Data agreements
Every use of learner data in the showcase is grounded in a data agreement held in a consent service. At registration the learner is onboarded as an individual there, and a consent record is written against each agreement; the learner can change the optional ones at any time from the Education Portal, and every surface that shows a consent state reads it live from the consent service.
The three agreements
| Agreement | Lawful basis | Data attributes | Learner control |
|---|---|---|---|
| Core enrolment processing | public_task | Identity reference, application data | Transparency record: registration itself is a public task and needs no consent, so this agreement documents the processing rather than asking permission |
| Anonymised education analytics | consent | Anonymised learner statistics | Fully optional opt-in at registration; opt-out at any time. Declining never affects registration or credentials |
| Employer qualification sharing | consent | Qualification data | Optional standing preference. Every actual share still requires Wallet approval of the specific request, field by field |
How the records are used
- At registration, the two optional choices on the form become consent records (
optIntrue or false) against the analytics and employer agreements, and the enrolment agreement is recorded as the transparency notice for the processing itself. - In the Education Portal, the My data choices page lets the learner opt in or out of each optional agreement at any time; the change is written to the consent service immediately.
- In the school workbench, the reviewer sees the current consent states live from the consent service, not the snapshot from the submitted form, so a later opt-out is visible immediately.
- Consent complements the Wallet; it never replaces it. The employer sharing agreement records a standing preference, but each actual disclosure happens only when the learner approves that specific presentation request in the Wallet, as shown in the walkthrough.
The right to be forgotten
The Education Portal carries a Delete my account action. It removes the learner's consent records from the consent service, then erases the local application, exchange records, profile, and sign-in account. Credentials already held in the Wallet stay with the holder, which is the point of a wallet: revocation through the status list, not deletion, is how an issued credential is withdrawn.
Auditability
Consent decisions, registrations, issuances, verifications and revocations are all written to the registry's append-only, hash-chained audit trail, which the showcase publishes read-only. Consent-record changes are also independently traceable in the consent service's own history.