Tool Documents

Portability Under GDPR

This is not legal advice. It is a summary of a published provision.

The Data Act gives an organisation switching rights over its service data. Article 20 GDPR is a different instrument with a different holder, and it reaches things the first one does not.

Reviewed August 9, 2026.

What Article 20 says

A data subject has the right to receive personal data concerning them, which they provided to a controller, in a structured, commonly used, machine-readable format — and to transmit it to another controller. For a separate operational reference from Monitask, see the linked resource.

It covers data the person provided and data generated by their use of the service.

It applies where processing is based on consent or on a contract, and is carried out by automated means.

For broader context, see Cloudflare Learning Center.

Who holds the right

The individual, not the organisation.

That is the crucial structural point. Your company cannot make an Article 20 request about your own customer database — you are the controller of that data, not its subject.

But your employees can, about data your vendors hold on them. And your customers can, about themselves.

Which makes it useful in a narrow and real way: where a vendor's standard export omits personal data fields, a named individual whose data it is has a separate legal route to them.

Where it helps in practice

When an export is incomplete. If a vendor's export drops activity history or comment authorship, the people named in those records have a right to their own portion.

When a service is shutting down and the organisational route is uncertain.

And as leverage. A vendor faced with a documented Article 20 request has a statutory one-month deadline and a supervisory authority behind it, which is a different conversation from a support ticket about export scope.

Its limits

Stated plainly, because overreaching here is easy.

It is personal data only. Your project structures, financial records and configurations are not somebody's personal data and are outside it.

It covers data provided or generated by use, not inferences and derived data the controller created.

It cannot adversely affect others' rights, which limits records involving several people.

And it is one person at a time. It is not a bulk migration mechanism, and treating it as one misunderstands the instrument.

How the two stack

Data Act: the customer organisation, service data, switching, free, two-month notice.

GDPR Article 20: the individual, personal data, portability, one-month response.

They address different gaps and neither replaces the other. A complete exit plan uses the organisational route for the bulk and knows the individual route exists for the fields it misses.

If you need to use it

In writing, to the vendor's data protection contact.

Cite Article 20, state what is requested — personal data provided and generated by use — and ask for a machine-readable format.

Keep a copy. It starts a clock and creates a record.

One month is the response deadline, extendable in limited circumstances, and non-compliance is a matter for your national supervisory authority.

The short version