Skip to content

Data Portability

What is Data Portability?

The right of individuals to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. Established under GDPR Article 20.

Privacy

Each of these is named in at least one of the same controls as data portability. The number is how many controls name both.

What the standards actually require on data portability

Requirements naming data portability across 6 standards, quoted from the control text.

PDPA Thailand2 controls

Data subjects may request personal data in a readable or commonly used machine-readable format and may request transfer to another controller.

Section 31 · Right to Data Portability

A consumer has the right to obtain a copy of the personal data that the consumer previously provided to the controller in a portable and, to the extent technically feasible, readily usable format that allows the consumer to transmit the data to another control...

§13-61-201(1)(c) · Right to Data Portability
Bahrain PDPL1 control

Right to data portability. Control from Bahrain PDPL framework, domain: Bahrain PDPL: Data Subject Rights.

BH-PDPL-09 · Right to data portability

Write into customer agreements what access to data the customer keeps when the contract ends, covering data format, retention period, scope of data retained and the deletion policy.

CCM-IPY-04 · Data Portability Contractual Obligations

Consumers may obtain a portable, readily usable copy of their personal data (up to twice per year).

COPA-1306-PORTABILITY · Right to Data Portability

Consumers may obtain a portable, readily usable copy of personal data they previously provided.

CTDPA-42-518-PORT · Right to Data Portability

Questions people ask about data portability

What is Data Portability?
The right of individuals to receive their personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller. Established under GDPR Article 20.
Why is Data Portability important for compliance?
Data Portability is a key concept in Privacy. Understanding data portability helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data Portability?
Data Portability appears in the requirement text of PDPA Thailand, Utah Consumer Privacy Act, Bahrain PDPL, Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1, Colorado Privacy Act. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data Portability?
Explore our compliance framework pages to see how data portability applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data Portability applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.