Data Portability
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Right to receive and transfer personal data
Overview
12 sources · Jul 23, 2026Legal Framework
Article 20 GDPR establishes the right to data portability, allowing data subjects to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. This right applies where processing is carried out by automated means and is based either on Article 6(1)(b) GDPR (contract performance) or Article 6(1)(a) GDPR (consent). The provision serves a dual function: it empowers individuals to obtain a copy of their data and, where technically feasible, enables direct controller-to-controller transmission.
Recital 73 confirms that the right to data portability may be restricted by Union or Member State law where necessary and proportionate in a democratic society to safeguard public security, prevent crime, or protect other enumerated interests. Recital 156 further signals that processing for archiving, scientific research, or statistical purposes is subject to safeguards that may limit portability in practice.
The doctrinal commentary highlights that national implementing legislation must equip supervisory authorities with the power to bring infringements before judicial authorities. The Court of Justice confirmed in Schrems (C-362/14) that this obligation predated the GDPR under the 1995 Privacy Directive, and the Dutch legislature subsequently codified it through Article 78a of the Wbp, now reflected in the UAVG. This enforcement architecture is essential to making the portability right effective in practice.
Key Developments
The Schrems ruling (C-362/14, 6 October 2015) established that national supervisory authorities are independently responsible for verifying whether transfers of personal data comply with EU requirements, even where an adequacy decision exists. While Schrems addressed international transfers rather than portability per se, it reinforced the principle that data subjects must have effective remedies when controllers fail to facilitate data movement.
In Bara (C-201/13, 1 October 2015), the Court of Justice addressed information obligations under Directive 95/46, holding that national law cannot substitute for the controller's duty to inform data subjects about recipients of their data. This reasoning extends to the portability context: controllers cannot rely on generic legal frameworks to discharge their obligation to explain how and to whom data will be transmitted.
The EDPB's Guidelines 3/2018 on territorial scope clarify when non-EU controllers must honor portability requests, broadening compliance obligations for entities targeting EU data subjects.
Practical Guidance
Verify the legal basis before refusing a portability request. Article 20 applies only where processing relies on consent or contract performance. Requests tied to legitimate interests or legal obligations fall outside the portability right, though access under Article 15 may still apply.
Provide data in a structured, machine-readable format. CSV, JSON, or XML formats satisfy the requirement. PDF exports alone are insufficient where the original data is stored in a structured database.
Assess technical feasibility for direct transmission. Where a data subject requests controller-to-controller transfer, Article 20 requires this only where technically feasible. Document the feasibility assessment and any technical limitations invoked as grounds for refusal.
Establish internal procedures with clear timelines. Portability requests must be handled without undue delay and within one month under Article 12(3). Implement automated export tools where volume warrants, and train front-line staff to recognize and route portability requests distinct from general access requests.
Map which datasets are portable. Not all personal data falls within scope—only data "provided by" the data subject. Inferred data, profiling outputs, and controller-generated analytics may be excluded, but this boundary remains contested and should be assessed conservatively.