Skip to main content
Category: Data Subject Rights

Machine-Readable Format

Also known as: Machine-Readable Data, Computer-Readable Format
Simply put

A machine-readable format is a way of storing data so that a computer can read and process it automatically, without a person having to interpret it first. Common examples include file types such as CSV, JSON, and XML. This contrasts with formats designed mainly for human reading, which computers cannot reliably process on their own.

Formal definition

A machine-readable format refers to a structured data format that can be automatically read and processed by a computer without human intervention, while preserving the data's semantic meaning. Typical examples cited in guidance include CSV, JSON, and XML, which represent data as structured rather than unstructured content. In a data protection context, this concept is relevant to certain data subject rights, such as data portability, which in the GDPR generally requires personal data to be provided in a structured, commonly used, and machine-readable format; practitioners should verify the precise requirements against the current text of the relevant GDPR provision, as the sources in this packet do not themselves set out the Regulation's wording. The definitions here derive from technical and open-data glossaries rather than from the GDPR itself, so their scope may differ from any legal definition applied under EU or UK data protection law.

Why it matters

Machine-readable format matters in data protection because certain data subject rights depend on it. In the GDPR, the right to data portability generally requires that personal data be provided in a structured, commonly used, and machine-readable format so that individuals can reuse it or have it transmitted to another controller. If an organisation exports personal data only as unstructured content, such as a scanned document or a format designed primarily for human reading, it may not satisfy this requirement. Practitioners should verify the precise wording and scope against the current text of the relevant GDPR provision, as the sources in this packet describe machine-readability from a technical and open-data perspective rather than a legal one.

The practical significance lies in interoperability. A machine-readable export allows data to move between systems and controllers with minimal manual handling, which supports the underlying policy aim of giving individuals greater control over their personal data. Where data is locked in proprietary or human-oriented formats, the effort and cost of reuse can undermine that aim in practice, even if a copy of the data has technically been provided.

Because the definitions used here derive from technical and open-data glossaries rather than the Regulation itself, the boundary of what qualifies as machine-readable in a legal sense may differ from these technical descriptions. Regulators and guidance may interpret the requirement in ways not fully captured by a purely technical definition, so the concept should be applied with reference to current official sources rather than treated as settled by the technical glossaries alone.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads generally need to understand what qualifies as a machine-readable format when designing processes for handling data subject requests, particularly portability-related requests. They should confirm the precise legal requirements against the current GDPR text rather than relying solely on technical glossary definitions, and note that regulator interpretation may vary.
Engineers and Data Teams
Engineers building export and data-handling functionality typically implement the structured formats, such as CSV, JSON, or XML, that make data automatically processable without manual interpretation. Their choices affect whether an organisation can supply data in a form that supports interoperability and reuse.
Privacy and Technology Lawyers
Lawyers advising on data subject rights and portability should distinguish the technical concept of machine-readability, described in the sources here, from any legal standard applied under EU or UK data protection law. The two may not align exactly, so advice should reference the operative provision and current guidance.

Inside Machine-Readable Format

Structured data format
Personal data organized in a way that can be processed automatically by software, as opposed to unstructured formats such as scanned images or free-form text that require manual interpretation. Common examples generally include CSV, XML, and JSON.
Interoperability characteristic
The quality that allows the data to be read, reused, and imported into other systems or by other controllers without disproportionate effort. This supports the practical exercise of the right to data portability.
Connection to the right to data portability
The machine-readable format concept is most closely associated with the right to data portability, under which a data subject can, in defined circumstances, receive their personal data in a structured, commonly used and machine-readable format. The precise conditions and article reference should be verified against the current official GDPR text.
Distinction from mere accessibility
A format being human-readable or openable does not make it machine-readable; the key is whether software can reliably extract and process the individual data elements automatically.

Common questions

Answers to the questions practitioners most commonly ask about Machine-Readable Format.

Does data have to be in a machine-readable format for it to be considered structured or usable under data protection law?
No. Machine-readable format is a distinct concept from whether data is structured or usable in a general sense. A machine-readable format specifically refers to a file format structured so that software applications can readily identify, recognise, and extract specific data, including individual statements of fact and their internal structure. Data can be usable to a human, or held in a structured filing system, without necessarily meeting the machine-readability threshold. Whether a particular format qualifies is generally a matter of assessment, and readers should verify against current official guidance.
Is a PDF a machine-readable format?
This should not be assumed. A format's machine-readability depends on whether software can readily identify, recognise, and extract the specific data and its structure, rather than on the file extension alone. Some formats present information in a way that is easier for automated processing than others. Because assessments can vary by context and by the specific way a file is generated, whether a given PDF or other document qualifies is subject to assessment rather than a fixed rule.
In what context does the requirement to provide data in a machine-readable format typically arise?
The concept is most commonly associated with the right to data portability, where, in applicable circumstances, individuals may receive personal data concerning them in a structured, commonly used, and machine-readable format. The precise conditions under which this applies, and the scope of the data covered, are governed by the relevant provisions and guidance, which readers should consult directly.
How should an organisation decide which format to provide when responding to a portability-related request?
In most cases the aim is to select a format that is structured, commonly used, and machine-readable, so that the receiving party can readily process the data. The suitability of a specific format is subject to assessment based on the nature of the data and how it can be extracted and re-used. Organisations typically document their reasoning and may wish to consult current regulatory guidance, as expectations can evolve.
Does providing data in a machine-readable format guarantee compliance with a data subject's request?
No single formatting step guarantees compliance. Machine-readability is one characteristic that may be relevant, but the broader response must be considered in light of the applicable legal requirements, the scope of the data involved, and the specific right being exercised. Compliance is generally context and risk dependent, so the format alone should not be treated as fully satisfying an obligation.
Where can an organisation find the authoritative criteria for what qualifies as machine-readable?
The precise criteria and current expectations are set out in the relevant official text and supervisory authority guidance, which readers should consult directly. Because interpretations and guidance in this area can develop over time, and because positions may differ between regulators or between the EU and UK regimes, any internal standard should be verified against the current official sources rather than treated as settled.

Common misconceptions

Any electronic file, such as a PDF or scanned document, satisfies the machine-readable requirement.
A file being digital does not make it machine-readable. Formats that primarily present information for human viewing, such as a scanned PDF, typically do not allow automated extraction of individual data elements and generally would not meet the standard.
The machine-readable format requirement applies to every response a controller gives to a data subject.
The structured, commonly used and machine-readable format standard is generally associated with the right to data portability and its specific conditions, not with all data subject requests. Other rights, such as access, may have different formatting expectations, which should be confirmed against the current official text and applicable guidance.
There is a single mandated file format that must be used.
The Regulation generally describes qualities the format should have rather than prescribing one specific file type. Which format is appropriate depends on the data and context, and regulator guidance on the point may evolve.

Best practices

Where the right to data portability applies, provide personal data in a structured, commonly used, and machine-readable format such as CSV, XML, or JSON, chosen based on the nature of the data and the likelihood of reuse.
Avoid supplying portability responses solely as scanned images or formats designed for human viewing, since these generally do not permit automated processing.
Assess interoperability in practice by confirming that the exported data can be reasonably imported and reused by another system without disproportionate effort.
Confirm that the machine-readable format standard is being applied to the correct right and situation, and distinguish it from other data subject rights that may have different formatting expectations.
Verify the applicable article references, conditions, and any current regulator guidance against the official GDPR text before finalizing internal procedures, as guidance in this area can evolve.
Document the format decision and the rationale for the chosen file type as part of your records demonstrating how portability requests are handled.