Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 20 Rätt till dataportabilitet


Summary What does Article 20 of the GDPR regulation say?

This article establishes the right to data portability for data subjects under the GDPR.

It gives individuals the right to obtain their personal data from a controller in a usable, machine-readable format and to move that data freely to another controller.

The right is not unlimited, however — it only applies where processing is based on consent or contract and is carried out by automated means.

The article also makes clear that this right does not override the right to erasure under Article 17, and cannot be used in ways that harm others or in public interest/official authority processing contexts.

Important points:

  • Data subjects can request their personal data in a structured, commonly used and machine-readable format and transmit it to another controller without hindrance.
  • The right only applies where processing is based on consent or contract and is carried out by automated means.
  • Direct controller-to-controller transmission is required where technically feasible, but the right cannot be exercised in a way that adversely affects the rights and freedoms of others.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Den registrerade ska ha rätt att få ut de personuppgifter som rör honom eller henne och som han eller hon har tillhandahållit den personuppgiftsansvarige i ett strukturerat, allmänt använt och maskinläsbart format och ha rätt att överföra dessa uppgifter till en annan personuppgiftsansvarig utan att den personuppgiftsansvarige som tillhandahållits personuppgifterna hindrar detta, om

      1. behandlingen grundar sig på samtycke enligt artikel 6.1 a eller artikel 9.2 a eller på ett avtal enligt artikel 6.1 b, och

      2. behandlingen sker automatiserat.

  1. ▼C1
    1. Vid utövandet av sin rätt till dataportabilitet i enlighet med punkt 1 ska den registrerade ha rätt till överföring av personuppgifterna direkt från en personuppgiftsansvarig till en annan, när detta är tekniskt möjligt.

    1. Utövandet av den rätt som avses i punkt 1 i den här artikeln ska inte påverka tillämpningen av artikel 17. Den rätten ska inte gälla i fråga om en behandling som är nödvändig för att utföra en uppgift av allmänt intresse eller som är ett led i myndighetsutövning som utförs av den personuppgiftsansvarige.

    1. Den rätt som avses i punkt 1 får inte påverka andras rättigheter och friheter på ett ogynnsamt sätt.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod