Data Portability: Answer Every Right to Data Portability Request Under GDPR Article 20
A portability request is not an access request with a different file extension. It covers a narrower slice of data, it only applies on certain legal bases, and it has to come out in a format another company can actually read. Obtainer works out which data qualifies and exports it, while your team keeps the final call.
found
scanned
Assembling the cover letter from the template...
Helps you comply, not legal advice
In short
Data portability is the right of a person to receive the personal data they provided to an organization in a structured, commonly used and machine-readable format, and to have it transmitted to another controller without hindrance. It comes from Article 20 of the GDPR. The right is narrower than the right of access in two ways that matter. First, it only applies where the processing is based on consent or on a contract, and only where the processing is carried out by automated means, so paper files and data you process on the basis of legitimate interests or a legal obligation fall outside it. Second, it covers data the person provided, including data observed from their activity, but not data you inferred or derived about them, such as a credit score or a profile you built. Where it is technically feasible, the person can also ask you to send the data directly to another controller, though Article 20 does not require you to build an interface that does not exist. The response runs on the GDPR clock: without undue delay and within one month, extendable by two months for complex requests. Obtainer identifies which of a person's data qualifies, exports it in a machine-readable format such as CSV or JSON, and routes it to a human for approval before it goes anywhere. Obtainer helps you comply. It is not legal advice, and the call on what qualifies stays with your team. Self-serve from $49/mo.
Last updated July 2026
What you get
Data portability, built for privacy, legal, and ops teams
Provided data, not inferred data
Portability covers what the person gave you and what you observed, not the profile you built about them. Obtainer separates the two so you export what the right covers rather than everything you hold.
A format the next company can read
Article 20 asks for structured, commonly used and machine-readable output. Exports come out as CSV or JSON rather than a PDF bundle that technically answers the request but defeats its purpose.
The legal basis decides the scope
The right only bites where processing rests on consent or a contract and is automated. Obtainer surfaces the data so your team can scope the export against the basis you actually rely on.
Approval before the export leaves
A portability export can carry data about other people. It waits at a human review gate, so you stay in control of what is sent and to whom.
How it works
From an intake request to a ready-to-review response in four steps
Intake and verify
Log the portability request and confirm the requester's identity, because a portable export is a copy of someone's data leaving your systems.
Scope it to Article 20
Establish which processing rests on consent or contract and is automated. That is the boundary of the right, and it is usually narrower than the person expects.
Separate provided from inferred
Obtainer surfaces the data the person provided or you observed, and sets aside what you inferred or derived, which the right does not reach.
Export, review, and send
Produce a structured CSV or JSON export, a human reviews it against the rights of others, then it ships. Helps you comply, not legal advice.
Frequently asked
Questions teams ask about data portability
What is the right to data portability?
The right to data portability, in Article 20 of the GDPR, lets a person receive the personal data they provided to an organization in a structured, commonly used and machine-readable format, and reuse it elsewhere. Where technically feasible they can ask you to transmit it directly to another controller. The point of the right is to let people move between services without losing their data.
When does the right to data portability apply?
Only when two conditions are both met. The processing has to be based on the person's consent or on a contract with them, and it has to be carried out by automated means. Data you process on the basis of legitimate interests, a legal obligation, or a public interest task is outside the right, as is anything held only on paper.
Is the right to data portability absolute?
No. It is limited by its conditions, it does not apply to processing necessary for a public interest task or official authority, and it must not adversely affect the rights and freedoms of others, which matters when an export contains data about third parties. Article 20 also says the right does not override the right to erasure. In practice it is one of the narrowest rights in the GDPR.
What is the difference between data portability and the right of access?
Access gives the person a copy of all the personal data you hold about them, on almost any legal basis, in an intelligible form. Portability gives them only the data they provided or you observed, only where processing is automated and based on consent or contract, and it has to be machine-readable so another company can ingest it. An access response can be a document. A portability response is a data file.
Does the CCPA include a right to data portability?
Not as a separate right. California folds portability into the right to know: when a consumer requests specific pieces of personal information and the business delivers it electronically, it must be in a portable and, to the extent technically feasible, readily usable format that lets the consumer transmit it to another entity. So the obligation exists, but it is a delivery requirement attached to an access request rather than a standalone right as in the GDPR.
What format should a data portability export use?
The GDPR does not name a format. It requires structured, commonly used and machine-readable output, which in practice means CSV for simple tabular data, JSON for nested or complex records, and XML where a receiving system expects it. A scanned PDF or a printout does not meet the standard, because a machine cannot reliably parse it.
Run a data subject access request end to end
Obtainer finds where a person's data lives across your systems, compiles it into one manifest, drafts the deadline-safe response, and tracks the GDPR and CCPA clock. You review, redact, and approve what gets disclosed. Helps you comply; not legal advice.