Why data rights change the portal question
Most GDPR checklists for client portals stop at encryption and hosting region. Those matter, but they are the easy part. The hard part arrives on the day a client, an employee of a client or a former contact asks what you hold about them.
Under the GDPR a person can ask for access to their data (Article 15), for erasure (Article 17) and for a portable copy (Article 20). The firm has to respond within one month (Article 12), with a possible extension for complex requests. If client documents sit in inboxes, personal drives and old download folders, that month goes into searching. If they sit in one workspace per engagement, the same request takes an afternoon.
So the useful question is not only whether a portal is GDPR compliant. It is whether the portal makes your data rights workflow faster. For the wider compliance picture, see our GDPR client portal checklist for EMEA firms.
Data rights scorecard: email vs file sharing vs structured portal
How three common setups handle the six jobs a data rights request creates.
| Data rights job | Email and attachments | Generic file sharing | Structured client portal |
|---|---|---|---|
| 1Find every file for one client | |||
| 2Show who accessed what, and when | |||
| 3Limit access by role | |||
| 4Delete or return data at engagement end | |||
| 5Hand over a complete copy | |||
| 6Prove where data is stored |
The last row is yellow in every column on purpose. Hosting region, sub-processors and certification depend on the vendor, never on the category. Check them tool by tool.
Six client portals compared for data rights workflows
Six tools professional services firms often shortlist, and how each one supports the jobs above. Product details change, so confirm specifics with each vendor.
EU residency, ISO 27001 certification, structured requests, a white-label portal and an audit trail. Every document is tied to a request inside an engagement, so finding what you hold about one client starts from a single overview.
Branded portals, permissions and secure transfer that many firms already know.
Zero-knowledge end-to-end encryption, with Swiss and EU roots.
Hybrid storage with governance tooling and ISO 27001:2022.
Document management combined with a branded client portal.
Guided document requests with reminders.
For a longer list, see 8 GDPR client portals for service firms and how to choose a GDPR client portal.
Five questions to ask before you buy
Ask the vendor to show a single engagement with all requests, files and comments. If the answer involves searching folders by name, the access request will still be manual.
You need to show who viewed, uploaded, downloaded and approved each item. This is also what your own auditors and insurers ask for.
Payroll files and shareholder data should not be visible to the whole team. Roles on both the firm side and the client side keep access as narrow as the work allows.
Erasure requests and retention periods both need a clean way to archive, return or delete an engagement. Professional retention duties can override an erasure request, so you need control, not automatic deletion.
EU hosting, a signed data processing agreement and a current list of sub-processors are the minimum.
Alkmist at a glance
Frequently asked questions
What is a GDPR client portal?
A secure workspace where a firm and its clients exchange documents and requests, with access controls, an audit trail and hosting terms that support GDPR compliance. It replaces email attachments and shared folders for client work.
How does a client portal help with data subject access requests?
It keeps every file and message for an engagement in one place, linked to the client. When someone asks what you hold about them, you start from one overview instead of searching inboxes and drives.
Does a client portal make a firm GDPR compliant?
No tool does that alone. Compliance depends on your processes, contracts and retention policy. A portal removes the weakest link, which is client data scattered across email, and gives you the records to show what happened.
Can a firm refuse an erasure request?
Sometimes. Legal retention duties, for example for accounting and audit files, can take priority over erasure. A portal should let you archive or delete per engagement so you can apply the right rule case by case. Check your own obligations with your DPO or legal counsel.
See a GDPR-first client portal in practice
EU-hosted, ISO 27001 certified, with structured requests and a full audit trail.
Book a demo



.png)
