Artifact GuideEU

DSA Researcher Data Access

A source-based guide for VLOPs and VLOSEs handling Article 40 data-access requests from vetted researchers studying systemic risks in the EU.

Use it to apply the DSA and Regulation (EU) 2025/2050 to portal setup, data catalogues, request handling, access safeguards, amendments, and evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Article 40 of the Digital Services Act requires designated very large online platforms and very large online search engines to support regulator access, to specified internal data, and qualifying researcher access to publicly accessible interface data. For vetted researcher access, Commission Delegated Regulation (EU) 2025/2050 has applied since 29 October 2025. It adds the DSA data access portal, public data catalogues, request procedures, access safeguards, and provider notification and documentation duties. It does not require a general-purpose public research API.

Section 1

When Article 40 researcher access applies

Researcher data access under Article 40 applies to services the Commission has designated as VLOPs or VLOSEs. Article 33 uses an average-monthly-active-recipient threshold equal to or higher than 45 million in the Union. The Commission designation and its application date trigger the enhanced duties.

For non-public data, the provider acts on a reasoned request from its Digital Services Coordinator of establishment for a specific project by vetted researchers. The project must contribute to detecting, identifying, and understanding systemic risks in the Union or assessing the adequacy, efficiency, and effects of mitigation measures. Article 40(12) separately covers direct access to publicly accessible interface data for researchers who meet its stated conditions; that route does not require DSC intermediation.

  • Confirm the service is a designated VLOP or VLOSE before treating Article 40 researcher access as the controlling workflow.
  • Separate regulator access from researcher access: Article 40 also covers DSC and Commission requests needed to monitor and assess compliance.
  • Map the request to the Article 40 research purposes rather than assuming that general market research, product analytics, journalism, or an ordinary user-data export qualifies.
  • Do not assume an always-open API obligation; Article 40 refers to access through appropriate interfaces specified in the request, including online databases or APIs.
Section 2

Vetted researcher request governance

The vetted researcher route runs through a Digital Services Coordinator. An applicant researcher needs an account on the DSA data access portal and submits information for one research project. The DSC of establishment decides whether it can formulate a reasoned request and, when the Article 40 conditions are met, awards vetted status for that project.

Researchers may apply through the DSC in the Member State of the research organisation to which the principal researcher is affiliated. That DSC performs an initial assessment and sends the application and supporting documents to the DSC of establishment, which makes the final decision. Under Regulation (EU) 2025/2050, the DSC of establishment must decide within 80 working days after submission whether to formulate a reasoned request or explain why it cannot, unless a duly justified delay is notified with reasons and a new date.

  • Check the portal record and reasoned request for the research purpose, provider and service, requested data, access start and end dates, and the technical, legal, and organisational access measures set by the DSC.
  • Check that the application covers each researcher's affiliation and independence from relevant commercial interests, project funding, the requested data and format, necessity and proportionality, research activities and timeframe, risk controls, and a commitment to publish results free of charge.
  • Keep a separate record of the security and confidentiality measures proposed by the researcher for the specific request.
  • Record communications with the DSC of establishment, the Commission, and the Board where Article 40 requires notice or coordination.
Section 3

Provider setup, response, and amendment grounds

Regulation (EU) 2025/2050 requires each data provider to maintain a DSA data access portal account and a dedicated contact. On its own online interface, the provider must make that contact, a portal link, a DSA data catalogue, and suggested access methods easy to find. The catalogue must describe potentially accessible data assets, structures, and metadata; the provider must update the catalogue and suggested methods regularly, including to reflect Article 34 risk assessments and Article 37 audits.

The reasoned request controls the access deadline, termination date, requested data, and technical, legal, and organisational access measures. The provider must give access within the reasonable period stated in the request.

Within 15 days after receiving the request, the provider may ask the DSC of establishment to amend it only because the provider cannot access the requested data or because access would create significant vulnerabilities for service security or confidential information, especially trade secrets. The provider must propose one or more alternative means of access that are appropriate and sufficient for the research purpose.

  • Maintain the public contact, portal link, DSA data catalogue, and sensitivity-matched suggested access methods required by Regulation (EU) 2025/2050.
  • Run a documented data-availability and vulnerability check immediately after receiving a reasoned request so the 15-day amendment window is not missed.
  • If amendment is needed, propose alternative access to the requested data or other data that is appropriate and sufficient for the research purpose.
  • Do not create invented API fields or undocumented datasets; tie each access method to data the platform actually holds and to the interface specified or accepted by the DSC.
  • Track the DSC's decision on any amendment request, the amended scope, and the new compliance period. A provider that disagrees may request mediation within five working days, but the DSC is not obliged to participate and mediation does not remove the right to judicial proceedings.
Section 4

Confidentiality, personal data, and service-security constraints

Article 40 does not override every confidentiality or security concern. DSCs and the Commission must use data accessed under Article 40 only for monitoring and assessing DSA compliance, while taking account of personal data protection, confidential information including trade secrets, and service security.

For vetted researchers, the application must address request-specific confidentiality, data-security, and personal-data risks and describe the technical, legal, and organisational safeguards. The DSC of establishment determines the access measures after considering those safeguards, the rights and interests of the provider and recipients, trade secrets, service security, storage and deletion, training, contracts, and whether a secure processing environment is needed.

  • Classify requested data by personal data, confidential information, trade-secret sensitivity, security impact, and public-interface availability.
  • Apply the measures in the reasoned request. If it requires a secure processing environment, verify individual identities, access limited to the requested data, confidential access modes, auditable logs, sufficient computing power, and monitoring of those controls.
  • Review whether planned publication of results can be free of charge while still respecting recipients' rights and interests under data-protection law.
  • Escalate any security or trade-secret objection through the Article 40 amendment process instead of silently narrowing the data.
Section 5

Evidence records to keep for researcher access

An evidence file should let a reviewer reconstruct the Article 40 path from the portal application through termination. It should show the research purpose, DSC route, requested and provided data, access decision, security review, amendment or mediation record, and final access state.

Keep public-data access separate from . Article 40 also requires access without undue delay to publicly accessible interface data, including real-time data where technically possible, for researchers who meet specified independence, funding, security, proportionality, and research-purpose conditions.

Can a VLOP or VLOSE reject a vetted researcher data request because the platform prefers not to share the data?

No. A provider may seek an amendment only on Article 40's stated grounds. Within 15 days after receiving the request, it may ask the DSC of establishment to amend the request if it cannot access the data or if access would create significant service-security or confidential-information vulnerabilities. The provider must propose alternative means of access that are appropriate and sufficient for the research purpose.

Does DSA researcher data access require a platform to publish a general-purpose research API?

No. Article 40 refers to access through appropriate interfaces specified in the request, including online databases or APIs. The evidence record should show which interface was specified or approved, which data it exposes, and why the access method fits the DSC request and security constraints.

Who decides whether a researcher is vetted for Article 40 access?

The Digital Services Coordinator of establishment grants vetted researcher status for the specific research and issues the reasoned request to the VLOP or VLOSE. If the researcher applies through the DSC in the Member State of their research organisation, that DSC conducts an initial assessment, but the DSC of establishment makes the final decision.

What must a VLOP or VLOSE publish before receiving a vetted researcher request?

Regulation (EU) 2025/2050 requires the provider to make four items easy to find on its online interface: its dedicated data-access contact, a link to the DSA data access portal, a DSA data catalogue describing potentially accessible data assets and their structure and metadata, and suggested access methods matched to data sensitivity. The catalogue and suggested methods must be updated regularly, including to reflect risk assessments and audits.

  • DSC request pack: requesting authority, provider and service, research title, systemic-risk purpose, data categories, timeframe, interface, and response deadline.
  • Eligibility pack: researcher affiliation, independence statement, funding disclosure, necessity and proportionality analysis, security measures, confidentiality measures, and publication commitment.
  • Data pack: data inventory, availability check, excluded data rationale, amendment request if any, alternative access proposal, and DSC decision.
  • Access pack: provisioning approval, reasoned-request measures, authentication and logging evidence, incident owner, access start and termination, and the notifications sent to the DSC within three working days after access was provided and after it ended.
  • Documentation pack: codebooks, changelogs, architectural documentation, or other information needed to access and understand the data, plus any notified vulnerability and proposed alternative information.
  • Public-data pack: record of publicly accessible data made available to qualifying researchers, technical feasibility notes for real-time access, and limits needed to preserve security and rights.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Articles 6 and 15 establish public provider information, three-working-day access and termination notifications, supporting documentation, and limits on provider-imposed data-management conditions.
digital-strategy.ec.europa.eu
Referenced sections
  • Commission explanation of DSC roles, cooperation with the Commission and Board, and the Commission's competence for VLOP and VLOSE enhanced due-diligence obligations.
eur-lex.europa.eu
Referenced sections
  • Supports reasoned requests, researcher eligibility, amendment handling, access interfaces, public-interface data, and termination of access.
Related guides

Explore more topics

DSA Ads and Recommender Systems: transparency duties, user choice, and evidence
An official source DSA guide to ad labels, targeting restrictions, recommender parameter disclosure, non-profiling options for VLOPs and VLOSEs, ad repositories, and compliance evidence.
DSA Applicability Test: classify intermediary services, platforms, marketplaces, VLOPs and VLOSEs
A cited EU Digital Services Act applicability test for classifying intermediary services, hosting services, online platforms, marketplaces, VLOPs and VLOSEs.
DSA Article 28 minors protection guide for online platforms
EU Digital Services Act guide to Article 28 minors protection: platform scope, child-safety measures, targeted ads limits, recommender controls, and official source evidence.
DSA average monthly active recipients: what platforms must publish
An official source FAQ on average monthly active recipients under the EU Digital Services Act, including publication, EU recipient scope, the 45 million VLOP/VLOSE threshold, and evidence records.
DSA Complaint and Dispute Workflows for Online Platforms
Build DSA complaint, appeal, statement-of-reasons, and out-of-court dispute workflows for online platform moderation decisions.
DSA crisis response for VLOPs and VLOSEs
EU Digital Services Act crisis response guide for VLOPs and VLOSEs: Article 36 Commission decisions, Article 48 crisis protocols, mitigation, governance, requests for information, and records.
DSA Dark Patterns: interface design checks for online platforms
Article 25 DSA guidance for reviewing online platform interfaces for deceptive, manipulative, or choice-distorting design patterns.
DSA Enforcement and Penalties in the EU
How Digital Services Act enforcement works: Commission and Digital Services Coordinator roles, VLOP and VLOSE investigations, fines, periodic penalty payments, and evidence readiness.
DSA illegal content notices: what must be included?
An official source FAQ on EU Digital Services Act illegal-content notices: Article 16 notice elements, acknowledgement, decision notices, trusted flagger priority, statements of reasons, and records.
DSA Marketplace Trader Traceability FAQ
Answer to what EU Digital Services Act Article 30 requires online marketplaces to collect, verify, display, retain, and evidence for trader traceability.
DSA Marketplace Trader Traceability Guide
EU Digital Services Act guide for online marketplaces collecting, checking, displaying, storing, and evidencing trader traceability information.
DSA notice and action plus statements of reasons guide
A source-cited Digital Services Act guide for notice intake, moderation decisions, statements of reasons, DSA Transparency Database submission, complaints, appeals, trusted flaggers, and records.
DSA Notice and Action Workflow for Hosting Services and Online Platforms
A source-cited DSA notice-and-action workflow covering notice intake, completeness checks, trusted flaggers, decisions, user communications, statements of reasons, appeals, and records.
DSA recommender transparency FAQ: Article 27 and VLOP options
What EU Digital Services Act recommender transparency requires: main parameters, user options, VLOP/VLOSE non-profiling choices, and evidence to keep.
DSA service tier classifier for platforms, marketplaces, VLOPs and VLOSEs
Classify a digital service under the EU Digital Services Act as intermediary, hosting, online platform, marketplace, VLOP or VLOSE, with EU recipient-count evidence and obligation outputs.
DSA statement of reasons FAQ
When DSA statements of reasons are required, what they must contain, when online platforms submit them to the DSA Transparency Database, and what appeal records to keep.
DSA statement of reasons log workflow for online platforms
Build a DSA statement of reasons log for moderation decisions, Transparency Database submission, complaint links, retention, and QA controls.
DSA transparency report template fields and cadence
A source-cited template outline for Digital Services Act transparency reports, covering applicable service tiers, reporting periods, CSV/XLSX format, retention, statement-of-reasons links, and required evidence tables.
DSA Transparency Reporting Obligations by Provider Tier
A source-cited guide to EU Digital Services Act transparency reports, active-recipient publication, statements-of-reasons submissions, VLOP/VLOSE reports, templates, cadence, and evidence.
DSA VLOP and VLOSE Risk Assessments and Mitigation Guide
A source-cited guide to Digital Services Act systemic risk assessments, mitigation measures, audits, transparency reports, data access, and governance evidence for VLOPs and VLOSEs.
DSA VLOP Audit Pack Workflow: Risk, Mitigation, Audit, and Transparency Records
Build a DSA VLOP or VLOSE audit pack covering Article 34 risk assessments, Article 35 mitigations, independent-audit evidence, transparency reports, data access, and compliance governance.
DSA VLOP Risk Assessment FAQ: Article 34, Mitigation, Audits
What VLOPs and VLOSEs must assess under the EU Digital Services Act, when to reassess, how Article 35 mitigation and annual audit evidence fit together, and what records to keep.
DSA vs DMA Platform Rules
Compare the EU Digital Services Act and Digital Markets Act by scope, designation thresholds, obligations, enforcement, evidence, and practical team ownership.
DSA vs GDPR: online-platform governance and personal-data obligations
Compare the EU Digital Services Act and EU GDPR by scope, ads, recommenders, minors, transparency, complaints, enforcement, and evidence.
DSA vs P2B Regulation: EU platform obligations compared
Compare the EU Digital Services Act with the Platform-to-Business Regulation for platform scope, business-user terms, content moderation, ranking transparency, complaints, enforcement, and evidence.
DSA vs Terrorist Content Online Regulation: notice-and-action vs removal orders
Compare DSA content-governance duties with the EU Terrorist Content Online Regulation removal-order workflow for scope, timing, evidence, authorities, and team ownership.
EU Digital Services Act checklist for platforms and hosting services
An official source DSA checklist for classifying service tiers, notice-and-action, statements of reasons, complaints, transparency reports, ads, recommenders, trader traceability, VLOP/VLOSE duties, and evidence records.
EU Digital Services Act Compliance Guide
DSA compliance guide for intermediary services, hosting providers, online platforms, marketplaces, and VLOP/VLOSE teams: obligations, controls, and evidence to keep.
EU Digital Services Act FAQ: DSA scope, platform duties, VLOPs, reports, and penalties
Concise EU Digital Services Act FAQ covering intermediary-service scope, active-recipient thresholds, illegal-content notices, statements of reasons, trader traceability, recommender transparency, systemic-risk duties, reporting, penalties, and complaints.
EU Digital Services Act penalties and fines: caps and enforcement roles
DSA penalty caps and enforcement roles: Member State fines, Commission fines for VLOPs and VLOSEs, 1% procedural fines, and 5% periodic penalty payments.
EU Digital Services Act requirements by service tier
Overview of DSA obligations for intermediary services, hosting providers, online platforms, marketplaces, VLOPs and VLOSEs, including notices, complaints, ads, transparency reports, audits, data access and enforcement.
EU Digital Services Act service types and scope
Classify DSA service scope across mere conduit, caching, hosting, online platforms, marketplaces, online search engines, and VLOP/VLOSE threshold duties.
EU DSA deadlines and compliance calendar: application dates, reporting cycles, and VLOP clocks
Calendar view of cited EU Digital Services Act dates: full application, user-number publication, VLOP/VLOSE designation clocks, statements of reasons, and transparency reporting cycles.
EU DSA Transparency Calendar: reporting, SoR database, AMAR updates
Build a DSA transparency calendar for annual reports, statement-of-reasons database submissions, active-recipient updates, and VLOP/VLOSE audit touchpoints.
EU DSA vs UK Online Safety Act: scope, duties, regulator, and evidence
Compare the EU Digital Services Act and UK Online Safety Act for platform scope, risk assessments, child protection, transparency, regulators, enforcement, and owners.