The Right to Data Portability — Article 20 GDPR in Practice
The right to data portability is one of the most “digital” rights granted by the GDPR — and one of the most frequently confused. It lets a person retrieve their data in a machine-readable format and move it to another provider, without having to re-enter everything from scratch. Its purpose is to increase users’ control over their own data and make it easier to switch providers — for example a social network, a bank or a streaming service.
In practice, the right under Article 20 GDPR is often confused with the right of access (Article 15) and applies more narrowly than is commonly assumed — only for certain processing bases and only to data processed by automated means. At the same time, its importance is growing: the direction of “data portability” is reinforced by new regulations such as the Data Act and open banking.
This article explains what the right to data portability is, when it applies, which data it covers, in what format and time frame it should be fulfilled, and how a controller should prepare for it.
What the Right to Data Portability Is
Under Article 20 GDPR, the data subject has the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format, and to transmit that data to another controller without hindrance from the controller to which it was provided. In addition, where technically feasible, the person has the right to have the data transmitted directly from one controller to another.
The right therefore consists of two elements: the ability to receive one’s own data in a “ready-to-move” format, and the ability to pass it to another entity. The aim is to avoid a “lock-in” effect with a single provider and genuinely facilitate migration.
When the Right to Data Portability Applies
This is the most important — and most frequently overlooked — element. The right to data portability applies only where two conditions are met cumulatively:
The basis of processing is consent or a contract. This means processing based on consent (Article 6(1)(a) or Article 9(2)(a)) or on the performance of a contract (Article 6(1)(b)).
The processing is carried out by automated means. The right does not cover records kept solely in paper form.
This means the right to data portability does not apply where processing is based on a legal obligation, legitimate interest, a task carried out in the public interest or the protection of vital interests. So if a controller processes data, for example, on the basis of tax legislation or its legitimate interest, a request to port such data has no basis — although the person may exercise other rights, including the right of access.
Which Data the Right Covers
The right covers only the data “provided” to the controller by the data subject. According to the data protection authorities’ guidance, this concept is interpreted broadly and covers two categories:
Data provided actively and knowingly — for example registration-form data, an address, the content of posts.
Observed data — generated by the person’s activity when using the service, such as search history, purchase history, location data or raw data from a wearable device.
The right does not, however, cover “derived” or “inferred” data — that is, information created by the controller on the basis of the person’s data, such as profiles, credit scores or categorisation results. This data is the result of the controller’s analysis, not data provided by the person, and remains outside the scope of Article 20.
Format and Fulfilment
The GDPR requires the data to be provided in a structured, commonly used and machine-readable format — in practice this means formats such as CSV, JSON or XML, rather than, say, a PDF scan or a printout. The point is that the data can actually be loaded into another controller’s system, not merely read by eye. The right encourages interoperability of formats, though it does not impose a specific standard.
If the person so requests, and it is technically feasible, the controller should transmit the data directly to another controller. At the same time, the GDPR does not oblige controllers to implement or maintain systems that are technically compatible with those of other entities — “technical feasibility” is assessed realistically, case by case.
Third Parties’ Rights
Fulfilling the right to data portability must not adversely affect the rights and freedoms of others. A problem arises where the ported data contains information about third parties — for example contacts in an address book or data of other participants in correspondence. The controller should provide the data in a way that does not infringe those persons’ rights, and the new controller that receives it may use it only within the limits of the GDPR and for the purpose for which the person porting the data uses it.
Data Portability vs the Right of Access (Article 15)
These two rights are often confused, though they differ significantly. The right of access (Article 15) is broader as to the scope of data — it covers all of the person’s data, regardless of the processing basis — but does not require providing it in a machine-readable format or transmitting it to another controller. The right to portability (Article 20) is narrower as to basis and scope (consent/contract only, provided data only, automated processing only), but it does include provision in a machine format and the ability to transmit it to another entity. In practice, a person may submit both requests at once.
Time Frame and Costs
A portability request is handled under the general rules on data subjects’ rights. The controller should respond without undue delay, and no later than within one month of receiving the request; this may be extended by a further two months given the complexity or number of requests, with the person informed. Fulfilment of the right is, as a rule, free of charge. Before releasing the data, the controller should verify the identity of the person making the request, so as not to disclose data to an unauthorised person.
Portability Does Not Mean Erasure
An important misconception: exercising the right to data portability does not automatically erase the data at the original controller. If the controller still has a basis for processing (for example, a contract is ongoing), it may continue processing despite providing a copy of the data. Erasure is a separate right — the right to be forgotten — which the person may exercise independently, where its conditions are met.
Where Data Portability Matters Most
The right to data portability gains importance especially where the ease of switching providers genuinely affects competition and user convenience: in banking and payments (where open banking complements it), in telecommunications and energy, in social media, e-commerce, streaming services, and in health apps and wearable devices. The direction of “portability” is also reinforced by the Data Act, which introduces a broader right of access to data from IoT products and services — covering non-personal data too and, where possible, transmission in real time.
How a Controller Should Prepare
To handle portability requests smoothly, it is worth:
- Identifying the processing that qualifies for the portability right (basis: consent or contract; means: automated).
- Pinpointing the data covered — provided and observed — and separating it from derived data and third-party data.
- Preparing an export mechanism in a machine format (e.g. self-service data download, export to CSV/JSON, an API where needed).
- Implementing identity verification of the requester.
- Drawing up a procedure for handling requests within the one-month deadline.
- Informing about the right in the privacy notice (Articles 13 and 14 GDPR).
Common Mistakes
Confusing portability with the right of access and using them interchangeably.
Fulfilling the right on the wrong basis — e.g. under legitimate interest or a legal obligation, where the right does not apply.
Providing data in a non-machine-readable format (a scan, PDF, printout).
Porting derived and inferred data that is not covered by the right.
Overlooking the rights of third parties present in the ported data.
No identity verification of the requester.
Assuming that porting means erasing the data at the original controller.
Checklist — The Right to Data Portability
- Establish which processes are based on consent or a contract and are automated.
- Identify the provided and observed data covered by the right.
- Exclude derived, inferred and third-party data from the scope.
- Prepare an export in a machine format (CSV, JSON, XML).
- Enable direct transmission of data where technically feasible.
- Implement identity verification of the requester.
- Establish a procedure and time frame (one month, extendable).
- Inform about the right in your privacy notices.
- Remember that porting does not remove the need to assess a separate erasure request.
Need Help with Data Subjects’ Rights and Article 20 GDPR?
The right to data portability can be tricky in practice — from establishing whether it applies at all, to preparing an export in the right format and separating out derived data. At the Law Office of Dr Joanna Maniszewska-Ejsmont, we help prepare procedures for handling data subjects’ requests, privacy notices and mechanisms for fulfilling GDPR rights — including the right to data portability.
Contact us — we will help you implement the handling of data subjects’ rights in your organisation in line with the GDPR.
