Understanding DSA Article 40: The Foundation for Researcher Data Access
Article 40 of the Digital Services Act (DSA) makes provision for researchers to access data from Very Large Online Platforms (VLOPs) or Very Large Online Search Engines (VLOSEs) for the purposes of studying systemic risk in the EU and assessing mitigation measures. This groundbreaking provision represents a significant shift in platform transparency and accountability, enabling the research community to contribute meaningfully to understanding the digital ecosystem.
The practical implementation of these DSA researcher data access requirements relies on a comprehensive framework established through a delegated act published by the Commission on 2 July 2025, which outlines rules granting access to data for qualified researchers under the Digital Services Act. This delegated act serves as the operational backbone for both VLOPs/VLOSEs and Digital Services Coordinators (DSCs) tasked with managing researcher applications.
Two Pathways to Research Data Access
There are two ways that researchers studying systemic risk in the EU can get access to data under Article 40 of the DSA. Understanding these distinct pathways is crucial for VLOPs and VLOSEs developing their compliance strategies.
Qualified Researcher Access (Article 40(12)): This is a process where a researcher who meets the relevant criteria can apply for access to publicly accessible data directly from a VLOP/VLOSE, for example, access to a content library or API of public posts. Researchers can request publicly accessible data – such as information about publicly accessible posts, accounts, or search results – beyond what platforms voluntarily provide, with researchers working on questions of systemic risks having a consistent, predictable avenue to obtain public data.
Vetted Researcher Access (Article 40(4)-(11)): This is a process where a researcher, who has been vetted or assessed by a Digital Services Coordinator to have met the criteria as set out in DSA Article 40(8), can request access to data held by a VLOP/VLOSE. This pathway provides access to non-public, internal platform data that has been strictly vetted through the DSC approval process.
Qualified Researcher Eligibility Criteria
For platforms, understanding who qualifies as a researcher is essential for implementing fair and consistent access policies. The DSA establishes specific eligibility requirements across both pathways.
Core Eligibility Requirements for All Researchers
To be entitled to access publicly accessible data, researchers must: be independent from commercial interests, disclose the funding of their research, and be able to fulfil data security and confidentiality requirements and to protect personal data.
Eligibility requirements are intentionally inclusive, covering researchers in academic and non-academic institutions (such as NGOs, or CSOs) as long as they demonstrate independence from commercial interests, disclose research funding, provide evidence of the capability to meet request-specific data security and confidentiality requirements (including appropriate technical and organizational measures).
Article 40(12) researchers need not be academics, and are defined in open-ended language as "including those affiliated to not for profit bodies, organizations and associations," with these researchers needing to meet four basic criteria.
Enhanced Requirements for Vetted Researcher Status
For researchers seeking access to non-public data through the vetted researcher pathway, the requirements are more stringent. Researchers must meet all of the following conditions: be affiliated to a research organisation as defined in the relevant EU directive; be independent from commercial interests; disclose the funding of the research; be capable of fulfilling the specific data security and confidentiality requirements corresponding to each request and protect personal data, describing in their request the appropriate technical and organisational measures that they have put in place to this end.
To be eligible, applicants must demonstrate affiliation with a recognised research organisation, independence from commercial interests, and the capacity to handle data responsibly in line with established security, confidentiality, and privacy standards.
Technical Security Requirements and Data Sharing Protocols
One of the most critical aspects of Article 40 implementation for VLOPs and VLOSEs involves establishing secure technical infrastructure for data access. The delegated act provides detailed specifications for how platforms must handle researcher data access.
Data Inventory and Accessibility Standards
According to Article 6.4 of the Delegated Act, every VLOP must establish a "data inventory," essentially a codebook that includes examples of available datasets and suggested modalities to access them. This transparency mechanism helps researchers understand what data is potentially available before submitting formal requests.
The delegated act clarifies the procedures for VLOPs and VLOSEs to share data with vetted researchers, including data formats and requirements for data documentation, and sets out which information Digital Services Coordinators, VLOPs and VLOSEs must make public to facilitate vetted researchers' applications to access relevant datasets.
Security and Processing Infrastructure
A secure processing environment is a protected technical environment where vetted researchers can analyse data under strict access controls, used to provide access to sensitive data and for logging and security measures that prevent unauthorized access. Platforms must evaluate whether researchers require access through secure processing environments or direct data exports, depending on the sensitivity of the data and the nature of the research.
Under Article 9 of the delegated act, the DSC of establishment determines the means of access, as it shall determine in the reasoned request the modalities according to which access to the data is to be granted by the data provider, with the DSC assessing the appropriateness of the data access modalities to achieve data security, data confidentiality and protect personal data while meeting the research objectives.
The Vetted Researcher Application Process
VLOPs and VLOSEs must be prepared to support the vetted researcher vetting process, which occurs at the DSC level but requires platform cooperation and responsiveness.
Application Submission and DSC Assessment
The primary responsibility of DSCs is to assess data access applications submitted by researchers and, where appropriate, to issue a formal reasoned request to the relevant data provider within 80 working days. This timeline is critical for platforms to understand when they should expect formal data access requests.
Researchers may submit their application to the Digital Services Coordinator of the Member State of the research organisation to which they are affiliated, following which the Digital Services Coordinator shall conduct an initial assessment as to whether the respective researchers meet all of the conditions, and shall subsequently send the application, together with supporting documents and the initial assessment, to the Digital Services Coordinator of establishment.
Platform Response Obligations
Within 15 days following receipt of a request, providers of very large online platforms or of very large online search engines may request the Digital Services Coordinator of establishment to amend the request, where they consider that they are unable to give access to the data requested. This provision allows platforms to raise legitimate concerns about data security, technical feasibility, or research scope before formal commitments are made.
VLOPs and VLOSEs should establish internal processes for reviewing DSC requests and determining whether proposed data access can be accommodated within their security frameworks and operational constraints.
Real-World Implementation Challenges
While the DSA Article 40 framework represents a significant advancement in researcher data access, implementation has revealed several practical challenges that platforms and regulators continue to navigate.
Compliance Gaps and Enforcement Actions
Enforcement actions have identified issues including overly restrictive interpretations of eligibility requirements for researchers, review processes that did not meet basic standards set out by Article 40.12, data access granted with overly limited quotas and duration, and prohibitions on independent researcher access including through scraping. These findings underscore the importance of platforms taking a balanced and principled approach to researcher data access.
For guidance on how enforcement authorities are interpreting Article 40 compliance, see our detailed analysis on DSA Enforcement 2026: Case Studies in Fines, Penalties, and Platform Non-Compliance.
Access Modality Negotiations
Since Article 40(12) does not specify how data should be made available to researchers, platforms provide a range of access modes: some provide researchers with API access, while others use content libraries or alternative mechanisms. The lack of prescriptive standards has led to varied approaches across platforms, though the delegated act aims to establish greater consistency.
Researchers have identified difficulties such as missing possibilities for researchers to amend access requests or engage in a mediation process as a dispute settlement mechanism. VLOPs and VLOSEs should consider establishing transparent mediation procedures to address researcher concerns when initial proposals cannot be accommodated.
Establishing Compliant Data Access Infrastructure
For VLOPs and VLOSEs seeking to establish robust, compliant researcher data access infrastructure, several foundational steps are essential.
Building Institutional Capacity
The delegated act's stated objective is to enable access "in a secure and efficient manner that is consistent across all Digital Services Coordinators, and in a way that ensures equality of treatment for researchers and data providers," with this standardized approach representing a reasonable attempt to ensure regulatory coherence across EU member states, avoiding the administrative complexity that would arise from divergent national implementations.
This objective should guide platforms' internal governance structures. Consider appointing dedicated teams to manage researcher applications, coordinate with DSCs, and oversee technical data delivery pipelines. The complexity of the DSA data access framework warrants investment in specialized expertise.
Documentation and Transparency Practices
Every VLOP must establish a data inventory that includes examples of available datasets and suggested modalities to access them, with this requirement mitigating common barriers in conducting research on the societal implications of platforms. Develop comprehensive data inventory documentation that clearly describes available datasets, access modalities, technical requirements, and potential limitations.
The Commission launched the DSA data access portal where researchers interested in accessing data under the new mechanism can find information and exchange with VLOPs, VLOSEs and DSCs on their data access applications. Ensure your platform maintains up-to-date information on this portal and responds promptly to inquiries.
Technical Infrastructure Planning
Evaluate your platform's technical architecture to determine which data access modalities best serve your security requirements and research objectives:
- API Access: Provides flexible, scalable access suitable for large-scale research projects and real-time data collection
- Secure Processing Environments: Restrict sensitive data to controlled environments where researchers work within defined security parameters
- Data Exports: Deliver curated datasets to researchers under strict usage agreements and confidentiality terms
- Hybrid Approaches: Combine multiple modalities depending on data sensitivity and research requirements
Coordination with Other Compliance Obligations
Article 40 data access requirements intersect with multiple other DSA and GDPR obligations. VLOPs and VLOSEs should integrate researcher data access into broader compliance frameworks addressing content moderation, risk mitigation, and transparency reporting.
For comprehensive guidance on integrating Article 40 obligations into your broader risk assessment and auditing practices, consult our DSA Independent Audits: A Practical Guide for VLOPs and VLOSEs in 2026, which addresses how independent auditors evaluate researcher data access compliance as part of systemic risk management audits.
Looking Forward: The Evolving DSA Article 40 Landscape
While Article 40(12) governing access to publicly available data has been in force since 2023, the Delegated Act specifying procedures for vetted researcher access to non-public data was only adopted in July 2025, with the DSA Data Access Portal becoming operational in October 2025, though implementation has been inconsistent, narrow in scope, and contested across member states.
As the Article 40 framework matures, VLOPs and VLOSEs should anticipate further refinements to technical standards, evolving interpretations of "proportionality" in data requests, and potentially enhanced expectations regarding researcher autonomy in data access negotiations. Staying informed through industry groups and regulatory updates will be essential for maintaining compliance as the framework develops.
For the latest guidance on DSA implementation challenges and regulatory developments, visit our blog for regular updates on the evolving compliance landscape.
Conclusion
Article 40 of the DSA establishes a comprehensive framework for researcher access to platform data, balancing the research community's need for evidence-based inquiry with legitimate platform concerns about security and commercial sensitivity. Successful implementation requires VLOPs and VLOSEs to invest in dedicated institutional capacity, develop transparent data governance practices, and establish robust technical infrastructure aligned with the delegated act specifications.
The framework represents a paradigm shift in platform accountability, enabling independent researchers to contribute meaningfully to understanding systemic risks in the digital ecosystem. By approaching Article 40 compliance proactively and comprehensively, platforms can transform researcher data access from a compliance obligation into an opportunity to strengthen their legitimacy and demonstrate commitment to accountability in the digital public sphere.
