Erase a person’s personal data

WordPress can erase or anonymise the personal data it holds about one person, for a request under data protection law or when someone leaves. On a Govintra intranet the tool does part of the job: it deals with the person’s comments and search history. The intranet profile, likes, forum posts and uploads are removed by deleting the account, which is usually what a leaver needs anyway. This page covers both, so that nothing is left behind by accident. Only administrators can do this.

Request an erasure

  1. Go to Tools, then Erase Personal Data.
  2. Under Add Data Erasure Request, enter the person’s username or email address. Leave Send personal data erasure confirmation email ticked to ask the person to confirm, or untick it when you already hold their written request or they have left.
  3. Select Send Request. The request appears in the table with the status Pending, and becomes Confirmed once the person uses the link in their email.

Run the erasure

Hover over the request and choose Erase personal data on a confirmed request, or Force erase personal data on one the person has not confirmed. WordPress then works through each eraser and reports Erasure completed. Mark the request Completed afterwards, or remove it.

What erasure removes, and what it leaves

On a Govintra intranet the erasure tool runs two erasers:

  • WordPress Comments: the person’s comments stay on the pages but their name, email address and other details are replaced with anonymous values.
  • Relevanssi Search Logs: searches recorded against the person are anonymised, where the search plugin keeps a log.

It leaves everything else exactly as it was: the account, the intranet profile with its phone numbers, job title, photo and other fields, the person’s likes, their forum topics and replies, and files they uploaded. So for most requests, erasure on its own is not enough.

Remove the profile and account

To remove the intranet profile, delete the account. Go to Users, find the person, and choose Delete. WordPress asks what to do with content they wrote: choose Attribute all content to another user, usually a generic communications account, so that news stories, tasks, thank-you messages and forum posts they authored stay on the intranet under a different name, or delete it all. Deleting the account removes every profile field and, unless the same picture is used elsewhere, the profile photo file. The person disappears from the staff directory, team pages and search straight away.

For several leavers at once, the (Govintra) Remove users plugin deletes accounts from a list of email addresses with the same reassignment.

Two things are not tidied by deleting an account and may need a hand:

  • Thank-you messages about the person on the Wonderwall keep the message but no longer show a name for them. Edit or bin them under Wall entries if the request covers them.
  • Mentions in content, such as a news story naming the person or a photo of them, are ordinary content and are edited by hand.

Suggested order for a leaver

  1. Export their personal data first if there is any chance it will be asked for. See Export a person’s personal data.
  2. Run Erase Personal Data so their comments and search history are anonymised.
  3. Delete the account, attributing their content to a generic account.
  4. Check the Wonderwall and any content that names them.

Related

Add a comment