How should we provide the data to individuals?
If an individual makes a request electronically, you should provide the information in a commonly used electronic format, unless the individual requests otherwise.
The GDPR includes a best practice recommendation that, where possible, organisations should be able to provide remote access to a secure self-service system which would provide the individual with direct access to his or her information (Recital 63). This will not be appropriate for all organisations, but there are some sectors where this may work well.
However, providing remote access should not adversely affect the rights and freedoms of others – including trade secrets or intellectual property.
Ref: https://ico.org.uk/for-organisations/guide-to-the-general-da...
Going out of your way to make the response useless is probably not a good idea.
* Ironically, people are using Google Drive to do this.
This makes me wonder: what if you encrypt using a proprietary tool, and sell a decryption tool through another company? You could actually make money from GDPR requests.