Right to Data Portability
The right to data portability lets individuals obtain the personal data they have provided to an organisation in a structured, commonly used, and machine-readable format, so they can reuse it or move it elsewhere. In some cases they can also ask the organisation to transmit that data directly to another organisation, where doing so is technically feasible. It is intended to give people more control over their personal data and to reduce the problem of data being locked into incompatible systems or 'silos'.
A data subject right established under Article 20 of the EU General Data Protection Regulation (Regulation 2016/679), and mirrored in the UK GDPR, entitling individuals to receive personal data concerning them, which they have provided to a controller, in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. Where technically feasible, the data subject may request that the controller transmit the data directly to another controller. As interpreted in EDPB (formerly WP29) guidance, the right generally applies only where the processing is based on the data subject's consent or on a contract and is carried out by automated means; it does not extend to all personal data a controller holds. The right is distinct from the general right of access and should be assessed against its specific scope and conditions. It is a legal obligation under the GDPR/UK GDPR rather than a voluntary standard, and its precise scope, exceptions, and enforcement should be verified against the current official regulatory text and supervisory authority guidance.
Why it matters
The right to data portability addresses a structural problem in digital markets: personal data becoming locked into incompatible systems, or what commentators describe as 'silos' or 'walled gardens'. By entitling individuals to receive the data they have provided in a structured, commonly used, and machine-readable format, the right is intended to give people greater control over their own information and to make it practical to move that information between service providers. For organisations, this shifts data from being a purely captive asset toward something the individual can, in defined circumstances, take with them.
For compliance teams, the practical significance lies in the specific and limited scope of the right. Unlike the general right of access, portability under Article 20 GDPR (and the mirrored provision in the UK GDPR) generally applies only where processing is based on the individual's consent or on a contract and is carried out by automated means. Misclassifying a request, or treating portability as coextensive with access, can lead either to over-disclosure or to failing to meet a valid request. Because the right also contemplates direct controller-to-controller transmission where technically feasible, organisations may need to consider interoperability and secure transfer mechanisms, not merely export functionality.
The precise boundaries of the right, its exceptions, and how supervisory authorities enforce it continue to be shaped by regulatory guidance and practice. Organisations should treat the statutory text and current guidance from the relevant supervisory authority as the controlling source rather than relying on general descriptions, and should verify the position applicable in their jurisdiction.
Who it's relevant to
Inside Right to Data Portability
Common questions
Answers to the questions practitioners most commonly ask about Right to Data Portability.

