pattern

Portability Export

also called Data Takeout, Article 20 Export

A machine-readable package of the personal data a person provided and that was observed about them, delivered as a long-running job with authentication controls because it concentrates everything about one individual into a single file.

gdprportabilityaccount-takeoverasync-jobsdata-classification

A customer asks for everything you hold about them. The product holds a profile, four years of activity events, uploaded files, support conversations and model-derived scores. Two things about that list are traps.

The scope is narrower than "everything". Portability under Article 20 covers personal data the subject provided and data observed about them, in a structured, commonly used, machine-readable format. Inferred and derived data — a risk score, a recommendation ranking — is generally outside portability even where it falls within the right of access, and conflating the two is both over-disclosure and a competitive problem.

The export is the most valuable object an account takeover can produce. It gathers into one downloadable file what an attacker would otherwise have to assemble from a session.

Why it matters

Most of the engineering cost is not the file format; it is classifying the data model field by field into provided, observed, derived and third-party-related — on a 300-field model spread over nine services, budget 2 to 3 days per owning team. That classification is also the artefact a regulator will ask to see, and the thing that decays silently when a new field is added.

The security dimension is routinely underweighted. An export endpoint without step-up authentication converts a stolen session into a complete dossier, and the pattern of request-export-then-change-password has been a recognised takeover signature on consumer platforms for years.

Implementation patterns

  • Classify every field before writing any code. Provided, observed, derived, third-party. Enforce it with a test that fails when a new personal-data field has no classification.
  • Run it as an operation resource: a creation call returning 202, idempotent on a key so a retried request does not produce a second export, and a signed URL with a short published lifetime.
  • Re-authenticate at request and at download, and deliver the link through a channel separate from the requesting session.
  • Delay and notify. A deliberate hold of some hours plus a notification with a cancellation link to the verified contact turns silent exfiltration into something the owner can stop. Document the delay so it does not read as obstruction.
  • Exclude other people's data. A group conversation is not solely the requester's; redact or summarise, and record the rule applied.
  • One versioned schema with a manifest: JSON for structured data, original files in a folder structure, a version field so an export remains readable later.
  • Log and rate-limit every export as a security-relevant event.

Industry example

The large consumer platforms all ship a takeout or download-your-data flow built this way — asynchronous generation, notification to the account's contact, a time-limited link — and the convergence is informative: they arrived at the same controls because they all experienced the takeover case. The rights themselves have applied in the EU since May 2018, and similar portability provisions now exist in several other regimes, so a classification done once serves more than one jurisdiction while a bespoke per-regime export does not.

Failure scenarios

  • An export three months behind the schema, because a field was added and nothing failed.
  • A forever-valid link sitting in a chat history with everything about a person behind it.
  • Over-disclosure of derived data, handing a competitor your scoring outputs, or of a third party's data inside a conversation.
  • A timeout for the largest accounts, so the obligation is met for the median user and not for the ones most likely to complain.
  • Takeover amplification, where a stolen session produces a complete dossier with no second factor and no notification.
  • An export that cannot be imported anywhere, which satisfies the letter of portability and none of its purpose.

Trade-offs

Choose Gains Pays
Async job with signed URL Works at any data volume; keeps large payloads out of the API tier A job system, artefact lifecycle, and polling for the client
Step-up auth plus delay and notify Removes the takeover amplification Friction on a legitimate request, and support questions about the delay
Field-level classification enforced in CI Export stays complete as the model evolves A pass across every team, then a permanent check developers must satisfy

When not to use it

For a product holding a profile and a settings object, a synchronous JSON endpoint is the whole answer and the machinery above is waste. Keep the delay-and-notify control even then, because account takeover does not care how small the data model is. And do not build a portability export to satisfy a right of access request: access is broader and often better served by a structured report, so building one mechanism for both obligations usually over-discloses on one side and under-delivers on the other.

Interview question

Q: Product wants a "download your data" button shipped this quarter. The data model has about 300 personal-data fields across nine services, and some of them are model outputs. Tell me what you would do first, what you would push back on, and how you would keep the export correct in a year.

What a strong answer covers: classification before implementation, with the provided / observed / derived distinction and the reason derived data is usually excluded · the async operation design with idempotency and a short-lived link · step-up authentication and notify-and-delay as security requirements rather than nice-to-haves · exclusion of third-party personal data in shared content · a CI check tying new fields to a classification as the only durable correctness mechanism · and pushing back on the idea that one export satisfies both portability and access.

Quick check

Quiz: Why is a derived risk score usually excluded from a portability export? — Because portability covers data the subject provided and data observed about them; a derived score is the controller's own output, and including it both over-discloses and exposes the model's behaviour.

Flashcard: What is the highest-value security control on a data export, and why? — Step-up re-authentication plus notify-and-delay, because the export concentrates everything about a person into one file and is therefore the richest prize available to a stolen session.