Back to the hub

What is the right to data portability under GDPR Article 20?

Article 20 of the GDPR gives a person the right to receive the personal data they provided to a controller in a structured, commonly used and machine-readable format, and to transmit it to another controller. It applies only where processing is based on consent or a contract and is carried out by automated means.

Applies to: Controllers that process personal data by automated means under consent or a contract, who must be able to export that data in a reusable format and, where feasible, send it to another controller.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Data portability is the GDPR right that lets people take their data with them. It sits close to the subject access right but does a different job: instead of simply seeing their data, a person can get a clean, machine-readable copy and move it to a competitor. For a SaaS business that turns portability into an engineering requirement rather than a policy line, and the conditions on it are precise.

What does GDPR Article 20 require?

Article 20(1) gives a person the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format, and to transmit that data to another controller without hindrance. Two conditions gate the right. The processing must be based on consent, under Article 6(1)(a) or Article 9(2)(a), or on a contract under Article 6(1)(b); and the processing must be carried out by automated means. Article 20(2) adds that, where technically feasible, the person can ask to have the data transmitted directly from one controller to another. The lawful basis you rely on therefore decides whether the right is even in play.

How is portability different from a subject access request?

The two rights overlap but are not the same. A subject access request under Article 15 lets a person obtain a copy of their data regardless of the lawful basis, and its purpose is transparency. Portability is narrower on what it covers and stricter on format. It reaches only the data the person provided, only where the basis is consent or contract and the processing is automated, and it requires a structured, machine-readable output built for reuse. In practice a business can satisfy an access request with a readable report, but a portability request needs an export a machine on the other end can ingest.

When does the right not apply?

Because the right is tied to two legal bases, a great deal of processing sits outside it. Data you process under a legal obligation, under legitimate interests, to protect vital interests, or for a public task is not portable. Article 20(3) states plainly that the right is without prejudice to the right to erasure and does not apply to processing necessary for a task carried out in the public interest or in the exercise of official authority. Article 20(4) adds that exercising it must not adversely affect the rights and freedoms of others, which matters when one person's export would reveal another person's data.

The exact wording, and why it is quoted so often

Article 20(1) reads that the data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format, and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where (a) the processing is based on consent pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) or on a contract pursuant to point (b) of Article 6(1), and (b) the processing is carried out by automated means. Article 20(2) adds the direct controller-to-controller transmission where technically feasible. Article 20(3) makes the right without prejudice to Article 17 and disapplies it to processing necessary for a task carried out in the public interest or official authority. Article 20(4) provides that it shall not adversely affect the rights and freedoms of others.

Next step

If you are not sure which of your processing activities are portable, the free 2-minute Obligation Scan checks whether the GDPR applies to you and flags the data-subject rights, including portability, that you need to support. The GDPR compliance hub sets out the wider obligations.

Compliance checklist

  • Identify which processing is based on consent or a contract and carried out by automated means, because only that data is portable.
  • Limit portability to the personal data the person provided, whether given directly or observed through their use of your service, rather than inferences or profiles you generated.
  • Provide the data in a structured, commonly used and machine-readable format, such as CSV or JSON, so it can be reused without manual re-entry.
  • Where technically feasible, support transmitting the data directly from one controller to another under Article 20(2).
  • Respond within one month under Article 12(3), and make sure fulfilling a request does not expose another person's data, as Article 20(4) requires.

Sources

Last verified: 2026-08-14

Informational, not legal advice.