A school esports platform should keep each kind of student record only as long as a lawful purpose or recordkeeping duty requires. When the right trigger comes along, it should delete or de-identify that record. When the relationship ends, it should return what the school is entitled to in a form it can use. That sounds fairly tidy until you look at how many records a season creates, and how many things could count as "the end".
What student data does a school esports platform hold?
Depending on its features, it can hold more kinds of information than you might expect, and each has a job to do. Rosters establish who can play. Game usernames get students into the right lobby. Match chat and screenshots help teams organise and sort out disputes. Support conversations, conduct reports, permission evidence, invoices, family profiles and public results all have their own reasons for being there too.
Picture a league three seasons in where nothing has been removed. It's still holding chat from matches nobody remembers and contact details for players who left school two years ago. None of that helps run the competition any more. It's simply a growing pool of student information that someone still needs to protect.
How long should each kind of record be kept?
Keep each record only as long as its lawful purposes and any recordkeeping duties require, so the answer will differ from one kind to the next. Chat used to organise a Tuesday match has done its job once the result is settled, while an invoice may need to stay around for years after the season.
In New Zealand, the Privacy Commissioner's guidance on retaining and disposing of information explains that IPP9 limits retention to what lawful purposes require. The Public Records Act governs state and state-integrated school records, including relevant records held by providers acting on their behalf. A platform's short cleanup period doesn't let a school destroy records it must keep. In the US, the 2025 COPPA amendments prohibit indefinite retention of covered under-13 personal information and require a written retention policy; the general compliance date was 22 April 2026. Check which rules apply to your school, operator and records.
The trigger matters just as much as the period. A season ending, a student leaving school, a report being resolved and an agreement ending are different events. "When no longer needed" doesn't tell you which one starts the clock. For each record type, including exported copies, ask the supplier:
- what it's for, who's responsible for it and who receives it
- what triggers removal, after how long, and what happens to backups
- whether removal means deletion or just stripping identifiers
- who can place a hold, whether exports and privacy requests cover it, and what evidence shows the action happened
Does deleting a student's data erase their results?
It doesn't have to. Where there's a lawful reason to keep them, a match and its result can remain part of a competition's history without every private detail staying attached. Deletion, hiding, restriction and irreversible anonymisation are different actions, though, so check what you're getting. Removing a surname and email address doesn't make a result anonymous if a distinctive gamer tag is still beside it. School Esports' demo-hosted privacy support guide makes a related point: removing a profile, sign-in or family profile isn't necessarily the same as removing competition records.
What happens to the data when a safeguarding report is still open?
Agree with the school's safeguarding and privacy leads which evidence needs preserving and why. Routine cleanup and an open report can pull in opposite directions. If chat clears on schedule while someone is still looking into what was said, the evidence can go with it. An unresolved report may call for a focused preservation decision, with restricted access, a named reviewer and a review date. Keep unrelated records on their normal schedule unless another lawful duty applies. Agreeing on the process beforehand saves operators from making it up under pressure. Our guide to safeguarding and student privacy in school esports covers the wider picture.
What should a school get back when it leaves a platform?
A school should get back whatever its agreement and the law entitle it to, which is why it's worth being clear about "export". A student's own download, a formal access request, a legal portability right, an organisation-wide export and an import into a new platform are different deliverables. A download button doesn't establish the others. Where the GDPR applies, the EDPB explains that portability covers qualifying data provided by the individual, including observed data, where processing is automated and based on consent or a contract. It doesn't cover every record the operator creates. The controller handles rights requests, with the processor's assistance.
Try the export before you need it, using synthetic records and never real students' data. Check the formats, attachments, timestamps and identifiers, and whether the connections between records survive. School Esports' demo-hosted provider policy describes an export window after an agreement ends, followed by deletion or anonymisation, with some categories staying. The illustrative demo participant notice uses different wording about timing and exceptions. Before relying on a date, confirm:
- which agreement controls the arrangement
- what starts the clock
- what's excepted
- how backups are handled
- what confirmation you'll get
Remember the copies too. Exported spreadsheets, backups, game publishers' systems and saved screenshots don't disappear when an account is removed. Work out who can act on each one and how requests reach them; account removal alone doesn't prove those copies have been cleared.
How School Esports handles the data lifecycle
School Esports is built independently with national federation expertise. Its demo-hosted privacy support guide describes a Your Data area for a personal download and correction or deletion requests. Some information involving other people or sensitive reviews needs separate privacy review. Parents and people without account access should use their competition's published contact details or request route.
The demo-hosted provider privacy policy describes scheduled chat cleanup after matches or rounds, code-set retention periods and manual review of dormant accounts. Some records stay after selected identifiers are removed. The separate main-site privacy policy applies to the platform and white-labelled services too: it describes a limited post-match period, possible preservation of relevant misconduct records and organisations' responsibility for exports. These are published descriptions, so confirm the policy and schedule that apply to your competition.
You can also read about assessing student-data processing under GDPR.



