All sample legal documents

Data Portability Request

A completed UK GDPR Article 20 request identifying portable personal data, secure delivery and lawful limits.

Jurisdiction: England and Wales - completed fictional worked example

Download Sample

An editable Microsoft Word version is available from the interactive page.

Important: This sample provides general legal information only and is not legal advice. Check the law, prescribed forms and signing requirements that apply to your exact jurisdiction and circumstances before use.

# DATA PORTABILITY REQUEST

Date: 3 June 2033

Parties: Hana Ito and BrightPath Fitness Ltd

## 1. Purpose and parties

Hana Ito asks BrightPath Fitness Ltd to provide personal data she supplied to it and data observed from her use of its connected services, where those data are processed by automated means on the basis of consent or contract. Her BrightPath account email is hana.ito@example.test and her customer number is BP-20481. This is a UK GDPR Article 20 portability request, not a request for another person's data.

## 2. Facts, scope and terms

The requested scope is Hana's profile fields, subscription and payment-history fields (excluding full card numbers), exercise and heart-rate records generated by her connected device, and the account activity data she entered or caused to be collected from 1 September 2031 to 31 May 2033. She asks for a commonly used, machine-readable CSV or JSON export and an explanation of field names.

## 3. Process and responsibilities

Hana also asks BrightPath, where technically feasible, to transmit the portable data directly to MoveWell Analytics Ltd at portability@movewell.example.test. BrightPath should confirm the recipient and use an authenticated transfer or encrypted download. It must verify identity and may ask for proportionate information; it should not send sensitive data to an unverified address.

## 4. Evidence, records and safeguards

The request does not require BrightPath to create new analysis, disclose another person's information, or provide inferred scores and proprietary algorithms merely because they relate to Hana. Data outside Article 20 may still be accessible under a subject-access request where applicable, but this letter does not waive any separate access right or require BrightPath to reveal material protected by law.

## 5. Review, escalation and outcome

BrightPath should acknowledge receipt and respond without undue delay and in any event normally within one month, subject to the UK GDPR rules for complexity and any lawful extension. A refusal or restriction should identify the reason and explain Hana's right to complain to the Information Commissioner's Office or seek a judicial remedy. No fee should be charged unless a request is manifestly unfounded or excessive under the applicable rules.

## 6. Reservations and practical protections

Hana asks BrightPath to record the date of receipt, the identity checks used, the data sources and date range searched, the export format and the security steps. If any device records belong jointly to another person, BrightPath should separate or redact that person's information and explain the result rather than silently omit the entire dataset.

## 7. England and Wales law and completion

This completed fictional request is dated 3 June 2033 and concerns processing subject to UK data-protection law. It is not consent to marketing or a request to delete the account. Hana can be contacted at her verified account address; BrightPath should retain a proportionate audit trail and correct any inaccurate data through its ordinary rectification route.

Create a version for your situation

Create a tailored Data Portability Request