Commission Delegated Regulation (EU) 2025/2050 of 1 July 2025 supplementing Regulation (EU) 2022/2065
as it stood on 2026-08-07, permalink: /eu-eurlex/32025r2050/2026-08-07
Outline, 16 provisions
art_1 art_2 art_3 art_4 art_5 art_6 art_7 art_8 art_9 art_10 art_11 art_12 art_13 art_14 art_15 art_16
Article 1
This Regulation lays down procedures and technical conditions for providing vetted researchers with access to data held by providers of very large online platforms and of very large online search engines, pursuant to Article 40(4) of Regulation (EU) 2022/2065, in particular:
| (a) | the technical conditions for the development and functioning of a data access portal; |
|---|
| (b) | the procedures and technical conditions for the management of the data access process by Digital Services Coordinators and data providers; |
|---|
| (c) | the requirements for the formulation of reasoned requests and the assessment of amendment requests; |
|---|
| (d) | the technical conditions for the provision of access to data by the data providers. |
|---|
Article 2
For the purposes of this Regulation, the definitions in Article 4 of Regulation (EU) 2016/679 and Article 3 of Regulation (EU) 2018/1725 shall apply. The following definitions shall also apply:
| (1) | ‘data access application’ means the information and relevant documentation submitted by applicant researchers to the Digital Services Coordinator of establishment or the Digital Services Coordinator of the Member State of the research organisation, to which the principal researcher is affiliated, to obtain the status of ‘vetted researcher’ as referred to in Article 40(8), first subparagraph, of Regulation (EU) 2022/2065, for a specific research project involving access to data from a data provider; |
|---|
| (2) | ‘data access process’ means the steps and procedures that may lead to the provision of access to the data as referred to in Article 40(4) of Regulation (EU) 2022/2065; |
|---|
| (3) | ‘applicant researcher’ means any natural person applying for access to data as referred to in Article 40(4) of Regulation (EU) 2022/2065, either individually, in a group or as part of an entity; |
|---|
| (4) | ‘principal researcher’ means the applicant researcher who submits the data access application in their individual capacity or on behalf of an entity or a group of applicant researchers; |
|---|
| (5) | ‘data provider’ means a provider of a very large online platform or of a very large online search engine designated as such in accordance with Article 33(4) of Regulation (EU) 2022/2065, to which a reasoned request might be addressed; |
|---|
| (6) | ‘reasoned request’ means a reasoned request for data access pursuant to Article 40(4) of Regulation (EU) 2022/2065; |
|---|
| (7) | ‘amendment request’ means a request for amendment pursuant to Article 40(5) of Regulation (EU) 2022/2065 submitted by the data provider to the Digital Services Coordinator of establishment following the receipt of a reasoned request; |
|---|
| (8) | ‘secure processing environment’ means secure processing environment as defined in Article 2, point (20), of Regulation (EU) 2022/868 of the European Parliament and of the Council (5). |
|---|
Article 3
The Commission shall establish and host a DSA data access portal.
The DSA data access portal shall have the following functions:
| (a) | support and streamline the management of the data access process for researchers, data providers and Digital Services Coordinators; |
|---|
| (b) | serve as the central digital point for information on the data access process and facilitate the information exchanges pursuant to this Regulation among applicant researchers, vetted researchers, data providers and Digital Services Coordinators. |
|---|
The DSA data access portal shall be interoperable with the information sharing system AGORA established by Implementing Regulation (EU) 2024/607. The Digital Services Coordinators shall have access in AGORA to the information submitted through the DSA data access portal.
Data providers shall have an account on the DSA data access portal.
To participate in the data access process, applicant researchers shall have an account on the DSA data access portal.
Article 4
Digital Services Coordinators shall be separate controllers with respect to the processing of personal data they carry out to manage the data access process and for publication of relevant information.
The Commission shall be a processor of personal data processed within the DSA data access portal.
The responsibilities of the Commission as processor for data processing activities conducted in the DSA data access portal shall be as set out in the Annex.
Article 5
Where personal data are registered in and exchanged via the DSA data access portal, the processing shall take place only in so far as it is proportionate and necessary for the purpose of the data access process and publication of relevant information.
The processing of personal data shall take place in the DSA data access portal only in respect of the following categories of data subjects:
| (a) | natural persons having an account on the DSA data access portal; |
|---|
| (b) | natural persons whose personal data is contained in the DSA data access portal or in any other exchange pursuant to this Regulation concerning the data access process. |
|---|
- The processing of personal data shall take place in the DSA data access portal only in respect of the following categories of personal data:
| (a) | identity data, such as name, user ID; |
|---|
| (b) | contact information such as address, email address, contact details; |
|---|
| (c) | personal data contained in the documentation demonstrating the affiliation to a research organisation, and any other personal information deemed necessary for the purpose of participating in the data access process. |
|---|
- The processing of personal data referred to in paragraph 1 shall be performed using information technology infrastructure located in the European Economic Area.
Article 6
Each Digital Services Coordinator and each data provider shall establish a dedicated point of contact, whose task shall be to provide information and support on the data access process.
The Digital Services Coordinators and data providers shall communicate their points of contact to the Commission, as soon as possible. The Commission shall publish the details of the points of contact referred to in paragraph 1 in the public interface of the DSA data access portal.
Each Digital Services Coordinator shall make available and easily findable on its online interface, the details of the point of contact established pursuant to paragraph 1 together with a link to the DSA data access portal.
Data providers shall make the following information available and easily findable on their online interfaces:
| (a) | the details of the point of contact established by them pursuant to paragraph 1; |
|---|
| (b) | a link to the DSA data access portal; |
|---|
| (c) | a DSA data catalogue, which describes the data assets, that may be accessed for the purposes set out in Article 40(4) of Regulation EU 2022/2065, as well as their data structure and metadata; |
|---|
| (d) | suggested access modalities for the data in the catalogue pursuant to point (c), adequate to the level of sensitivity of the different data assets. |
|---|
- The information referred to in paragraph 4, points (c) and (d), shall be regularly updated, in particular to reflect data related to the risk assessments carried out pursuant to Article 34 of Regulation (EU) 2022/2065 and the audits carried out pursuant to Article 37 of that Regulation.
Article 7
- Within 80 working days from the submission of a data access application, the Digital Services Coordinator of establishment, taking due account of the prerequisites set out in Article 8 and, where applicable, any other assessment relevant for these purposes, shall decide whether a reasoned request can be formulated and shall undertake one of the following actions:
| (a) | formulate a reasoned request, submit it to the data provider and notify the principal researcher of the submission of the reasoned request; |
|---|
| (b) | inform the principal researcher of the reasons why the reasoned request could not be formulated. |
|---|
- Where, in duly justified cases, the Digital Services Coordinator of establishment needs additional time to formulate a reasoned request, it shall notify the principal researcher as soon as possible and shall indicate the reasons for the delay as well as a new date for undertaking the actions referred to in paragraph 1.
Article 8
The Digital Services Coordinator of establishment shall decide whether a reasoned request can be formulated taking into account the following elements:
| (a) | for each applicant researcher:(i)a confirmation of affiliation to a research organisation as defined in Article 2, point (1), of Directive (EU) 2019/790 of the European Parliament and of the Council (6);(ii)a declaration of independence from commercial interests relevant to the specific project for which the data are requested;(iii)a commitment to making their research results publicly available free of charge; |
|---|---|
| (i) | a confirmation of affiliation to a research organisation as defined in Article 2, point (1), of Directive (EU) 2019/790 of the European Parliament and of the Council (6); |
| (ii) | a declaration of independence from commercial interests relevant to the specific project for which the data are requested; |
| (iii) | a commitment to making their research results publicly available free of charge; |
| (b) | information about funding supporting the research project for which the data are requested; |
|---|
| (c) | a description of the data requested, including format, scope and, where possible, the specific attributes, relevant metadata and data documentation, also considering the information made available pursuant to Article 6(4) of this Regulation; |
|---|
| (d) | information on the necessity and proportionality of the access to the data and the information on the time frames of the research for which the data are requested; |
|---|
| (e) | information on the identified risks in terms of confidentiality, data security and personal data protection related to the data that would be accessed, a description of the technical, legal and organisational measures that will be put in place, including, where possible, suggested access modalities, to mitigate such risks when processing the requested data; |
|---|
| (f) | a description of the research activities to be conducted with the requested data; |
|---|
| (g) | a summary of the data access application containing the following elements:(i)the research topic;(ii)the data provider from which data are requested;(iii)a description of the data requested, as referred to in point (c). |
|---|---|
| (i) | the research topic; |
| (ii) | the data provider from which data are requested; |
| (iii) | a description of the data requested, as referred to in point (c). |
Article 9
The Digital Services Coordinator of establishment shall determine the modalities, including the technical, legal and organisational measures, that the data provider is to use for providing access to the data to the vetted researchers.
The Digital Services Coordinators shall be allowed to consult the relevant supervisory authorities established pursuant to Article 51 of Regulation (EU) 2016/679.
When determining the access modalities, the Digital Services Coordinator of establishment shall take into account the information provided in the data access application, in particular the information referred to in Article 8, point (e), considering also the rights and interests of the data providers and the recipients of the service concerned, including the protection of confidential information, trade secrets, and maintaining the security of their service and the information made available by the data providers pursuant to Article 6(4), point (d).
In addition to the elements referred to in paragraph 3, the Digital Services Coordinator of establishment shall, when determining access modalities, take into account the following elements:
| (a) | where the access involves the processing of personal data:(i)the assessment of the risks concerning processing of personal data as described in Article 8(e), including, where applicable, data protection impact assessments within the meaning of Article 35 of Regulation (EU) 2016/679;(ii)envisaged technical and organisational measures as submitted pursuant to Article 8(e); |
|---|---|
| (i) | the assessment of the risks concerning processing of personal data as described in Article 8(e), including, where applicable, data protection impact assessments within the meaning of Article 35 of Regulation (EU) 2016/679; |
| (ii) | envisaged technical and organisational measures as submitted pursuant to Article 8(e); |
| (b) | relevant network security measures, encryption, access control mechanisms, backup policies, data integrity mechanisms, incident response plans; |
|---|
| (c) | where applicable, information on the intended storage period and the relevant data destruction plans; |
|---|
| (d) | any organisational measures such as internal review processes, restrictions of access rights and information sharing; |
|---|
| (e) | any proposed contractual clauses, such as non-disclosure agreements, data agreements and any other type of written statements, laying down possible conditions of access and processing between the principal researcher and the data provider; |
|---|
| (f) | existence of training on data security and protection of personal data received by the applicant researchers; |
|---|
| (g) | whether secure processing environments is necessary to process the data. |
|---|
- Where the Digital Services Coordinator of establishment considers that a secure processing environment is to be used to provide access to the data requested, the Digital Services Coordinator of establishment shall require documentation attesting that the operator of that environment:
| (a) | specifies access conditions to the secure processing environment in order to minimise the risk of the unauthorised reading, copying, modification or removal of the data hosted in the secure processing environment; |
|---|
| (b) | ensures that vetted researchers have access only to data covered by the reasoned request, by means of individual and unique user identities and confidential access modes; |
|---|
| (c) | keeps identifiable logs of access to the secure processing environment for the period necessary to verify and audit all processing operations in that environment; |
|---|
| (d) | ensures that the computing power at the disposal of the vetted researchers is appropriate and sufficient for the purposes of the research project; |
|---|
| (e) | monitors the effectiveness of the measures listed in points (a) to (d). |
|---|
Article 10
- A reasoned request shall contain at least the following elements:
| (a) | the date by which the data provider shall give access to the data requested and the date on which such access shall be terminated; |
|---|
| (b) | the access modalities determined pursuant to Article 9; |
|---|
| (c) | the summary of the data access application referred to in Article 8 point (g). |
|---|
The Digital Services Coordinator of establishment may include in the reasoned request the names and contact details of all vetted researchers mentioned in the data access application where this is necessary to enable access to the requested data, in accordance with the access modalities specified in the reasoned request.
If providing access involves a transfer of personal data to a third country or international organisation within the meaning of Chapter V of Regulation (EU) 2016/679, the reasoned request shall include information on the need to put in place or refer to an appropriate transfer mechanism to ensure compliance with Regulation (EU) 2016/679.
Article 11
- Upon formulation of a reasoned request, the Digital Services Coordinator of establishment shall publish an overview of the reasoned request in the public interface of the DSA data access portal. The overview shall contain all the following:
| (a) | the summary of the data access application referred to in Article 8 point (g); |
|---|
| (b) | the access modalities determined pursuant to Article 9. |
|---|
- The overview referred to in paragraph 1 shall be updated to reflect any changes resulting from a modification of one or more elements following the examination of an amendment request or the outcome of a mediation in accordance with Article 13.
Article 12
Upon the receipt of an amendment request pursuant to Article 40(5) of Regulation (EU) 2022/2065, the Digital Services Coordinator of establishment shall inform the principal researcher concerned.
When deciding on an amendment request made pursuant to Article 40(5), point (a), of Regulation (EU) 2022/2065, the Digital Services Coordinator of establishment shall take into account the following:
| (a) | whether the reasons for the alleged lack of access to data are duly substantiated; |
|---|
| (b) | whether that lack of access to data is permanent or temporary. |
|---|
- When deciding on an amendment request made pursuant to Article 40(5), point (b), of Regulation (EU) 2022/2065, the Digital Services Coordinator of establishment shall take into account all the following:
| (a) | whether the alleged vulnerabilities and their significance are duly substantiated; |
|---|
| (b) | the likelihood and severity of harm resulting from these alleged significant vulnerabilities; |
|---|
| (c) | the extent to which the access modalities set out in the reasoned request effectively mitigate the risk of such harm occurring. |
|---|
At any time during the assessment of an amendment request, the Digital Services Coordinator of establishment may ask the data provider or the principal researcher for any additional information that it considers necessary to complete its assessment.
Such request for additional information shall be made as soon as possible to allow the data provider or the principal researcher sufficient time to respond and, in any event, shall not affect the deadline set in Article 40(6), second subparagraph of Regulation (EU) 2022/2065. Where the data provider or the principal researcher fails to provide the requested information at all or within a period specified by the Digital Services Coordinator of establishment or provides partial information, the Digital Services Coordinator of establishment shall make its decision within the timeframe laid down in Article 40(6) of Regulation (EU) 2022/2065, based on the information that was made available to it within a reasonable delay.
Article 13
If the data provider disagrees with the decision of the Digital Services Coordinator of establishment on the amendment request, the data provider may, within a period of five working days from the communication by the Digital Services Coordinator of establishment pursuant to Article 40(6), second subparagraph of Regulation (EU) 2022/2065, request in writing the Digital Services Coordinator of establishment to participate in mediation.
The Digital Services Coordinator of establishment shall not be obliged to participate in the mediation process.
The written request referred to in paragraph 1, shall include a concise description of the specific elements of the decision, as communicated by the Digital Services Coordinator of establishment pursuant to Article 40(6), second subparagraph of Regulation (EU) 2022/2065, to which the data provider objects.
The Digital Services Coordinator of establishment and the data provider shall agree on the appointment of a mediator and initiate the mediation within 20 working days from the submission of the mediation request pursuant to paragraph 3.
Before agreeing to the appointment of a mediator, the Digital Services Coordinator of establishment shall verify that the mediator is impartial and independent and possesses the relevant expertise related to the subject matter as described in the written request referred to in paragraph 1.
The data provider shall bear all costs of the mediation.
The Digital Services Coordinator of establishment shall inform the principal researcher of the mediation request referred to in paragraph 1 without undue delay and may decide to invite the principal researcher to join the mediation as a party. Where the data access application has been submitted to the Digital Services Coordinator of the research organisation, the Digital Services Coordinator of establishment may invite the Digital Services Coordinator of the research organisation to participate in the mediation process. Any party invited to join the mediation by the Digital Services Coordinator of establishment shall not be obliged to participate in the mediation process.
Participation in mediation shall not affect the right of the parties to initiate judicial proceedings at any time before, during or after the mediation.
The Digital Services Coordinator of establishment shall set a time limit for the mediation, which shall not exceed 40 working days starting on the day of the initiation of the mediation pursuant to paragraph 4.
The mediator may terminate the mediation earlier in one of the following cases:
| (a) | one of the parties requests explicitly to terminate the mediation; |
|---|
| (b) | it becomes clear that the conduct of the parties during the mediation, including a failure to engage in good faith, makes it unlikely that an agreement will be reached. |
|---|
Where the mediation results in an agreement between the parties, the Digital Services Coordinator of establishment shall take such agreement into account and, where appropriate, modify the reasoned request and inform the principal researcher of the modification.
Where the parties fail to reach an agreement, the Digital Services Coordinator of establishment shall notify the data provider that the decision of the Digital Services Coordinator of establishment on the amendment request, as last communicated pursuant to Article 40(6), second subparagraph of Regulation (EU) 2022/2065, shall be considered valid and shall serve as the relevant basis for further steps in the process and inform the principal researcher.
The Digital Services Coordinator of establishment shall register in AGORA a summary record of the mediation, prepared by the mediator and signed by all parties. The record shall include the following information:
| (a) | the date of the written request for mediation by the data provider; |
|---|
| (b) | the identities and contact details of the parties; |
|---|
| (c) | the start and end dates of the mediation; |
|---|
| (d) | the outcome of the mediation, including any agreement reached or the reason for termination of the mediation. |
|---|
Article 14
Before formulating a reasoned request, or taking a decision on an amendment request, the Digital Services Coordinator may decide to consult experts.
The experts shall be independent and impartial and possess relevant expertise and proven skills and have the capacity and resources to perform the identified task, without incurring undue delay.
To attest impartiality, the experts shall sign a declaration confirming that they:
| (a) | have no financial or personal ties to the data provider or the applicant researchers; |
|---|
| (b) | have no interest in the outcome of the data access process; |
|---|
| (c) | are free from any conflicts of interest. |
|---|
- The Digital Services Coordinator shall encode any consultation carried out pursuant to paragraph 1, along with the expert opinion received in response to the consultation, without undue delay in AGORA.
Article 15
- Data providers shall notify the Digital Services Coordinator of establishment within three working days of the fact:
| (a) | that access to the requested data has been provided to vetted researchers, in accordance with the reasoned request; |
|---|
| (b) | that the access for the vetted researchers has been terminated. |
|---|
Data providers shall provide vetted researchers with any additional information needed to access and understand the requested data, such as codebooks, changelogs and architectural documentation. In cases where the provision of such information may result in a significant vulnerability of the data provider’s services, the data provider shall notify the Digital Services Coordinator of establishment of that risk and, where possible, propose alternative information.
When providing access to data, data providers shall not impose on vetted researchers data management requirements such as archiving, storage, refresh and deletion requirements, or limitations to the use of standard analytical tools, that may hinder the performance of the relevant research, unless such requirements or limitations are explicitly mentioned in the reasoned request.
Where personal data are processed, data providers shall not impose on vetted researchers any conditions in relation to the processing of the shared personal data other than those specified in the reasoned request.
Article 16
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2026-08-07 → this version applied |
| valid | 2025-07-01 → open publisher-asserted |
| type | REG_DEL Commission Delegated Regulation (EU) 2025/2050 of 1 July 2025 supplementing Regulation (EU) 2022/2065 of the European Parliament and of the Council by laying down the technical conditions and procedures under which providers of very large online platforms and of very large online search engines are to share data with vetted researchers |
| language | en |
| published | 2025-07-01 |
| lex_id | eu-eurlex:32025r2050:2025-07-01 |
| record sha256 | eddfa6ab956932b36ccabef14949ff960b8aa030156e9c7fac2703476803dde4 |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2025-07-01) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |