Newsletter
12.06.2026
# 4
#DSA40 Data Access Newsletter
The Fine Print Is Still Being Written
Dear DSA40 Community,
welcome back to the #DSA40 Collaboratory newsletter. This is the fourth installment – and a lot has happened since our last newsletter.
In fact, starting with the next newsletter (coming at the start of next month) we’re changing our approach to keeping you informed: Instead of irregular, longer updates and analysis that tries to bridge data access and systemic risk, we aim to bring you monthly updates with more digestible amounts of information that you can dive in at will.
While this does mean that we’re dropping the “Risk in Focus” section, we won’t let go of DSA data access’ infamous purpose limitation. Instead, we will focus on news items, reports, and papers that will help you get closer to data access. We’re looking forward to sharing this growing collection with you on our website soon!
For one last time, we stick to the old format and will:
- Bring you up to speed with the latest community initiatives
- Highlight tips and resources that may be helpful for your data access request to non-public data
- Recap key developments and everything we’ve been up to since the last time we mailed you
- Share our summer reading list
After all, the fine print of the DSA’s implementation is still being written – as is this newsletter. But enough of the introductions. Let’s get started!
Community Support
- Starting with shameless self-promotion, we would like to let you know that we are finalising our tracker dataset. Don’t worry, this does not mean that we’ll stop collecting researcher experiences. However, we won’t consider any entries made after the end of the week for our upcoming publication. So, if you have made data access requests under Art. 40, please document them in the tracker until 19 June! By participating, you help us get a better idea of why applications get rejected or accepted, which helps us provide better guidance to the community. Based on the first responses, we’ve already published initial insights and our FAQ – and will continue to update both as you continue to share data with us.
- Mateus Correia de Carvalho, Catalina Goanta, and Giovanni de Gregorio are currently investigating the DSA’s implementation of the research data access obligations. Specifically, they’re trying to to understand (i) researchers’ interpretations of ‘systemic risk’; (ii) practical and structural obstacles for the preparation and processing of their applications; and (iii) their expectations towards data access for systemic risk research. Support their work by completing their survey!
- At the end of last year, the Social Data Science Alliance (SDSA) conducted a survey to map out research questions that could and should be addressed using Art. 40(4) data access. This survey is now complete: the questions have been organised into a taxonomy, which is presented in this report. Their second project will be announced shortly. Also, the SDSA is an open organisation – so, consider joining SDSA as a member!
- And while we’re talking about community, let’s not forget the DSA Data Access Task Force, hosted by the Coalition for Independent Technology Research (CITR) – a place to exchange information and jointly drive our shared work towards a connected and empowered research community. Sounds interesting? Reach out to Vineet to learn how to join!
- Also: if you speak German, we recommend this online webinar titled “Der Forschungszugang nach Digital Services Act (DSA): Chancen und Herausforderungen für die (offene) Erforschung von großen Online-Plattformen” on 30 June 13:15 to 14:45 CEST. You can register here.
- A different flavour of Community Support is brought to you by the European Commission which launched a call for proposals with the unwieldy title “DIGITAL-2026-BESTUSE-AWARENESS – Common Research Framework for Situational Awareness on Information Integrity” last month. While the call aims at “scaling, facilitating and accelerating research and analytical efforts focussing on the information environment and information integrity” more broadly, it also includes objectives that specifically link to the build out of the DSA’s data access regime. Definitely worth a look.
Tips & Resources for Data Access Applications
Background
With the Delegated Act on data access in force since October 2025, researchers can now use the DSA data access portal to apply for access to data that is not publicly accessible in the platforms’ interface. However, considering the significant documentation requirements, the relatively low amounts of experience with this new mechanism on all sides, and its political contentiousness, it will take some time for non-public data to run smoothly. Or, was we predicted in our policy paper in August 2025:
Initial vetting will likely be slow and strict, possibly resulting in few accepted applications, as DSCs set towards building a solid foundation and replicable examples with the first successful requests. It is important for both DSCs and researchers to understand this process as a collaborative exercise, not unlike an experiment in which knowledge emerges from trial and error. While such a high chance of initial failure is sure to frustrate many researchers, constructive engagement with the DSCs is a key foundational condition for both the start and the future of data access.
And in fact, none of the applications for access to non-public data in the first round was accepted. Two of the applicants have written publicly about it. AlgorithmWatch wrote about their request to Google on how AI Overviews affect website visits before the decision, and Catalina Goanta and Anda Iamnitchi reflected on their request about how TikTok’s content monetisation drove commercial and political content during the Romanian elections after they got rejected. Goanta and Iamnitchi observe that data access applications under Art. 40(4) are only the start to a complex legal procedure and require significant institutional support.
Tips & Resources to Non-Public Data
In order to help researchers navigate the difficulties related to drafting an access application, we have collected as many potentially helpful resources that we could get our hands on – and have started to combine them into one document for researchers that are considering applying for data access under Art. 40(4) DSA:
check out version 0.2 of our
This checklist guides researchers through all the different considerations required to meet all the requirements for non-public data access. We’re currently using it to draft our own applications and will continue to develop it as more information and helpful resources become available. If you have feedback or think that we missed something, please let us know!
Our checklist draws on a whole set of different resources from a variety of different stakeholders.
The main source of information is the Irish DSC, Coimisiún na Meán (CnaM), which offers a recently updated comprehensive guidance document, detailing all application criteria and what documentation can be provided to demonstrate that the applicant researchers meet them, an FAQ, and a newsletter on their webpage. We especially recommend subscribing to the “Vetted Researcher Newsletter” as it reliably includes very helpful pointers to additional resources. There, CnaM also shared a list of tips, an abbreviated version of which we are including here:
- Quality over quantity. Submit only one application to one platform at the start. This gives you the chance to iron out all gaps or omissions first and allows you to easily scale your application to other platforms once you’ve been successful. Also, CnaM has to vet every single application it receives and does so on a purely chronological basis. This means application slop may lead to further delays by binding resources that could go into outreach or the vetting of well-prepared applications.
- Start locally. Given that there may be specific requirements at the national level, make sure to seek information on data access from both the DSC in your member state and the DSC of the member state in which the platform is established. The German DSC for example will always have to contact the relevant data protection authority, while CnaM will only assess applications and supporting documents submitted in English or Irish. You can find an overview and contact information of all DSCs and links to their websites here.
- Be diligent. Make sure all information, including affiliations and the contact details of your research organisation, in your application is accurate, consistent and up to date before you submit. For example: the address of your research organisation should match its address in the funding and tenders portal. Also, double check which requirements relate to your research project and which relate to everyone that applies. Each individual researcher must demonstrate their affiliation to a research organisation and independence of commercial interests, so make sure to provide documents for all applicants, or that they are signed by everyone (where relevant).
- Evidence, evidence, evidence! Make sure to back up any statements made in relation to aspects of their application with the relevant evidence. For example, if you say that you have specific funding in place for this research, you must attach a copy of the funding supporting evidence. Similarly, if you state that your research has ethical approval in place, you also need to attach documents that prove that.
- Call for backup. You will need institutional support from your research organisation – especially the Data Protection Office, Research Offices and ICT teams – to show that your application meets the data security, data protection and confidentiality requirements. Reach out to them as early as possible and let them know what you need for your application (our checklist includes a set of documents that you can ask them about).
In a recent article for the Forum section of Political Communication the Collaboratory’s own Jakob Ohme and LK Seiling provide some additional notes to keep in mind when drafting an application, which we have adapted below:
- Refine your request. You should have a well-defined question that is unambiguously anchored in identifiable systemic risks. Starting with a clear idea should allow you to formulate a tight and well-scoped data access request. After all, to fulfill the necessity and proportionality requirements you need to be able to clearly show how the data that you have requested contributes to your investigation. At this point in time it’s probably strategically smarter to not be overly ambitious in the amount of data you request.
- Form functional teams. You may want to collaborate across institutions, or even continents. While this is theoretically possible, you should keep in mind that the required documentation will increase with the amount of researchers and organisations on the application. Think twice about who really needs to access the data to run analyses – and who may be part of the research project developing the research questions but does not necessarily need to be vetted as part of the application.
- Be realistic about timelines. When planning your research project, you need to account for ~80 working days of regulatory review, potential rejection, platform-initiated amendment or mediation procedures (max. ~75 working days), and potential delays in data provision. Also, you may be asked to provide additional information during the initial 80 working day vetting phase – so perhaps don’t submit your application right before taking your vacation. Additionally, you should be realistic about the timeframe for which you are requesting access to the data. After all, you don’t want to lose data access half-way through the review process. A generous research project timeline with estimates for data cleaning, analysis, writing, and peer review can go a long way to demonstrate that your requested access is necessary and proportionate.
- Ensure replicability. Sharing the data you get granted access to is not an option. This means that anyone planning a replication of your research will have to submit new access requests for the same data. Given these constraints, you should plan for replication from the outset and document your research project accordingly. Procedural clarity and open source code for data processing and analysis can go a long way towards replicability.
- Sharing is caring. Only reasoned requests resulting from successful applications will be made public in the data access portal, which means that by default there exists no collective means to learn from rejected applications and the reasoning provided by DSCs. Our DSA40 Data Access Tracker is supposed to close this gap by allowing you to share as much information as you want with us, so that we can feed it back into the community.
Also, on a more general note, and to not make this list look like The Ten Commandments:
- We are all pioneers. This data access framework is new to everyone – including DSCs, researchers, and platforms. So if you engage in the process at this point in time, know that there will be frustrations and confusions on all sides. But don’t let this discourage you – after all, this is what comes with charting an untrodden path. Also, try and empathise with the other people involved in this process, and maybe don’t submit your access application during the summer break.
If you want to understand what kinds of data platforms hold, you should definitely also have a look at the EDMO report on Platform Datasets, authored by the wonderful people at the Integrity Institute. To get even deeper into the weeds, we recommend Matt Motyl’s comprehensive documentation of platform APIs, different data types, and existing datasets over at show-me-the-data.com.
In case you are more interested in data protection, AWO, a law firm and strategy consultancy specializing in data protection, has got you covered: their summary paper on “Data Protection and DSA Data Access for Platform Research” is a great primer on the core concepts of EU data protection law and how they relate to the requirements for data access based on Art. 40(4) DSA. The Online Tool for Data Protection concepts by Gesellschaft für Freiheitsrechte (GFF) will help you translate the data protection theory into practice: it is custom made to support researchers with creating risk assessments and documentation of the technical and organisational measures they have in place to safeguard the accessed data.
Finally, we’d like to draw your attention to some resources on creating a data management plan – another essential document for applications to access non-public data, like the Data Management Expert Guide by the Consortium of European Social Science Data Archives (CESSDA), DMPonline, and the Research Data Management Organiser (RDMO) – which are a great starting points for any researcher independent of experience level.
What about access to public data?
With all that buzz around non-public data access, one may feel like access to publicly accessible data set out in Art. 40(12) is a thing of the past. But don’t worry – we have not forgotten about public data access! In fact, during the last months we have kept pushing to also improve the state of this access pathway (see below) and are actively working on tools to further facilitate the submission of access requests directly to the platforms. We hope to be able to tell you more soon!
A Data Access Timeline from Sept. 2025 to May 2026
We know, this newsletter is already long – but for the sake of completeness, we will now give our best to provide you with a short recap of the key developments regarding data access. We’ll limit ourselves to bullet points here, but in case you want to dive deeper – for further considerations of DSA enforcement more generally, and different risks that were at the center of discussion during the last few months – there’s also a full text version including additional information and commentary on our website.
September
Was a busy month for the Collaboratory as we
- published a policy paper on the different data access options in the DSA and related challenges that keep the DSA’s framework from reaching its potential
- helped coordinate the DSA Data Access Task Force at the 2025 CITR Summit in Berlin, and
- hosted the first DSA40 Data Access Days, welcoming ~100 attendees on two days during which we discussed public and non-public data access and started preparing applications; click the link for a summary and recordings of the expert talks
Also noteworthy:
- CnaM released the results of a researcher survey to “better understand the needs, challenges and expectations”. Out of the 116 respondents, 54% (~60) indicated that they planned to submit a data access application within the first 3 months after the delegated act came into force. Keep in mind that the data was collected before the delegated act was published, so respondents may have been a little overly optimistic.
- Meta and the Center for Open Science quietly updated the information on their Instagram Data Access Pilot, allowing selected projects to access user information to study teenage well-being.
October
- On 29 October 2025, the delegated act (DA) finally went into effect,
- allowing the submission of access applications for non-public data via the DSA data access portal, and
- mandating VLOPSEs to provide easily findable and accessible” data catalogues, describing their “data assets, their data structures and metadata”. The initial offerings did not meet these criteria, so Alexander Hohlfeld had to track them in his DSA database first, before the Commission dedicated a page to them on the data access portal in November
- Before that, the European Commission preliminarily found TikTok and Meta in breach of their transparency obligations under the DSA – including for putting in place “burdensome procedures and tools” for researcher data access (LK, the Collaboratory’s coordinator, put these findings into context for Science magazine)
But it wasn’t just the European Commission that made a splash in October:
- Mozilla published their report on Fairer Terms for Data Access under Art. 40(12) DSA, which identifies and groups problematic passages in the platforms’ terms of service alongside a model data sharing agreement
- On the 3rd birthday of the Digital Services Act, AlgorithmWatch, Mozilla, and the DSA40 Data Access Collaboratory coordinated a group of over 20 researchers and institutions to request the top 1000 most viral posts from various social media platforms. While the requests were rejected (sign this petition if you think this data should be public!), TikTok did end up adding two parameters to their API documentation that should allow researchers to filter the videos returned by the API by view and comment count.
- Columbia World Projects and the Hertie School for Digital Governance released the “Building Capacity for Data Access, Analysis + Accountability” report, which identifies current gaps in social media data access and lays out where public and private funders can meet these opportunities.
November
- The European Board for Digital Services released the first report on the most prominent and recurrent systemic risks as well as mitigation measures
- The Court of Justice of the European Union also ruled against Amazon, providing some hints to the nature of the systemic risk management obligations in the process. The details were recently analysed on the DSA Observatory’s blog.
- The European Commission published the Digital Omnibus Proposal, which suggested substantial revisions to GDPR and AI Act under the banner of “simplification,” including a concerning change raised by Natali Helber at University of Amsterdam: the proposed amendment to Article 12(5) GDPR would allow controllers to refuse or charge fees for data access requests deemed an “abuse” of data rights — directly threatening individual data access and thus research methods that rely on voluntary data donations. We responded by coordinating an open letter, signed by over 230 researchers from 25 countries and nearly 100 institutions.
- We also joined the Mozilla Festival in Barcelona to support the launch of the Better Access: Data for the Common Good report, which outlines different information environments, high-influence public platform data within those environments, and three complementary mechanisms that platforms should enable for meaningful data access.
- The release of the report was also accompanied by a series on Tech Policy Press, for which LK and Mark Scott wondered “How To Stabilize Researcher Data Access?”.
- LK also showed up in the Tech Policy Press Podcast alongside Peter Chapman and Brandi Guerkink to discuss why independent researchers need better access to platform data.
December
- The European Commission imposed a 120 million € fine on Elon Musk’s X for non-compliance with the DSA – among the reasons: X’s obstructive behaviour against researchers requesting access to data.
- On the same day, the European Commission accepted TikTok’s commitments on advertising transparency (full document), which include simplifying researcher access (reducing required fields), expanding searchable data, and reducing update delays (one day max), among others.
- the Social Media Archive at University of Michigan (SOMAR), which used to handle all data access requests to Meta, stopped handling access requests and announced that “all applications for Meta Content Library and API access are now managed via Meta’s” Research Tools Manager
January
- Whatsapp was designated as a VLOP by the European commission. This means, updates from the last 30 days in WhatsApp channels that are verified or have a minimum of 100 followers can now also be accessed through the Meta Content Library
February
February saw some new developments relating to the X fine:
- The Republican members of the House Judiciary Committee published a report framing the DSA as censorship and leaked a redacted version of the X decision, in the process. Oliver Marsh from AlgorithmWatch and our Collaboratory’s own LK Seiling summarised its relevance for data access on Tech Policy Press.
- Also, X, X.AI Holdings, and Musk personally challenged the fine in front of the EU General Court
In other news
- The Berlin Court of Appeal ruled that the CSO Democracy Reporting International (DRI) is entitled to receive publicly accessible data from X under the DSA, confirming “lack of data access as a tort,” which means that the harm researchers suffer by not being able to access data occurs in the member state and can therefore be litigated there also.
- 170 work days after the initial press release, the European Commission quietly released the decision and commitments relating to their investigation of AliExpress’ potential violations of the DSA
March
- The first negative responses to access applications under Art. 40(4) were discussed publicly
- The latest round of reports under the Code of Conduct on Disinformation was published
- After two years of unstandardised, only partially machine readable reports, March also gave us the first harmonised transparency reports
May
- The European Commission held a roundtable on data access for vetted researchers, inviting all VLOPSEs and the DSCs to discuss access to non-public data. While the specific details of the meeting were not disclosed, it signalled that Article 40(4) access is moving forward.
- CnaM published updated guidelines, clarifying the right to be heard for platforms
- On 22 May 2026, 113 days after the initial press release, the European Commission quietly uploaded their version of the fine to their supervision and enforcement overview, which included some passages that X had previously redacted.
Our Summer Reading List
The State of (DSA) Data Access
- Bekavac, L., & Mayer, S. (2026). Auditing Meta and TikTok Research API data access under Article 40(12) of the Digital Services Act [Preprint]. arXiv.
- Peters, Y., & Weller, K. (2026). Little mentioning, moderate attention, great relevance: The quality of online platform data in the Digital Services Act. Platforms & Society, 3, 1–17.
- Kazaz, J., & Klingová, K. (2025). Access to data for researchers: A state of play 2025. GLOBSEC.
- Santini, R. M., Leal, H., Salles, D., Belisário, A., Mattos, B., & Pinho, D. (2026). Data not found: Social media data transparency for information integrity. NetLab UFRJ & Minderoo Centre for Technology and Democracy.
- Pierri, F., Araujo, T., Kruikemeier, S., Lorenz-Spreen, P., Vanden Abeele, M. M. P., Vandenbosch, L., Gonçalves-Sa, J., & Grabowicz, P. A. (2025). Research opportunities and challenges of the EU’s Digital Services Act [Preprint]. arXiv.
- Tavishi, A., & Shobhit S. (2025). Platform transparency under the EU’s Digital Services Act: Opportunities and challenges for the Global South. Centre for Communication Governance, National Law University Delhi.
- Darius, P., Breuer, J., Kruschinski, S., Loecherbach, F., Riedl, J., & Stier, S. (2026). Election research in the age of regulated data access under the EU Digital Services Act. Internet Policy Review, 15(1).
Conceptualising Data Access
- Botero Arcila, B., Ramaciotti, P., & Cabale, E. (2026). Seeing in the dark: Towards a broad construction of the access to data provisions of the DSA. Internet Policy Review, 15(1).
- Stalla-Bourdillon, S., & Lieutaud, M. (2026). Data accessibility as a platform affordance: The shaping of research possibilities on online platforms with prospective legal methods. [Preprint]. SSRN.
Methodological Considerations
- Stravato Emes, C. (2026). Auditing risks of platforms in use under the DSA: A case for user-side observability. [Preprint]. SSRN.
- Chen, Y., Kmetty, Z., Iñiguez, G., & Omodei, E. (2025). The public that engages invisibly: What visible engagement fails to capture in online political communication. Communication Methods and Measures, 19(4), 294–312.
- Oswald, L., Schulz, W., Hertwig, R., Lazer, D., & Stier, S. (2025). The tip of the iceberg: How the social media production–consumption gap distorts public opinion for citizens and researchers [Preprint]. SocArXiv.
- Di Bona, G., Fraxanet, E., Komander, B., Lo Sasso, A., Morini, V., Vendeville, A., Falkenberg, M., & Galeazzi, A. (2026). Sampled social media data risk biased and inconsistent estimates of online social phenomena [Preprint]. OSF Preprints.
The Role of Social Media Research
- Scharfbillig, M., Lewandowsky, S., Altay, S., Van Alstyne, M., Kozyreva, A., Hertwig, R., Lorenz-Spreen, P., DiResta, R., Valenzuela, S., Egidy, S., Quattrociocchi, W., & Orben, A. (2026). Fractured reality: How democracy can win the global struggle over the information space (JRC144603). Publications Office of the European Union.
- Lewandowsky, S. (2026). Internet platforms must be held accountable for their actions. Science, 391(6785), eaee9835.
- Bak-Coleman, J., West, J., O’Connor, C., & Bergstrom, C. T. (2026). Industry influence in high-profile social media research [Preprint]. arXiv.
- Heiss, R., & Freiling, I. (2026). Addressing social media platforms’ influence on academic research. Humanities and Social Sciences Communications, 13, Article 192.
- Citron, D. K., & Waldman, A. E. (2025). The evolution of trust and safety. [Preprint]. SSRN.
- Moran, R. E., Schafer, J., Bayar, M., & Starbird, K. (2025). The end of trust and safety?: Examining the future of content moderation and upheavals in professional online safety efforts. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems (pp. 1–14). ACM.
On Various Risks and Risk Factors
- Goldin, I., & Vogel, T. (2010). Global governance and systemic risk in the 21st century: Lessons from the financial crisis. Global Policy, 1(1), 4–15.
- Forum on Information and Democracy. (2026). Strengthening information integrity on climate change and the environment.
- Correia de Carvalho, M., & Griffin, R. (2026). Who speaks and who is heard? Civil society participation and participatory justice in DSA systemic risk management. DSA Observatory.
- Packin, N. G., & Rabinovitz, S. (2026). Prediction markets as a public health threat. Science, 392(6795), 257–260.
- Entrena-Serrano, C. (2025). Watch, scroll, repeat: How interface design shapes consumptive curation affordances on TikTok. Social Media + Society, 11(3).
- Eyal, N. (2014). Hooked: How to build habit-forming products. Portfolio/Penguin.
- boyd, d. (2015). Blame society, not the screen time. The New York Times.
