Skip to content
compliancebase
GDPRChapter III — Right to Data Portability

Article 20

Right to Data Portability

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

When applicable, provide personal data supplied by the individual in a structured, commonly used, machine-readable format and support direct transmission where technically feasible.

Points of focus

  • Determine which data and lawful bases fall within portability
  • Produce interoperable, secure exports
  • Avoid adversely affecting the rights of others

Implementation notes

Publish a stable JSON or CSV export schema, distinguish supplied and observed data from inferred outputs, and secure generation and download with step-up authentication and expiry. Operationalize determine which data and lawful bases fall within portability in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain portability scope analysis and export schema with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a pdf screenshot is offered as the only portable format Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample portability scope analysis and export schema with dates and named reviewers. Be ready to walk through how you detect and correct: a pdf screenshot is offered as the only portable format

Evidence auditors typically request:

  • Portability scope analysis and export schema
  • Machine-readable export sample and validation tests
  • Secure direct-transfer or download process

Common gaps

  • A PDF screenshot is offered as the only portable format
  • The export includes inferred scores or another account member's data without analysis

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 20This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Right to Data Portability applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — determine which data and lawful bases fall within portability — with evidence stored where auditors and customers can sample it.

Lead with portability scope analysis and export schema and pair it with machine-readable export sample and validation tests. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a pdf screenshot is offered as the only portable format Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above