Practical guide

How to draft a personal data portability request with AI

4 min read · Updated June 2026 · Editorial oversight: Avv. Federico Papa

The personal data portability request is a key mechanism established under Article 20 of the GDPR, enabling data subjects to receive their personal data in a structured format or to request its direct transfer to another controller. This right applies exclusively to processing operations based on consent or on a contract, and is limited to data provided by the data subject. Exercising this right facilitates switching between service providers, preventing vendor lock-in and strengthening individual control over personal data. The controller must respond to the request without undue delay, in compliance with the timeframes set out in Article 12 of the GDPR.

In brief

Article 20 of the GDPR regulates the right to data portability, allowing data subjects to receive personal data in structured, machine-readable formats like CSV, XML, or JSON. This right applies to automated processing based on consent or contract, covering data provided directly or through observation. Users can utilize AI to draft requests specifying the data controller, the DPO, and the technical scope. Under Article 12, controllers must provide the data free of charge within one month, with a potential two-month extension for complex cases, preventing technological lock-in.

The steps

  1. 1.

    Verify applicability requirements

    You must first ensure that the data processing is based on the data subject's consent or on a contract. The right to portability does not apply if the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority. Furthermore, the data must have been provided by the data subject and processed by automated means.

  2. 2.

    Identify controller and DPO

    The request must be addressed to the data controller, accurately identifying its registered office or dedicated contact details. Where a Data Protection Officer (DPO) has been designated, it is advisable to copy them on the communication to expedite processing. Correctly identifying the recipient ensures compliance with the statutory response deadlines established by European legislation.

  3. 3.

    Formulate the subject line

    The request must explicitly reference the exercise of the right to data portability pursuant to Article 20 of the GDPR. You must clearly specify whether the request concerns the receipt of data in a structured, readable format or direct transmission to another data controller. The subject line must be unambiguous to prevent the request from being misclassified as a standard access request under Article 15 of the GDPR.

  4. 4.

    Specify the technical format

    The data subject is entitled to receive data in a structured, commonly used, and machine-readable format, such as CSV, XML, or JSON. It is recommended to explicitly express a preference for an open, interoperable format that does not require expensive proprietary software. The controller must ensure that the format provided enables the effective transfer and reuse of the information.

  5. 5.

    Define the scope of data

    It is necessary to clearly define the scope of the request, distinguishing, for example, between personal details, activity logs, and recorded preferences. Data portability applies to data provided actively and knowingly by the data subject, as well as data generated by observing user activity. However, data derived or inferred by the controller through complex analytics or proprietary algorithms is excluded from the scope of this right.

  6. 6.

    Request transmission to third parties

    Where direct transfer to a new provider is requested, full identification details of the receiving controller must be provided. Pursuant to Article 20(2) of the GDPR, such transmission must be carried out where technically feasible, with the burden of proof regarding any technical impediments resting on the transferring controller. The request must include explicit authorization for the data transfer.

Legal basis: art. 20 GDPRart. 12 GDPR

The template structure

The standard sections that make up the document. The full template can be opened and completed directly on edit.legal.

  1. Sender

    Personal details and contact information of the data subject exercising the right.

  2. Data Controller

    Identification details of the data controller and, where designated, the Data Protection Officer (DPO).

  3. Subject: exercise of the right to data portability

    Formal statement of intent to exercise the right under Article 20 of Regulation (EU) 2016/679.

  4. Request content

    Detailed description of the data categories subject to the request and specification of the requested digital format.

  5. Receiving data controller

    Details of the new controller where direct data transfer between controllers is requested.

  6. Place, date, and signature

    Space for date, handwritten or digital signature, and list of any identification attachments.

Mistakes to avoid

  • Requesting portability of data not provided by the data subject, but generated or inferred independently by the controller.
  • Invoking the right to portability for paper records, given that the provision applies exclusively to automated processing.
  • Assuming that failure to attach an identity document results in automatic rejection: the controller may only request additional information where reasonable doubts exist regarding identity.
  • Confusing the right to data portability with the right of access under Article 15 of the GDPR, erroneously requesting explanations on the logic of the processing.

Frequently asked questions

What is the deadline for responding to the request?

The controller must respond without undue delay and at the latest within one month of receipt. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests.

Does exercising the right to data portability involve any cost?

No, Article 12 of the GDPR provides that information and communications supplied under Article 20 must be provided free of charge.

What happens if direct transmission is not technically feasible?

If a genuine technical impediment exists, the controller must still provide the data to the data subject in a structured, interoperable format, allowing them to upload it independently to the new provider.

Avv. Federico Papa
Editorial oversight: Avv. Federico Papa·ICAM

What edit.legal automates

  • Automated selection of the most common interoperable technical formats for the request.
  • Automatic inclusion of updated legal references to Articles 12 and 20 of the GDPR.
  • Generation of specific clauses for direct transmission between data controllers.

Put edit.legal to the test on actual cases

Try edit.legal for free on an active case. No credit card required.

Try edit.legal for free