Two things live here, and they are not the same. Export is you taking your data out. Erasure requests are members asking to be removed, and those come with a legal clock attached.
Exporting members
From the member list, choose export. You decide what goes into the file and in which format.
- System fields, the built-in ones such as name, email, status and dates.
- Custom fields, the ones you defined yourself.
- More data, the extras beyond the profile itself.
The file comes as CSV, Excel or JSON. CSV for another system, Excel for a person, JSON when something will read it programmatically.
Your column selection is remembered, so the export you build once is a click next time.
Filter before you export. The file covers everything your current search and filters return, so narrowing the list first is what gets you the fifty people you were asking about instead of all four thousand. Ticking rows does not change it.
To export only the rows you tick, tick them in the list and open More in the bar that appears and choose Export CSV. That file is always CSV with the standard columns, so the column and format choices above do not apply.
One member's own data
When a single person asks for a copy of their data, the list export is the wrong tool. Open their profile, go to Security, and use Export data (GDPR).
You get a ZIP file with everything stored about that member: profile and membership, tags and custom fields, access and course progress, orders and subscriptions, community activity, sign-ins, devices and files. That is the answer to an access request under Art. 15 GDPR.
Erasure requests
When a member asks to have their account erased, the request appears on the data requests page. It is a queue, and every item in it carries a deadline.

The deadline
The law gives you 30 days from the request. Each item shows how many days are left, and an item past that point is marked overdue.
You can sort the queue by most urgent, so the item closest to its deadline is the one you see first. On a normal week the list is short and this takes minutes.
The deadline is not advisory. Leaving requests unanswered is a compliance problem, not an inbox problem.
Erasing an account
Opening a request shows the member, when they asked, and any reason they gave.
Erasing is permanent, so you confirm twice: you tick that you understand it cannot be undone, and only then does the button work.
What happens is precise.
| Removed | Kept |
|---|---|
| Name, email, address, avatar | Orders, invoices and payments, anonymised |
| Logins, sessions and API tokens |
The account is anonymised rather than deleted from existence, because financial records have to survive. Your books stay correct and complete, and nothing in them points back at a person any more.
There is no undo. Once an account is erased, you cannot restore the person's name or reach them again. Be sure the request is genuine and from the account holder.
Rejecting a request
Not every request has to be granted. If there is a lawful reason to refuse, you can reject it, and the reason is recorded with the request.
Rejecting is for genuine grounds, such as an open legal obligation. It is not for inconvenience.
Deletion outside the queue
You can also delete a member directly from their profile, and that has its place for a test account or a duplicate you created.
For anything that started as a request from the person, go through the queue. That way the request, the decision and the date of the erasure sit in one place if anyone ever asks you to show your work.
Contacts
Contacts are handled from the contacts list rather than here. An unsubscribe is not an erasure. An unsubscribed contact stays on your list with their address suppressed, so you can prove they must not be emailed.