Admin GuidesData Retention & Privacy

Data Retention & Deletion Requests

Who this guide is for: The organization Owner and administrators responsible for privacy compliance — configuring how long session recordings are kept (an Owner-level setting), and handling data-subject deletion requests under Quebec Law 25 / PIPEDA (Owner and Admin).

EmbayLMS enforces a fixed retention schedule automatically. A nightly job permanently removes data that has reached the end of its legal retention period and irreversibly anonymizes personal information that must be removed while the underlying training records are retained.

Important: retention purges are permanent. Unlike deleting a course or a user in the admin UI (which can be restored from the trash), data removed by the retention schedule is destroyed and cannot be recovered.

What is retained, and for how long

Data classRetention periodWhat happens at expiry
Training completion records & certificates7 years from completionPermanently deleted
Audit logs3 years from the eventPermanently deleted
Deactivated user accounts90 days after deactivationIdentity anonymized; account deleted entirely if no records remain under retention
Quiz answer detail (per-question)2 years from the attemptPer-question answers deleted; the summary score is kept with the completion record
Session (VILT) recordingsConfigurable — default 1 year from the session dateRecording link permanently removed

These periods come from the EmbayLMS data retention policy and meet the legal training-record obligations common to regulated industries. Only the recording period is configurable per tenant; the others are fixed. Both are shown on Settings → Data Management → Data Retention.

Configuring recording retention

The Data Retention tab is Owner-level. Opening it needs the settings read permission (settings:read) and changing the recording period needs the settings update permission (settings:update); the Owner role has both, and Admins have neither. A member whose custom role grants only the read permission sees the current value read-only.

  1. Go to Settings → Data Management and open the Data Retention tab.
  2. Under Session recording retention, choose a period in Keep session recordings for — from 30 days to 7 years (default: 1 year, marked (default)). A value set before this page existed is kept in the list and marked (current setting).
  3. If you choose a period shorter than the current one, a warning names the age past which recordings will be removed. Check your session dates before continuing.
  4. Click Save. A confirmation appears; the change applies from the next nightly retention run and is recorded in the audit log.

The Fixed retention periods table on the same page lists the other periods above for reference; they cannot be changed there.

Every active Owner and Admin receives an email 30 days before any recording is removed, with the list of affected sessions, so instructors can download anything worth keeping. Each session triggers this notice only once.

Configuration reference

FieldValuesDefaultNotes
Keep session recordings for30, 60, 90 or 180 days, or 1, 2, 3, 5 or 7 years (2,555 days)1 year (365 days)Shortening the period removes older recordings on the next nightly run — the page warns before you save
Pre-expiry admin noticeFixed: 30 days before removal—Sent to every active Owner and Admin, in each recipient’s language (English / French)

Handling a deletion request (Law 25)

When a learner (or former employee) asks for their personal information to be deleted, Quebec Law 25 gives you 30 days to respond. EmbayLMS resolves the central conflict for you: completed training records often must be kept for 7 years, but the person’s identity does not.

Step 1 — Verify the requester’s identity. Confirm the request really comes from the account holder (for example, a reply from the registered email address). Do this before touching anything in the LMS.

Step 2 — Process the request. Go to Users, open the user, and in the Privacy section choose Process deletion request. In the dialog:

  1. Read the summary of what will happen — the dialog names the user.
  2. In Identity verification note, describe how you verified the identity (10 to 500 characters — for example, Verified by a reply from the registered email address on 2026-09-23). Do not include personal details in the note; it is stored in the audit log.
  3. Type the confirmation word shown (DELETE in English, SUPPRIMER in French) to unlock the button.
  4. Click Anonymize permanently.

You need the delete users permission (Owner and Admin have it). The action is not offered on your own account, on a user whose personal information has already been anonymized, or on a user whose role ranks above yours (an Admin cannot process a request for the Owner). A deactivated user can be processed from the Deactivated view of the Users list.

Step 3 — What the system does, automatically:

  • The user’s name becomes an anonymous code (anon_…), the email address is replaced with a non-routable anonymized address, and the employee ID and custom profile fields are cleared. This cannot be undone — no link between the code and the person is kept anywhere.
  • Passwords, authenticator (MFA) secrets, and backup codes are destroyed.
  • Notifications and personal preferences are deleted.
  • Personal details inside historical audit entries are redacted.
  • Completed training records and certificates within their 7-year retention period are kept, anonymized. Certificates remain verifiable by their certificate number but show no personal name.
  • If the user has no records under retention, the account and all its data are deleted entirely.

Step 4 — Respond to the requester. The dialog shows the itemized summary — what was deleted, what was anonymized, how many records, and the legal basis for each, with the date the request was fulfilled. Send this summary to the requester to close the request within the 30-day window. Click Done to close it: an anonymized user’s profile reloads showing the anonymous code; a fully deleted user returns you to the Users list.

What you do NOT need to do

  • Schedule anything. The retention job runs nightly, per organization.
  • Delete deactivated users manually. 90 days after deactivation their identity is anonymized or removed automatically.
  • Worry about backups. Deletions and anonymization propagate through all retained backups within 35 days, and are re-applied if a backup is ever restored.

Audit trail

Every retention run and every deletion request writes an audit log entry (actor system for scheduled runs, or the processing administrator for deletion requests) with record counts only — never personal information. These entries are your compliance evidence for auditors and the Privacy Officer.

Troubleshooting

SymptomLikely causeFix
”This user’s personal information has already been anonymized” in the Privacy sectionThe request was already processed, or the 90-day deactivation cleanup ran firstNothing to do — confirm via the audit log (retention.deletion_request or retention.user_anonymization) and respond to the requester with the recorded outcome
”You cannot process your own deletion request”You opened your own accountAsk another administrator to process it, or contact Embay support for the account owner
No Privacy section on the user’s pageYou lack the delete-users permission, or the user’s role ranks above yours (e.g. the Owner)Ask the Owner, or an administrator of equal or higher rank, to process it
Anonymize permanently stays disabledThe verification note is shorter than 10 characters, or the confirmation word is not typed exactly (it is case-sensitive)Complete the note and type the word shown in the field label
No Data Retention tab under Data ManagementOpening the tab needs the Owner-level settings:read permission, which Admins do not haveAsk the Owner to open the tab, or to grant the permission through a custom role
A recording disappeared without warningRetention period was shortened after the session was already past the new period — expiry can apply on the next nightly runCheck the audit log entry (retention.sweep, recordingsExpired); recover from the source platform (e.g. Zoom cloud) if still available there
An expiry notice email was not receivedYour account is inactive or is not an Owner or Admin, or the notice was already sent previously for those sessionsVerify the account is an active Owner or Admin and check the audit log recordingExpiryNoticesSent count
A certificate shows anon_… instead of a nameThe learner was anonymized (deletion request or 90-day cleanup)Expected behavior — the certificate stays valid and verifiable by its number
Need to keep records longer than the schedule (legal hold)Litigation or regulatory holdContact Embay support — legal holds are registered by the Privacy Officer and suspend purges for the affected records