When a participant asks for their personal data to be deleted, treat it as a GDPR right-to-erasure request. Removing access to a single learning journey is not the same as erasing their data.
Confirm the scope of the request
First identify the participant and the email address they used in Knowly. Then clarify whether the request is about:
one learning journey
all learning journeys in one team
the whole Knowly organisation
every Knowly organisation your company uses
The path depends on that scope.
Erasing one person from the organisation
To erase a single person's data, open the organisation's people list, find the person, and select Remove from organization. Knowly asks you to confirm — Are you sure you want to remove {name} from the organization? — and you confirm with Yes, remove.
Despite the name, this does more than remove access: it removes the person and their personal data from every learning journey they were in, and it can't be undone. Their answers, messages, and profile are deleted or anonymised. That is what makes it the right tool for an erasure request.
Removing from one journey is different
Removing a participant from a single learning journey only takes them out of that journey. Their organisation account, and their data in other journeys, stay in place. Use that when the request is scoped to one journey — see removing a participant from a learning journey. For a full erasure, remove them from the organisation instead.
If the person comes from your directory
If your organisation uses SCIM or another directory sync, Remove from organization isn't available for directory-managed people — Knowly hides it and blocks the deletion, because your identity provider owns those accounts. Remove or deprovision the person in your identity provider instead. Depending on your setup, Knowly then either erases or suspends their data when it next syncs. See directory sync with SCIM and removing a participant from your organisation.
Bulk cleanup is a separate task
If you need to erase many old participants for GDPR housekeeping, use bulk-deleting old participant data for GDPR housekeeping instead of handling each person as a separate one-off request.