Inspection Access Rights and Cooperation Obligations
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.A dedicated topic is needed to address the specific rights of inspectors to access facilities, systems, and documents, and the corresponding obligations of AI providers and deployers to cooperate with inspections.
Overview
13 sources · Jul 23, 2026Legal Framework
Article 82 of the Digital Services Act (DSA) governs the interaction between access restrictions and cooperation with national judicial authorities. This provision establishes that providers must cooperate with national courts when addressing requests for access restrictions, ensuring that judicial oversight is integrated into the operational framework of digital services. The rationale is to balance the operational realities of digital platforms with the necessity of judicial intervention, ensuring that access can be restricted only when justified and properly mandated by a competent court.
In the broader context of data protection, Articles 15 and 12 of the GDPR establish the baseline for access rights and the obligation to facilitate them. While these provisions directly address data subject access, they establish a normative framework that extends to regulatory inspections: controllers must provide access to information and systems without undue delay, and cannot systematically refuse access based on generalized privacy concerns.
Key Developments
The Court of Justice of the European Union has established that access rights cannot be categorically denied on the grounds of privacy violations without a specific, contextual analysis of the circumstances. In the Jehovah's Witnesses case, the Court clarified that a blanket refusal to grant access is impermissible; controllers must evaluate each request individually. This principle translates directly to regulatory inspections: authorities must be granted access unless a specific, legally sound justification for refusal exists in the individual case.
The Bara ruling further reinforces that national law cannot serve as a substitute for specific information obligations. Controllers cannot rely on general legal frameworks to dispense with their duty to inform or provide access to specific data transfers or processing operations.
Data Protection Authorities have actively enforced these cooperation standards. The Hellenic Data Protection Authority sanctioned an insurance company for failing to provide adequate access to data subjects, demonstrating that non-cooperation with access requests—whether from individuals or regulators—carries significant liability. Similarly, the Croatian Data Protection Authority penalized a hospital for failing to implement adequate technical and organizational measures, highlighting that the ability to grant access is contingent upon having the proper infrastructure in place.
The Council's recent articulation of new powers for the AI Office signals an expansion of inspection capabilities. Regulators are poised to gain enhanced authority to access the facilities, systems, and documentation of AI providers and deployers, making proactive cooperation a central compliance requirement.
Practical Guidance
- Establish a dedicated protocol for responding to regulatory inspection requests within the timelines mandated by Article 82 DSA and relevant GDPR provisions, ensuring that judicial orders are processed and executed without undue delay.
- Implement an individualized assessment mechanism for all access requests, whether from data subjects or regulators, to comply with the Jehovah's Witnesses standard; avoid blanket refusals based on generalized privacy or confidentiality concerns.
- Maintain comprehensive technical and organizational measures that ensure the immediate retrievability of documents and system logs, as demonstrated by the Croatian DPA enforcement action; the inability to produce requested materials due to poor infrastructure constitutes a violation.
- Ensure that all data processing records clearly document the recipients and purposes of data transfers, satisfying the information requirements established in Bara and preventing disputes during inspections.
- Monitor the evolving mandate of the AI Office and prepare internal systems for expanded inspection access, anticipating that new powers will require granular documentation of AI system training data, models, and deployment logs.