Skip to content
All documentation

Data Export (Portability)

How a data subject exports their own personal data, and how an org admin exports a member's data on request.

What it is

Portability (GDPR Art 20) is delivered as a JSON snapshot with a schema_version and exported_at timestamp, so an exported file is versioned and auditable. Encrypted columns are returned as plaintext because the export is handed to the subject themselves.

Use: self-service export

A signed-in member requests GET /api/me/export to download a JSON file of their own data: profile, consent history, survey responses they submitted, learning progress, exercise submissions, and assigned courses. Only the caller's own user id is ever queried, so the response cannot contain another subject's or tenant's data.

Use: admin (controller) export

An owner or admin exports a member's data on behalf of a subject-access request via GET /api/admin/members/export?userId=<id>. This requires an owner/admin session, a fresh MFA step-up, and the target must belong to the acting admin's own organization.

Setup

No configuration is required. The routes are available to any authenticated user (self) or admin (member).

Security

  • Tenant isolation is enforced on the admin path: a request for a member of a different organization returns 404.
  • The export never includes another subject's rows, and never includes another organization's data.