Civil Law And Data Portability Enforcement Litigation In Europe .
Civil Law And Data Portability Enforcement Litigation In Europe
1. Introduction
Data portability enforcement litigation concerns disputes over a person's right under Article 20 GDPR to obtain personal data in a structured, commonly used and machine-readable format and, where technically feasible, to transmit that data directly to another controller without hindrance.
The right is designed to promote both individual control over personal data and practical switching/interoperability between digital services. It is narrower than the general right of access under Article 15: portability principally concerns personal data provided by the data subject, automated processing, and processing based on consent or contract. (Homepage | Data Protection Commission)
European case law specifically devoted to Article 20 remains comparatively limited. Consequently, the most useful authorities comprise:
direct Article 20 court decisions;
national supervisory-authority decisions;
CJEU decisions concerning the scope and enforcement of GDPR data-subject rights;
closely analogous European authorities concerning access, personal-data control and effective remedies.
The EDPB's enforcement register confirms that Article 20 has already featured in numerous cross-border enforcement decisions, including decisions from 2021 onward. (European Data Protection Board)
2. Legal Foundation: Article 20 GDPR
Article 20 creates two related rights.
First right — Receive the data
The data subject can obtain personal data concerning them in:
structured form;
commonly used form;
machine-readable form.
Second right — Direct transmission
The data subject may request transmission directly from:
Controller A → Controller B
where technically feasible.
The right normally applies where:
processing is based on consent or contract;
processing is carried out by automated means; and
the requested information falls within Article 20's substantive scope. (Homepage | Data Protection Commission)
3. Data Portability Is Not the Same as Data Access
This distinction is fundamental.
| Article 15 | Article 20 |
|---|---|
| Right of access | Right to portability |
| Broad right to obtain personal data | More specific right |
| Applies more generally | Limited legal conditions |
| Copy of personal data | Structured, machine-readable data |
| Primarily transparency/control | Reuse and switching |
| Does not necessarily require transfer to another controller | Can require direct controller-to-controller transmission |
The Irish Data Protection Commission expressly emphasizes that access and portability are distinct rights, even though they are closely connected. (Homepage | Data Protection Commission)
4. Case 1 — Meta Platforms Ireland Ltd v Data Protection Commission
High Court of Ireland, [2026] IEHC 323, 21 May 2026
This is currently one of the most significant European court decisions directly concerning Article 20 portability enforcement.
Facts
The proceedings originated from a complaint concerning a data subject's request to Meta/Facebook for:
access to personal data;
portability of personal data;
data held in Facebook's internal Hive data warehouse.
The complainant sought raw or original data in a machine-readable format and argued that ordinary user-facing tools did not provide the information necessary to exercise his rights.
The DPC's draft findings included a proposed finding that Meta had infringed Article 20(1) GDPR by refusing to comply with the portability request. (Bailii)
The DPC's proposed corrective measures were potentially very substantial, including a proposed fine of approximately €360–430 million and measures affecting broader data-access practices. (Bailii)
High Court issue
Meta challenged the DPC's approach, including the scope of the investigation and whether the regulator could move from an individual complaint toward broader systemic enforcement.
Importance
The case demonstrates that an Article 20 complaint can become much more than an individual data request.
It may develop into:
Individual portability complaint → regulatory investigation → systemic compliance order → substantial administrative enforcement.
Principle
A single data-portability complaint can raise questions concerning systemic compliance with Articles 12, 15 and 20 GDPR.
Important qualification
The judgment primarily concerns the lawfulness and scope of the DPC's enforcement process, rather than constituting a final merits judgment that Meta violated Article 20. The DPC's underlying findings described in the judgment were provisional at that stage. (Bailii)
5. Case 2 — LG Wiesbaden, 2 O 49/24, 15 January 2025
Direct Article 20 judgment
This German Regional Court decision is particularly useful because it addresses who can invoke portability.
Facts
The claimant sought to invoke Article 20 GDPR against a credit-rating agency.
The agency processed personal information to calculate credit scores.
The claimant argued that he should be able to exercise the right to portability concerning the information held by the credit agency.
Court's approach
The court concluded that Article 20 did not apply because the relevant personal data had not been provided by the data subject in the sense required by Article 20.
The right therefore could not simply be transformed into a general mechanism for obtaining every item of personal information held by a controller. (gdprhub.eu)
Principle
Article 20 is not a general-purpose data-export right equivalent to Article 15.
The source of the data matters.
Importance
This is particularly important for:
credit agencies;
analytics companies;
AI platforms;
data brokers;
advertising platforms;
profiling systems.
A controller may possess extensive information about a person without all of that information necessarily falling within Article 20.
6. Case 3 — Irish DPC/Meta — Michael Veale Portability Complaint
The underlying Meta portability dispute is also important as an enforcement proceeding independently of the later Irish judicial-review litigation.
The complaint concerned Facebook's refusal to provide data from its internal Hive system in the form requested by the data subject.
The complainant argued that a meaningful portability right required more than a curated or simplified export because he wanted to independently analyse and reuse the information.
The dispute illustrates a fundamental Article 20 question:
How much data must a controller provide for portability to be meaningful?
The Irish proceedings record that the complainant sought a structured, machine-readable export capable of independent analysis and reuse. (Bailii)
Principle
Data portability must be considered in light of its functional purpose—reuse and transmission—not merely the production of a nominal data file.
Caveat
This remains part of the Meta enforcement litigation and should not be presented as a final CJEU ruling establishing that every underlying Hive data item must be ported.
7. Case 4 — Italian Garante, Weople Decision, 2024
Direct data-portability enforcement authority
The Italian Data Protection Authority considered the Weople data-intermediation model.
The system involved users delegating the exercise of certain data-subject rights, including portability, concerning data held by third parties such as:
social networks;
loyalty programmes;
companies with which users had relationships.
The authority examined whether the delegation mechanism genuinely represented the data subject's specific and unambiguous intention and whether it properly defined:
the object of the delegation;
its duration;
the actions that the intermediary could perform. (European Data Protection Board)
Principle
A data subject's delegation of portability rights must reflect a sufficiently specific and unambiguous intention.
Importance
This becomes increasingly important where data portability is exercised through:
personal-data intermediaries;
data wallets;
data cooperatives;
personal information management systems;
AI agents acting for users.
8. Case 5 — EDPB Final Decision, EDPBI:FR:OSS:D:2021:226
French cross-border enforcement
The EDPB register records a French one-stop-shop decision dated 9 April 2021 in which Article 20 GDPR was expressly identified as a main legal reference.
The decision also concerned:
Article 12;
Article 17;
data-subject rights.
The outcome was a reprimand. (European Data Protection Board)
Significance
This illustrates that failure to comply with portability obligations may be treated as an enforcement violation, even where the authority does not impose a financial penalty.
Principle
Article 20 creates an enforceable regulatory obligation, not merely a voluntary best-practice standard.
9. Case 6 — EDPB/Irish Cross-Border Decision, EDPBI:IE:OSS:D:2024:1441
The EDPB register records an Irish one-stop-shop decision of 19 September 2024 involving:
Article 12;
Article 15;
Article 17;
Article 18;
Article 20;
Article 21;
Article 22.
The outcome was an amicable settlement. (European Data Protection Board)
Legal importance
The decision illustrates how portability disputes frequently occur together with other data-subject rights.
For example:
User requests access + erasure + portability + objection.
A controller therefore has to identify the specific legal conditions applicable to each right, rather than responding to all rights as if they were identical.
10. Case 7 — EDPB/Irish Cross-Border Decision, EDPBI:IE:OSS:D:2025:3573
The EDPB register records another Irish cross-border decision dated 22 August 2025 involving:
Article 12;
Article 15;
Article 16;
Article 17;
Article 18;
Article 19;
Article 20;
Article 21;
Article 22.
The decision concerned data-subject rights and online platforms and ended in an amicable settlement. (European Data Protection Board)
Importance
The decision illustrates the increasing importance of portability in online-platform governance.
Portability can be particularly relevant where users wish to move between:
social networks;
digital platforms;
online marketplaces;
financial applications;
health applications;
cloud services.
11. Case 8 — EDPB/Irish Cross-Border Decision, EDPBI:IE:OSS:D:2025:3518
Another Irish cross-border decision dated 26 June 2025 involved Article 20 together with the other principal data-subject rights.
The matter concerned:
access;
rectification;
erasure;
restriction;
portability;
objection;
automated decision-making.
The outcome was an amicable settlement. (European Data Protection Board)
Principle
Controllers must treat portability as part of an integrated rights-management system rather than as an isolated technical feature.
12. Case 9 — EDPB/Irish Cross-Border Decision, EDPBI:IE:OSS:D:2025:3564
The EDPB register records an Irish decision dated 15 August 2025 involving Article 20 alongside Articles 12, 15, 16, 17, 18, 19, 21 and 22.
The outcome was an amicable settlement. (European Data Protection Board)
Although such administrative settlements are not equivalent to a reasoned appellate judgment, they are useful evidence of how Article 20 is being handled in European supervisory enforcement.
13. Case 10 — CJEU, Nowak v Data Protection Commissioner, C-434/16
Important analogous CJEU authority
Nowak concerned the scope of “personal data” under EU data-protection law.
The CJEU adopted a broad approach to personal data, holding that information is personal data where it relates to an identified or identifiable individual and is sufficiently connected to that person.
Relevance to portability
Article 20 only applies to personal data.
Therefore, the scope of “personal data” is a necessary preliminary question.
The Nowak principle supports a substantive rather than excessively formalistic approach to identifying personal data.
Important qualification
Nowak did not decide Article 20 portability itself.
It is therefore an analogical CJEU authority, not a direct portability judgment.
14. Case 11 — CJEU, Wirtschaftsakademie Schleswig-Holstein, C-210/16
The CJEU examined joint controllership and responsibility for processing involving a Facebook fan page.
The Court emphasized that responsibility under EU data protection law can extend beyond the party physically holding or technically processing the data.
Data-portability relevance
In a portability dispute, identifying the legally responsible controller is critical.
The question may be:
Who actually determines the purposes and means of processing?
rather than simply:
Who stores the data?
Principle
Technical possession of data and legal responsibility for processing are not necessarily the same thing.
Classification
This is an analogical CJEU authority, not an Article 20 judgment.
15. Case 12 — CJEU, Google Spain, C-131/12
Google Spain established important principles concerning:
controller responsibility;
data-subject rights;
effective protection;
balancing privacy with competing interests.
It concerned the right to delisting rather than portability.
Relevance
The case supports the broader proposition that GDPR rights must be practically effective rather than merely theoretical.
For portability litigation, this supports examining whether the format supplied actually permits:
meaningful reuse and transfer.
Classification
Again, analogical rather than direct Article 20 authority.
16. The Scope of Portable Data
One of the most difficult questions is:
What data must actually be ported?
Article 20 is not simply:
“Give me everything you know about me.”
The EDPB portability guidance distinguishes between data provided by the data subject and other categories of data. The EDPB has formally endorsed the guidelines on the right to data portability. (European Data Protection Board)
Potentially relevant data can include information:
actively provided by the user;
generated through use of a service in circumstances falling within the portability framework;
contained in user profiles;
generated through transactions.
But inferred or derived data may raise more difficult questions.
17. Observed Data vs Inferred Data
Consider a fitness platform.
User-provided
Height: 175 cm
Observed
Heart-rate readings generated while using the device.
Inferred
“User is likely at high risk of cardiovascular disease.”
The third category is considerably more controversial for portability.
The controller may argue:
This is our proprietary analytical output.
The data subject may argue:
It relates to me and is essential to understanding my profile.
Article 20 therefore cannot be interpreted independently of:
Article 4 definitions;
Article 15 access;
Article 20's specific wording;
rights of others;
trade secrets;
intellectual property.
18. Machine-Readable Format
Article 20 requires a format that is:
structured;
commonly used;
machine-readable.
A PDF may sometimes satisfy a particular access request, but portability is specifically concerned with machine usability.
Examples of potentially suitable formats can include:
CSV;
JSON;
XML;
standardized API output.
The legal question is not simply whether the file can technically be opened.
The question is:
Can another system reasonably process and reuse the information?
19. Direct Controller-to-Controller Transmission
Article 20 is particularly important where the user says:
“Send my data directly to the new provider.”
The controller should assess whether direct transmission is:
technically feasible;
legally permissible;
sufficiently secure;
compatible with the rights and freedoms of others.
The Irish DPC confirms that direct transmission can be requested where technically feasible. (Homepage | Data Protection Commission)
20. Technical Feasibility
A controller cannot necessarily argue:
“Our systems are incompatible, therefore portability does not exist.”
Technical feasibility is part of the statutory framework, but the controller's own technical architecture may be relevant to assessing whether genuine interoperability is possible.
A dispute can therefore involve:
APIs;
authentication;
data schemas;
encryption;
interoperability standards;
transfer protocols;
identity verification.
21. Data Portability and Data Interoperability
These concepts overlap but are not identical.
Portability
Individual right:
“Give or transmit my data.”
Interoperability
System capability:
“Can two platforms exchange information effectively?”
A portability claim may expose a deeper interoperability problem.
For example:
Platform A → proprietary format → Platform B cannot easily import.
The legal question becomes whether the export nevertheless satisfies Article 20's requirements.
22. Data Portability and Competition
Portability can also have market effects.
Imagine:
Platform A has 10 million users.
Users cannot easily move their data to:
Platform B.
The resulting switching cost can strengthen Platform A's position.
Data portability can therefore support:
consumer choice;
switching;
innovation;
competition;
multi-homing.
However, Article 20 remains primarily a data-protection right, not a general competition-law interoperability obligation.
23. Data Portability and Digital Markets
The EU's digital regulatory framework increasingly addresses interoperability and switching.
Therefore, a dispute may involve both:
GDPR Article 20
Individual portability right.
and
Digital Markets Act / sectoral legislation
Potential obligations concerning access, switching or interoperability.
The two regimes should not be conflated.
24. Restrictions on Portability
The right is not absolute.
Article 20 itself recognizes limitations concerning:
rights and freedoms of others.
Examples include:
Third-party personal data
A user's exported dataset may contain another person's information.
Trade secrets
The export should not necessarily reveal proprietary information unrelated to the individual's personal data.
Intellectual property
A controller may have legitimate IP interests.
Security
A transfer mechanism must not create unacceptable security risks.
But a controller should not simply respond:
“Trade secret — therefore no portability.”
The restriction has to be legally justified and proportionate.
25. Excessive Requests
Article 12(5) permits certain responses to manifestly unfounded or excessive requests.
The threshold is high.
The Irish DPC states that controllers relying on this provision must be able to demonstrate why the request qualifies and that there should be relatively few cases where refusal can be justified on this basis. (Homepage | Data Protection Commission)
26. One-Month Rule
Article 12 generally requires the controller to respond to a data-subject request:
without undue delay and in any event within one month.
The period may be extended by up to two further months where necessary because of the complexity or number of requests, but the controller must communicate the extension and reasons within the original period.
This makes delay itself an important enforcement issue.
27. Refusal Must Be Explained
A controller that refuses portability should generally identify:
the legal basis for refusal;
why Article 20 does not apply;
whether another GDPR right applies;
relevant restrictions;
available complaint/remedy mechanisms.
A vague response such as:
“We do not offer data portability”
may be insufficient where Article 20 applies.
28. Administrative Enforcement
Supervisory authorities can use GDPR enforcement powers including:
warnings;
reprimands;
compliance orders;
bans/restrictions;
administrative fines.
The EDPB register demonstrates that Article 20 is already appearing in actual European cross-border enforcement, including reprimands and settlements. (European Data Protection Board)
29. Civil Remedies
A data-portability dispute can also produce civil litigation.
Potential remedies may include:
Injunction
Order the controller to provide the data.
Declaration
Court declares that Article 20 applies.
Damages
Potentially where the GDPR's compensation requirements are satisfied.
Corrective measures
Through supervisory authorities.
Contractual claims
Where portability obligations are also incorporated into a service contract.
30. Portability and GDPR Compensation
An important distinction:
Violation of Article 20 does not automatically mean that substantial damages are payable.
A compensation claim under Article 82 GDPR requires the elements established by CJEU case law concerning:
infringement;
damage;
causal connection.
Thus:
failure to provide portable data
and:
compensable damage caused by that failure
are separate questions.
This distinction is important in litigation.
31. Portability in Employment Relationships
Data portability can arise in:
HR platforms;
employee benefits systems;
professional networking platforms;
payroll applications;
recruitment systems.
However, employment-related processing may not always satisfy the Article 20 conditions.
The claimant must examine:
legal basis;
purpose;
data source;
automated processing;
whether the data were provided by the individual.
32. Portability in Banking and Fintech
This is an increasingly important area.
Potential data include:
transaction history;
account information;
payment records;
investment data;
financial-profile information.
The distinction between:
GDPR portability
and
sectoral open-banking/data-access rights
is critical.
PSD2/open-banking mechanisms can provide access rights that operate differently from Article 20.
33. Portability in Healthcare
Healthcare portability creates additional complexity.
Possible data:
medical records;
test results;
prescriptions;
fitness information;
wearable-device data.
But healthcare data may involve:
special-category data;
third-party information;
professional confidentiality;
patient safety;
interoperability standards.
Article 20 must therefore be reconciled with other legal obligations.
34. Portability in Social Media
Social media is perhaps the clearest example.
A user may wish to move:
profile information;
posts;
photographs;
contacts;
activity information;
interactions.
But third-party information creates difficulty.
For example:
User's exported contact list contains 500 other people's names.
The controller must consider the rights of those other individuals.
35. Portability and AI Platforms
A modern issue is:
Can a user demand portability of AI interaction data?
Potential categories include:
prompts;
conversation history;
user-provided documents;
generated outputs;
preference profiles;
inferred characteristics.
Article 20 analysis must distinguish:
user-provided personal data
from:
AI-generated/inferred information
and:
provider's proprietary model information.
A portability request should not automatically become a demand for disclosure of the AI model itself.
36. Cross-Border Enforcement
European portability disputes can involve:
Data subject in France
Controller in Ireland
Cloud infrastructure in Germany
Recipient controller in Spain.
The GDPR's one-stop-shop mechanism may become relevant where a cross-border processing operation is involved.
The EDPB explains that the mechanism allows lead and concerned supervisory authorities to cooperate on cross-border cases. (European Data Protection Board)
37. Procedural Importance of the Meta Litigation
The Meta v DPC litigation is especially important because it shows how procedural questions can become as significant as the substantive portability question.
Issues include:
scope of a complaint;
regulator's investigative powers;
systemic enforcement;
corrective measures;
proportionality;
procedural fairness;
legitimate expectations.
Thus:
Data-portability enforcement is not simply a technical data-export dispute; it can become major regulatory litigation.
38. Comparative Case Table
| Authority | Jurisdiction | Article 20 connection | Key point |
|---|---|---|---|
| Meta v DPC [2026] IEHC 323 | Ireland | Direct | Scope and enforcement of portability investigation |
| LG Wiesbaden 2 O 49/24 | Germany | Direct | Article 20 limited to data falling within its conditions |
| Weople/Garante 2024 | Italy | Direct | Delegation of portability must reflect specific user intention |
| EDPB FR:OSS:D:2021:226 | France | Direct | Article 20 violation; reprimand |
| EDPB IE:OSS:D:2024:1441 | Ireland/cross-border | Direct | Article 20 enforcement; amicable settlement |
| EDPB IE:OSS:D:2025:3573 | Ireland/cross-border | Direct | Article 20 + online-platform rights |
| EDPB IE:OSS:D:2025:3518 | Ireland/cross-border | Direct | Article 20 enforcement; settlement |
| Nowak, C-434/16 | CJEU | Analogical | Broad concept of personal data |
| Wirtschaftsakademie, C-210/16 | CJEU | Analogical | Controller responsibility |
| Google Spain, C-131/12 | CJEU | Analogical | Practical effectiveness of data-subject rights |
39. Important Distinction Between Court Cases and Regulatory Decisions
For examination purposes, do not describe all of the above as “case law” in exactly the same sense.
Judicial case law
Examples:
Meta v DPC;
LG Wiesbaden;
Nowak;
Wirtschaftsakademie;
Google Spain.
Supervisory enforcement decisions
Examples:
EDPB one-stop-shop decisions;
Italian Garante Weople decision.
The latter are extremely useful for enforcement practice but are not judicial precedents equivalent to CJEU or national appellate judgments.
40. Main Legal Principles
Principle 1 — Article 20 is a distinct right
It cannot simply be merged with Article 15 access rights. (Homepage | Data Protection Commission)
Principle 2 — Portability has conditions
Consent/contract, automated processing and the relevant category of personal data matter. (Homepage | Data Protection Commission)
Principle 3 — Article 20 is not unlimited
Rights of other persons can restrict portability.
Principle 4 — Data source matters
The German Wiesbaden decision demonstrates that not every piece of information held by a controller automatically falls within Article 20. (gdprhub.eu)
Principle 5 — Machine readability matters
The right concerns usable, structured and machine-readable information, not merely a paper or PDF copy. (Homepage | Data Protection Commission)
Principle 6 — Direct transmission is possible
Where technically feasible, the data can be sent directly to another controller. (Homepage | Data Protection Commission)
Principle 7 — Delegated portability requires genuine authorization
The Italian Weople decision illustrates the importance of a specific and unambiguous delegation. (European Data Protection Board)
Principle 8 — Regulatory enforcement can be substantial
The Meta litigation demonstrates the potential for an individual portability complaint to develop into systemic regulatory proceedings. (Bailii)
Principle 9 — Portability and competition are related but legally distinct
Article 20 is a GDPR right, not a general competition-law interoperability rule.
Principle 10 — European portability jurisprudence is still developing
National courts and supervisory authorities currently provide much of the practical interpretation.
41. Typical Data-Portability Litigation Formula
A claimant can structure the case as:
DATA SUBJECT
↓
PERSONAL DATA
↓
PROCESSING
↓
AUTOMATED PROCESSING
↓
CONSENT / CONTRACT
↓
DATA FALLS WITHIN ARTICLE 20
↓
VALID REQUEST
↓
STRUCTURED + COMMONLY USED + MACHINE-READABLE FORMAT
↓
DIRECT TRANSMISSION WHERE TECHNICALLY FEASIBLE
↓
NO VALID RESTRICTION
↓
CONTROLLER REFUSAL / DELAY / INADEQUATE FORMAT
↓
SUPERVISORY COMPLAINT OR COURT ACTION
↓
CORRECTIVE ORDER / DECLARATION / POSSIBLE COMPENSATION
42. Exam-Oriented Revision Table
| Topic | Keyword |
|---|---|
| GDPR | Article 20 |
| Portability | Data transfer/reuse |
| Access | Article 15 |
| Format | Structured |
| Machine-readable | Interoperability |
| Controller | Data holder/responsible entity |
| Recipient | New controller |
| Legal basis | Consent/contract |
| Automation | Required |
| Data source | Provided by data subject |
| Direct transmission | Technically feasible |
| Third parties | Rights and freedoms |
| Trade secrets | Possible restriction |
| Delay | Article 12 |
| Refusal | Reasons required |
| Enforcement | DPA/EDPB |
| Remedy | Court/regulator |
| Compensation | Article 82 |
| Platforms | Switching |
| Competition | Indirect relationship |
| AI | Derived/inferred data |
| Banking | Open banking distinction |
| Healthcare | Sensitive data |
| Cross-border | One-stop-shop |
43. Conclusion
Data portability enforcement litigation in Europe is principally governed by Article 20 GDPR together with Articles 12, 15 and the general GDPR enforcement and remedy provisions.
The emerging jurisprudence shows that the central disputes are not merely about whether a company possesses data. They concern:
whether the information qualifies as personal data;
whether the data falls within Article 20's narrower scope;
whether the data was provided by the data subject;
whether processing is automated;
whether consent or contract is the relevant legal basis;
whether the export is genuinely structured and machine-readable;
whether direct transmission is technically feasible;
whether third-party rights or other legal restrictions apply; and
whether regulatory or judicial remedies should follow from non-compliance.
The Meta v DPC [2026] IEHC 323 litigation is particularly significant because it demonstrates how an individual Article 20 dispute can develop into major systemic regulatory proceedings, while LG Wiesbaden 2 O 49/24 provides a useful judicial limitation on the scope of Article 20. The EDPB enforcement register further confirms that portability is now a recurring subject of European supervisory enforcement. (Bailii)
Ultra-short revision formula
ARTICLE 20 → PERSONAL DATA → DATA PROVIDED BY SUBJECT → AUTOMATED PROCESSING → CONSENT/CONTRACT → MACHINE-READABLE FORMAT → DIRECT TRANSMISSION → TECHNICAL FEASIBILITY → THIRD-PARTY RIGHTS → ENFORCEMENT → REMEDY.

comments