CCSP Legal, Risk, and Compliance Practice Question
Which of the following is a key requirement for data portability under the General Data Protection Regulation (GDPR)?
⚠ Common exam trap
A common mix-up: candidates confuse data portability with the right of access or erasure, leading candidates to pick deletion timelines or device-transfer requirements that GDPR does not mandate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data must be provided in a structured, commonly used, and machine-readable format.
GDPR Article 20 requires that when data portability applies, the controller must provide the personal data 'in a structured, commonly used and machine-readable format.' This ensures the data can be transmitted to another controller without hindrance, typically using formats such as JSON, XML, or CSV. The right applies to data processed by automated means based on consent or contract.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data must be transferred directly to the data subject's own device.
Why it's wrong here
GDPR Article 20 requires data in a structured, commonly used, machine-readable format transmitted to another controller where technically feasible; direct transfer to the subject's own device is not mandated. It is tempting because subject access requests do deliver data to the individual, but portability targets controller-to-controller transmission.
- ✓
Data must be provided in a structured, commonly used, and machine-readable format.
Why this is correct
GDPR Article 20 requires portability in a structured, commonly used and machine-readable format, enabling the data subject to transmit data to another controller without hindrance. This format requirement is the specific technical condition the regulation imposes.
- ✗
Data portability applies only to pseudonymized data.
Why it's wrong here
Article 20 covers personal data provided by the data subject and data observed from their activity, processed by consent or contract, whether or not pseudonymised; pseudonymisation is not the limiting criterion. It is tempting because pseudonymised data still counts as personal data, but that fact does not restrict portability's scope.
- ✗
Data must be deleted within 30 days of a portability request.
Why it's wrong here
Article 20 sets no 30-day deletion deadline; it governs transmission format and scope, while erasure timelines sit under Article 17. It is tempting because GDPR requests generally carry a one-month response window, but that deadline concerns answering the request, not deleting the ported data afterwards.
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.