O1.12.1Right to data portabilitydesignresearch

Portability lets users retrieve their data in a structured format

Aliases: data portability · data migration right · controller-to-controller transfer

What it is

The right to data portability lets a person, under applicable conditions, receive personal data they provided in a structured, commonly used, machine-readable format and transmit it to another controller. Under the GDPR, it applies to automated processing based on consent or contract and supports direct controller-to-controller transmission where technically feasible. It differs from a viewing screen or PDF report: the aim is reuse and migration, not human reading alone.

Why it happens

Account history, created content, and observed activity accumulate into switching cost. Portability turns those investments from a closed database into a personal resource that can move, reducing data lock-in and supporting alternatives. Scope, semantic structure, and request usability must work together. A file without field meaning, parsability, or importability satisfies the appearance of a copy while failing migration.

Studying it

Task audits can ask participants to request, download, identify, and import data into another tool, measuring discovery, verification, delay, scope understanding, and migration success. Institutional analysis should examine processing basis, automation, and the boundary of data “provided by” the person. Access and portability must be distinguished; a broader access copy is not automatically the portable set, and successful download is not evidence of downstream reuse.

Where it stops holding

Portability is not a globally uniform or unconditional right. Jurisdiction, processing basis, data source, and others' rights constrain scope. Exports containing messages or jointly created material need third-party safeguards without necessarily requiring blanket refusal. Portability also does not delete source data or terminate a contract; erasure, closure, or consent withdrawal may be separate actions.

Applying it

  • Distinguish view, portable download, direct transfer, and deletion in account and privacy entry points, stating each outcome.
  • Let people select data class and time range, previewing inclusions, exclusions, and treatment of joint data.
  • Provide asynchronous status, expiry notice, and recoverable download for large requests rather than requiring an open page.
  • Test new, long-lived, and shared-content accounts through import into another tool; accept only when scope is intelligible, files parse, and core records are reusable.

Related

  • Same group: O1.12.2 Machine readability determines whether another service can import an export · O1.12.3 Derived and inferred data are usually outside portability scope · O1.12.4 Export can become a bulk-exfiltration attack surface
  • Adjacent: O1.07 Right to erasure and data deletion · P3.05 Freedom to leave
  • Search terms: right to data portability · data export · controller-to-controller transfer

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/O1.12.1