Skip to content

General: Withdraw science consent when an account is anonymized #13938

Description

@MaximilianAnzinger

Split out of #13357, which introduces course-level science consent.

Problem

UserService renames the science event identity to the anonymized login on soft delete, and UserOwnedContentDeletionService renames it to deleted-user-{id} on deletion. Neither touches science_course_consent.

The consent row therefore survives, and the events stay fully exportable under a consistent pseudo-login. Nothing in the account deletion flow tells the student that their research data remains in the collection pool, so "delete my account" means something narrower than a student would reasonably read it to mean.

Suggested direction

Decide what deletion should mean for already-collected research data, then make the flow say it:

  • withdraw consent (write a SCIENCE__OPT_OUT marker so the timeline stays truthful) and stop the events being exportable, or
  • keep the data deliberately, and say so in the account deletion confirmation.

The export is already gated on a consent decision that predates each event, so withdrawing consent alone does not retroactively exclude data collected while it was given — that is a separate decision worth taking explicitly.

Notes

Not a regression — recorded under "Known limitations" in #13357.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    accountPull requests that affect the corresponding moduleatlasPull requests that affect the corresponding modulecourse

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions