> ## Content Index
> Fetch the complete content index at: https://www.thedelatorrereview.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What is the "Right to Data Portability" under the GDPR?
- URL: https://www.thedelatorrereview.com/what-is-the-right-to-data-portability-under-the-gdpr/
- Published: 2019-02-22T03:03:00.000Z
- Updated: 2026-07-18T03:17:41.000Z
- Description: The GDPR's right to data portability allows individuals to obtain certain personal data they have provided to an organization and transfer it to another service. This article explains Article 20 GDPR, when the right applies, obligations, exceptions, and practical compliance tips.
- Author: Lydia
- Tags: GDPR, Right to Data Portability, Privacy Rights, EU, Data Protection Law

> **Key points:** (1) The GDPR gives individuals the right to receive certain personal data they have provided to an organization and to transfer that data to another organization. (2) The right to data portability is intended to make it easier for individuals to switch between service providers and reuse their personal data across different services. (3) Where technically feasible, individuals may also request that one controller transmit their personal data directly to another controller. (4) The right only applies in limited circumstances, including where processing is based on consent or a contract and is carried out by automated means. (5) It generally covers personal data that the individual has provided to the controller, including data actively submitted and certain data generated through the individual's use of a service, but it does not apply to all personal data held by an organization.

## What is the right to data portability and why is it important?

The right to data portability gives individuals greater control over their personal data by allowing them to obtain certain personal information they have provided to an organization and reuse it across different services. Rather than being "locked in" to a particular provider, individuals can move their data to another organization more easily, promoting competition, innovation, and user choice.

Under [Article 20](https://gdpr-info.eu/art-20-gdpr/?ref=thedelatorrereview.com) of the GDPR, an individual has the right to:

- Receive a copy of certain personal data in a structured, commonly used, and machine-readable format; and/or
- Request that the data be transmitted directly to another controller, where technically feasible.

This right enables individuals to retain and reuse their personal data for their own purposes. For example, a user may wish to transfer playlists from one music streaming service to another, move fitness data between health applications, or download contact information from an email provider for use with a different service.

The GDPR also makes clear that:

- The right to data portability does not affect the right to erasure under [Article 17.](https://gdpr-info.eu/art-17-gdpr/?ref=thedelatorrereview.com)
- The right does not apply where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
- Exercising the right must not adversely affect the rights and freedoms of others.

### When does the right apply?

The right to data portability is **not absolute**. It only applies where **all** of the following conditions are met:

- **The processing is based on the individual's consent or on a contract.** Processing based on legal obligations, legitimate interests, or public tasks generally does not qualify.
- **The processing is carried out by automated means.** The right does not apply to information maintained solely in paper records.
- **The request concerns personal data that the individual has provided to the controller.** This includes information actively supplied by the individual and, in many cases, data generated through the individual's use of a service (such as usage history or activity logs), but it generally does not include data created solely by the controller, such as internal analyses or inferred profiles.

Where technically feasible, individuals may also request that one controller transmit the data directly to another.

### What data is covered by the right to data portability?

The right to data portability applies only to **personal data that the individual has "provided to" the controller.** The concept is broader than information that an individual actively types into a form.

It generally includes both:

- **Data actively provided by the individual**, such as their name, email address, mailing address, username, date of birth, or other information submitted when creating or using an account.
- **Data generated through the individual's use of a service or device**, often referred to as **observed data**. This includes information collected by observing the individual's activities while using a product or service.

Examples of observed data include:

- Website browsing and search history;
- Traffic and location data;
- Usage logs and activity history;
- Data generated by connected devices, such as smart meters, fitness trackers, or other wearable devices.

The right to data portability does not extend to data that the controller creates or derives from the information it collects. For example, it generally does not include:

- Internal analyses or assessments;
- Risk scores;
- Predictive models;
- Profiles or inferences generated by the organization based on the individual's behavior.

Although these derived or inferred data are generally not portable, they may still constitute personal data and therefore may be accessible through a right of access request under [Article 15](https://gdpr-info.eu/art-15-gdpr/?ref=thedelatorrereview.com) GDPR, provided no exception applies.

The right also applies to pseudonymous personal data that can be linked back to an individual, but it does not apply to truly anonymous information, which is no longer considered personal data under the GDPR.

## How can a Portability Request be made?

The GDPR does not prescribe a particular format for making a data portability request. As a result, an individual may submit a request verbally or in writing, and it may be made to any part of an organization—it does not need to be addressed to a specific department, privacy team, or designated contact.

A request does not need to refer to the "right to data portability," cite Article 20 GDPR, or use any particular legal language. If an individual clearly indicates that they want to receive their personal data in a portable format or have it transferred to another organization, the request should generally be treated as a valid data portability request.

Because any employee may receive a valid request, organizations should ensure that employees who regularly interact with customers, users, or employees are trained to recognize data portability requests and route them promptly to the appropriate personnel.

## Verifying the identity of the requester

If an organization has reasonable doubts about the identity of the individual making a data portability request, it may ask for additional information to verify the requester's identity before responding.

Any request for additional information should be proportionate. Organizations should request only the information that is reasonably necessary to confirm the individual's identity and should avoid collecting excessive personal data as part of the verification process.

The time for responding to the request begins once the organization receives the additional information necessary to verify the requester's identity.

When requesting additional information, the organization should inform the individual:

- Why additional information is needed to verify their identity;
- That they have the right to lodge a complaint with the competent supervisory authority if they disagree with the organization's handling of the request; and
- That they have the right to seek a judicial remedy to enforce their rights under the GDPR.

## Complying with a data portability request

Once an organization determines that a valid data portability request has been received and the legal requirements are met, it must take appropriate steps to comply with the request.

A controller may satisfy its obligations by:

- Providing the requested personal data directly to the individual in a structured, commonly used, and machine-readable format; or
- Providing a secure automated tool that enables the individual to extract their own personal data.

Providing an automated download tool does not require organizations to give individuals unrestricted or ongoing access to their internal systems. The obligation is limited to enabling the individual to obtain the personal data covered by the portability request.

### Direct transmission to another controller

Individuals may also request that their personal data be transmitted directly to another controller, where technically feasible.

Whether direct transmission is technically feasible should be assessed on a case-by-case basis. The GDPR does not require organizations to adopt or maintain systems that are technically compatible with every other controller's systems. However, organizations should take a reasonable and practical approach and should not rely on technical limitations as an unnecessary barrier to portability.

### Data must be provided without hindrance

The GDPR requires controllers to facilitate the exercise of the right to data portability without hindrance. Organizations should therefore avoid creating unnecessary obstacles that delay or prevent individuals from exercising this right.

For example, controllers should not impose:

- Unnecessary legal requirements;
- Technical barriers that make the transfer unreasonably difficult; or
- Financial charges that are not permitted under the GDPR.

The controller remains responsible for ensuring that any transmission of personal data is secure and that the data is delivered to the correct recipient, whether the recipient is the individual or another controller designated by the individual.

### In what format must the data be provided?

The GDPR requires controllers to provide portable personal data in a structured, commonly used, and machine-readable format. Although these terms are not expressly defined in the GDPR, they are intended to ensure that individuals can readily access, reuse, and transfer their personal data to another service or organization.

- **Structured:** A structured format organizes data in a way that allows software to identify and extract individual data elements efficiently. For example, a spreadsheet organizes information into rows and columns, making it easy for both people and computer systems to process the data.
- **Commonly used:** A commonly used format is one that is widely recognized and regularly used within an industry or across software applications. However, simply being popular is not enough—the format must also be structured and machine-readable.
- **Machine-readable:** A machine-readable format allows computer systems to automatically read, process, and exchange data without requiring manual intervention. These formats make it easier for individuals to import their data into another service and may also facilitate direct controller-to-controller transfers through technologies such as application programming interfaces (APIs).

That said, the GDPR does not require controllers to use a particular file format. Instead, organizations should select a format that satisfies the legal requirements while taking into account the nature of the data and common practices within their industry. Recital 68 of the GDPR encourages controllers to develop **interoperable formats** that facilitate the transfer of personal data between different systems. Interoperability allows different applications and services to exchange and understand the same information without requiring identical technical systems.

Importantly, the GDPR encourages interoperability but does not require controllers to make their internal systems technically compatible with those of other organizations.

Many industries already use established formats for exchanging information. Where an existing industry-standard format is **structured, commonly used, and machine-readable**, it may be an appropriate way to respond to a data portability request.

- **Proprietary formats may require conversion** Organizations are free to use proprietary formats within their own internal systems. However, if those formats cannot readily be used by individuals or other organizations, the controller may need to convert the personal data into a suitable portable format before providing it.

**Common examples of acceptable formats**: Although the GDPR does not mandate any particular format, several widely used open formats generally satisfy the requirements for data portability.

- **CSV (Comma-Separated Values)** CSV is one of the most common formats for tabular data. It stores information as plain text, with each row representing a record and commas separating individual values. CSV files are widely supported by spreadsheet programs and other software, making them an appropriate format for many data portability requests.
- **XML (Extensible Markup Language)** XML is an open standard designed to represent structured data in a format that is both human-readable and machine-readable. It is commonly used for exchanging information between systems and can readily support APIs and other automated data transfers.
- **JSON (JavaScript Object Notation)** JSON is another widely used open standard for exchanging data between applications and online services. It supports complex data structures while remaining highly machine-readable and reasonably easy for humans to understand. JSON is commonly used by web applications and APIs and is often well suited for responding to portability requests.
- **Other formats may also be appropriate** CSV, XML, and JSON are common examples, but they are not the only acceptable formats. Other structured, commonly used, and machine-readable formats—such as RDF (Resource Description Framework) or industry-specific standards—may also satisfy the GDPR's requirements, provided they enable individuals to effectively access, reuse, and transfer their personal data.

Controllers should, however, consider the nature of the portability request. If the individual cannot make use of the format, even if it is structured, commonly-used and machine-readable then the data will be of no use to them.

### Responsibility for personal data after it is transmitted

The controller is responsible for ensuring that personal data is **transmitted securely and to the correct recipient** when responding to a data portability request. Appropriate technical and organizational measures should be used to protect the data during the transfer.

Once the data has been successfully provided to the individual or transmitted to another controller at the individual's request, the original controller is generally not responsible for how the recipient subsequently processes that information. At that point, the recipient is responsible for ensuring that any further processing complies with applicable data protection laws.

As a matter of good practice, controllers should also make individuals aware of the sensitivity of the data being provided and encourage them to take appropriate measures to protect it after receipt.

### Responsibilities of the receiving controller

A controller that receives personal data through a data portability request must process that information in accordance with the GDPR and other applicable data protection laws.

Before retaining or using the transferred data, the receiving controller should consider whether:

- The data is **adequate, relevant, and limited** to what is necessary for the intended processing purposes;
- It has a **lawful basis** for processing the personal data;
- The transferred data includes personal information relating to third parties; and
- Appropriate safeguards are in place to protect the rights and freedoms of those third parties.

If the receiving controller has no lawful reason to retain some or all of the transferred data, it should delete that information without undue delay.

> **Example**: An individual switches from one online service provider to another and requests that their personal data be transmitted directly to the new provider under Article 20 GDPR. The transferred data includes information relating to third parties, such as contacts or shared account information. The receiving controller may have a lawful basis to process the transferred data to provide the requested service to the individual. However, that does **not** automatically permit the controller to use the third-party information for unrelated purposes, such as sending direct marketing communications to those individuals. Any further processing must have an independent lawful basis and comply with the GDPR's principles, including purpose limitation and data minimization.

## Best practices for organizations

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/ChatGPT-Image-Jul-17--2026-at-08_09_51-PM.png)

Organizations should also establish internal procedures to:

Recognize and promptly escalate potential data portability requests;

- Verify the identity of the requester, where appropriate;
- Record the details of all requests received, particularly those made verbally (such as by telephone or in person), and maintain a log of verbal requests;
- Confirm with the requester that the request has been correctly understood, helping to avoid misunderstandings or later disputes about its scope;
- Assess whether the legal requirements for the right to data portability are satisfied;
- Prepare the data in a structured, commonly used, and machine-readable format; and
- Where requested and technically feasible, securely transmit the data directly to another controller.

**Requests involving third-party information**: Although the right to data portability only applies to personal data that the individual has provided to the controller (including certain data generated through the individual's use of a service), some portable data may also relate to other identifiable individuals. For example, contact lists, shared documents, messages, or information associated with a joint account may include another person's personal data.

Article [20(4)](https://gdpr-info.eu/art-20-gdpr/?ref=thedelatorrereview.com) GDPR provides that exercising the right to data portability **must not adversely affect the rights and freedoms of others**. In most cases, providing the data directly to the individual making the request will not create significant concerns, particularly where that individual originally provided or created the information. However, organizations should still consider whether fulfilling the request—especially where the data will be **t**ransmitted directly to another controller—could adversely affect the rights or freedoms of third parties.

In practice, for data portability, outright refusal on third-party grounds will be much less common than for the right of access because the scope of portable data is already limited.

**Large or complex requests**: Data portability requests may sometimes cover large volumes of personal data or involve multiple systems. In these circumstances, organizations may ask the individual to provide additional information to help identify the data being requested—for example, by identifying particular accounts, services, time periods, or categories of data.

However, an individual is not required to narrow the scope of a valid request. Even if the individual declines to do so, the organization must still make reasonable efforts to identify, collect, and provide all personal data that falls within the scope of the right to data portability.

**Controllers remain responsible**: Even where personal data is processed by a service provider, the controller remains legally responsible for responding to Subject Access Requests.

Controllers should ensure that contracts with processors require appropriate cooperation so that requests can be answered within the GDPR deadline. Reliance on a processor does not extend the time available to respond.

**Requests made on behalf of others** The GDPR does not require a data portability request to be submitted personally by the individual. A third party—such as a lawyer, family member, or other authorized representative—may exercise the right on an individual's behalf, provided they have authority to do so.

Organizations should take reasonable steps to verify that authority before disclosing or transmitting personal data. Depending on the circumstances, this may include requesting a signed authorization, a power of attorney, or other appropriate evidence of the representative's authority.

In some cases, an organization's existing relationship with the representative or other surrounding circumstances may provide sufficient assurance that the representative is authorized to act on the individual's behalf. However, organizations are generally entitled to request formal proof of authorization before responding to the request.

Where there are concerns that the individual may not fully understand the implications of authorizing another person to receive or direct the transfer of their personal data, it may be appropriate to provide the portable data directly to the individual. The individual can then decide whether to share it with their representative or instruct the organization regarding its transmission to another controller.

**Individuals who lack legal capacity:** The GDPR does not contain specific rules governing data portability requests made on behalf of individuals who lack the legal or mental capacity to manage their own affairs. In those circumstances, organizations should follow the applicable laws of the relevant Member State regarding legal representation, guardianship, and decision-making authority to determine who may validly exercise the right on the individual's behalf.

## Time limits, refusals, and fees

**Time to respond:** Under the GDPR, controllers must respond to a data portability request without undue delay and, in most cases, within one month of receiving the request. In certain circumstances, this deadline may be extended where permitted by the GDPR. 

As with other data subject rights, the one-month period generally begins when the controller has received the request or, where appropriate, any additional information reasonably necessary to verify the requester's identity. Organizations should assess requests promptly and communicate with the individual if an extension is justified under the GDPR.

**Refusing to comply with a data portability request**: The right to data portability is an important GDPR right, but it is not absolute. In limited circumstances, a controller may refuse all or part of a request where the GDPR or applicable Member State law permits it.

For example, a controller may be unable to transmit personal data directly to another controller where doing so would adversely affect the rights and freedoms of others. Similarly, if direct transmission is not technically feasible, the controller is not required to carry it out. However, the controller must be able to demonstrate that any refusal or limitation is legitimate and is not being used as an unnecessary hindrance to the exercise of the right.

The right to data portability may also be restricted under the laws of a Member State in certain circumstances. 

**Manifestly unfounded or excessive requests**: A controller may also refuse to act on a request—or charge a reasonable fee—if the request is **manifestly unfounded or excessive**, particularly where it is repetitive.

In these circumstances, the controller may:

- Charge a reasonable fee reflecting the administrative costs of responding to the request; or
- Refuse to act on the request.

The controller bears the burden of demonstrating that the request is manifestly unfounded or excessive and must be able to justify its decision.

**Informing the individual:** If a controller refuses to comply with a request, whether in whole or in part, it must inform the individual without undue delay and no later than one month after receiving the request. The response must explain:

- the reasons for refusing to take action;
- the individual's right to lodge a complaint with the competent supervisory authority; and
- the individual's right to seek a judicial remedy.

## Additional Reading

[Article 20](https://gdpr-info.eu/art-20-gdpr/?ref=thedelatorrereview.com) of GDPR

Suitable Recitals [(68) Right of Data Portability](https://gdpr-info.eu/recitals/no-68/?ref=thedelatorrereview.com)

The European Data Protection Board has published [guidelines](https://ec.europa.eu/newsroom/document.cfm?doc%5Fid=44099&ref=thedelatorrereview.com) and [FAQs](http://ec.europa.eu/information%5Fsociety/newsroom/image/document/2016-51/wp242%5Fannex%5Fen%5F40854.pdf?ref=thedelatorrereview.com) on data portability for organizations.

Further reading on formats:

- The Open Data Handbook is published by Open Knowledge International and is a guide to ‘open data’. The Handbook is updated regularly and can be accessed here: [http://opendatahandbook.org](http://opendatahandbook.org/?ref=thedelatorrereview.com)
- W3C candidate recommendation for XML is available here: [http://www.w3.org/TR/2008/REC-xml-20081126/](http://www.w3.org/TR/2008/REC-xml-20081126/?ref=thedelatorrereview.com)
- W3C’s specification of the JSON data interchange format is available here: [https://tools.ietf.org/html/rfc7159](https://tools.ietf.org/html/rfc7159?ref=thedelatorrereview.com)
- W3C’s list of specifications for RDF is available here: [http://www.w3.org/standards/techs/rdf#w3c\_all](http://www.w3.org/standards/techs/rdf?ref=thedelatorrereview.com#w3c%5Fall)

Future of Privacy Forum [CPDP 2019 Panel: Understanding the limits and benefits of data portability](https://fpf.org/2019/02/26/cpdp-2019-panel-understanding-the-limits-and-benefits-of-data-portability/?ref=thedelatorrereview.com)

![](https://storage.ghost.io/c/54/ef/54efeb65-4f2f-479e-b4bb-a9ee526feeaa/content/images/2026/07/Screenshot-2026-07-04-at-4.45.19---PM-58.png)