Learn
What Is Data Portability?

When you sign up for a cloud service, you bring your files, your notes, your photos, your work. The question most people forget to ask is: can you take it all back out again?
Data portability is the principle that you should be able to move your data from one service to another in a usable format, without unreasonable barriers. It sounds simple. In practice, it is one of the most reliable indicators of whether a platform respects your autonomy or depends on trapping you.
The core idea
Data portability means that the information you put into a service, and the information created on your behalf while you use it, should be available for you to export, transfer, or migrate elsewhere. This includes documents, images, contacts, messages, metadata, folder structures, tags, and anything else you would reasonably consider "yours."
The concept has roots in consumer protection and competition law, but it applies just as much to individuals managing personal files as it does to businesses evaluating enterprise software. If you cannot leave a service without losing your work, you are not a customer. You are a captive.
Why portability matters
The most obvious reason is vendor lock-in. When a service makes it difficult to export your data, the cost of switching rises. You might tolerate price increases, feature regressions, or privacy policy changes because rebuilding your files and workflows elsewhere feels too expensive. This dynamic gives platforms an incentive to make leaving harder, not easier.
Beyond lock-in, portability affects long-term access. Services shut down. Companies get acquired. Pricing models change. If your files exist only inside a proprietary system with no export path, you are one corporate decision away from losing access to your own work. This is not a theoretical concern. The history of consumer technology is littered with shuttered services whose users lost years of accumulated data.
Portability also affects who controls your data in a meaningful sense. You might legally own your files, but if they are stored in a format only one application can read, or if the only way to retrieve them is through a rate-limited API that exports them without their organisational structure, ownership becomes a technicality.
What the law says
Several regulations now enshrine data portability as a right, though the scope and enforcement vary.
The General Data Protection Regulation (GDPR), which applies across the European Union, includes a specific right to data portability under Article 20. It requires that data controllers provide personal data in a "structured, commonly used and machine-readable format" and allow users to transmit that data to another controller. The right applies to data the user has provided, processed on the basis of consent or contract. It does not cover data the controller has derived or inferred, which creates a grey area around things like recommendation profiles, usage analytics, or AI-generated summaries.
The EU Data Act, which began applying in September 2025, extends portability obligations beyond personal data to include non-personal data generated by connected devices and digital services. It requires service providers to make data available in a format that allows switching, and it prohibits contractual clauses that unreasonably restrict switching.
In the United States, the picture is more fragmented. California's CCPA and its successor, the CPRA, include a right to access personal data in a portable format, but the emphasis is on disclosure rather than interoperability. Several other states have enacted or proposed similar provisions. At the federal level, there is no comprehensive data portability law, though sector-specific rules exist in areas like healthcare (HIPAA) and finance.
These regulations set a floor, not a ceiling. A platform can be fully compliant with GDPR's portability provisions and still make it functionally painful to leave. Legal compliance and good portability are related but distinct.
What good portability looks like
Good portability is not just a button that says "Export." It is a set of design choices that run through the entire product.
Standard file formats are the foundation. If your notes are stored as plain text, Markdown, or HTML, any other application can read them. If your images are JPEGs or PNGs rather than proprietary wrappers, they are universally accessible. Standard formats mean your data has value outside the system that created it.
Comprehensive export tools matter too. A good export should include not just the content of your files but also their organisation: folder structures, tags, metadata, timestamps, relationships between items. Losing your filing system is almost as disruptive as losing the files themselves.
API access allows more sophisticated migration. If a service offers a well-documented API, you or a developer can build automated migration workflows, selective exports, or ongoing synchronisation with other tools. APIs also enable interoperability while you are still using the service, which reduces the pressure to make a binary stay-or-leave decision.
Bring-your-own-storage is perhaps the strongest form of portability. When a platform lets you connect your own cloud storage rather than insisting you upload everything to its proprietary infrastructure, your data never becomes dependent on the platform in the first place. If you stop using the service, your files are already where you control them. Fabric takes this approach, allowing you to connect existing services like Google Drive, Dropbox, or OneDrive and work with your files where they already live, rather than requiring you to import everything into a closed system.
Open integrations reinforce portability by letting your data flow between tools while you use them. A platform that connects to the services you already rely on reduces the chance that your information becomes siloed in one place.
What bad portability looks like
Bad portability takes many forms, and most are subtle enough that you only notice them when you try to leave.
Proprietary formats are the clearest warning sign. If a platform stores your data in a format that only its own software can read, you are locked in by design. Even if an export function exists, converting proprietary formats to standard ones often loses metadata, formatting, or structural information.
Incomplete exports are common. Some services let you download your files but strip out tags, folder structures, comments, or version history. The raw content survives, but the work you did to organise it does not. For anyone with a large collection of files, reconstructing that organisation in a new service can take weeks.
Rate-limited or obstructed exports are another pattern. A service might technically offer an export function but make it so slow, so poorly documented, or so buried in settings menus that most users give up. Some platforms require you to request an export and then wait days for a download link, which introduces friction that benefits the platform, not the user.
No export at all is the worst case, and it still exists. Some services, particularly smaller or newer ones, simply do not offer any way to bulk-export your data. You might be able to manually copy items one at a time, but there is no systematic way to retrieve everything. This is a clear sign that the platform does not consider your data to be meaningfully yours.
How to evaluate portability before committing
If you are choosing a platform for your files, notes, or knowledge, portability should be part of the evaluation from the start, not an afterthought once you are already invested.
Ask what formats your data will be stored in, and whether you can export in those formats or only in proprietary ones. Check whether the export includes metadata and organisational structure, not just raw files. Look for API documentation, which signals that the platform expects and supports interoperability. Consider whether the platform requires you to upload your files to its own storage or whether it can work with storage you already control.
Read the terms of service with an eye toward what happens when you leave. Some platforms specify that data will be available for export for a limited time after account closure. Others are silent on the topic, which is not reassuring. For a deeper look at what terms of service reveal about your relationship with a provider, see who owns your data in cloud storage.
Try the export before you have committed. If a platform offers a free tier or trial, upload a representative set of files, organise them, and then attempt an export. The quality of that export tells you more about the platform's values than any marketing page.
Think about what happens to data that lives only inside the application. Notes, bookmarks, annotations, saved searches: these are all data you create, and they should all be portable. A platform that lets you export your uploaded files but not your notes and documents is only partially portable.
The portability spectrum
Portability is not binary. It exists on a spectrum, and most platforms fall somewhere in the middle.
At one end, you have fully open systems where your data is stored in standard formats on infrastructure you control, with no dependency on the application layer. At the other end, you have closed systems where your data exists only inside the platform, in proprietary formats, with no export mechanism.
Most cloud services sit somewhere between these extremes. They may support export but not in all formats. They may offer an API but with limited endpoints. They may store files in standard formats but keep organisational metadata in a proprietary database.
The question is not whether a platform is perfectly portable (few are) but whether its portability is good enough that you could leave without catastrophic loss. If the answer is no, you should think carefully about how much of your work you are willing to entrust to it.
For researchers and writers, portability is especially critical because their work accumulates over years and often outlives any individual tool. For freelancers and founders, being locked into a platform can create operational risk when business needs change.
The relationship between portability and privacy
Data portability and data privacy are often discussed separately, but they are closely connected. A platform that makes it hard to leave also makes it hard to enforce your privacy preferences. If you discover that a service is using your data in ways you did not expect, the ability to export and delete becomes essential. Without portability, your only leverage is to stop using the service, while your data remains behind.
The right to erasure under GDPR (the "right to be forgotten") is a complement to portability. Together, they give you the ability to take your data somewhere else and ensure it is removed from the old service. But understanding what happens to your data when you leave a service requires looking beyond the export function to the platform's retention and deletion policies.
Platforms that practise data minimisation tend to have better portability as well, because they store less data that is tightly coupled to their own systems.
Portability as a design principle
The best platforms treat portability as a design principle rather than a compliance checkbox. They build their systems around standard formats from the start, rather than bolting on an export tool later. They make it easy to connect to other services, rather than treating every external integration as a threat to retention.
This is the approach behind platforms like Fabric, where bringing your own cloud storage means your files are never locked inside a single system. The workspace layer adds search, organisation, and AI assistance on top of storage you already own, rather than requiring you to surrender your files to access those features.
When evaluating any platform, the simplest test of portability is this: if this company disappeared tomorrow, how much of my data would survive, and how much of my organisational work would I have to redo? The answer should be "most of it" and "very little."
Frequently asked questions
What is data portability in simple terms?
Data portability is the ability to take your data out of one service and move it to another, in a format that is usable elsewhere. It means your files, notes, and other information are not trapped inside a single platform.
Is data portability a legal right?
In many jurisdictions, yes. The GDPR gives EU residents a right to receive their personal data in a portable format. The EU Data Act extends this to non-personal data from digital services. In the US, state-level laws like the CCPA include related provisions, though federal portability law is limited.
What is the difference between data portability and data access?
Data access means you can see and download your data. Data portability means you can move it to another service in a format that service can use. Access without portability often means you can download files but not in a way that preserves their organisation or usability elsewhere.
How do I know if a platform has good data portability?
Look for standard file formats, comprehensive export tools that include metadata and folder structures, API access, and ideally the ability to use your own storage. Try exporting before you commit to the platform.
What is vendor lock-in?
Vendor lock-in occurs when switching away from a service is so costly or difficult that you remain with it even if better alternatives exist. Poor data portability is one of the main mechanisms of lock-in.
Can I lose my data if a cloud service shuts down?
Yes, if the service does not offer adequate export tools or if you do not export your data before the shutdown. Services typically provide a notice period, but the quality of the export varies widely. Using a platform that works with your own cloud storage mitigates this risk.
What is bring-your-own-storage?
Bring-your-own-storage means a platform lets you connect cloud storage you already control (such as Google Drive, Dropbox, or iCloud) rather than requiring you to upload files to the platform's own servers. Your data stays in your storage, and the platform accesses it with your permission.
Does data portability mean my data is less secure?
Not inherently. Portability is about format and accessibility, not about weakening security. A well-designed platform can offer both strong portability and strong privacy and security.
What formats should I look for in a portable platform?
Standard, widely supported formats: Markdown or HTML for notes, JPEG and PNG for images, PDF for documents, CSV or JSON for structured data. Avoid platforms that store your content in formats only their own software can open.
How does data portability relate to data deletion?
They are complementary rights. Portability lets you take your data out. Deletion (the right to erasure) lets you ensure the old service removes it. Together, they give you full control over the lifecycle of your data. For more on what happens after deletion, see what happens to your data when you delete an app.






