Use this article when you need to remove a person's identifiable data from Administrate, for example to satisfy a data-protection ("right to be forgotten") request.
Before you start
Establish the scope of the request first:
- Who is the subject? Anonymization operates on a Contact. When the Contact belongs to an individual Account (a person acting as their own account), that Account's identifying details are anonymized with it. Organization Accounts are not anonymized; remove or anonymize the individual Contacts under them instead.
- What remains? Financial documents and booking, registration and attendance records are outside the scope of anonymisation and remain in place. Do not ask Support to remove them as part of an anonymisation request: deleting them can damage reporting and record relationships. Your organisation remains responsible for determining its retention obligations.
- Record the details. Note the Contact ID (and Account ID where relevant) and the legal scope of the request so there is an audit trail of what was actioned and why.
How anonymization works
Anonymization is performed by Administrate on request; it is not a self-service action in the user interface. When run, it:
- replaces the Contact's name and email addresses with redacted placeholder values
- clears identifying fields such as job title, address details, phone numbers and biography
- removes the Contact's portal credentials
- clears issued certificates
- removes the Contact's audit history and records an audit entry showing the personal data was redacted
- applies the same redaction to the linked Account when it is an individual Account
Anonymization is not reversible. Once run, the original values cannot be recovered.
Requesting anonymization
Submit a request to Administrate Support including:
- the Contact ID (and Account ID for an individual Account)
- confirmation that you are authorised to request the irreversible anonymisation of the Contact and, where applicable, their individual Account
Do not delete related records yourself
Deleting registrations, invoices or bookings piecemeal to "erase" a person can leave relationships and statutory records in an inconsistent state, and does not remove the personal data held on the remaining records. Use the anonymisation process for the person's identifying data; it intentionally leaves related financial and operational records in place.