Skip to content
Topic Developing

Data Access and Scrutiny Mechanisms under DSA

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal β€” legal information, not advice.

This new topic is needed because the content specifically addresses data access and scrutiny as a distinct DSA requirement, which encompasses mechanisms for authorities, researchers, and civil society to access and examine platform data for compliance verification and systemic risk assessment.

6 linked items 6 Laws

Overview

6 sources Β· Jul 23, 2026

Legal Framework

Article 40 of the Digital Services Act (DSA) establishes the core framework for data access and scrutiny, requiring very large online platforms (VLOPs) and very large online search engines (VLOSEs) to provide access to data for vetted researchers. Recital 97 clarifies the scope: access is available to researchers affiliated with research organisations as defined under Article 2 of Directive (EU) 2019/790, which expressly includes civil society organisations conducting scientific research in support of a public interest mission.

The framework distinguishes between two access modalities. First, platforms must make data available through publicly accessible repositories or application programming interfaces, enabling researchers to query datasets without individualised requests. Second, where additional data is needed, vetted researchers may submit specific data access requests that platforms must respond to within a defined timeframe.

The doctrinal commentary highlights that adherence to approved codes of conduct or certification mechanisms can serve as an element demonstrating that a platform has implemented sufficient safeguards for data access. This does not create a legal presumption of compliance β€” platforms retain independent responsibility to verify that their data access infrastructure meets Article 40 requirements, even where they participate in a certification scheme.

Recital 97 further mandates that all data access requests be proportionate and appropriately protect the rights and legitimate interests of platforms and third parties, including trade secrets, intellectual property, and personal data protection obligations under the GDPR.

Key Developments

The European Commission has begun designating Digital Services Coordinators (DSCs) and establishing the vetting infrastructure required to operationalise Article 40. The vetting process requires researchers to demonstrate independence, scientific competence, and a research design that contributes to identifying systemic risks under Article 34 DSA.

Early enforcement signals indicate that DSCs will scrutinise whether platforms have implemented functional, non-discriminatory data access mechanisms. Platforms that offer only partial datasets, impose unreasonable rate limits, or structure APIs in ways that impede meaningful analysis face regulatory exposure. The Commission's preliminary guidance emphasises that data access must enable both retrospective analysis and ongoing monitoring of systemic risks.

Where platforms rely on approved codes of conduct to demonstrate compliance, the doctrinal commentary makes clear that such adherence constitutes supporting evidence rather than a safe harbour. Regulators retain discretion to assess whether the platform's actual data access practices satisfy the sufficiency standard independently.

Practical Guidance

  • Establish dual-track access infrastructure: Implement both publicly accessible data repositories and a structured process for responding to individual vetted researcher requests, as Article 40 requires both modalities.

  • Design APIs and repositories for genuine usability: Ensure that data endpoints provide comprehensive, machine-readable datasets without arbitrary rate limits or filtering that would undermine researchers' ability to assess systemic risks under Article 34.

  • Implement proportionality assessments for each request: Evaluate whether the scope of data sought is proportionate to the research objective, and document trade secret, IP, and personal data protections applied β€” Recital 97 makes this a legal requirement.

  • Do not over-rely on certification or code of conduct participation: While adherence to an approved mechanism supports your compliance position, maintain independent verification that data access practices meet Article 40 standards, as no presumption of compliance arises.

  • Coordinate with your Digital Services Coordinator: Engage proactively with the relevant DSC on the vetting of researchers and the technical specifications of data access, as DSCs play a central role in approving and supervising the Article 40 framework.

Everything on this topic, by type links go to the exact provision / paragraph / section