Data Portability: rights under GDPR explained

Like all rights the right to data portability is not absolute. It only applies in some circumstances. The restrictions, and potential complexity that arises from them, on this right illustrate the importance of knowing the lawful basis for your data processing. Also, you should be drafting clear privacy statements, and having a comprehensive record of processing activity. While legislation acknowledges the existence of this right [1], there are no specific provisions setting out how to comply with it.

This is because the right only applies to data:

  • Obtained through consent, or if it is processed for the purposes of a contract
  • And to date provided to you by the data subject themselves (and this includes the data about third parties).

You need to be careful of the second point. The information could have been provided passively, or even collected from them by you without them being aware of it. For example, this includes the collection of IP addresses or leaving cookies when someone visits your website. Other examples include data collected from devices, such as location or usage.

[1] Article 20 of the GDPR

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Data Portability: How to Comply

When people exercise their right to data portability they have two options. They can have their data sent to them in a structured machine-readable format; or ask you to send it to a third party. You must do either without delay and in any event within 30 days. There are specific rules requiring organisations not to hinder the free movement of data. It is important then to ensure that you have appropriate systems in place to facilitate data portability.

It should not be too difficult to identify data that have been obtained directly from an individual with their consent or for the purposes of processing a contract, and collate this into a machine readable format for transmission, even if it contains the data of another person.

But before you send it you must review it to ensure that transmission of the data would not harm the “rights and freedoms” of another person (including you!).

There is some good news though – when you transmit the data to a third party at the request of a data subject you are not responsible for any further processing: you are not creating a controller/processor relationship with the third party (which is fortunate as they could easily be a direct competitor.

In addition you can refuse unreasonable or excessive requests, and an example of this is when someone makes repeated requests for their data to be transmitted – alternatively you can charge a reasonable fee for compliance.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

No Age Restriction on Data Portability

As with all rights under the GDPR there is no age restriction or limit for people to exercise them. This means you could get requests for data portability from a child. There is no reason why such requests should be a problem. But, it is important to remember:

  • If the child was under 13 when the data were provided it may have come with the consent of someone exercising parental authority or equivalent. As soon as the child reaches 13 or over the right to give, withhold or withdraw consent transfers to them.
  • A child’s data is more likely to have the data of a third party, such as a parent or guardian in it.
  • Children of all ages may be less aware of the consequences of entering into a contract, or of transmitting data. It is worth taking extra care to review any requested data to ensure the rights and freedoms of others are not compromised.

As people become aware of their rights, the right to data portability is one they will exercise. Evidence from our own clients is that people are learning about, and exercising their rights at a faster rate than we anticipated. Certainly for the first few requests, it can be a challenge to fully comply. We recommend testing your systems to ensure you can respond to these requests.

Top tips:

  • Make sure you understand your data processing activity and the legal basis for it
  • Your privacy statement must include any data collection and processing that people may not be aware of
  • Understand the limits to data potability, particularly where the line between data provided by the data subject and other data lies
  • Send data to third parties within 30 days of requests being made.
  • Remember the data privacy principles require data accuracy: only transmit data you know is correct and up to date.
  • Data must be transmitted in a machine readable format: XML or CSV format should be sufficient.
  • Requests relating to children should not be a problem. However, remember the age of competence is 13 for consent. You should take extra care not to compromise the rights and freedoms of others.
  • Get ready for requests for data portability now – and test your systems.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial