GDPR Data Export for Hosting Resellers: What to Deliver

A practical GDPR data-export matrix for hosting resellers: know exactly which customer, billing, domain, and server records you hold and how to deliver access, portability, and erasure requests.

billing softwarereseller hostingcompliancegdprdata export

You get a GDPR request from a customer. You have 30 days to respond. Do you know exactly where their data lives and how to export it? If you are a hosting reseller, your data is scattered across your billing system, your upstream providers, and your own local tools. This article gives you a practical matrix to map every record and meet access, portability, and erasure requests without missing a deadline.

What data do you hold as a hosting reseller?

As a reseller, you hold customer data in three main categories: identity and contact details, billing and payment records, and service-related data such as domains, hosting accounts, and server logs. Each category has different retention rules and export formats. Start by listing every system you use: your billing platform, your domain registrar, your upstream hosting provider, your support desk, and any spreadsheets or local databases.

Customer and identity records

These include names, email addresses, postal addresses, phone numbers, and any government IDs you collected for fraud checks. They usually live in your billing system. If you use a separate CRM or helpdesk, duplicate records may exist there. Export format: CSV or JSON with all fields clearly labelled.

Billing and payment records

Invoices, credit notes, payment history, and tax details. These are often stored in your billing software and sometimes in a payment gateway like Stripe or PayPal. Export format: PDF invoices plus a CSV of transactions. Note that you must retain some financial records for tax purposes even after an erasure request, but you can redact personal data not required by law.

Domain records

Domain names, registrant contact details, DNS records, and WHOIS data. If you resell domains through an upstream registrar, the registrant data may be held by that registrar. You need to know which entity is the data controller for each domain. Export format: CSV of domains with associated contacts, and a zone file for DNS.

Server and service records

Hosting account details, IP addresses, server logs, backup files, and support tickets. These may be on your own infrastructure or on your upstream provider's systems. Export format: account configuration files, log excerpts, and database dumps if applicable.

Where does each record live across upstream and local systems?

Data location determines how quickly you can respond and whether you need to involve a third party. Create a simple table with columns: data type, system, controller, processor, export method, and retention period. Here is a worked example for a typical reseller using a billing platform and an upstream VPS provider.

  • Customer name and email: stored in your billing system. You are the controller. Export via billing system's API or CSV export.
  • Payment card token: stored by your payment gateway. You are the controller, gateway is the processor. Export by requesting a copy from the gateway.
  • Domain registrant details: stored by your upstream registrar. You may be the controller if you collected the data, but the registrar is a processor. Export via registrar API or manual request.
  • Server logs: stored on your upstream provider's servers. You are likely the controller if you configured logging, but the provider is a processor. Export by requesting logs from the provider or accessing them through your control panel.

For each system, note whether you can export data yourself or must ask a third party. This affects your response time. If you rely on an upstream provider, check their GDPR compliance and data processing agreement (DPA).

What export formats and retention rules must you be ready to deliver?

GDPR gives individuals the right to access, portability, and erasure. Each right has specific requirements for format and timing.

Access requests

You must provide a copy of all personal data you hold, plus information about how it is used. Format: commonly CSV or PDF, but the data must be intelligible. You can provide a structured document with sections for each data category. Do not charge a fee unless the request is manifestly unfounded or excessive. Respond within one month, extendable by two months for complex requests.

Portability requests

This applies only to data provided by the individual and processed by automated means based on consent or contract. You must provide it in a structured, commonly used, machine-readable format (e.g., JSON, CSV) and, where technically feasible, transmit it directly to another controller. For hosting resellers, this often means exporting customer account details, service configurations, and billing history.

Erasure requests

You must delete personal data without undue delay, unless you have a legal obligation to keep it (e.g., tax law). You must also inform any third parties with whom you shared the data. For each record in your matrix, note whether it can be erased or must be retained. For example, invoices must be kept for tax purposes, but you can anonymise the customer name after the retention period.

Retention periods vary by data type and jurisdiction. Common rules: financial records for 6-7 years, server logs for 30-90 days, support tickets for 2-3 years. Document your retention schedule and stick to it.

How to build your own data-export matrix

Use a spreadsheet with the following columns: Data category, Specific records, System, Controller/Processor, Export format, Retention period, Erasure action. Fill it in for every system you use. Review it quarterly and update when you add new services.

If you use a billing and automation platform like Teculiar, much of this data is centralised, which simplifies exports. Teculiar is a platform for hosting, domain, and VPS resellers to manage billing, provisioning, and support. Check what export capabilities your tools offer. For example, can you export all customer data in one click? Does it include domain and server details?

What to do next

  • List every system that holds customer data, including upstream providers.
  • Fill in the data-export matrix for each record type.
  • Test your export process with a dummy request to see how long it takes.
  • Review your retention periods and update your privacy policy.

Start by mapping your data today, so you are ready when the next request arrives.