If they ask for something specific in an informal way, that can be provided
But from the GDPRs data portability point of view, it's everything that's linked to the account. Export your Facebook data for a good example of this.
HN example: it would be the information in your profile, the links/text you submitted (but not the content of the link itself), the comments (the comment IDs) you upvoted, stories flagged/upvoted (for the lenght of time this is kept, for example, if after a while user ids that upvoted a comment are erased and only the score is kept, that's fine) and maybe some other background information (for example: password hashes/access logs/etc)
> what format that information needs to be in,
Machine readable format. HTML/XML/JSON is fine.
> how to locate it and package it, and whether new infrastructure needs to be created to manage this request pipeline.
Well that's not the problem of the law, is it?
You know your data scheme. You know whether you can run this in your existing infrastructure or not.
for TABLE in YOUR_TABLES
SELECT * from TABLE where UserID == $user_id;
end for