Article 20
Right to Data Portability
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
When applicable, provide personal data supplied by the individual in a structured, commonly used, machine-readable format and support direct transmission where technically feasible.
Points of focus
- Determine which data and lawful bases fall within portability
- Produce interoperable, secure exports
- Avoid adversely affecting the rights of others
Implementation notes
Publish a stable JSON or CSV export schema, distinguish supplied and observed data from inferred outputs, and secure generation and download with step-up authentication and expiry. Operationalize determine which data and lawful bases fall within portability in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain portability scope analysis and export schema with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a pdf screenshot is offered as the only portable format Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample portability scope analysis and export schema with dates and named reviewers. Be ready to walk through how you detect and correct: a pdf screenshot is offered as the only portable format
Evidence auditors typically request:
- Portability scope analysis and export schema
- Machine-readable export sample and validation tests
- Secure direct-transfer or download process
Common gaps
- A PDF screenshot is offered as the only portable format
- The export includes inferred scores or another account member's data without analysis
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 20 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 20: Regulation (EU) 2016/679, Article 20 — Right to Data Portability