Source: OJ L, 2025/2050, 9.10.2025

Current language: EN

Article 9 Access modalities


    1. The Digital Services Coordinator of establishment shall determine the modalities, including the technical, legal and organisational measures, that the data provider is to use for providing access to the data to the vetted researchers.

    1. The Digital Services Coordinators shall be allowed to consult the relevant supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679.

    1. When determining the access modalities, the Digital Services Coordinator of establishment shall take into account the information provided in the data access application, in particular the information referred to in Article 8, point (e), considering also the rights and interests of the data providers and the recipients of the service concerned, including the protection of confidential information, trade secrets, and maintaining the security of their service and the information made available by the data providers pursuant to Article 6(4), point (d).

    1. In addition to the elements referred to in paragraph 3, the Digital Services Coordinator of establishment shall, when determining access modalities, take into account the following elements:

      1. where the access involves the processing of personal data:

        1. the assessment of the risks concerning processing of personal data as described in Article 8(e), including, where applicable, data protection impact assessments within the meaning of Article 35 of Regulation (EU) 2016/679;

        2. envisaged technical and organisational measures as submitted pursuant to Article 8(e);

      2. relevant network security measures, encryption, access control mechanisms, backup policies, data integrity mechanisms, incident response plans;

      3. where applicable, information on the intended storage period and the relevant data destruction plans;

      4. any organisational measures such as internal review processes, restrictions of access rights and information sharing;

      5. any proposed contractual clauses, such as non-disclosure agreements, data agreements and any other type of written statements, laying down possible conditions of access and processing between the principal researcher and the data provider;

      6. existence of training on data security and protection of personal data received by the applicant researchers;

      7. whether secure processing environments is necessary to process the data.

    1. Where the Digital Services Coordinator of establishment considers that a secure processing environment is to be used to provide access to the data requested, the Digital Services Coordinator of establishment shall require documentation attesting that the operator of that environment:

      1. specifies access conditions to the secure processing environment in order to minimise the risk of the unauthorised reading, copying, modification or removal of the data hosted in the secure processing environment;

      2. ensures that vetted researchers have access only to data covered by the reasoned request, by means of individual and unique user identities and confidential access modes;

      3. keeps identifiable logs of access to the secure processing environment for the period necessary to verify and audit all processing operations in that environment;

      4. ensures that the computing power at the disposal of the vetted researchers is appropriate and sufficient for the purposes of the research project;

      5. monitors the effectiveness of the measures listed in points (a) to (d).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod