Skip to content
Topic Contested in court

Data Portability

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Right to receive and transfer personal data

46 linked items 4 Laws10 Case Law17 Guidance15 News

Overview

12 sources · Jul 23, 2026

Legal Framework

Article 20 GDPR establishes the right to data portability, allowing data subjects to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. This right applies where processing is carried out by automated means and is based either on Article 6(1)(b) GDPR (contract performance) or Article 6(1)(a) GDPR (consent). The provision serves a dual function: it empowers individuals to obtain a copy of their data and, where technically feasible, enables direct controller-to-controller transmission.

Recital 73 confirms that the right to data portability may be restricted by Union or Member State law where necessary and proportionate in a democratic society to safeguard public security, prevent crime, or protect other enumerated interests. Recital 156 further signals that processing for archiving, scientific research, or statistical purposes is subject to safeguards that may limit portability in practice.

The doctrinal commentary highlights that national implementing legislation must equip supervisory authorities with the power to bring infringements before judicial authorities. The Court of Justice confirmed in Schrems (C-362/14) that this obligation predated the GDPR under the 1995 Privacy Directive, and the Dutch legislature subsequently codified it through Article 78a of the Wbp, now reflected in the UAVG. This enforcement architecture is essential to making the portability right effective in practice.

Key Developments

The Schrems ruling (C-362/14, 6 October 2015) established that national supervisory authorities are independently responsible for verifying whether transfers of personal data comply with EU requirements, even where an adequacy decision exists. While Schrems addressed international transfers rather than portability per se, it reinforced the principle that data subjects must have effective remedies when controllers fail to facilitate data movement.

In Bara (C-201/13, 1 October 2015), the Court of Justice addressed information obligations under Directive 95/46, holding that national law cannot substitute for the controller's duty to inform data subjects about recipients of their data. This reasoning extends to the portability context: controllers cannot rely on generic legal frameworks to discharge their obligation to explain how and to whom data will be transmitted.

The EDPB's Guidelines 3/2018 on territorial scope clarify when non-EU controllers must honor portability requests, broadening compliance obligations for entities targeting EU data subjects.

Practical Guidance

  • Verify the legal basis before refusing a portability request. Article 20 applies only where processing relies on consent or contract performance. Requests tied to legitimate interests or legal obligations fall outside the portability right, though access under Article 15 may still apply.

  • Provide data in a structured, machine-readable format. CSV, JSON, or XML formats satisfy the requirement. PDF exports alone are insufficient where the original data is stored in a structured database.

  • Assess technical feasibility for direct transmission. Where a data subject requests controller-to-controller transfer, Article 20 requires this only where technically feasible. Document the feasibility assessment and any technical limitations invoked as grounds for refusal.

  • Establish internal procedures with clear timelines. Portability requests must be handled without undue delay and within one month under Article 12(3). Implement automated export tools where volume warrants, and train front-line staff to recognize and route portability requests distinct from general access requests.

  • Map which datasets are portable. Not all personal data falls within scope—only data "provided by" the data subject. Inferred data, profiling outputs, and controller-generated analytics may be excluded, but this boundary remains contested and should be assessed conservatively.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 4
Art. 13(2)(b) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concern… GDPR Art. 14(2)(c) the existence of the right to request from the controller access to and rectification or erasure of personal data or restriction of processing concern… GDPR Art. 20(1) The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structure… GDPR Art. 20(2) In exercising his or her right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitte… GDPR art 20 Right to data portability GDPR Apr 2016 rec 68 Recital 68 — data subject data portability right GDPR Apr 2016 rec 73 Recital 73 — lawful restrictions on data subject rights GDPR Apr 2016 rec 156 Recital 156 — safeguards for archiving research processing GDPR Apr 2016
Case Law 10
CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 CJEU Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems CJEU Jul 2020 CJEU Data Protection Commissioner v. Schrems and Facebook CJEU Oct 2015 CJEU SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”) CJEU Oct 2015 CJEU DENNEKAMP V. EUROPEAN PARLIAMENT (15.7.2015) (“DENNEKAMP II”) CJEU Jul 2015 CJEU PARLIAMENT V. COUNCIL (PNR) CJEU May 2006 CJEU SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”) CJEU Oct 2015 CJEU V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”) CJEU Jul 2011 CJEU SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”) CJEU Oct 2015
Guidance 17
guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 guidelines on certification as a tool for transfers Guidelines 07/2022 on certification as a tool for transfers EDPB Feb 2023 guidelines on deceptive design patterns in social media platform interfaces how to recognise Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them EDPB Feb 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 guidelines on processing personal data in the context of connected vehicles and mobility rel Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Jan 2020 guidelines on the territorial scope of the gdpr Guidelines 3/2018 on the territorial scope of the GDPR (Article 3) EDPB Nov 2019 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 guidelines on derogations of article 49 Guidelines 2/2018 on derogations of Article 49 under Regulation 2016/679 EDPB May 2018 guidelines on the use of facial recognition technology in the area of law enforcement Guidelines 05/2022 on the use of facial recognition technology in the area of law enforcement EDPB May 2023 guidelines on virtual voice assistants Guidelines 02/2021 on virtual voice assistants EDPB Jul 2021 guidelines on transparency Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01) EDPB Nov 2025 van de tekst in de afbeeldingen in de bijlage Translations proofread by EDPB Members. This language version has not yet been proofread. EDPB Nov 2025
News 15
EDPB Draft adequacy decision for Brazil: EDPB adopts opinion EDPB Nov 2025 DataGuidance Hunton summarises two articles from the new SCCs: the 'local laws and government access' section DataGuidance Oct 2022 IAPP The EU-US Data Privacy Framework: A new era for data transfers? IAPP Oct 2022 Future of Privacy Forum What Happened to the Risk-Based Approach to Data Transfers? Future of Privacy Forum Sep 2022 eucrim CJEU: PNR Directive Valid if Limited to the “Strictly Necessary” eucrim Aug 2022 Politico European regulators are finalizing a decision blocking Meta from transferring data to the US Politico Aug 2022 Garante Privacy Italian SA bans use of Google Analytics. No adequate safeguards for data transfers to the USA Garante Privacy Jun 2022 Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 EURactiv European Commission sued for violating EU’s data protection rules EURactiv Jul 2022 Kromann Reumert DeFine is a calculator for GDPR fines based on method of the EDPB Kromann Reumert Feb 2022 Brooklyn Law School Digital Privacy Rights and CLOUD Act Agreements between US and UK Brooklyn Law School Sep 2022 EURactiv European Commission sued for violating transfer rules by using Amazon Web Services EURactiv Jul 2022 Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 IAPP Meta to change UK terms of service, maintain data flows IAPP Feb 2023 Hunton Andrews Kurth Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations Hunton Andrews Kurth Sep 2022