Skip to main content
Category: Data Subject Rights

Interoperability

Also known as: Data Interoperability
Simply put

Interoperability is the ability of different IT systems, applications, or organizations to work together and exchange information so it can be understood and used with minimal manual effort. In a data privacy context, this typically involves systems sharing data in a coherent way, often relying on common standards. It does not by itself determine whether such data sharing is lawful, which depends on the applicable legal framework.

Formal definition

Interoperability generally refers to the characteristic of a product or system that enables it to work with other products or systems, typically through a standards-based approach that allows different IT systems, applications, and devices to access, exchange, integrate, and use data with minimal end-user intervention. Definitions vary by source and originated in information technology contexts before extending to organizational and cross-national cooperation. Where personal data is involved, interoperability describes technical and operational capability only; it is distinct from, and does not establish, any lawful basis, transfer mechanism, or other compliance requirement, which must be assessed separately against the relevant data protection framework.

Why it matters

Interoperability is increasingly central to how organizations design systems that share and reuse data across applications, providers, and borders. When systems can exchange information coherently and with minimal manual intervention, organizations can reduce duplication, improve service delivery, and support functions such as data portability requests. However, the technical ability to move or combine data does not, by itself, resolve the legal questions that arise when that data is personal data. A system can be fully interoperable and still involve processing that lacks an appropriate legal basis or an adequate transfer mechanism.

For this reason, interoperability should be treated as a capability rather than a compliance state. The fact that two systems can exchange personal data does not mean that a given exchange is lawful; that determination depends on the applicable data protection framework, which under the GDPR generally requires an Article 6 legal basis and, for special category data, an additional Article 9 condition. Interoperability can make certain data flows easier to execute, which in turn can raise the practical importance of documenting purpose, minimization, and, where relevant, the mechanism relied upon for any cross-border movement.

Because definitions of interoperability vary by source and the term originated in information technology contexts before extending to organizational and cross-national cooperation, practitioners should be careful not to import assumptions from one domain into another. What counts as interoperable in a technical or engineering sense may not map neatly onto the compliance obligations that attach when personal data is involved, and those obligations should be assessed separately.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to ensure that interoperable data flows are matched to an appropriate legal basis and, where personal data moves across borders, an appropriate transfer mechanism. Because interoperability makes data sharing easier to execute, it can increase the importance of documenting purpose, minimization, and the compliance rationale for each exchange rather than relying on technical capability as an assurance of lawfulness.
Engineers and System Architects
Those designing systems that access, exchange, integrate, and use data are responsible for the standards-based approaches that enable interoperability. They should engage privacy and legal colleagues early, since a technically sound integration does not by itself confirm that the resulting personal data processing is permitted under the applicable framework.
Privacy and Technology Lawyers
Lawyers advising on data sharing should distinguish clearly between the technical capability to exchange data and the separate legal questions of basis, transfer, and other obligations. Given that interoperability definitions vary by source and originated outside the privacy domain, careful scoping is needed to avoid conflating engineering concepts with compliance conclusions.
Organizations Handling Data Portability and Cross-System Sharing
Entities that support portability requests or integrate data across providers rely on interoperability to move information coherently. They should treat each transfer of personal data as requiring its own compliance assessment against the relevant data protection framework, verifying current requirements against the official text rather than assuming a settled position.

Inside Interoperability

Technical interoperability
The capacity of different systems, applications, or data formats to exchange and process personal data without loss of meaning. In a data protection context, this typically underpins mechanisms such as the right to data portability, though interoperability itself is a broader technical property rather than a defined GDPR term.
Data portability dimension
Interoperability is closely associated with the right to data portability, which under the GDPR generally applies to personal data processed on the basis of consent or contract and carried out by automated means. Portability requires structured, commonly used, and machine-readable formats, but the Regulation encourages rather than strictly mandates full interoperability between controllers.
Semantic and organisational alignment
Beyond format exchange, interoperability can involve shared vocabularies, standards, and organisational agreements so that transferred data retains its meaning and can be used by the receiving system. The precise standards involved are often set by sector guidance rather than the Regulation text.
Scope boundary
Interoperability concerns apply to personal data of individuals within the scope of the GDPR. It does not, in itself, alter the underlying legal basis for processing or transfers, and it generally does not extend to anonymous data, which falls outside the Regulation.

Common questions

Answers to the questions practitioners most commonly ask about Interoperability.

Does interoperability mean the same thing as data portability under the GDPR?
No. Although the concepts are related, they are not the same. Data portability under Article 20 of the GDPR is a specific data subject right that, subject to its conditions, allows individuals to receive personal data they have provided to a controller in a structured, commonly used, and machine-readable format and, where technically feasible, to have it transmitted to another controller. Interoperability is a broader technical and organizational property describing the ability of systems, services, or organizations to exchange and make use of information. Interoperability can support the exercise of portability, but it is not itself a legal right, and portability does not require full interoperability in every case.
Is achieving interoperability a compliance obligation that the GDPR imposes on all controllers?
Not as a standalone, universal mandate. The GDPR does not generally require controllers to make their systems interoperable in the abstract. Interoperability appears as a supporting consideration, for example in the context of technical feasibility for data portability, rather than as a blanket obligation. Some interoperability requirements may arise from other instruments, sectoral rules, or national implementing law rather than from the core GDPR text. Readers should verify the specific source of any interoperability requirement against the current official text and applicable sectoral or member state law.
When implementing interoperability between systems that exchange personal data, what should be considered regarding legal basis?
Each exchange of personal data enabled by interoperability must rest on an appropriate legal basis under Article 6, and the correct basis depends on the context and the roles of the parties. The relevant basis is not automatically consent; it may instead be contract, legal obligation, public task, legitimate interests, or another Article 6 basis, subject to assessment. Where special category data under Article 9 is exchanged, an additional Article 9 condition is needed. The basis should be identified and documented before enabling the exchange.
How should the roles of the parties be characterized when building interoperable data flows?
The roles should be assessed on the facts of each arrangement rather than assumed. Depending on how purposes and means are determined, parties in an interoperable exchange may act as separate controllers, as joint controllers, or in a controller-to-processor relationship. This characterization affects which arrangements are appropriate, such as a data processing agreement under Article 28 where a processor is involved. Clarifying and documenting roles at the design stage helps ensure the correct instruments are put in place.
What data protection by design considerations arise when developing interoperable systems?
Interoperable systems should generally be designed with data protection principles built in from the outset, consistent with the data protection by design and by default obligation. This typically includes considering data minimization so that only data necessary for the purpose is exchanged, applying appropriate technical and organizational security measures to the exchange, and ensuring that shared formats or interfaces do not undermine purpose limitation. The specific measures appropriate will depend on the risk presented by the processing.
Does enabling interoperability affect the handling of cross-border data transfers?
It can, where interoperable exchanges result in personal data being transferred outside the relevant jurisdiction. In such cases, the applicable transfer rules must be considered and an appropriate transfer mechanism and any necessary supplementary measures assessed. Because adequacy decisions, transfer tools, and supplementary measures evolve over time, the position should be reviewed against the current legal framework rather than treated as fixed, and any snapshot verified against official sources.

Common misconceptions

The GDPR imposes a general legal obligation to make systems interoperable.
The GDPR references portability and encourages the development of interoperable formats, but it generally does not compel controllers to adopt technically compatible processing systems. The extent of any obligation is context dependent and readers should verify against the current official text and applicable sector rules.
Interoperability is the same as the right to data portability.
Portability is a specific data subject right with defined conditions, typically limited to data provided by the individual and processed by consent or contract via automated means. Interoperability is a broader technical characteristic that may support portability but is not legally identical to it.
Enabling interoperability removes the need to establish a legal basis for sharing or transferring data.
Interoperability addresses how data can be exchanged, not whether it lawfully may be. A valid Article 6 basis (and an Article 9 condition for special category data) is still required, and cross-border transfers remain subject to applicable transfer mechanisms and safeguards.

Best practices

Distinguish clearly in your documentation between interoperability as a technical property and the specific right to data portability, so that obligations are not overstated.
Confirm and record the applicable Article 6 legal basis (and any Article 9 condition for special category data) before enabling data exchange between systems, since interoperability does not supply that basis.
Use structured, commonly used, and machine-readable formats where portability applies, and consult current sector or regulator guidance on relevant standards rather than assuming a fixed requirement.
Where interoperability involves transfers outside the EEA, assess the applicable transfer tools and any supplementary measures, recognising that adequacy decisions and transfer mechanisms evolve over time.
Verify the current official text and any national implementing law or member state derogations before relying on a specific interpretation, as the position can vary.
Apply data protection by design and by default when building interoperable systems, limiting exchanged data to what is necessary and documenting the assessment behind those choices.