Right to data portability
In June 2025, the South Korean government proposed to extend the “right to portability” from certain fields (medicine, telecom) to all sectors of the economy. That is, a citizen can demand the controller (organization) to transfer his or her personal data to him or her or, at his or her direction, to any third party. The organization will be obliged to implement the user's request to transfer his
Из выпуска мониторинга No. 6 (18), June 2025 · выпуск целиком, PDF · на сайте Института Гайдара

The experience of South Korea
In June 2025, the South Korean government proposed to extend the “right to portability” from certain fields (medicine, telecom) to all sectors of the economy. That is, a citizen can demand the controller (organization) to transfer his or her personal data to him or her or, at his or her direction, to any third party. The organization will be obliged to implement the user's request to transfer his personal data if:
− It has over $110 mn in revenue and over 1 million users.
− It has more than 5,000 users and1 accumulates sensitive or unique data of such users.
− Universities with more than 20,000 students or operators of public administration systems (e.g. outpatient clinics).
However, data that the operator compound with other data or analytics, such as a database of users' likes aggregated by gender and age and combined with data on users' music preferences, is exempt from regulation. In this way, the law protects the right of companies to create databases and other products based on user data.
Notably, the user can request to transfer personal data both directly to himself (e.g., to download a data file to his computer) and to third parties - specialized intermediary organizations. Such organizations act as agents for data subjects, so they have the right to receive and store data on behalf of the user, provide access to his data, and transfer them to third-party organizations at his request, but they cannot process the data received. Organizations must comply with information security requirements, technical and organizational measures to prevent data leakage, etc.
The EU experience
In foreign legislative practice, the right to data portability first appears in the EU General Data Protection Regulation in 2016. The right was introduced to enable users to freely transfer between companies, primarily digital platforms2 competing with each other.
The Korean initiative to establish the institution of specialized user data management organizations is similar to the institution of data intermediary in the EU. However, in the EU, such an intermediary can provide services not only for personal data but also for non-personal data.
Russia’s experience
In Russia, the right to data portability is currently not established - there is no right to receive a copy of the processed data, nor is there a right to request the transfer of processed data to another data controller. There is also no special regulation for providers of data intermediation services.
- https://www.oecd.org/en/publications/is-generative-ai-a-general-purpose-technology_704e2d12-en.html ↑
- https://ethics.a-ai.ru/ ↑
- Sensitive data - data on ideology, political views, criminal record, biometrics data, etc. Unique data - passport number, driver's license number, etc. ↑
From the monitoring issue No. 6 (18), June 2025. Download the full issue (PDF) · issue page at the Gaidar Institute