What is Data Portability?

Data portability is the right and technical ability to obtain and move a person's personal data from one system to another in a usable, machine-readable format. It helps participants and organisations access, reuse and transfer survey responses without vendor lock-in.

Data portability refers to both a legal right (in many jurisdictions) and a practical capability of software systems to provide personal data back to the person it concerns, or to transfer it directly to another service. For organisations collecting survey responses, portability means exporting a respondent’s answers — including metadata such as language, timestamps and consent status — in standard, machine-readable formats (for example CSV or JSON). The goal is to make the data easy to reuse, analyse or migrate while preserving structure and context (original language text, automatic translations, question IDs), and to do so securely and in line with privacy rules. Portability does not necessarily cover aggregated or fully anonymised datasets, and it may be limited by legal exceptions (for example where providing the data would harm others’ privacy).

Usage example

A resident asks the council for a copy of their responses to a consultation. The council exports the respondent’s answers from Hearo as a CSV that includes: the original free-text responses (in Arabic), the platform’s English translation, the language tag for each answer, timestamps and the participant’s consent statement — then emails the file or transfers it to another system at the resident’s request.

Practical application

Why it matters: Data portability builds trust, meets legal obligations and prevents vendor lock-in. For teams using multilingual survey tools, portability ensures you can: - Give participants control over their personal data and comply with rights requests (e.g., GDPR Article 20). - Move responses between tools or internal systems for analysis, archiving or continued engagement without losing language context or translation history. - Preserve audit trails (who asked, when, in which language) for transparency and accountability. Practical steps organisations should take include offering exports in open formats (CSV/JSON), including language and translation metadata, verifying requester identity and consent, and using secure transfer methods. Portability complements — but does not replace — other privacy practices like deletion, access requests and careful handling of third-party processors.

FAQ

Who can request data portability?

Typically the person whose personal data is being processed (the participant). Depending on local law, authorised representatives may also request it. Organisations should verify identity before releasing personal data to protect privacy.

What exactly must be provided when someone requests portability?

You should provide personal data that the organisation has collected directly from the individual, in a structured, commonly used and machine‑readable format. For survey platforms this usually includes the respondent’s answers, language tags, timestamps, question identifiers and any consent records. It can include both the original text and translations if those are held by the system.

Does data portability mean we must hand over aggregated or anonymised datasets?

No. Portability rights generally apply to personal data that can be linked to an identifiable person. Fully anonymised or aggregated datasets that no longer identify individuals are usually outside the scope of portability rights.

Are there limits or exceptions to portability (for example translation or third‑party data)?

Yes. Portability may be limited where fulfilling the request would infringe others’ rights, reveal another person’s personal data, or is technically infeasible. Data derived or inferred by the organisation (for example certain algorithmic inferences) may not always be covered. When third-party processors are involved, organisations must coordinate to deliver the data securely while honouring contractual and legal responsibilities.