Preserved

Preserved

Yes

Temporary departure, may return

Anonymise

Removed

Preserved (anonymised)

No

GDPR request, permanent departure

Delete

Removed

Removed

No

Complete removal from system


Automatic Anonymisation

Learn Amp can automatically anonymise users after they have been deactivated for a set period. This helps maintain GDPR compliance without manual intervention.

This is a self-serve setting — you do not need to contact us to switch it on. On screen it is called Automatic pseudonymisation.

Only the Owner can change it. Anyone else with access to company settings will see it as read-only, with a note naming the Owner.

To set it up:

  1. Go to Settings → Company settings → People → Data protection

  2. Under Automatically pseudonymise deactivated users, choose Never, or a period from 1 year up to 7 years after deactivation

  3. Save

When you select a period, the page tells you how many users are already eligible. If no such warning appears, no users currently meet the criteria.

⚠️ Eligible users are not processed the moment you save. They are picked up by a scheduled process, so allow time before checking whether a particular user has been anonymised.

⚠️ Users who have already been anonymised are skipped permanently. Once a record has been anonymised it is never processed again, so changing this setting later will not re-run it against them.

💡 Tip: Common settings are 2-3 years after deactivation, but this should align with your organisation's data retention policy.


GDPR Considerations

Right to Be Forgotten

When a former employee or learner requests their data be removed under GDPR Article 17, anonymisation fulfils this requirement while preserving aggregate reporting data.

Data Subject Access Requests

Before anonymising, consider whether you need to provide the user with a copy of their data. Once anonymised, you won't be able to identify their specific records.

Audit Trail

The anonymisation action is logged in the system, recording:

  • When the anonymisation occurred

  • Who performed the action

  • The original user ID (for audit purposes only)

This means you can confirm from the audit trail whether a specific user has already been anonymised, and when.


FAQs

Q: Can I anonymise an active user?
No, users must be deactivated before they can be anonymised. This is a safety measure to prevent accidental data loss.

Q: Will anonymised users still appear in historical reports?
Yes, their activity data is preserved but shown as "Anonymous User [ID]" rather than their name.

Q: Can I recover an anonymised user's data?
No, anonymisation is permanent and cannot be reversed. Always ensure this is the correct action before proceeding.

Q: Does anonymisation affect content the user created?
Content they created remains in the system, but the creator is shown as "Anonymous User" instead of their name.

Q: Who can turn on automatic anonymisation?
Only the Owner. It is a self-serve setting under Settings → Company settings → People → Data protection, and other roles see it as read-only.

Q: I enabled the setting but a user has not been anonymised yet. Why?
Eligible users are processed on a schedule rather than the instant you save, so allow some time. If the user was anonymised previously, they are skipped permanently and will not be processed again.

Q: How do I handle a GDPR deletion request?
For GDPR "right to be forgotten" requests, anonymisation is usually sufficient. If complete deletion is required, contact Learn Amp support.

Q: Can I anonymise users in bulk?
Currently, manual anonymisation must be done individually. For large-scale needs, use the automatic anonymisation setting described above.


Troubleshooting

Issue

Solution

Issue

Solution

"Anonymise" option not available

Ensure the user is deactivated first. You cannot anonymise active or pending users.

Cannot edit the automatic setting

Only the Owner can change it. Other roles see a read-only notice naming the Owner.

User still showing in searches after anonymisation

Allow a few minutes for the search index to update. The user should appear as "Anonymous User [ID]".

Need to recover anonymised data

Unfortunately, anonymisation cannot be reversed. Consider this carefully before proceeding.

Automatic anonymisation has not run for a user

Check the period set under Settings → Company settings → People → Data protection, and confirm the user has been deactivated for longer than that period. Eligible users are processed on a schedule rather than immediately. A user who was anonymised previously is skipped permanently.

No warning appears when I select a period

That means no users currently meet the criteria for that period.

Unsure if anonymisation is appropriate

For GDPR requests, anonymisation is usually sufficient. Consult with your legal or compliance team if uncertain.


Last Reviewed: September 2026