What to do, in order
- 1Decide what you are asking forSeparate your own personal data, which falls under Article 20, from your clients' records, which you control and your provider processes on your behalf. The letter asks for both under the right heading for each.
- 2Find the right contactLook in the provider's privacy notice for a data protection officer or a privacy email address. Send it there rather than through a support chat window, so you have evidence of the date.
- 3Fill in the letterCopy the template on this page, complete every square bracket and delete any category of data that does not apply to you. Keep the sentence stating the one month deadline.
- 4Send it and record the dateEmail it, keep the sent copy and put the one month date in your diary. Ask for written confirmation of receipt.
- 5Check what comes backOpen the export and check it is complete and machine-readable before you close your account. Access normally ends with the subscription.
- 6Escalate if you have toChase in writing with a short final deadline. If that fails, complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
What the right to data portability is
Article 20 of the UK GDPR gives you the right to get a copy of the personal data you have given to an organisation, in a format you can actually reuse. It also lets you have that data sent straight to another organisation where doing so is technically feasible. It exists precisely so that changing supplier does not mean starting from nothing.
The right applies where two things are both true. First, the organisation is processing your data because you consented or because it is necessary for a contract with you. Second, the processing is automated rather than done on paper. A subscription to a software platform meets both, which is why this right is the right one to reach for when you are switching.
It covers the data you provided. That includes what you typed into a form and also what the platform observed from your activity, such as your transaction history. It does not cover data the organisation worked out about you, such as a score or a profile it built. Article 20 also does not let you take data in a way that harms somebody else, which matters when the records involve other people.
How this differs from the right of access
People use the two interchangeably and they are not the same thing. The right of access under Article 15 is broader in what it covers. The right to portability under Article 20 is narrower in what it covers but stronger in the shape you get it back in.
Article 15 gets you a copy of all the personal data an organisation holds about you, whatever its source and whatever its lawful basis, plus supplementary information: why it is processing your data, who it shares it with, how long it keeps it, where it came from and what rights you have. There is no requirement that it arrives in a reusable format. A readable copy is enough.
Article 20 gets you a narrower set of data, but it has to arrive in a structured, commonly used and machine-readable format and you can ask for it to be sent directly to your new provider. A PDF or a screenshot is unlikely to satisfy that, because neither is readily machine-readable. CSV, JSON and XML are the formats usually pointed at.
If you are switching, ask under Article 20 and add Article 15 as a fallback for anything the organisation says falls outside it. The template on this page does exactly that, so you are not left making a second request a month later.
Whose data is whose when you run a business
This is the part most templates get wrong. Getting it wrong gives a provider an easy way to answer half your letter. Article 20 is a right you hold as an individual, over personal data about you. Your client list is not personal data about you. It is personal data about each of your clients.
For those records you are the data controller and your software provider is your processor. It holds them on your behalf, under your instructions. So the route to getting them back is not Article 20 at all. It is Article 28(3)(g) of the UK GDPR together with your contract, which requires a processor to delete or return all the personal data to the controller at the end of the service, at the controller's choice.
In practice you want both in one letter, clearly separated. Your own personal data goes under Article 20. Your clients' records go under Article 28 and the contract. Asking for the second under Article 20 gives a provider a reason to say the request is misconceived. Asking under both closes that door.
It follows that your own clients hold their Article 20 rights against you rather than against your software provider. If a client asks you for their data, that is your request to answer as their controller.
What a provider must give you and when
The deadline is the same for both routes in practice. It is worth quoting back at anyone who stalls.
- Format. Structured, commonly used and machine-readable. CSV, JSON and XML all qualify. A PDF export, a printout or a set of screenshots is unlikely to.
- Deadline. Without undue delay and at the latest within one calendar month of receiving your request. The clock starts when they receive it, not when they get round to it.
- Extension. They may extend by up to two further months where the request is complex or where you have made a number of requests. They must tell you within the first month and explain why. An extension announced in week six is not a valid extension.
- Cost. Free of charge. A provider may only charge a reasonable fee or refuse outright where a request is manifestly unfounded or excessive. The burden of showing that sits with them.
- Direct transfer. Where it is technically feasible, they must send the data straight to the provider you name. Technically feasible is not the same as convenient, but they are not obliged to build a bespoke integration.
- Identity. They can ask for reasonable proof of who you are before they act. If they do, the clock pauses until you supply it, so send proof early rather than waiting to be asked.
The request letter
Copy the letter below, fill in every square bracket and send it. It asks under Article 20 for your own personal data and under Article 28 for the client records you control. It names the formats and the deadline too, so there is nothing left to interpret.
Trim anything that does not apply to you. A mobile therapist has no staff rotas to ask for. What you should not trim is the sentence naming the deadline or the request for written confirmation of receipt, because those two are what you rely on if the request is later ignored.
Data portability request letter
[Your name] [Your business name] [Your address] [Your email address] [Today's date] The Data Protection Officer [Provider name] [Provider address or their privacy email address] Dear Sir or Madam Request for data portability and for the return of controller data I hold an account with [Provider name]. My account identifier is [account number, business name or the email address you registered with]. Part one. My own personal data, under Article 20 I am exercising my right to data portability under Article 20 of the UK GDPR. Please provide the personal data concerning me that I have provided to you, in a structured, commonly used and machine-readable format such as CSV or JSON. This includes my account and contact details, my billing and subscription history and the record of my own activity in the account. Where it is technically feasible, please also transmit that data directly to [new provider name] at [new provider contact], under Article 20(2). If you consider that any part of this falls outside Article 20, please provide that part under Article 15 of the UK GDPR instead, so that I still receive a complete copy of the personal data you hold about me. Part two. My clients' records, under Article 28 and our contract I am the controller of the personal data of my own clients that is held in my account. You process that data on my behalf as my processor. Under Article 28(3)(g) of the UK GDPR and under our agreement, I am exercising my choice to have that data returned to me. Please provide the following in a structured, commonly used and machine-readable format: 1. Client records, including names, contact details, addresses, dates of birth where held, notes and any tags or categories. 2. The full appointment and booking history, including dates, times, services, staff and status. 3. Services, prices, packages, memberships and any gift card or account balances. 4. Invoices, quotes, payments, refunds and transaction history. 5. Consent records and marketing preferences, including the date and source of each consent. 6. Any photographs, forms or documents uploaded to client records. 7. Reviews and any correspondence held against a client record. Please also confirm the retention position for anything you intend to keep after this account closes, along with the lawful basis for keeping it. Timing I understand that you must act on the Article 20 request without undue delay and in any event within one calendar month of receiving it. If you intend to extend that period because the request is complex, please tell me within that first month and give me your reasons. Please confirm in writing that you have received this request. Yours faithfully [Your name] [Your position, if you are writing on behalf of a business]
How to send it and what to keep
Send it by email to the provider's privacy or data protection address, which is usually published in their privacy notice. If they list a postal address for a data protection officer, send it there too. A request made through a support chat window is still a valid request, but it is much harder to evidence later.
Keep the sent copy, the date, any read receipt and every reply. Put the one month date in your diary the moment you send it. If they respond asking for identification, note that date as well, because the clock pauses while you supply it and a provider that later claims a different start date will be arguing against your own record.
One practical point. Do not close your account or cancel your subscription until the data is in your hands and you have opened it and checked it. Access usually disappears with the subscription. A request answered after you have lost the ability to verify the answer is worth considerably less.
If the provider refuses or misses the deadline
Most requests are answered. When one is not, escalate in order rather than jumping to the end, because each step creates the record the next one needs.
If they refuse
A refusal has to be reasoned. They must tell you why, tell you that you can complain to the supervisory authority and tell you that you can seek a remedy through the courts. All of that has to happen within the same one month.
Read the reason before you react. Some refusals are partly right. Data they inferred about you is genuinely outside Article 20. So is anything that would adversely affect somebody else's rights. If the refusal is only partly right, write back accepting the valid part and pressing on the rest, which narrows the dispute rather than widening it.
If the deadline passes in silence
Send one written chaser that references the original date, restates the deadline and gives a short final period such as fourteen days. Say plainly that you will complain to the Information Commissioner's Office if you do not hear back. Keep it factual and unemotional, because this letter is likely to be read by a regulator later.
If you are still getting nowhere
The Information Commissioner's Office is the UK supervisory authority for data protection and you can complain to it at ico.org.uk or on 0303 123 1113. It is free. You will normally be expected to have raised the matter with the organisation first, which is what the chaser is for, so keep your copies.
You also have a separate right to seek a remedy through the courts and to claim compensation if you have suffered damage. That is a bigger step than a complaint and worth taking advice on before you start.
If you are leaving Youzse
The same letter works against us. You are entitled to send it. We would rather tell you that plainly than have you find out that a page about data rights quietly excluded the company that published it.
In practice you should not need the letter. Your records stay exportable from inside your account for as long as it is open. Customers, bookings, invoices, payments, quotes, staff and reviews each export as CSV. There is a full account export that produces JSON, a CSV archive or a PDF covering the lot. You do not need to ask anyone's permission and you do not need a reason.
One thing that cannot come with you, from us or from anyone else, is stored card details. Card credentials sit with the payment processor rather than in your account, so wherever you go next your customers re-enter a card the first time they pay. Any platform that offers to hand you a customer card number is describing something you should decline.
If you want the request handled formally rather than doing it yourself, send the letter to the privacy address in our Privacy Policy and we will treat it as a data subject request with the same one month deadline as anyone else.
General information, not legal advice
This page explains how the right to data portability generally works and gives you a starting point for a letter. It is general information rather than legal advice. It cannot account for the terms of your particular contract or the facts of your particular situation.
If a lot of money is at stake, if a provider is holding data you need to keep trading or if you are getting a refusal you do not understand, take advice from a solicitor or a data protection specialist. The Information Commissioner's Office also publishes free guidance for individuals and for organisations at ico.org.uk.
Youzse published this page and Youzse is one of the providers it can be used against. Nothing on it is drafted to make leaving us harder than leaving anyone else.
Common questions about data portability
How long does my provider have to respond?
Without undue delay and at the latest within one calendar month of receiving your request. They may extend by up to two further months where the request is complex or where you have made a number of requests, but they must tell you within the first month and explain why.
Can they charge me for it?
No. A data portability request has to be dealt with free of charge. A provider may only charge a reasonable fee or refuse outright where a request is manifestly unfounded or excessive. It is for them to show that it is.
What format should the data arrive in?
Structured, commonly used and machine-readable. CSV, JSON and XML all qualify. A PDF export, a printout or a set of screenshots is unlikely to, because none of them is readily machine-readable.
Does this let me take my client list with me?
Not under Article 20, because your client list is personal data about your clients rather than about you. You are the controller of those records and your provider is your processor, so your route to them is Article 28(3)(g) of the UK GDPR and your contract, which requires a processor to return or delete controller data at the end of the service. The letter on this page asks under both.
What if they ignore me?
Send one written chaser referencing the original date and giving a short final period. If that fails, complain to the Information Commissioner's Office, the UK supervisory authority for data protection, at ico.org.uk or on 0303 123 1113. Complaining is free. You also have a separate right to seek a remedy through the courts.
Can I use this letter against Youzse?
Yes and you should not need to. Your records stay exportable from inside your Youzse account while it is open, as CSV per area or as a full account export in JSON, a CSV archive or a PDF. If you would rather make the request formally, send the letter to the privacy address in our Privacy Policy and it is handled with the same one month deadline as any other request.
Moving your records into Youzse
Once the export lands, the import wizard maps clients, bookings, services and invoices from a CSV. Your records stay exportable afterwards, in the same formats, for as long as your account is open.
See how switching works