Data Portability
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Right to receive and transfer personal data in structured, machine-readable format
Overview
21 sources · Jul 23, 2026Legal Framework
Article 20 GDPR establishes the right to data portability, entitling data subjects to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller. This right applies cumulatively where two conditions are met: the processing must be based on consent under Article 6(1)(a) or Article 9(2)(a), or on a contract under Article 6(1)(b); and the processing must be carried out by automated means. The data subject may also request direct transmission of personal data from one controller to another where technically feasible.
The rationale is to strengthen user control over personal data and reduce lock-in effects, enabling individuals to switch service providers without losing their data history. The right covers only personal data provided by the data subject, including data generated by their activity (such as usage logs or sensor data), but not data derived through inference or profiling that goes beyond what the subject directly supplied.
Recital 73 confirms that Union or Member State law may impose restrictions on the portability right where necessary and proportionate in a democratic society to safeguard public security, prevention of crime, or other legitimate public interests. The Digital Services Act reinforces the broader machine-readable transparency ethos by requiring annual content moderation reports in machine-readable format from intermediary service providers, reflecting a regulatory trend toward standardized data exportability.
Key Developments
The Court of Justice's reasoning in Schrems (C-362/14) and Schecke (C-92/09 and C-93/09, 9 November 2010) clarified the boundaries of consent-based processing, which is directly relevant because portability under Article 20 is contingent on consent or contractual necessity as the lawful basis. In Schecke, the Court distinguished mandatory statutory processing from genuine consent, establishing that merely informing data subjects does not equate to consent. Controllers relying on Article 6(1)(a) as the basis for portability must therefore ensure consent is freely given, specific, informed, and unambiguous.
Enforcement actions illustrate the financial exposure when portability obligations are violated alongside other GDPR requirements. The Croatian DPA (AZOP) imposed a €4.5 million fine on a telecommunications operator for multiple GDPR infringements, a sector where portability requests are frequent given the volume of user-generated data. The Italian Garante fined the Migliarino San Rossore Massaciuccoli Regional Park Authority €8,000, demonstrating that public-sector bodies are equally subject to data subject rights enforcement.
The EDPB's Guidelines 1/2020 on connected vehicles highlight that portability must be considered in IoT contexts, where vehicle-generated data constitutes personal data provided by the user through their driving behavior and vehicle interactions.
Practical Guidance
Verify the lawful basis before responding. Confirm that processing relies on Article 6(1)(a), 6(1)(b), or Article 9(2)(a). If processing is based on legitimate interests or legal obligation, portability does not apply.
Define the scope of "provided data" carefully. Include data actively supplied by the user and data generated through observed activity, but exclude inferred or derived data such as risk scores or internal analytics that go beyond what the subject provided.
Implement automated export in standard formats. Provide data in commonly used, structured, machine-readable formats such as JSON, CSV, or XML. Manual compilation on a case-by-case basis risks non-compliance and operational inefficiency.
Assess technical feasibility for direct transmission. Where a data subject requests direct controller-to-controller transfer, document the technical assessment. If direct transmission is not feasible, provide the data to the subject and explain the limitation.
Establish a portability request workflow. Integrate portability handling into existing subject rights processes, ensuring responses within one month under Article 12(3), with clear escalation procedures for complex or voluminous requests.