Source: OJ L, 2025/2050, 9.10.2025

Current language: EN

Data access for vetted researchers

COMMISSION DELEGATED REGULATION (EU) 2025/2050

of 1 July 2025

supplementing Regulation (EU) 2022/2065 of the European Parliament and of the Council by laying down the technical conditions and procedures under which providers of very large online platforms and of very large online search engines are to share data with vetted researchers

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market for Digital Services and amending Directive 2000/31/EC(1), and in particular Article 40(13) thereof,

Whereas:

Open full page
Recital 1Article 40 grants vetted researchers data access

Article 40 of Regulation (EU) 2022/2065 lays down rules regarding access to data to be granted by providers of very large online platforms and of very large online search engines. In particular, it enables researchers who have completed a process to demonstrate that they fulfil the conditions laid down in paragraph 8 of that Article (‘vetted researchers’) to be provided with such access.

Recital 2Purpose: technical conditions for data access

Under Article 40(4) of Regulation (EU) 2022/2065, vetted researchers are to be provided with access to data to help them study systemic risks in the Union and assess the effectiveness of measures to mitigate those risks. Their findings can constitute valuable input for the enforcement of Regulation (EU) 2022/2065 and foster accountability of providers of very large online platforms and of very large online search engines. The purpose of this Regulation is to lay down the technical conditions and the procedures necessary to enable such access, in a secure and efficient manner that is consistent across all Digital Services Coordinators, and in a way that ensures equality of treatment for researchers and data providers.

Recital 3Establishment of the DSA data access portal

To ensure that the data access process is consistent across all Digital Services Coordinators and to make that process clear and transparent for everyone, it is necessary to create a dedicated digital infrastructure (‘the DSA data access portal’). The DSA data access portal should allow researchers, data providers, and Digital Services Coordinators to participate in the data access process, have access to and disseminate relevant information, such as the details of the dedicated points of contact, and communicate with one another. The DSA data access portal should not be considered as one of the access modalities to be used for the provision of access to the data pursuant to a reasoned request.

HAS ADOPTED THIS REGULATION:

  1. Chapter IGeneral provisions
  2. Chapter IIInformation and contact obligations
  3. Chapter IIIRequirements for formulating and processing of reasoned requests
  4. Chapter IVConditions for providing the data requested to vetted researchers
  5. Chapter VFinal provisions
Annex
  1. AnnexResponsibilities of the Commission as processor for data processing activities conducted in the context of the DSA data access portal

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 1 July 2025.

For the Commission

The President

Ursula VON DER LEYEN

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod