I haven't commented so far because I don't realistically see a change made in this in the upcoming days, although I agree the current system may seem a bit blurry.
On a user perspective, you are just willing to access your own data, which is more than fair. On xat side, if an individual requests for their data, they cannot confirm whether the individual asking is actually the content owner.
What this means is that xat also has the right to ask you for a personal ID (passport, national ID card, ...) before handing you out your data. This is also part of GDPR and the 30 days cou