GDPR Article 20: what is the right to data portability?
Article 20 of the GDPR gives a person the right to receive the personal data they provided to a controller in a structured, commonly used and machine-readable format, and to transmit it to another controller. It applies only where processing is based on consent or a contract and is carried out by automated means.
Applies to: Controllers that process personal data by automated means under consent or a contract, who must be able to export that data in a reusable format and, where feasible, send it to another controller.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanData portability is the GDPR right that lets people take their data with them. It sits close to the subject access right but does a different job: instead of simply seeing their data, a person can get a clean, machine-readable copy and move it to a competitor. For a SaaS business that turns portability into an engineering requirement rather than a policy line, and the conditions on it are precise.
What does GDPR Article 20 require?
Article 20(1) gives a person the right to receive the personal data concerning them, which they have provided to a controller, in a structured, commonly used and machine-readable format, and to transmit that data to another controller without hindrance. Two conditions gate the right. The processing must be based on consent, under Article 6(1)(a) or Article 9(2)(a), or on a contract under Article 6(1)(b); and the processing must be carried out by automated means. Article 20(2) adds that, where technically feasible, the person can ask to have the data transmitted directly from one controller to another. The lawful basis you rely on therefore decides whether the right is even in play.
How is portability different from a subject access request?
The two rights overlap but are not the same. A subject access request under Article 15 lets a person obtain a copy of their data regardless of the lawful basis, and its purpose is transparency. Portability is narrower on what it covers and stricter on format. It reaches only the data the person provided, only where the basis is consent or contract and the processing is automated, and it requires a structured, machine-readable output built for reuse. In practice a business can satisfy an access request with a readable report, but a portability request needs an export a machine on the other end can ingest.
When does the right not apply?
Because the right is tied to two legal bases, a great deal of processing sits outside it. Data you process under a legal obligation, under legitimate interests, to protect vital interests, or for a public task is not portable. Article 20(3) states plainly that the right is without prejudice to the right to erasure and does not apply to processing necessary for a task carried out in the public interest or in the exercise of official authority. Article 20(4) adds that exercising it must not adversely affect the rights and freedoms of others, which matters when one person's export would reveal another person's data.
The exact wording, and why it is quoted so often
Article 20(1) reads that the data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format, and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where (a) the processing is based on consent pursuant to point (a) of Article 6(1) or point (a) of Article 9(2) or on a contract pursuant to point (b) of Article 6(1), and (b) the processing is carried out by automated means. Article 20(2) adds the direct controller-to-controller transmission where technically feasible. Article 20(3) makes the right without prejudice to Article 17 and disapplies it to processing necessary for a task carried out in the public interest or official authority. Article 20(4) provides that it shall not adversely affect the rights and freedoms of others.
Data portability examples
The conditions in Article 20(1) decide each case, so it helps to run them against ordinary product features.
A contacts list a user typed into your CRM under their subscription contract is portable. The data was provided by the user, processing rests on a contract, and it is automated. A CSV or JSON export satisfies the format requirement; a PDF does not, because a PDF is not machine-readable in the sense Article 20 uses.
Order history in an e-commerce account is portable on the same reasoning. Uploaded photos and files are portable too, and the fact that they are large is not an exemption.
A lead score or churn-risk rating your model produced about the user is not covered by Article 20, because the user did not provide it. It may still be reachable through the Article 15 right of access, which is a separate right with a different scope.
Employee records you hold because employment law requires you to keep them are not portable under Article 20 either, because the lawful basis is a legal obligation rather than consent or contract.
Where a user asks you to send their data straight to a competitor's product, Article 20(2) applies, and the duty runs only where technically feasible. That qualifier is doing real work: it is in the text of Article 20(2) itself, and it is the reason a direct transfer request can be answered with an export when no interoperable route exists.
What is the deadline for a data portability request?
Article 20 sets no deadline of its own. Read on its own it looks like an open-ended obligation, and that is a misreading: the clock for every right in Articles 15 to 22 sits in Article 12(3), which applies to portability exactly as it applies to access.
Article 12(3) reads that the controller shall provide information on action taken on a request under Articles 15 to 22 to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.
Three operational points come out of that.
The default is one month, and the standard above it is "without undue delay," so a controller that could have answered in a week does not get the full month by right.
The extension is available but it is conditional and it has its own deadline. Two further months are permitted where necessary given complexity and volume, but the data subject must be told about the extension, and told the reasons, within the original one month. An extension claimed in month two is not an extension under Article 12(3).
And an electronic request gets an electronic answer by default, which for portability aligns neatly with the Article 20(1) format requirement.
Article 12(4) covers the refusal case: if the controller does not take action on the request, it must inform the data subject without delay.
How portability relates to the right of access
Because both rights run on the same Article 12(3) clock and often arrive in the same message, it is worth being clear on what each one delivers.
The Article 15 right of access gives confirmation of processing, the data itself, and eight named categories of information about that processing, whatever the lawful basis. Article 20 gives a reusable export, and only for data the person provided, only under consent or contract, only where processing is automated.
A request that says "send me everything you have on me, in a format I can upload elsewhere" is both requests at once, and answering only the portability half leaves the eight Article 15 items unanswered inside the same one-month period.
Next step
If you are not sure which of your processing activities are portable, the free 2-minute Obligation Scan checks whether the GDPR applies to you and flags the data-subject rights, including portability, that you need to support. The GDPR compliance hub sets out the wider obligations, and the subject access request page covers the broader right that catches what portability does not.
Compliance checklist
- Identify which processing is based on consent or a contract and carried out by automated means, because only that data is portable.
- Limit portability to the personal data the person provided, whether given directly or observed through their use of your service, rather than inferences or profiles you generated.
- Provide the data in a structured, commonly used and machine-readable format, such as CSV or JSON, so it can be reused without manual re-entry.
- Where technically feasible, support transmitting the data directly from one controller to another under Article 20(2).
- Respond within one month under Article 12(3), and make sure fulfilling a request does not expose another person's data, as Article 20(4) requires.
Sources
- Regulation (EU) 2016/679 (GDPR), Article 20 (right to data portability), official text on EUR-Lex
- UK Information Commissioner's Office, right to data portability
Last verified: 2026-09-18
Informational, not legal advice.