The General Data Protection Regulation (GDPR) introduced several new individual rights intended to strengthen control over personal data in a digital economy. Among these, the Right to Data Portability, set out in Article 20 GDPR, is one of the most technically demanding and conceptually distinctive.

The right to data portability enables individuals to receive certain categories of their personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another service provider. For businesses, this right introduces both legal and operational obligations, particularly where services rely heavily on automated processing and user-generated data.

This page explains the scope and purpose of the right to data portability, what data is covered, how it differs from other data-subject rights, and how supervisory authorities assess compliance in practice.

Legal Basis and Purpose of the Right to Data Portability

Article 20 GDPR provides that a data subject has the right to receive the personal data concerning them which they have provided to a controller, in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance. Where technically feasible, the individual also has the right to request direct transmission of data from one controller to another.

The legislative intent behind this right is broader than individual transparency. Unlike the right of access, which primarily supports accountability and oversight, data portability was introduced to enhance individual control over personal data, reduce vendor lock-in in digital services, promote competition and innovation by enabling switching between providers, and support interoperability in data-driven markets.

This economic and structural dimension distinguishes data portability from most other GDPR rights.

When Does the Right to Data Portability Apply?

The right to data portability is not universal. Article 20 applies only where specific conditions are met. The processing must be based on consent or contract: data portability applies only where personal data is processed on the basis of consent (Article 6(1)(a) GDPR or Article 9(2)(a)) or necessity for the performance of a contract (Article 6(1)(b)).

Processing based on legal obligation, public interest, vital interests, or legitimate interests does not fall within Article 20’s scope. The processing must also be carried out by automated means — purely manual processing is excluded. The right applies to data processed in automated systems, such as databases, digital platforms, and cloud services. Finally, the request must concern personal data provided by the data subject.

What Does “Data Provided by the Data Subject” Mean?

One of the most misunderstood aspects of data portability is the concept of “data provided by the data subject.” Supervisory authorities have clarified that this includes more than data actively submitted through forms.

According to EDPB-endorsed guidelines, portable data includes actively provided data, such as names, email addresses, profile details, uploaded files, messages, and preferences, as well as observed data, such as location data, usage logs, search history, or activity data generated through use of a service.

However, the right does not extend to derived or inferred data, such as behavioural profiles, credit scores, risk assessments, or analytics outputs generated by the controller, or to internal annotations or evaluations unrelated to data provided by the individual. This distinction is critical for businesses offering analytics-driven or personalised services.

Structured, Commonly Used, and Machine-Readable Formats

Article 20 requires that personal data be provided in a format that enables reuse and interoperability. While the GDPR does not mandate specific technical standards, supervisory authorities consistently reference formats such as CSV, JSON, and XML.

Formats should allow data to be easily imported into another system without manual intervention. Providing scanned PDFs or unstructured exports will generally not satisfy this requirement. The emphasis is on practical usability, not mere disclosure.

Direct Transmission Between Controllers

In addition to receiving a copy, individuals may request that their data be transmitted directly from one controller to another, where technically feasible.

This obligation does not require controllers to build new systems or APIs in all cases. However, regulators expect organisations to assess feasibility honestly and not rely on technical barriers as a default refusal.

Where direct transmission is not technically feasible, controllers must still provide the data to the individual in a portable format without hindrance.

Time Limits and Procedural Requirements

Data portability requests are subject to the same procedural framework as other GDPR rights: responses must be provided without undue delay and within one month; the deadline may be extended by up to two additional months for complex requests, with notice given within the first month; and the service is generally free of charge for the first copy.

Supervisory authorities treat missed deadlines and partial responses as clear compliance failures, particularly where organisations receive recurring portability requests.

Data Portability vs. Right of Access

Although both rights involve providing personal data to individuals, Article 20 and Article 15 serve different functions. Key differences include: scope (access covers all personal data relating to an individual; portability covers only data provided by the individual), purpose (access supports transparency and oversight; portability supports reuse and switching), and format (portability requires machine-readable, reusable formats; access does not always require this level of technical structuring).

Controllers must assess requests carefully to determine which right applies—or whether both apply concurrently.

Limits and Safeguards: Protecting the Rights of Others

Article 20 expressly provides that the right to data portability must not adversely affect the rights and freedoms of others.

This may arise where data sets include information relating to multiple individuals, such as shared communications, group activity logs, or collaborative content. In such cases, controllers may need to redact third-party data, provide partial data sets, or balance competing rights.

This safeguard mirrors similar limitations under the right of access and requires a contextual, case-by-case assessment.

Interaction with Other GDPR Rights

The right to data portability exists alongside—and does not replace—other rights, including the right to access (Article 15), the right to rectification (Article 16), and the right to erasure (Article 17).

Importantly, Article 20 specifies that exercising portability is without prejudice to the right to erasure. In other words, a portability request does not automatically trigger deletion obligations, nor does deletion negate prior portability rights.

Practical Impact on Businesses

From a business perspective, data portability presents several compliance challenges: system design (services must be able to extract and export relevant data subsets), data classification (organisations must distinguish portable data from derived data), security (portability increases the risk of unauthorised disclosure if authentication and delivery processes are weak), and scalability (high-volume services may receive large or repeated requests).

Regulators regard data portability as a design-time obligation rather than a reactive compliance task. Organisations that fail to account for portability during system development face increasing remediation costs later.

Sector-Specific Relevance

Data portability has particular relevance in sectors such as digital platforms and online services, telecommunications, financial services, health and fitness technologies, and IoT-enabled consumer products.

In these contexts, data portability plays both a regulatory and competitive role, shaping how users interact with ecosystems over time.

Enforcement Trends and Regulatory Scrutiny

While data portability complaints are less frequent than access complaints, supervisory authorities increasingly view Article 20 as a test of technical compliance maturity.

Regulators expect organisations not only to know what data is portable, but to be able to explain and justify exclusions with reference to the law. Unsupported claims that data is “derived” or “technically infeasible” often attract closer scrutiny.

The EDPB guidelines consistently emphasise good-faith implementation and avoidance of artificial barriers.

Integrating Data Portability into Governance

Mature GDPR programmes integrate data portability into broader governance frameworks, including data mapping and classification exercises, Article 30 records of processing, privacy-by-design processes, and data subject rights workflows.

Organisations that treat portability as an afterthought often struggle to deliver compliant responses within required timeframes.

Conclusion

The Right to Data Portability under Article 20 GDPR represents a shift in how personal data rights intersect with digital markets. It empowers individuals not only to see their data, but to take it with them—to reuse, transfer, and control it across services.

For businesses, compliance requires more than legal awareness. It requires technical preparedness, clear data governance, and an understanding of what portability does—and does not—require.

Organisations that design systems and processes with portability in mind are better positioned to meet regulatory expectations, support user trust, and adapt to evolving data-driven markets.

See Also