# Data Portability — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/data-portability
> Sources are cited per item. Verify against the official texts before relying on them.

Right to receive and transfer personal data

## Overview

## Legal Framework

Article 20 GDPR establishes the right to data portability, allowing data subjects to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. This right applies where processing is carried out by automated means and is based either on Article 6(1)(b) GDPR (contract performance) or Article 6(1)(a) GDPR (consent). The provision serves a dual function: it empowers individuals to obtain a copy of their data and, where technically feasible, enables direct controller-to-controller transmission.

Recital 73 confirms that the right to data portability may be restricted by Union or Member State law where necessary and proportionate in a democratic society to safeguard public security, prevent crime, or protect other enumerated interests. Recital 156 further signals that processing for archiving, scientific research, or statistical purposes is subject to safeguards that may limit portability in practice.

The doctrinal commentary highlights that national implementing legislation must equip supervisory authorities with the power to bring infringements before judicial authorities. The Court of Justice confirmed in *Schrems* (C-362/14) that this obligation predated the GDPR under the 1995 Privacy Directive, and the Dutch legislature subsequently codified it through Article 78a of the Wbp, now reflected in the UAVG. This enforcement architecture is essential to making the portability right effective in practice.

## Key Developments

The *Schrems* ruling (C-362/14, 6 October 2015) established that national supervisory authorities are independently responsible for verifying whether transfers of personal data comply with EU requirements, even where an adequacy decision exists. While *Schrems* addressed international transfers rather than portability per se, it reinforced the principle that data subjects must have effective remedies when controllers fail to facilitate data movement.

In *Bara* (C-201/13, 1 October 2015), the Court of Justice addressed information obligations under Directive 95/46, holding that national law cannot substitute for the controller's duty to inform data subjects about recipients of their data. This reasoning extends to the portability context: controllers cannot rely on generic legal frameworks to discharge their obligation to explain how and to whom data will be transmitted.

The EDPB's Guidelines 3/2018 on territorial scope clarify when non-EU controllers must honor portability requests, broadening compliance obligations for entities targeting EU data subjects.

## Practical Guidance

- **Verify the legal basis before refusing a portability request.** Article 20 applies only where processing relies on consent or contract performance. Requests tied to legitimate interests or legal obligations fall outside the portability right, though access under Article 15 may still apply.

- **Provide data in a structured, machine-readable format.** CSV, JSON, or XML formats satisfy the requirement. PDF exports alone are insufficient where the original data is stored in a structured database.

- **Assess technical feasibility for direct transmission.** Where a data subject requests controller-to-controller transfer, Article 20 requires this only where technically feasible. Document the feasibility assessment and any technical limitations invoked as grounds for refusal.

- **Establish internal procedures with clear timelines.** Portability requests must be handled without undue delay and within one month under Article 12(3). Implement automated export tools where volume warrants, and train front-line staff to recognize and route portability requests distinct from general access requests.

- **Map which datasets are portable.** Not all personal data falls within scope—only data "provided by" the data subject. Inferred data, profiling outputs, and controller-generated analytics may be excluded, but this boundary remains contested and should be assessed conservatively.

## Legislation (full text of key provisions)

### Right to data portability

*Source: GDPR, gdpr-art-20-en, 2016-04-27 — https://overview.legal/posts/90459*

### Recital 68 — data subject data portability right

*Source: GDPR, gdpr-rec-68-en, 2016-04-27 — https://overview.legal/posts/91651*

To further strengthen the control over his or her own data, where the processing of personal data is carried out by automated means, the data subject should also be allowed to receive personal data concerning him or her which he or she has provided to a controller in a structured, commonly used, machine-readable and interoperable format, and to transmit it to another controller. Data controllers should be encouraged to develop interoperable formats that enable data portability. That right should apply where the data subject provided the personal data on the basis of his or her consent or the processing is necessary for the performance of a contract. It should not apply where processing is based on a legal ground other than consent or contract. By its very nature, that right should not be exercised against controllers processing personal data in the exercise of their public duties. It should therefore not apply where the processing of the personal data is necessary for compliance with a legal obligation to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of an official authority vested in the controller. The data subject's right to transmit or receive personal data concerning him or her should not create an obligation for the controllers to adopt or maintain processing systems which are technically compatible. Where, in a certain set of personal data, more than one data subject is concerned, the right to receive the personal data should be without prejudice to the rights and freedoms of other data subjects in accordance with this Regulation. Furthermore, that right should not prejudice the right of the data subject to obtain the erasure of personal data and the limitations of that right as set out in this Regulation and should, in particular, not imply the erasure of personal data concerning the data subject which have been provided by him or her for the performance of a contract to the extent that and for as long as the personal data are necessary for the performance of that contract. Where technically feasible, the data subject should have the right to have the personal data transmitted directly from one controller to another.

### Recital 73 — lawful restrictions on data subject rights

*Source: GDPR, gdpr-rec-73-en, 2016-04-27 — https://overview.legal/posts/91661*

Restrictions concerning specific principles and the rights of information, access to and rectification or erasure of personal data, the right to data portability, the right to object, decisions based on profiling, as well as the communication of a personal data breach to a data subject and certain related obligations of the controllers may be imposed by Union or Member State law, as far as necessary and proportionate in a democratic society to safeguard public security, including the protection of human life especially in response to natural or manmade disasters, the prevention, investigation and prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, or of breaches of ethics for regulated professions, other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, the keeping of public registers kept for reasons of general public interest, further processing of archived personal data to provide specific information related to the political behaviour under former totalitarian state regimes or the protection of the data subject or the rights and freedoms of others, including social protection, public health and humanitarian purposes. Those restrictions should be in accordance with the requirements set out in the Charter and in the European Convention for the Protection of Human Rights and Fundamental Freedoms.

### Recital 156 — safeguards for archiving research processing

*Source: GDPR, gdpr-rec-156-en, 2016-04-27 — https://overview.legal/posts/91827*

The processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes should be subject to appropriate safeguards for the rights and freedoms of the data subject pursuant to this Regulation. Those safeguards should ensure that technical and organisational measures are in place in order to ensure, in particular, the principle of data minimisation. The further processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is to be carried out when the controller has assessed the feasibility to fulfil those purposes by processing data which do not permit or no longer permit the identification of data subjects, provided that appropriate safeguards exist (such as, for instance, pseudonymisation of the data). Member States should provide for appropriate safeguards for the processing of personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. Member States should be authorised to provide, under specific conditions and subject to appropriate safeguards for data subjects, specifications and derogations with regard to the information requirements and rights to rectification, to erasure, to be forgotten, to restriction of processing, to data portability, and to object when processing personal data for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes. The conditions and safeguards in question may entail specific procedures for data subjects to exercise those rights if this is appropriate in the light of the purposes sought by the specific processing along with technical and organisational measures aimed at minimising the processing of personal data in pursuance of the proportionality and necessity principles. The processing of personal data for scientific purposes should also comply with other relevant legislation such as on clinical trials.

## Case law

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/5945 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311*

“the national supervisory authorities are responsible for monitoring compliance with the EU rules concerning the protection of natural persons with regard to the processing of personal data. Each of those authorities is therefore vested with the power to check whether a transfer of personal data from its own Member State to a third country complies with the requirements laid down in that regulation” / “The exercise of that responsibility is of particular importance where personal data is tra

### Data Protection Commissioner v. Facebook Ireland Ltd, and Maximillian Schrems

*Source: CJEU, 2020-07-16 — https://overview.legal/posts/6120 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311&ref=6120*

“[…] the standard data protection clauses adopted by the Commission on the basis of Article 46(2)(c) of the GDPR are solely intended to provide contractual guarantees that apply uniformly in all third countries to controllers and processors established in the European Union and, consequently, independently of the level of protection guaranteed in each third country. In so far as those standard data protection clauses cannot, having regard to their very nature, provide guarantees beyond a contrac

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6145*

Necessity/proportionality: The Decision does not contain any finding regarding US rules intended to limit the interference when they pursue legitimate objectives such as national security, nor refer to effective legal protection against such interference. FTC procedures and private dispute resolution mechanisms concern compliance with safe harbor principles (against US organizations) and cannot be applied with respect to measures originating from the State. Moreover, the Commission found that if

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6144 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6144*

Independence of DPA: The Directive seeks to ensure an effective, complete, and high level of protection of the fundamental rights and freedoms of natural persons. The guarantee of a DPA’s independence is intended to ensure effectiveness and reliability of the monitoring of compliance, and is an essential component of data protection. DPAs powers extend to their own Member State, but not to processing in third countries. However, DPAs are responsible for monitoring transfers from a Member State t

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/5957 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201*

Right to be informed: National law that does not require the specific transfer involved in the case cannot constitute “prior information” under Article 10 of Directive 95/46 (information requirement where data is collected from the data subject), enabling the controller to dispense with his obligation to inform the data subject of the recipients of the data. (¶¶ 34–38). Article 11 (information requirement where data is not collected from data subject) requires that specified information be provi

### DENNEKAMP V. EUROPEAN PARLIAMENT (15.7.2015) (“DENNEKAMP II”)

*Source: CJEU, 2015-07-15 — https://overview.legal/posts/6153 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013TJ0115&ref=6153*

Data transfers: Articles 7–9 of Regulation 45/2001 precisely limit the possibility of transferring personal data so as to make it subject to strict conditions which, if not fulfilled, prohibit any transfer. Those conditions always include the necessity of the transfer in the light of various aims. (¶ 58)

### PARLIAMENT V. COUNCIL (PNR)

*Source: CJEU, 2006-05-30 — https://overview.legal/posts/5985 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62004CJ0317*

Transfers: Where the transfers of personal data are authorized under an agreement that was adopted ultra vires, the authorization is void.

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/6148 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201&ref=6148*

Personal data: Tax data transferred are personal data, since they are “information relating to an identified or identifiable natural person.” (¶ 29)

### V & EDPS V. EUROPEAN PARLAMENT, 5.7.2011 (“V v. European Parliament”)

*Source: CJEU, 2011-07-05 — https://overview.legal/posts/6179 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=6179*

Lawful Basis: The applicant did not consent to the transfer of her medical file by the Commission to the European Parliament. The transfer was not “necessary for the purposes of complying with the specific rights and obligations of the controller in the field of employment law,” in accordance with Article 10(2)(b). The Parliament’s obligation to control fitness for duty could have been achieved by less intrusive means. Nor does Article 10(3) justify the transfer. (¶¶ 137–139)

### SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”)

*Source: CJEU, 2015-10-01 — https://overview.legal/posts/6150 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0201&ref=6150*

Processing: Both the transfer of the data by ANAF, and the subsequent processing by CNAS, constitute processing of personal data. (¶ 29)

## Guidance

### Art. 29 WP Guidelines on GDPR transparency requirements (WP260 rev.01)

*Source: EDPB, edpb-guidelines-on-transparency, 2025-11-21 — https://overview.legal/posts/38076 — original: https://www.edpb.europa.eu/system/files/2023-09/wp260rev01_en.pdf*

The Article 29 Data Protection Working Party issued these guidelines (WP260 rev.01), adopted on 29 November 2017 and last revised on 11 April 2018, to provide interpretive and practical guidance on the transparency requirements under the GDPR (Articles 12–14). The document addresses the form, timing, content, and modalities of information provided to data subjects, including issues such as plain language, layered privacy notices, information for children, and exceptions to the obligation to provide information. No fines or enforcement actions are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 07/2022 on certification as a tool for transfers

*Source: EDPB, edpb-guidelines-on-certification-as-a-tool-for-transfers, 2023-02-24 — https://overview.legal/posts/38131 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-072022-on-certification-as-a-tool-for-transfers_en*

The GDPR requires in its Article 46 that data exporters shall put in place appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by data exporters under Article 46 for framing transfers to third countries by introducing, amongst others, certification as a new transfer mechanism (Articles 42 (2) and 46 (2) (f) GDPR). These guidelines provide guidance as to the applicati...

### Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them

*Source: EDPB, edpb-guidelines-on-deceptive-design-patterns-in-social-media-platform-interfaces-how-to-recognise, 2023-02-24 — https://overview.legal/posts/38056 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032022-on-deceptive-design-patterns-in-social-media-platform_en*

These Guidelines offer practical recommendations to social media providers as controllers of social media, designers and users of social media platforms on how to assess and avoid so-called 'deceptive design patterns' in social media interfaces that infringe on GDPR requirements. To this end, the EDPB recommends  that  controllers  make  use  of  interdisciplinary  teams,  consisting,  among  others,  of designers,  data  protection  officers  and  decision-makers.  It  is  important  to  note  ...

### Guidelines 04/2021 on Codes of Conduct as tools for transfers

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-as-tools-for-transfers, 2022-02-22 — https://overview.legal/posts/38133 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-042021-on-codes-of-conduct-as-tools-for-transfers_en*

The  GDPR  requires  in  its  Article  46  that  controllers/processors shall  put  in  place  appropriate safeguards for transfers of personal data to third countries or international organisations. To that end, the GDPR diversifies the appropriate safeguards that may be used by organisations under Article 46 for  framing transfers  to third countries  by  introducing  amongst  others, codes  of  conduct  as a new transfer  mechanism  (articles  40-3  and  46-2-e).  In  this  respect, as  provi...

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

### Guidelines 8/2020 on the targeting of social media users

*Source: EDPB, edpb-guidelines-on-the-targeting-of-social-media-users, 2021-04-13 — https://overview.legal/posts/38073 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-82020-on-the-targeting-of-social-media-users_en*

The EDPB adopted Guidelines 8/2020 on the targeting of social media users to clarify the roles, responsibilities, and legal obligations of the various actors involved in social media targeting, including social media providers, targeters, and users. The guidelines analyze different targeting mechanisms—based on provided, observed, and inferred data—and address controller determinations, legal bases, transparency requirements, DPIAs, and the processing of special categories of data. No fines are imposed, as this is interpretive guidance intended to assist stakeholders in achieving GDPR compliance.

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

## Recent developments

### Draft adequacy decision for Brazil: EDPB adopts opinion

*Source: EDPB, 2025-11-05 — https://overview.legal/posts/49127 — original: https://www.edpb.europa.eu/news/news/2025/draft-adequacy-decision-brazil-edpb-adopts-opinion_en*

Brussels, 5 November - During its latest plenary, the EDPB adopted an opinion on the European Commission’s draft decision on the adequate level of protection of personal data in Brazil.* Once adopted, the decision will ensure that personal data can flow freely from Europe to Brazil and that individuals can retain control over their data. In its opinion, requested by the Commission, the EDPB assesses whether the Brazilian data protection framework and the rules on government access to personal da

### Hunton summarises two articles from the new SCCs: the 'local laws and government access' section

*Source: DataGuidance, 2022-10-18 — https://overview.legal/posts/6254 — original: https://www.dataguidance.com/opinion/eu-deep-dive-qas-regarding-local-laws-and-government#entry-1086*

Under Clause 14 of the Data Transfer SCCs, the data importer must carry out a transfer risk assessment to verify whether the laws and practices of the receiving third country could prevent the data importer from complying with the Data Transfer SCCs. If the risk assessment shows that the Data Transfer SCCs alone will not ensure an essentially equivalent level of protection for the personal data in the receiving third country, supplementary safeguards will need to be implemented, such as end-to-e

### The EU-US Data Privacy Framework: A new era for data transfers?

*Source: IAPP, 2022-10-07 — https://overview.legal/posts/6264 — original: https://iapp.org/news/a/the-eu-u-s-data-privacy-framework-a-new-era-for-data-transfers/#entry-996*

> Legally, until an adequacy determination is granted, companies should continue to follow the European Data Protection Board’s recommendations on measures that supplement transfer tools.
But, once the EU is named as a “qualifying state” (assuming it will be) and complaints can be summited, this should become less daunting. The EDPB recommendations state that companies must “assess if there is anything in the law or practice of the third country that may impinge on the effectiveness of the appro

### What Happened to the Risk-Based Approach to Data Transfers?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/6271 — original: https://fpf.org/blog/what-happened-to-the-risk-based-approach-to-data-transfers/#entry-912*

The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute principles), the RBA of Article 24 therefore applies. Other than the DPAs assume, this is not contradicted by the ECJ in Schrems II nor by the EDPB recommendations on additional measures following the Schrems II judgment, according to Lokke Moerel, Professor of Global ICT Law at Tilburg University and a Dutch Cyber Security

### CJEU: PNR Directive Valid if Limited to the “Strictly Necessary”

*Source: eucrim, 2022-08-04 — https://overview.legal/posts/6292 — original: https://eucrim.eu/news/cjeu-pnr-directive-valid-if-limited-to-the-strictly-necessary/#entry-388*

> In a landmark ruling of 21 June 2022, the CJEU (Grand Chamber), upheld the EU’s regime to collect and use records of travellers, provided that it is strictly interpreted in line with the EU’s fundamental rights. In addition, indiscriminate processing of the data in cases of flights carried out only within the EU is banned unless there is a threat of terrorism. In general, the passengers’ data must also be deleted after six months at the latest.

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **International Transfer** — https://overview.legal/topics/internationale-doorgifte
  Transfer of personal data outside the EU/EEA
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data

---
Generated by overview.legal · https://overview.legal/topics/data-portability · 2026-08-22
