Under the GDPR, which of a streaming subscriber's data falls under the Art. 20 right to data portability, and which does not?
answer
- narrower than access
- who supplied the data
- only two lawful bases
- automated means, machine-readable format
basics
~20 sUnder GDPR Art. 20, portability covers personal data the subscriber provided, processed on consent or contract by automated means, delivered in a structured, commonly used, machine-readable format. Scores the service computes and data processed on other lawful bases fall outside.
solid answer
~40 sUnder the GDPR, `Art. 20(1)` sets three cumulative conditions: the data concerns the person and **was provided by them**; the processing is based on **consent** (`Art. 6(1)(a)` or `9(2)(a)`) or **contract** (`Art. 6(1)(b)`); and it is carried out **by automated means**. The person receives the data in a **structured, commonly used and machine-readable format** and may have it transmitted **directly to another controller where technically feasible** (`Art. 20(2)`). For a streaming account, sign-up details, ratings and playlists are in scope; a churn score or recommendation profile the service computed is not "provided", and data held only under a legal obligation or legitimate interests is outside the lawful-basis condition. Porting does not erase anything (`Art. 20(3)`), and the export must not adversely affect others' rights (`Art. 20(4)`).
go deeper
Recall the three conditions: data the person provided, processing on consent or contract, and automated means. Know the format words: structured, commonly used and machine-readable.
Explain how portability differs from access, walk a real account's data through the three conditions, and say why computed scores fall outside while typed-in data falls inside.
Handle the edges: observed data such as viewing history, household accounts under Art. 20(4), direct transmission only where technically feasible, and a port that must not trigger an erasure.
Decide how far to go beyond the minimum: a self-service export in a documented format reduces per-request cost, but its scope must follow the Art. 20 conditions, not marketing promises.
## What portability adds to access Under the GDPR, the right of access (`Art. 15`) lets a person see all personal data a controller processes about them, with context. **Data portability** (`Art. 20`) is narrower but does something access does not: it gives the person their data in a form another system can reuse, and lets them send it to another controller. Recital 68 frames it as strengthening control over one's own data. Where access answers "what do you hold about me?", portability answers "let me take it with me". ## The three conditions `Art. 20(1)` applies only where **all** of the following hold: | Condition | Text | Consequence | |---|---|---| | Provided by the person | "personal data ... which he or she has provided to a controller" | Data the controller creates about the person is not captured by these words | | Consent or contract | processing based on `Art. 6(1)(a)`, `Art. 9(2)(a)` or `Art. 6(1)(b)` | Legitimate interests, legal obligation and public-task processing are outside | | Automated means | "the processing is carried out by automated means" | Paper files are outside | Recital 68 confirms the lawful-basis limit: the right should not apply where processing is based on a legal ground other than consent or contract. ## Mapping the streaming account | Data | Provided by the subscriber? | Basis | In scope? | |---|---|---|---| | Name, email, billing address given at sign-up | Yes | Contract | Yes | | Film ratings, watchlists and playlists the subscriber built | Yes | Contract | Yes | | Viewing history generated by using the service | Arguable | Contract | Usually treated as in scope | | Recommendation profile, churn-risk score | No, computed by the controller | Contract or legitimate interests | No | | Invoices kept to meet tax law | Partly | Legal obligation for the retention | No | | Account-sharing fraud signals | No | Legitimate interests | No | The viewing-history row is the grey zone. The text says "provided"; supervisory guidance has generally read that word to include data the person generates through their use of a service, while scores and inferences the controller derives are not provided by the person under any reading. An interview answer should say which reading it assumes. ## Format and transmission - **Format.** "Structured, commonly used and machine-readable" — recital 68 adds "interoperable". A scanned printout fails the test; a documented export in a common structured format passes it. - **No compatibility duty.** Recital 68 states that the right should not create an obligation for controllers to adopt or maintain processing systems which are technically compatible; controllers are encouraged to develop interoperable formats. - **Direct transmission.** `Art. 20(2)`: the person may have the data sent directly from one controller to another **where technically feasible**. That is a conditional right, not a duty to build a connector to every rival service. - **Timing and cost.** The `Art. 12(3)` clock applies — one month from receipt, extendable by two further months — and the request is free under `Art. 12(5)` unless manifestly unfounded or excessive. ## Limits written into Art. 20 1. **Erasure is separate.** `Art. 20(3)`: the right is without prejudice to `Art. 17`. Porting does not delete anything at the original controller; recital 68 adds it does not imply erasure of data still necessary for performing a contract. A subscriber who wants both must ask for both. 2. **Public functions.** `Art. 20(3)`: the right does not apply to processing necessary for a task in the public interest or in the exercise of official authority. 3. **Other people.** `Art. 20(4)`: the right must not adversely affect the rights and freedoms of others. A household account where several people keep their own profiles and watch history is the practical case: the requester's export should not carry the other members' data. ## Common mistakes - Treating portability as a second access right that covers everything held. - Including inferred scores and profiles in the export, or excluding the data the person typed in. - Offering portability for data processed on legitimate interests, or refusing it for contract-based data. - Assuming a port also closes the account or erases the data. - Building a direct transfer to every competitor on the belief that `Art. 20(2)` requires it.
- Under the GDPR, must the controller receiving ported data accept whatever format the sending controller exports?Art. 20 places the format duty on the sending controller: structured, commonly used and machine-readable, with direct transmission only where technically feasible. Recital 68 says the right creates no obligation for controllers to adopt or maintain technically compatible systems. The receiving controller decides what to take in, and needs its own lawful basis for whatever it then processes.
- Under the GDPR, how does the portability right differ from the access right for the same subscriber?Access under Art. 15 covers all personal data processed about the person, on any lawful basis, plus context such as purposes, recipients and retention. Portability under Art. 20 is narrower — only data the person provided, on consent or contract, processed by automated means — but it must come in a reusable machine-readable format and may be sent directly to another controller.
saying these in an interview costs you the question
- Portability covers every piece of personal data the controller holds
- Portability applies whatever the lawful basis of the processing
- A scanned printout of the account page satisfies the format requirement
- Porting data to another service erases it from the original service
- Controllers must build direct transfer interfaces to every rival service