GDPR data export
GDPR (and similar laws) gives every individual the right to receive a copy of all the personal data you hold about them. Momentumpro makes this a one-click action.
Two types of export
1. Self-service export (any user)
Any logged-in user can export their own data:
- Profile → Privacy → Export my data.
- A ZIP file is generated within minutes.
- Email arrives with a download link.
2. Subject Access Request (admin)
For requests from non-users (former employees, customers, anyone whose data is in your tenant):
- Admin → Privacy → New SAR.
- Pick the subject type (Employee / Customer / Vendor) and the record.
- Optionally pick a scope (all data / payroll only / contracts only).
- Click Generate.
What's in the export
A typical export ZIP contains:
/personal-information.json Profile fields, contracts, IDs
/employment-history.json Job changes, promotions, departments
/attendance.csv Every clock-in / clock-out
/leave-requests.csv All leave history
/expenses.csv All expense reports
/payslips/ PDF payslips for every period
/documents/ Original PDFs (contracts, certificates)
/audit-trail.csv Every change to their record
/README.txt Index of files and meanings
The ZIP is encrypted with a password emailed separately.
Right to be forgotten
For deletion requests:
- Admin → Privacy → Hard delete.
- Pick the record.
- Confirm — this is irreversible.
Some data is legally retained even after deletion:
- Payroll records — typically 7 years for tax compliance.
- Audit log entries about the user (anonymized).
The platform automatically applies the right retention rules based on your tenant's country.
Lawful basis tracking
For each data subject, Momentumpro tracks the legal basis for processing:
- Contract — for employees and customers.
- Legitimate interest — for vendors.
- Consent — for marketing communications.
When the basis ends (e.g. employment ends + 7 years), the system flags the record for review.
Privacy reports
For your DPO:
- Monthly SAR report — how many requests, response times.
- Retention status — records due for deletion this month.
- Lawful basis register — auditable record of why each subject's data is held.