Regulation (EU) 2025/2050 requires each data provider to maintain a DSA data access portal account and a dedicated contact. On its own online interface, the provider must make that contact, a portal link, a DSA data catalogue, and suggested access methods easy to find. The catalogue must describe potentially accessible data assets, structures, and metadata; the provider must update the catalogue and suggested methods regularly, including to reflect Article 34 risk assessments and Article 37 audits.
The reasoned request controls the access deadline, termination date, requested data, and technical, legal, and organisational access measures. The provider must give access within the reasonable period stated in the request.
Within 15 days after receiving the request, the provider may ask the DSC of establishment to amend it only because the provider cannot access the requested data or because access would create significant vulnerabilities for service security or confidential information, especially trade secrets. The provider must propose one or more alternative means of access that are appropriate and sufficient for the research purpose.