Settingsintermediate

How to Export Customer Data

Build a subject, review the frozen scope, and generate a downloadable ZIP export of everything Atender holds about a customer, for GDPR Article 15/20 subject access and data portability requests.

8 min read

How to Export Customer Data

When a customer asks what Atender holds about them — or asks for a copy of it under GDPR Article 15 (right of access) or Article 20 (data portability) — you don’t need to go table-by-table with engineering. Customer Data Export builds a subject, freezes the scope of everything linked to them, and packages it into downloadable ZIP parts you can hand to the customer or their solicitor.

This is the disclosure twin of right to be forgotten: the same subject-resolution logic decides who’s in scope, but instead of scheduling a deletion, export produces an archive. Nothing about the customer’s data is changed or removed by running an export.

Who can do this

Building and managing exports requires the privacy.manage permission, which is currently granted to owners only. If you don’t see Customer Data Export under Settings, ask an owner on your team to run the request on your behalf.

Step 1: Start a new export

  1. Go to Settings → Administration → Customer Data Export.
  2. Choose New export. This opens a three-step wizard.
  3. On the first step, identify the subject — by picking an existing contact, or by entering a raw email address or phone number. However you identify them, Atender resolves this to a single subject before moving on, folding in every channel and identifier linked to that person.

Step 2: Review the frozen scope

Once the subject is resolved, Atender computes the scope — every category of data held about them (conversations, messages, attachments, call recordings and their metadata, CSAT responses, form submissions, order and review integrations, verification sessions, and other linked records), broken out with size totals per category.

This scope is frozen at review time: it’s what the export will actually contain, taken as a snapshot the moment you reached this step. There is no size cap on what can be included — a category is either in scope or explicitly excluded (see Understanding exclusions), it is never silently truncated to fit.

Use this step to sanity-check that you’ve got the right person and that the scope looks like what the request is asking for, especially for customers with multiple channels or merged contact identities.

Step 3: Choose export options

The final step lets you set options that affect what’s packaged into the ZIP, such as whether to include internal notes alongside customer-facing content. Review your choices, then confirm to submit the request.

Once submitted, the request enters the build queue — you don’t need to keep the tab open.

The request lifecycle

An export request moves through a small set of statuses, shown on the Customer Data Export list:

  • Building — the export is being assembled. Large exports are split into multiple parts behind the scenes; you don’t need to do anything while this runs.
  • Ready — the ZIP parts are available to download.
  • Ready — with exclusions — the export completed, but one or more items couldn’t be included (see below). It’s still downloadable and still counts as a completed request.

A ready export is subject to a retention window: the clock starts the moment the export becomes ready, not when you first requested it, so a long build doesn’t eat into the time you have to download it. Once that window expires, the request’s files are purged and are no longer available — if you need the data again, you’ll need to run a new export, which will reflect the customer’s data as it stands at that later date.

Downloading the export

From a ready (or ready — with exclusions) request, use the download action to retrieve the export. Large exports are split into multiple ZIP parts rather than one file — download each part listed against the request. Every download is streamed through Atender directly to you; there’s no separately shareable link, so anyone downloading the file needs the same privacy.manage access you used to build it.

Understanding exclusions

Sometimes an export can’t include everything the scope identified — most commonly because:

  • A call recording was already removed by your organization’s own retention settings before the export ran.
  • An externally hosted recording or attachment was never available to fetch, or its URL is no longer reachable.
  • A category was deliberately switched off in Step 3 of the wizard (for example, internal notes left unchecked).

When this happens, the request still reaches Ready, but its status shows as Ready — with exclusions, and the ZIP includes an EXCLUSIONS.md file listing exactly what was left out and why — this file is written even when there are no exclusions, so its presence isn’t itself a signal that something is missing.

Treat “Ready — with exclusions” as complete-with-caveats, not incomplete: everything that could be gathered was gathered, and the exclusions list is the definitive record of what wasn’t and why. If you’re responding to a formal subject access request, it’s worth keeping that exclusions list alongside the export as part of your evidence of what was disclosed.

Tags

How ToPrivacy