Data portability rights for employees.
Data Portability Rights for Employees
Introduction
Data portability rights for employees refer to an employee’s ability, in appropriate circumstances, to obtain personal data held about them by an employer in a structured, commonly used and machine-readable format and, where legally required, have that data transmitted to another organisation.
The concept is particularly important in modern employment relationships because employers collect large amounts of employee information, including recruitment records, payroll information, performance data, attendance records, training records, and electronically generated workplace information.
Data portability is closely connected with privacy, informational self-determination, employee mobility, transparency and control over personal information. However, the right is not absolute. It may be restricted where providing or transferring the information would adversely affect the rights of others, reveal confidential business information, or fall outside the relevant statutory requirements.
Meaning of Employee Data Portability
Employee data portability generally involves three related ideas:
- Access to personal data – an employee may have a right to know what personal information an employer holds.
- Receiving data in a usable format – where applicable, the employee may request the information in a structured and machine-readable form.
- Transmission to another organisation – in certain legal regimes, the employee may ask that data be transferred directly to another data controller.
For example, an employee changing jobs may seek transferable information concerning qualifications, training records, employment history or other personal information that can legally be provided.
Data Portability Under the GDPR
Article 20 of the General Data Protection Regulation (GDPR) expressly establishes a right to data portability. Where the statutory conditions are satisfied, the data subject has the right to receive personal data concerning them in a structured, commonly used and machine-readable format and to transmit it to another controller.
The right generally applies where processing is:
- based on the individual's consent or on a contract; and
- carried out by automated means.
Importantly, not every piece of information held by an employer automatically becomes portable merely because it relates to an employee.
Employee Data and Employment Records
Employment records can contain different categories of information:
- name and contact details;
- employment history;
- salary and payroll information;
- qualifications;
- training records;
- attendance information;
- performance information;
- leave records;
- disciplinary records;
- workplace communications;
- biometric information;
- electronically generated activity data.
Whether each category is portable depends on the applicable law, the legal basis for processing, the nature of the information and whether portability requirements are satisfied.
Limits on the Right
Data portability does not give an employee an unrestricted right to obtain an employer's entire database.
Important limitations may include:
1. Rights of third parties:
A record may contain information relating to colleagues, customers or other individuals. Disclosure must not unnecessarily prejudice their rights.
2. Confidential business information:
Trade secrets and commercially confidential information may need protection.
3. Employer's independent information:
Information created independently by an employer, such as certain internal evaluations or managerial assessments, may not necessarily fall within the scope of portability.
4. Legal restrictions:
Employment, privacy, evidence, financial-services and other sector-specific laws may impose additional restrictions.
5. Automated processing requirement:
Under Article 20 GDPR, portability is particularly concerned with personal data processed by automated means and under the specified legal bases.
Data Portability and Employee Mobility
Portability can become particularly valuable when employees move between employers.
For example, an employee may have accumulated:
- professional certifications;
- training history;
- employment-related qualifications;
- work-related personal information;
- digitally stored professional records.
If the law permits portability, transferring relevant information can reduce duplication and make employee mobility easier.
However, portability should not be confused with a right to take an employer's confidential database, customer list, proprietary software, trade secrets or other corporate property when leaving employment.
Data Portability and HR Technology
Modern HR systems increasingly use:
- cloud-based HR platforms;
- artificial intelligence;
- automated recruitment systems;
- employee monitoring software;
- payroll databases;
- learning-management systems.
These systems make portability technically easier but also create significant legal questions concerning data ownership, privacy, accuracy, security and interoperability.
Employers should therefore establish procedures for identifying portable personal data and separating it from confidential corporate information.
Important Case Laws
1. Google LLC v CNIL (2020)
The Court of Justice of the European Union considered the territorial application of EU data-protection rights in relation to search-engine operators.
Relevance:
The case demonstrates the broad importance of effective data-protection rights and the need to consider the practical enforcement of rights relating to personal information.
Principle:
Data-protection rights must be interpreted within the statutory framework while maintaining an appropriate balance with competing interests.
2. Rigas satiksme v Datu valsts inspekcija (2017)
The CJEU considered the disclosure of personal information and the relationship between personal-data protection and legitimate interests.
Relevance to employees:
Employee data may involve competing interests. A request for personal information cannot always be considered in isolation; the rights and interests of other individuals may also have to be protected.
Principle:
Personal-data rights must be balanced against legitimate competing interests under the applicable data-protection framework.
3. Nowak v Data Protection Commissioner (2017)
In Peter Nowak v Data Protection Commissioner, the CJEU considered whether examination answers constituted personal data.
The Court adopted a broad understanding of personal data where information is connected with an identifiable individual.
Relevance:
The case is significant for employment-related information because documents generated during professional or educational processes may constitute personal data when they relate to an identifiable person.
Principle:
Information can constitute personal data even when its form or context is different from conventional identification information.
4. Breyer v Bundesrepublik Deutschland (2016)
The CJEU considered whether dynamic IP addresses could constitute personal data.
Relevance:
The case illustrates that information does not have to directly identify an individual in isolation to qualify as personal data.
For employers using digital systems, logs, identifiers and electronic records may therefore potentially constitute personal data.
Principle:
The concept of personal data can extend to information that permits identification when combined with additional information.
5. Österreichische Post AG v Österreichische Datenschutzbehörde (2023)
The CJEU considered compensation for infringement of data-protection rights under the GDPR.
Relevance to employment:
Employees may potentially seek remedies where unlawful processing or mishandling of their personal information causes legally recognised harm.
Principle:
GDPR rights are enforceable rights, and remedies must be effective within the framework established by EU law.
6. Lloyd v Google LLC (2021)
The UK Supreme Court considered claims arising from alleged misuse of personal data by Google.
Relevance:
The case highlights the importance of establishing actual legal entitlement and legally recognised damage rather than assuming that every breach of data-protection requirements automatically produces a compensable loss.
Principle:
Data-protection litigation requires careful consideration of the statutory requirements, the nature of the breach and the claimant's legally recognised loss.
7. Vidal-Hall v Google Inc (2015)
The English Court of Appeal considered claims relating to misuse of private information and data protection.
Relevance:
The case demonstrates the importance of protecting personal information and recognised that privacy-related harm can have legal consequences.
Principle:
Misuse of personal information may give rise to legal remedies even where traditional forms of financial loss are not readily established.
8. Justice K.S. Puttaswamy (Retd.) v Union of India (2017)
The Supreme Court of India recognised privacy as a fundamental right under the Indian Constitution.
Relevance to employees:
Although the judgment was not specifically about employee data portability, it provides an important constitutional foundation for privacy and control over personal information in India.
The judgment recognised informational privacy as an important aspect of individual autonomy and dignity.
Principle:
Individuals have constitutionally protected privacy interests, subject to constitutionally permissible restrictions.
Data Portability in India
India does not presently provide an employee data-portability right that is identical in scope to Article 20 GDPR.
The Indian legal framework instead involves constitutional privacy principles and statutory regulation of digital personal data. The Digital Personal Data Protection Act, 2023 provides a framework governing processing of digital personal data and establishes rights and obligations relating to personal data.
Therefore, Indian employees should distinguish between:
- a right to access or obtain personal information;
- a right to correction;
- privacy protections;
- obligations concerning processing of personal data; and
- a specific statutory right to data portability.
These concepts are not necessarily identical.
Employer Responsibilities
Employers handling employee data should consider:
- Maintaining an inventory of employee personal data.
- Identifying which information is legally transferable.
- Separating personal data from confidential business information.
- Using interoperable formats where legally appropriate.
- Establishing procedures for employee data requests.
- Verifying the identity of the requesting employee.
- Protecting third-party information.
- Maintaining appropriate security during data transfers.
- Keeping records of disclosures and transfers.
- Ensuring compliance with applicable privacy and employment laws.
Difference Between Data Access and Data Portability
| Data Access | Data Portability |
|---|---|
| Allows an individual to obtain information about their personal data | Allows qualifying personal data to be received in a usable format |
| Mainly concerned with transparency | Mainly concerned with control and reuse |
| Does not necessarily require machine-readable format | Structured/machine-readable format is important under GDPR |
| Does not automatically mean transfer to another organisation | May allow direct transmission to another controller |
| Broader concept in some legal regimes | More specific statutory right |
Conclusion
Data portability rights for employees represent an important development in modern privacy and employment law. They can give employees greater control over their personal information and facilitate the movement and reuse of qualifying data.
However, portability is not an unlimited right to take all employment records from an employer. Its scope depends heavily on the applicable legislation, the type of data, the legal basis for processing, third-party rights and legitimate employer interests.
In the European Union, Article 20 GDPR provides a clearly defined statutory portability right subject to specific conditions. In India, privacy jurisprudence—particularly the constitutional recognition of informational privacy in Puttaswamy—provides an important foundation, but it should not be treated as creating an automatic GDPR-style employee portability right.

comments