GDPR
Chapter III - Rights of the Data Subject

GDPR GDPR-Art.20: Right to data portability

Where processing is based on consent or on a contract and is carried out by automated means, provide the personal data the data subject has provided to the controller in a structured, commonly used and machine-readable format, and do not hinder its transmission to another controller. Where technically feasible, transmit the data directly from one controller to another at the data subject's request. The right is without prejudice to the right to erasure, does not apply to processing necessary for the performance of a public interest task or the exercise of official authority, and must not adversely affect the rights and freedoms of others.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 94 controls across 72 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

EU Data Act · 3 controls

  • DA-Art.3 Obligation to make connected-product data accessible by design (Article 3)
  • DA-Art.4 User right to access product data (Article 4)
  • DA-Art.5 User right to share data with third parties (Article 5)

APPI · 2 controls

  • APPI-A27 Restriction on Provision to Third Parties
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • P1 Demonstrates Commitment to Integrity and Ethical Values
  • P7 Identifies and Analyzes Risk
  • CCM-IPY-02 Application Interface Availability
  • CCM-IPY-03 Secure Interoperability and Portability Management

HITECH Act · 2 controls

  • HITECH-Scope-ARRA-XIII-42USC-Ch156-Subtitles HITECH Act Statutory Scope, ARRA Title XIII Origin and 42 USC Chapter 156 Structure (Subtitles A through D)
  • HITECH-SubtitleA-ONC-HIT-Standards-EHR-MU-PI HITECH Subtitle A - ONC, HIT Standards Committee, EHR Certification, Meaningful Use / Promoting Interoperability
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • 502 Interoperability with Assistive Technology
  • 707 Real-Time Text Functionality
  • CH-FADP-09 Notification of data files to the FDPIC
  • FADP-13 Right to Data Portability (Article 28)
  • SO2.3 Open-source health data standards
  • SO3.4 Standards and interoperability governance
  • P3-S3 Cooperative Arrangements/Procedures
  • DS-2 Ensure software supply chain security

Bahrain PDPL · 1 control

  • BB-DPA-14 Section 15 - Right to Data Portability

CCPA/CPRA · 1 control

  • §1798.110 Right to Know Categories and Specific Pieces of Personal Information Collected
  • PIPL-Art45 Right to Access, Copy and Portability
  • DIQ-1 Data Integration and Interoperability
  • DMA-Art.6 Article 6 obligations susceptible to specification (Article 6)
  • UAE-PDPL-Art.8 Records of processing activities (UAE PDPL Article 8)

ISO 27701:2019 · 1 control

  • 7.3.8 Providing copy of PII processed
  • ISO8000-MDG-01 Master Data Quality
  • INCDPA-ConsumerRights-Access-Correction-Deletion-Portability-OptOut-TargetedAd-Sale-Profiling-Appeal-45Day Indiana CDPA Consumer Rights - Access + Correction + Deletion + Portability + Opt-Out of Targeted Advertising/Sale/Profiling + 45-Day Response + 45-Day Extension + Authorised Agent + Appeal Process

Indonesia PDP Law · 1 control

LGPD · 1 control

  • LGPD-BR-Data-Subject-Rights-Article-18-Confirmation-Access-Correction-Anonymization-Portability-Revoke-Sharing Brazil LGPD Data Subject Rights + Article 18 + 9 Rights + Confirmation + Anonymization
  • LV-PDPL-Data-Subject-Rights-Access-Correction-Erasure-Restriction-Portability-Objection-Sec18-Sec38 Latvia PDPL Data Subject Rights + Access + Correction + Erasure + Portability + Section 18 + 38

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment

Mauritius DPA · 1 control

  • MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-ARCO-Rights-Articles-22-25-Acceso-Rectificacion-Cancelacion-Oposicion-Reglamento-89-103 Mexico LFPDPPP ARCO Rights + Articles 22-25 + Acceso + Rectificacion + Cancelacion + Oposicion + Reglamento 89-103
  • MN-CDPA-Consumer-Rights-Section-325O-04-Access-Correct-Delete-Portability-List-Third-Parties-Opt-Out-Appeal-AIQUEST-Profile Minnesota CDPA Consumer Rights + Section 325O.04 + Access + Correct + Delete + Portability + List of Third Parties + Opt-Out + Appeal + AI Question Profile
  • MT-CDPA-Consumer-Rights-MCA-30-14-2807-Access-Correct-Delete-Portability-Opt-Out-Appeal-AG-Referral Montana CDPA Consumer Rights + MCA 30-14-2807 + Access + Correct + Delete + Portability + Opt-Out + Appeal + AG Referral
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-3 PII Data Subject Rights and Automated Decision-Making
  • NRFCS-4 Consumer Privacy Rights, Consent, Marketing, and Loyalty Data
  • NHPA-4 Sensitive Data, Children, and Minors 13-16 Opt-In Consent
  • NJDPA-4 Sensitive Data, Children, and Adolescents 13-17 Opt-In
  • NGNDPR-4 Data Subject Rights and Automated Decision-Making
  • OREGONCPA-2 Consumer Rights: Access, Correction, Deletion, Portability, Opt-Out

PDPA Singapore · 1 control

  • PDPASG-3 Access, Correction, Data Portability, and Individual Rights

PDPA Thailand · 1 control

  • PDPATH-3 Data Subject Rights, Automated Decisions, Accuracy

POPIA · 1 control

  • POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions
  • NORWAY-2 Data Subject Rights and Automated Decision-Making

Peru DPL · 1 control

  • PERU-5 Security of Personal Data and Processor Agreements

Privacy Act 2020 · 1 control

  • NZPRV-3 IPP 6-8 Access, Correction, Accuracy

Qatar DPL · 1 control

  • QATAR-3 Data Subject Rights

SOC 2 · 1 control

Saudi Arabia PDPL · 1 control

  • SA-PDPL-09 Right to data portability
  • IM8-DAT.3 Data Sharing and Transfer
  • CIA-MYD-05 MyData service authorisation and operation

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TEXASTDPSA-1 Scope, Applicability, Exemptions

Turkey KVKK · 1 control

  • TURKEYKVKK-1 VERBIS Registration and Lawful Basis
  • Standard 9 Data Sharing
  • UKGDPRREG-2 Data Subject Rights (Articles 12-22)
  • OB-API.2 Open Data API Specification
  • CPSC-STD.4 Interoperability Safety

Uruguay DPL · 1 control

  • URUGUAY-2 Data Subject Rights (ARCO + Habeas Data)

Vietnam PDPD · 1 control

  • VIETNAMPDP-1 Scope, Categorisation, Lawful Basis

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-2 Consumer Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter III - Rights of the Data Subject

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.20 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 94 it maps to, and the evidence behind each claim, over MCP and REST.