Security & Privacy · THE NO-PANIC PLAN
Prepare a Personal Data Archive Across Online Accounts
A personal data archive is a set of copies exported from services you use; it is not a complete record of everything a company holds and does not itself delete data from the service. Each provider offers different exports, formats, account controls, and processing times. This guide combines direct service export instructions from Google and Apple with Microsoft's privacy dashboard and the European Commission's explanation of GDPR data portability. Legal rights vary by location and data type, so use the official route for your account and check the law that applies to you. Data Subject Request Tracker can record provider names and request status only; never put passwords, identity documents, or archive contents in it.
MISSION Help an individual make and verify personal copies of data from multiple online accounts, organize the exports, and store them with appropriate access controls.
Start from each provider's official account or privacy pageTHE REAL-WORLD BIT
What happens outside this browser tab?
Define the archive's purpose; inventory accounts and likely data; find each provider's official export or privacy route; request only needed data; track delivery without sensitive details; inspect archives and organize them securely; and remove temporary copies according to a retention plan.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Decide what the archive is for and set a boundary
Write down why you need the archive: a personal backup, a move between services, a record of your own activity, or preparation for a specific data request. List the categories and date range you actually need so that the archive does not become a large, difficult-to-protect collection by default. An account export is usually a copy of selected data offered by that provider; it may exclude records, inferences, or data held in another system. Do not treat a download as proof that the provider has no more data or as an erasure request. If your purpose is to exercise a legal access or portability right, check the official privacy authority in your jurisdiction because eligibility, scope, and exceptions are defined by law.
- 02
Inventory accounts and the data each one may export
Make a private list of services where you have an account, such as email, cloud files, photos, social platforms, and productivity tools. For each service, note the account owner, whether it is personal or managed by work or school, which data categories matter, and whether an administrator controls export access. Do not place passwords, recovery codes, full email addresses, or account contents in a general checklist. Providers expose different categories and managed accounts may restrict downloads. Google's Takeout guidance, for example, lets an account holder select Google product data for an archive; this does not establish that other providers offer the same export or coverage. Confirm that each account belongs to you or that you are authorized to manage it before requesting a copy.
- 03
Find the official export or privacy route for each provider
Open the account's official settings page by typing the provider's known domain or following its signed-in help centre, rather than trusting a message that unexpectedly asks you to download data. Look for Download your data, Export, Privacy, or a data request option. Google provides Google Takeout for creating a copy of supported account data, and Apple directs account holders to its Data & Privacy portal for available privacy choices. Microsoft's privacy dashboard exposes certain account activity and controls; the categories shown there are not the same as a full export of every Microsoft record. If you are in the EU or otherwise covered by GDPR, the European Commission describes data portability as a right under specified conditions, not a universal full-account export. Follow the exact provider route and its identity checks.
- 04
Request only the categories you need and save the provider's confirmation
Choose data categories, date ranges, and delivery options carefully. Read the provider's description of each category and archive format before starting; selecting everything may create very large files that are hard to store safely. Use the provider's own signed-in process and authentication, and do not give a password or one-time code to a person who contacts you. Note the submission date, provider, selected categories, confirmation number, and any delivery estimate in a private record, without copying the archive or credentials into a tracker. Some providers may delay or limit an export for account-security review, organization settings, or other reasons. Contact official support from within the account if the request is blocked or a promised delivery does not arrive; never use an unsolicited recovery service.
- 05
Track each request without storing the exported data in a tracker
Keep a small status record for each provider: service label, date requested, status, expected next action, and the date you checked it. Data Subject Request Tracker (11727) can organize these non-sensitive items; it is not connected to provider accounts and does not send a legal request or enforce a response deadline. Use only a deadline that the provider or applicable official authority has actually stated. Check the signed-in account or the provider's official email for a download notice, and verify the sender through the account rather than clicking a surprising attachment. When a service says it is ready, download the archive directly from its official portal over a trusted connection and store it in a location you control.
- 06
Verify the archive and preserve the original download
Check that each downloaded archive is complete enough for its stated purpose: confirm it opens, inspect its folders and manifest or readme if supplied, identify the requested categories, and note any error or missing item. Preserve the untouched archive before extracting or converting files, because extraction can fail or alter metadata. Do not assume that one provider's export format will import cleanly into another service; compare supported formats and test a small non-sensitive sample before attempting migration. If the archive is unexpectedly empty, incomplete, or unreadable, return to the provider's official help route and ask what data categories and dates the export contains. Record the issue without attaching the archive to a public ticket or third-party checklist.
- 07
Organize, protect, and eventually remove working copies
Place the verified archive in a clearly named folder with the provider, request date, categories, and format; avoid putting sensitive personal details in filenames. Store it in an encrypted device or trusted storage account protected by a unique password and multi-factor authentication, and limit sharing to people who need access. Keep the original download separate from any extracted or converted working copy, and document how to restore it. Avoid leaving archives in a public computer, shared download folder, or unprotected USB drive. When you no longer need a temporary copy, remove it from downloads, recycle bin, and shared locations, following your device and storage provider's deletion controls. A personal archive is sensitive data: review access periodically and do not upload it to Nirmion tools.
THE HELPER CREW
Tools for the fiddly bits.
These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-10