Data Portability
Data portability is the ability to move data from one system, platform, or provider to another. It is intended to prevent data from being locked into incompatible closed systems, sometimes described as silos or walled gardens. In some jurisdictions it also refers to a legal right that lets individuals obtain and reuse their own personal data across services.
Data portability denotes the capability to transfer data between two or more systems, typically in a structured, commonly used, and machine-readable format that supports reuse and interoperability. As a technical property, it addresses the movement of data between platforms and is distinct from the broader concerns of data quality, security, or governance that may apply during and after transfer. As a legal right, portability is granted under multiple regimes rather than a single jurisdiction: for example, Article 20 of the EU General Data Protection Regulation (GDPR) establishes a right for data subjects to receive personal data concerning them; comparable statutory rights exist elsewhere, such as under the California Consumer Privacy Act/California Privacy Rights Act and, in the health context, under U.S. HIPAA. Scope and conditions vary by regime, covering, for instance, which categories of data qualify, the required transfer format, and whether direct provider-to-provider transfer is mandated, so portability obligations should be assessed against each applicable jurisdiction and sector rather than assumed to be uniform.
Why it matters
Data portability directly affects an organization's ability to change vendors, avoid lock-in, and maintain resilience across its third-party relationships. When data is trapped in incompatible closed systems, sometimes described as silos or walled gardens, an organization may find it costly or impractical to exit a provider, integrate a new service, or recover its own information if a supplier relationship ends. Assessing a vendor's portability capabilities during onboarding, and reassessing them over the life of the contract, helps risk and procurement teams understand exit options before they become urgent.
Portability also carries direct compliance implications, because it is not only a technical property but a legally enforceable right under multiple regimes rather than a single one. Article 20 of the EU GDPR establishes a right for data subjects to receive personal data concerning them, but comparable statutory rights exist elsewhere, for example under the California Consumer Privacy Act/California Privacy Rights Act and, in the U.S. health context, under HIPAA. Because scope and conditions differ across these regimes, an organization relying on a third party to process personal data may inherit obligations that vary by jurisdiction and sector.
It is important to keep the scope of portability narrow when evaluating risk. Portability addresses whether data can be moved between systems; it does not by itself guarantee data quality, security, or governance during and after transfer. Treating a portability feature as if it resolves those broader concerns can create a false sense of assurance, so portability should be assessed alongside, not as a substitute for, controls covering integrity, confidentiality, and downstream governance.
Who it's relevant to
Inside Data Portability
Common questions
Answers to the questions practitioners most commonly ask about Data Portability.
