A controller refuses a data portability request because the personal data were collected on a legal-obligation basis rather than consent or contract. Is that refusal typically aligned with GDPR portability rules?
Select an answer to reveal the explanation.
Short Explanation
Portability is a suitcase for data you handed over under consent or a contract deal—not a moving truck for every legal archive. If the controller held the data because the law forced collection, that suitcase usually stays closed. Know the gate conditions before packing.
Full Explanation
Article 20 data portability applies where processing is based on consent or contract, concerns data provided by the data subject, and is carried out by automated means. Processing grounded solely in a legal obligation typically falls outside those conditions. Refusing portability in that scenario can therefore be consistent with the right’s defined scope.