After the race · Administrators

GDPR & erasure

The system holds only what judging needs, and gives administrators simple tools to anonymise a race once results are final, delete what's no longer needed, and answer a request for a copy of someone's data.

Your organisation is the data controller. This page explains what the system does; it isn't legal advice. Say in your event's entry conditions and privacy notice that judging decisions, their times and the competition record are recorded and kept, and for how long.

What's held

AboutHeld
AthletesBib, name, country (or club) and place
OfficialsCode, name, country, role, judge number, and an email address only if one is given (used only to send them their PIN)
AdministratorsName and email address
The audit logWho did what and when, including administrator emails and official codes

Never held: dates of birth, phone numbers, addresses, device identifiers, location, or any tracking or analytics. A Roster Athletics import reads the files, keeps only name, number and club or country, and discards everything else without storing it.

The public posting board shows bib numbers and red-card symbols only, never names.

Recommended practice after an event

  1. Export the summary sheet and keep it. It's the official competition record. (Summary sheet export)
  2. Revoke any graphics API keys issued for scoreboards or broadcast.
  3. Purge the race's personal data once results are official.
  4. Delete the meet once the protest period has passed.
  5. Trim the audit log to the retention period in your privacy notice, keeping it at least as long as results can be protested.

Purging a race's personal data

  1. Export the summary sheet first. The purge can't be undone.
  2. In administration, open the race and press GDPR: purge personal data.
  3. Read the confirmation and confirm. The race is anonymised and archived.
ChangesStays
  • Athlete names and countries become Athlete 41
  • The race's copy of the panel loses each official's name, country and login code
  • Chief judge, recorder and assistant names on the race are cleared
  • Judge numbers: J3 stays J3, because every card must stay attributed to a numbered judge
  • Cards, times, places and disqualifications
  • The race as a usable statistical record

The anonymised names appear everywhere the race is shown: the boards, a summary sheet exported afterwards, the JSON export and the graphics feed. Copies taken before the purge (a summary sheet already downloaded, or what a scoreboard or broadcaster has already received) aren't affected.

Officials are not touched

Purging a race doesn't affect the officials themselves. Their entry in the registry, their code and their PIN keep working at every other meet, because judges are usually working elsewhere that same week. Removing a person is a separate decision (below).

Deleting races and meets

ActionRemovesWhen
Delete raceThe race and everything in it: athletes, cards, zone times, placesWhen you want it gone entirely rather than anonymised
Delete meetThe meet, its races and its panel assignmentsAfter the protest period. This removes the last link between a judge number and a person.

Why the meet matters: even after a purge, a card still belongs to the panel position it was given under, and panel positions belong to the meet. While the meet exists, J3 could still be traced back to the person who held that position. Deleting the meet closes that link.

Officials' own data

Answering a request for a copy of someone's data

In administration, open the race and press Export data (JSON). It downloads a complete machine-readable copy of the race: athletes, panel, cards and times. Pass on the parts that relate to the person asking.

The audit log

The audit log records every change: cards, voids, corrections, closings and reopenings with their reasons, late card decisions, exports and purges. That's what makes the record trustworthy, and it covers the record TR 54.7.8 requires.

It has no automatic expiry. Choose a retention period, state it in your privacy notice, and trim older entries to match; whoever hosts the system can do this with a single command. Keep it at least as long as results can be protested.

Who can do what

ActionWho
Purge a race, delete a race or meet, export JSONAdministrators of that organisation, and superadmins
Clear an official's email addressAny administrator
Delete an official from the registrySuperadmin only

Every one of these is recorded in the audit log with the administrator who did it.

Quick reference

First export the summary sheet, then revoke graphics keys
Purge race → GDPR: purge personal data once results are official
Delete the meet once the protest period has passed
Request race → Export data (JSON)

Applies to version 2.14 and later.