Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Data Subject Rights

Right to Data Portability

Also known as: Data Portability, Right to Data Portability under Article 20 GDPR
Simply put

The right to data portability lets individuals obtain the personal data they have provided to an organisation in a structured, commonly used, and machine-readable format, so they can reuse it or move it elsewhere. In some cases they can also ask the organisation to transmit that data directly to another organisation, where doing so is technically feasible. It is intended to give people more control over their personal data and to reduce the problem of data being locked into incompatible systems or 'silos'.

Formal definition

A data subject right established under Article 20 of the EU General Data Protection Regulation (Regulation 2016/679), and mirrored in the UK GDPR, entitling individuals to receive personal data concerning them, which they have provided to a controller, in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. Where technically feasible, the data subject may request that the controller transmit the data directly to another controller. As interpreted in EDPB (formerly WP29) guidance, the right generally applies only where the processing is based on the data subject's consent or on a contract and is carried out by automated means; it does not extend to all personal data a controller holds. The right is distinct from the general right of access and should be assessed against its specific scope and conditions. It is a legal obligation under the GDPR/UK GDPR rather than a voluntary standard, and its precise scope, exceptions, and enforcement should be verified against the current official regulatory text and supervisory authority guidance.

Why it matters

The right to data portability addresses a structural problem in digital markets: personal data becoming locked into incompatible systems, or what commentators describe as 'silos' or 'walled gardens'. By entitling individuals to receive the data they have provided in a structured, commonly used, and machine-readable format, the right is intended to give people greater control over their own information and to make it practical to move that information between service providers. For organisations, this shifts data from being a purely captive asset toward something the individual can, in defined circumstances, take with them.

For compliance teams, the practical significance lies in the specific and limited scope of the right. Unlike the general right of access, portability under Article 20 GDPR (and the mirrored provision in the UK GDPR) generally applies only where processing is based on the individual's consent or on a contract and is carried out by automated means. Misclassifying a request, or treating portability as coextensive with access, can lead either to over-disclosure or to failing to meet a valid request. Because the right also contemplates direct controller-to-controller transmission where technically feasible, organisations may need to consider interoperability and secure transfer mechanisms, not merely export functionality.

The precise boundaries of the right, its exceptions, and how supervisory authorities enforce it continue to be shaped by regulatory guidance and practice. Organisations should treat the statutory text and current guidance from the relevant supervisory authority as the controlling source rather than relying on general descriptions, and should verify the position applicable in their jurisdiction.

Who it's relevant to

Data Protection Officers and Privacy Teams
DPOs and privacy staff need to distinguish portability requests from general access requests and to identify whether the underlying processing rests on consent or contract and is automated, since the right generally applies only in those circumstances. They are typically responsible for ensuring requests are correctly classified and handled within the applicable framework.
Controllers Processing Personal Data by Automated Means
Organisations acting as controllers that process personal data based on consent or a contract, and by automated means, are the parties on whom the obligation falls. They may need to provide data in a structured, commonly used, and machine-readable format and, where technically feasible, transmit it directly to another controller.
Product, Engineering, and IT Teams
Delivering portability in practice depends on export functionality and, where relevant, on the technical feasibility of direct controller-to-controller transmission. Engineering and IT teams are relevant to implementing structured, machine-readable formats and secure transfer mechanisms that support interoperability and reduce data lock-in.
Legal and Compliance Counsel
Because the scope, exceptions, and enforcement of the right are set by the GDPR and UK GDPR text and supervisory authority guidance, legal and compliance professionals are relevant to assessing how the right applies to specific processing activities and jurisdictions. Application to particular circumstances requires professional judgment and verification against current authoritative sources.

Inside Right to Data Portability

Scope of the right
A right established under the EU GDPR (and mirrored in the UK GDPR) allowing data subjects to receive personal data they have provided to a controller, and in certain cases to have it transmitted directly to another controller. It generally applies only where processing is based on consent or on a contract, and is carried out by automated means.
Data covered
Typically limited to personal data the data subject has actively provided or that has been observed through their use of a service. Data derived or inferred by the controller (for example, a profile or credit score created through analysis) is generally understood to fall outside the scope, though interpretations continue to evolve.
Format requirement
Where the right applies, the data should generally be provided in a structured, commonly used, and machine-readable format so that it can be reused and transferred, rather than in a format that impedes portability.
Direct transmission
Where technically feasible, the data subject may request transmission of the data directly from one controller to another. Feasibility is assessed case by case, and there is no general obligation to build interoperable systems for this purpose.
Relationship to other rights
Data portability is distinct from the right of access, though the two are related. Access concerns obtaining a copy of and information about processing, while portability concerns reuse and transfer in a machine-readable form under narrower legal bases.
Limitations and safeguards
The right must not adversely affect the rights and freedoms of others, which is particularly relevant where provided data also contains information about third parties. It is subject to conditions on legal basis and processing method and is not an unlimited entitlement.

Common questions

Answers to the questions practitioners most commonly ask about Right to Data Portability.

Does the right to data portability apply to all personal data an organization holds about an individual?
No. This is a common misconception. The right to data portability is generally narrower than the broader right of access. It typically applies only to personal data that the individual has provided to the controller and that is processed on the basis of consent or the performance of a contract, and where the processing is carried out by automated means. Data derived or inferred by the organization, or personal data processed under other legal bases, generally falls outside its scope. The precise conditions should be verified against the current official text of the applicable regulation, as interpretation continues to evolve.
Is data portability just another name for the right of access?
No. Although the two rights overlap because both concern personal data relating to the individual, they are distinct. The right of access generally entitles a person to obtain a copy of their personal data and information about how it is processed, often in a human-readable form. The right to data portability is narrower in scope but adds a specific requirement to provide the data in a structured, commonly used and machine-readable format, and in some cases to have it transmitted directly to another controller. Treating them as identical risks under- or over-delivering on a given request.
In what format should data be provided in response to a portability request?
The right generally requires that the data be provided in a structured, commonly used and machine-readable format, so that it can be reused and, where feasible, transmitted to another service. The regulation typically does not mandate one specific file type; the emphasis is on interoperability rather than a named standard. Organizations should assess what format best supports reuse for the data in question, and should verify current regulatory guidance and any sector-specific expectations rather than assuming a single universal format applies.
Is an organization obliged to transmit data directly to another provider?
Direct transmission from one controller to another is generally required only where it is technically feasible. The individual may request that their data be sent directly to another organization, but the obligation is qualified by feasibility, and there is typically no requirement to adopt or maintain technically compatible systems with other controllers. What counts as feasible is fact-specific. Organizations should document their assessment and verify current guidance, as enforcement practice and interpretation in this area continue to develop.
How does data portability interact with the rights of third parties whose data may be included?
Responding to a portability request should generally not adversely affect the rights and freedoms of others. Where the data an individual provided also relates to third parties, organizations typically need to consider how to satisfy the request without unfairly compromising those third parties' rights. This is a fact-specific balancing exercise, and the appropriate approach depends on the circumstances and the applicable regulatory guidance. Application to a particular case requires professional judgment.
Can an organization charge a fee or refuse a portability request?
As a general matter, responding to a portability request is expected to be handled without charge, though specific rules on fees, timelines, and grounds for refusing or extending responses vary by regulation and can depend on factors such as whether a request is manifestly unfounded or excessive. Because these thresholds and any permitted charges are defined in the applicable law and may be interpreted differently across jurisdictions, organizations should verify the exact conditions against the current official text and relevant regulatory guidance rather than assuming a fixed rule.

Common misconceptions

The right to data portability applies to all personal data a controller holds.
It generally applies only to data the data subject provided, where processing is based on consent or a contract and carried out by automated means. Data based on other legal grounds, or data inferred or derived by the controller, typically falls outside its scope.
Data portability is the same as the right of access.
They are distinct rights. Access lets a data subject obtain a copy of their data and information about its processing, while portability focuses on receiving certain data in a structured, machine-readable format for reuse or transfer, under narrower conditions.
Controllers must always transmit data directly to a competitor or another provider on request.
Direct controller-to-controller transmission is required only where technically feasible, and there is generally no obligation to adopt or maintain technically compatible systems solely to enable such transfers.

Best practices

Map which processing activities rely on consent or contract and are automated, so you can identify where the portability right actually applies rather than treating all data as in scope.
Distinguish data provided or observed by the data subject from data you have derived or inferred, and document the basis for excluding derived data from a portability response.
Establish a repeatable process to export in-scope data in a structured, commonly used, and machine-readable format, and be prepared to justify the format chosen.
Assess technical feasibility before committing to direct controller-to-controller transmission, and record the reasoning where such transfer is declined.
Build safeguards to prevent disclosure of third-party personal data contained within a data subject's records when responding to portability requests.
Verify obligations against the current text of the applicable regime (EU GDPR, UK GDPR, or other jurisdiction) and relevant regulatory guidance, since interpretation and enforcement practice continue to develop; treat this entry as informational and seek professional judgment for specific cases.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps