# Data Access and Scrutiny Mechanisms under DSA — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/data-access-scrutiny-mechanisms-dsa
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because the content specifically addresses data access and scrutiny as a distinct DSA requirement, which encompasses mechanisms for authorities, researchers, and civil society to access and examine platform data for compliance verification and systemic risk assessment.

## Overview

## Legal Framework

Article 40 of the Digital Services Act (DSA) establishes the core framework for data access and scrutiny, requiring very large online platforms (VLOPs) and very large online search engines (VLOSEs) to provide access to data for vetted researchers. Recital 97 clarifies the scope: access is available to researchers affiliated with research organisations as defined under Article 2 of Directive (EU) 2019/790, which expressly includes civil society organisations conducting scientific research in support of a public interest mission.

The framework distinguishes between two access modalities. First, platforms must make data available through publicly accessible repositories or application programming interfaces, enabling researchers to query datasets without individualised requests. Second, where additional data is needed, vetted researchers may submit specific data access requests that platforms must respond to within a defined timeframe.

The doctrinal commentary highlights that adherence to approved codes of conduct or certification mechanisms can serve as an element demonstrating that a platform has implemented sufficient safeguards for data access. This does not create a legal presumption of compliance — platforms retain independent responsibility to verify that their data access infrastructure meets Article 40 requirements, even where they participate in a certification scheme.

Recital 97 further mandates that all data access requests be proportionate and appropriately protect the rights and legitimate interests of platforms and third parties, including trade secrets, intellectual property, and personal data protection obligations under the GDPR.

## Key Developments

The European Commission has begun designating Digital Services Coordinators (DSCs) and establishing the vetting infrastructure required to operationalise Article 40. The vetting process requires researchers to demonstrate independence, scientific competence, and a research design that contributes to identifying systemic risks under Article 34 DSA.

Early enforcement signals indicate that DSCs will scrutinise whether platforms have implemented functional, non-discriminatory data access mechanisms. Platforms that offer only partial datasets, impose unreasonable rate limits, or structure APIs in ways that impede meaningful analysis face regulatory exposure. The Commission's preliminary guidance emphasises that data access must enable both retrospective analysis and ongoing monitoring of systemic risks.

Where platforms rely on approved codes of conduct to demonstrate compliance, the doctrinal commentary makes clear that such adherence constitutes supporting evidence rather than a safe harbour. Regulators retain discretion to assess whether the platform's actual data access practices satisfy the sufficiency standard independently.

## Practical Guidance

- **Establish dual-track access infrastructure**: Implement both publicly accessible data repositories and a structured process for responding to individual vetted researcher requests, as Article 40 requires both modalities.

- **Design APIs and repositories for genuine usability**: Ensure that data endpoints provide comprehensive, machine-readable datasets without arbitrary rate limits or filtering that would undermine researchers' ability to assess systemic risks under Article 34.

- **Implement proportionality assessments for each request**: Evaluate whether the scope of data sought is proportionate to the research objective, and document trade secret, IP, and personal data protections applied — Recital 97 makes this a legal requirement.

- **Do not over-rely on certification or code of conduct participation**: While adherence to an approved mechanism supports your compliance position, maintain independent verification that data access practices meet Article 40 standards, as no presumption of compliance arises.

- **Coordinate with your Digital Services Coordinator**: Engage proactively with the relevant DSC on the vetting of researchers and the technical specifications of data access, as DSCs play a central role in approving and supervising the Article 40 framework.

## Legislation (full text of key provisions)

### Data access and scrutiny

*Source: DSA, dsa-art-40-en, 2022-10-19 — https://overview.legal/posts/94689*

### Recital 97 — researcher data access framework

*Source: DSA, dsa-rec-97-en, 2022-10-19 — https://overview.legal/posts/95591*

This Regulation therefore provides a framework for compelling access to data from very large online platforms and very large online search engines to vetted researchers affiliated to a research organisation within the meaning of Article 2 of Directive (EU) 2019/790, which may include, for the purpose of this Regulation, civil society organisations that are conducting scientific research with the primary goal of supporting their public interest mission. All requests for access to data under that framework should be proportionate and appropriately protect the rights and legitimate interests, including the protection of personal data, trade secrets and other confidential information, of the very large online platform or of the very large online search engine and any other parties concerned, including the recipients of the service. However, to ensure that the objective of this Regulation is achieved, consideration of the commercial interests of providers should not lead to a refusal to provide access to data necessary for the specific research objective pursuant to a request under this Regulation. In this regard, whilst without prejudice to Directive (EU) 2016/943 of the European Parliament and of the Council (32), providers should ensure appropriate access for researchers, including, where necessary, by taking technical protections such as through data vaults. Data access requests could cover, for example, the number of views or, where relevant, other types of access to content by recipients of the service prior to its removal by the providers of very large online platforms or of very large online search engines.

### Recital 98 — researcher access to public data

*Source: DSA, dsa-rec-98-en, 2022-10-19 — https://overview.legal/posts/95593*

In addition, where data is publicly accessible, such providers should not prevent researchers meeting an appropriate subset of criteria from using this data for research purposes that contribute to the detection, identification and understanding of systemic risks. They should provide access to such researchers including, where technically possible, in real-time, to the publicly accessible data, for example on aggregated interactions with content from public pages, public groups, or public figures, including impression and engagement data such as the number of reactions, shares, comments from recipients of the service. Providers of very large online platforms or of very large online search engines should be encouraged to cooperate with researchers and provide broader access to data for monitoring societal concerns through voluntary efforts, including through commitments and procedures agreed under codes of conduct or crisis protocols. Those providers and researchers should pay particular attention to the protection of personal data, and ensure that any processing of personal data complies with Regulation (EU) 2016/679. Providers should anonymise or pseudonymise personal data except in those cases that would render impossible the research purpose pursued.

### Recital 96 — very large platform compliance data access

*Source: DSA, dsa-rec-96-en, 2022-10-19 — https://overview.legal/posts/95589*

In order to appropriately monitor and assess the compliance of very large online platforms and of very large online search engines with the obligations laid down by this Regulation, the Digital Services Coordinator of establishment or the Commission may require access to or reporting of specific data, including data related to algorithms. Such a requirement may include, for example, the data necessary to assess the risks and possible harms brought about by the very large online platform’s or the very large online search engine’s systems, data on the accuracy, functioning and testing of algorithmic systems for content moderation, recommender systems or advertising systems, including, where appropriate, training data and algorithms, or data on processes and outputs of content moderation or of internal complaint-handling systems within the meaning of this Regulation. Such data access requests should not include requests to produce specific information about individual recipients of the service for the purpose of determining compliance of such recipients with other applicable Union or national law. Investigations by researchers on the evolution and severity of online systemic risks are particularly important for bridging information asymmetries and establishing a resilient system of risk mitigation, informing providers of online platforms, providers of online search engines, Digital Services Coordinators, other competent authorities, the Commission and the public.

### Recital 138 — Commission investigation and referral powers

*Source: DSA, dsa-rec-138-en, 2022-10-19 — https://overview.legal/posts/95673*

The Commission should be able to investigate infringements on its own initiative in accordance with the powers provided for in this Regulation, including by asking access to data, by requesting information or by performing inspections, as well as by relying on the support of the Digital Services Coordinators. Where supervision by the competent national authorities of individual alleged infringements by providers of very large online platforms or very large online search engines points to systemic issues, such as issues with a wide impact on collective interests of recipients of the service, the Digital Services Coordinators should be able to, on the basis of a duly reasoned request, refer such issues to the Commission. Such a request should contain, at least, all the necessary facts and circumstances supporting the alleged infringement and its systemic nature. Depending on the outcome of its own assessment, the Commission should be able to take the necessary investigative and enforcement measures pursuant to this Regulation, including, where relevant, launching an investigation or adopting interim measures.

### Recital 139 — Commission enforcement discretion over very large platforms

*Source: DSA, dsa-rec-139-en, 2022-10-19 — https://overview.legal/posts/95675*

In order to effectively perform its tasks, the Commission should maintain a margin of discretion as to the decision to initiate proceedings against providers of very large online platforms or of very large online search engine. Once the Commission initiated the proceedings, the Digital Services Coordinators of establishment concerned should be precluded from exercising their investigative and enforcement powers in respect of the concerned conduct of the provider of the very large online platform or of very large online search engine, so as to avoid duplication, inconsistencies and risks from the viewpoint of the principle of ne bis in idem. The Commission, however, should be able to ask for the individual or joint contribution of the Digital Services Coordinators to the investigation. In accordance with the duty of sincere cooperation, the Digital Services Coordinator should make its best efforts in fulfilling justified and proportionate requests by the Commission in the context of an investigation. Moreover, the Digital Services Coordinator of establishment, as well as the Board and any other Digital Services Coordinators where relevant, should provide the Commission with all necessary information and assistance to allow it to perform its tasks effectively, including information gathered in the context of data gathering or data access exercises, to the extent that this is not precluded by the legal basis according to which the information has been gathered. Conversely, the Commission should keep the Digital Services Coordinator of establishment and the Board informed on the exercise of its powers and in particular when it intends to initiate the proceeding and exercise its investigatory powers. Moreover, when the Commission communicates its preliminary findings, including any matter to which it objects, to providers of very large online platforms or of very large online search engines concerned, it should also communicate them to the Board. The Board should provide its views on the objections and assessment made by the Commission, which should take this opinion into account in the reasoning underpinning Commission's final decision.

## Related topics

- **VLOP/VLSE Framework** — https://overview.legal/topics/vlop-vlse-regulatory-framework-overview
  The content title specifically focuses on 'Very large online platforms and very large online search engines' as a distinct regulatory category under the DSA. A 
- **Competent Authorities Designation and Powers under DSA** — https://overview.legal/topics/dsa-competent-authorities-designation
  The content is titled 'Competences' from the DSA and discusses the allocation and scope of authority powers under the Digital Services Act. This requires a dedi
- **Digital Services Coordinator** — https://overview.legal/topics/digital-services-coordinator-establishment-role
  While 'digital-services-coordinators-dsa' exists, a more specific topic on the establishment, institutional framework, and foundational role of DSCs would bette
- **Digital Services Coordinators under DSA** — https://overview.legal/topics/digital-services-coordinators-dsa
  This new topic is needed because Digital Services Coordinators are a distinct institutional role under DSA with specific designation procedures, responsibilitie
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities

---
Generated by overview.legal · https://overview.legal/topics/data-access-scrutiny-mechanisms-dsa · 2026-08-22
