Newsletter
12.06.2026
# 4
#DSA40 Data Access Newsletter
The Fine Print Is Still Being Written
Dear DSA40 Community,
welcome back to the #DSA40 Collaboratory newsletter. This is the fourth installment – and a lot has happened since our last newsletter.
In fact, starting with the next newsletter (coming at the start of next month) we’re changing our approach to keeping you informed: Instead of irregular, longer updates and analysis that tries to bridge data access and systemic risk, we aim to bring you monthly updates with more digestible amounts of information that you can dive in at will.
While this does mean that we’re dropping the “Risk in Focus” section, we won’t let go of DSA data access’ infamous purpose limitation. Instead, we will focus on news items, reports, and papers that will help you get closer to data access. We’re looking forward to sharing this growing collection with you on our website soon!
For one last time, we stick to the old format and will:
- Bring you up to speed with the latest community initiatives
- Highlight tips and resources that may be helpful for your data access request to non-public data
- Recap key developments and everything we’ve been up to since the last time we mailed you
- Share our summer reading list
After all, the fine print of the DSA’s implementation is still being written – as is this newsletter. But enough of the introductions. Let’s get started!
Community Support
- Starting with shameless self-promotion, we would like to let you know that we are finalising our tracker dataset. Don’t worry, this does not mean that we’ll stop collecting researcher experiences. However, we won’t consider any entries made after the end of the week for our upcoming publication. So, if you have made data access requests under Art. 40, please document them in the tracker until 19 June! By participating, you help us get a better idea of why applications get rejected or accepted, which helps us provide better guidance to the community. Based on the first responses, we’ve already published initial insights and our FAQ – and will continue to update both as you continue to share data with us.
- Mateus Correia de Carvalho, Catalina Goanta, and Giovanni de Gregorio are currently investigating the DSA’s implementation of the research data access obligations. Specifically, they’re trying to to understand (i) researchers’ interpretations of ‘systemic risk’; (ii) practical and structural obstacles for the preparation and processing of their applications; and (iii) their expectations towards data access for systemic risk research. Support their work by completing their survey!
- At the end of last year, the Social Data Science Alliance (SDSA) conducted a survey to map out research questions that could and should be addressed using Art. 40(4) data access. This survey is now complete: the questions have been organised into a taxonomy, which is presented in this report. Their second project will be announced shortly. Also, the SDSA is an open organisation – so, consider joining SDSA as a member!
- And while we’re talking about community, let’s not forget the DSA Data Access Task Force, hosted by the Coalition for Independent Technology Research (CITR) – a place to exchange information and jointly drive our shared work towards a connected and empowered research community. Sounds interesting? Reach out to Vineet to learn how to join!
- Also: if you speak German, we recommend this online webinar titled “Der Forschungszugang nach Digital Services Act (DSA): Chancen und Herausforderungen für die (offene) Erforschung von großen Online-Plattformen” on 30 June 13:15 to 14:45 CEST. You can register here.
- A different flavour of Community Support is brought to you by the European Commission which launched a call for proposals with the unwieldy title “DIGITAL-2026-BESTUSE-AWARENESS – Common Research Framework for Situational Awareness on Information Integrity” last month. While the call aims at “scaling, facilitating and accelerating research and analytical efforts focussing on the information environment and information integrity” more broadly, it also includes objectives that specifically link to the build out of the DSA’s data access regime. Definitely worth a look.
Tips & Resources for Data Access Applications
Background
With the Delegated Act on data access in force since October 2025, researchers can now use the DSA data access portal to apply for access to data that is not publicly accessible in the platforms’ interface. However, considering the significant documentation requirements, the relatively low amounts of experience with this new mechanism on all sides, and its political contentiousness, it will take some time for non-public data to run smoothly. Or, was we predicted in our policy paper in August 2025:
Initial vetting will likely be slow and strict, possibly resulting in few accepted applications, as DSCs set towards building a solid foundation and replicable examples with the first successful requests. It is important for both DSCs and researchers to understand this process as a collaborative exercise, not unlike an experiment in which knowledge emerges from trial and error. While such a high chance of initial failure is sure to frustrate many researchers, constructive engagement with the DSCs is a key foundational condition for both the start and the future of data access.
And in fact, none of the applications for access to non-public data in the first round was accepted. Two of the applicants have written publicly about it. AlgorithmWatch wrote about their request to Google on how AI Overviews affect website visits before the decision, and Catalina Goanta and Anda Iamnitchi reflected on their request about how TikTok’s content monetisation drove commercial and political content during the Romanian elections after they got rejected. Goanta and Iamnitchi observe that data access applications under Art. 40(4) are only the start to a complex legal procedure and require significant institutional support.
Tips & Resources to Non-Public Data
In order to help researchers navigate the difficulties related to drafting an access application, we have collected as many potentially helpful resources that we could get our hands on – and have started to combine them into one document for researchers that are considering applying for data access under Art. 40(4) DSA:
check out version 0.2 of our
This checklist guides researchers through all the different considerations required to meet all the requirements for non-public data access. We’re currently using it to draft our own applications and will continue to develop it as more information and helpful resources become available. If you have feedback or think that we missed something, please let us know!
Our checklist draws on a whole set of different resources from a variety of different stakeholders.
The main source of information is the Irish DSC, Coimisiún na Meán (CnaM), which offers a recently updated comprehensive guidance document, detailing all application criteria and what documentation can be provided to demonstrate that the applicant researchers meet them, an FAQ, and a newsletter on their webpage. We especially recommend subscribing to the “Vetted Researcher Newsletter” as it reliably includes very helpful pointers to additional resources. There, CnaM also shared a list of tips, an abbreviated version of which we are including here:
- Quality over quantity. Submit only one application to one platform at the start. This gives you the chance to iron out all gaps or omissions first and allows you to easily scale your application to other platforms once you’ve been successful. Also, CnaM has to vet every single application it receives and does so on a purely chronological basis. This means application slop may lead to further delays by binding resources that could go into outreach or the vetting of well-prepared applications.
- Start locally. Given that there may be specific requirements at the national level, make sure to seek information on data access from both the DSC in your member state and the DSC of the member state in which the platform is established. The German DSC for example will always have to contact the relevant data protection authority, while CnaM will only assess applications and supporting documents submitted in English or Irish. You can find an overview and contact information of all DSCs and links to their websites here.
- Be diligent. Make sure all information, including affiliations and the contact details of your research organisation, in your application is accurate, consistent and up to date before you submit. For example: the address of your research organisation should match its address in the funding and tenders portal. Also, double check which requirements relate to your research project and which relate to everyone that applies. Each individual researcher must demonstrate their affiliation to a research organisation and independence of commercial interests, so make sure to provide documents for all applicants, or that they are signed by everyone (where relevant).
- Evidence, evidence, evidence! Make sure to back up any statements made in relation to aspects of their application with the relevant evidence. For example, if you say that you have specific funding in place for this research, you must attach a copy of the funding supporting evidence. Similarly, if you state that your research has ethical approval in place, you also need to attach documents that prove that.
- Call for backup. You will need institutional support from your research organisation – especially the Data Protection Office, Research Offices and ICT teams – to show that your application meets the data security, data protection and confidentiality requirements. Reach out to them as early as possible and let them know what you need for your application (our checklist includes a set of documents that you can ask them about).
In a recent article for the Forum section of Political Communication the Collaboratory’s own Jakob Ohme and LK Seiling provide some additional notes to keep in mind when drafting an application, which we have adapted below:
- Refine your request. You should have a well-defined question that is unambiguously anchored in identifiable systemic risks. Starting with a clear idea should allow you to formulate a tight and well-scoped data access request. After all, to fulfill the necessity and proportionality requirements you need to be able to clearly show how the data that you have requested contributes to your investigation. At this point in time it’s probably strategically smarter to not be overly ambitious in the amount of data you request.
- Form functional teams. You may want to collaborate across institutions, or even continents. While this is theoretically possible, you should keep in mind that the required documentation will increase with the amount of researchers and organisations on the application. Think twice about who really needs to access the data to run analyses – and who may be part of the research project developing the research questions but does not necessarily need to be vetted as part of the application.
- Be realistic about timelines. When planning your research project, you need to account for ~80 working days of regulatory review, potential rejection, platform-initiated amendment or mediation procedures (max. ~75 working days), and potential delays in data provision. Also, you may be asked to provide additional information during the initial 80 working day vetting phase – so perhaps don’t submit your application right before taking your vacation. Additionally, you should be realistic about the timeframe for which you are requesting access to the data. After all, you don’t want to lose data access half-way through the review process. A generous research project timeline with estimates for data cleaning, analysis, writing, and peer review can go a long way to demonstrate that your requested access is necessary and proportionate.
- Ensure replicability. Sharing the data you get granted access to is not an option. This means that anyone planning a replication of your research will have to submit new access requests for the same data. Given these constraints, you should plan for replication from the outset and document your research project accordingly. Procedural clarity and open source code for data processing and analysis can go a long way towards replicability.
- Sharing is caring. Only reasoned requests resulting from successful applications will be made public in the data access portal, which means that by default there exists no collective means to learn from rejected applications and the reasoning provided by DSCs. Our DSA40 Data Access Tracker is supposed to close this gap by allowing you to share as much information as you want with us, so that we can feed it back into the community.
Also, on a more general note, and to not make this list look like The Ten Commandments:
- We are all pioneers. This data access framework is new to everyone – including DSCs, researchers, and platforms. So if you engage in the process at this point in time, know that there will be frustrations and confusions on all sides. But don’t let this discourage you – after all, this is what comes with charting an untrodden path. Also, try and empathise with the other people involved in this process, and maybe don’t submit your access application during the summer break.
If you want to understand what kinds of data platforms hold, you should definitely also have a look at the EDMO report on Platform Datasets, authored by the wonderful people at the Integrity Institute. To get even deeper into the weeds, we recommend Matt Motyl’s comprehensive documentation of platform APIs, different data types, and existing datasets over at show-me-the-data.com.
In case you are more interested in data protection, AWO, a law firm and strategy consultancy specializing in data protection, has got you covered: their summary paper on “Data Protection and DSA Data Access for Platform Research” is a great primer on the core concepts of EU data protection law and how they relate to the requirements for data access based on Art. 40(4) DSA. The Online Tool for Data Protection concepts by Gesellschaft für Freiheitsrechte (GFF) will help you translate the data protection theory into practice: it is custom made to support researchers with creating risk assessments and documentation of the technical and organisational measures they have in place to safeguard the accessed data.
Finally, we’d like to draw your attention to some resources on creating a data management plan – another essential document for applications to access non-public data, like the Data Management Expert Guide by the Consortium of European Social Science Data Archives (CESSDA), DMPonline, and the Research Data Management Organiser (RDMO) – which are a great starting points for any researcher independent of experience level.
What about access to public data?
With all that buzz around non-public data access, one may feel like access to publicly accessible data set out in Art. 40(12) is a thing of the past. But don’t worry – we have not forgotten about public data access! In fact, during the last months we have kept pushing to also improve the state of this access pathway (see below) and are actively working on tools to further facilitate the submission of access requests directly to the platforms. We hope to be able to tell you more soon!
A Data Access Timeline from Sept. 2025 to May 2026
We know, this newsletter is already long – but for the sake of completeness, we will now give our best to provide you with a short recap of everything we’ve been up to, key developments regarding data access, DSA enforcement more generally, and different risks that were at the center of discussion during the last few months.
September
Everything Data Access
In September, only a month before the delegated act (DA) went into effect, we published a policy paper: In “Data Access for Researchers under the Digital Services Act: From Policy to Practice”, LK Seiling, Clara Iglesias Keller, Jakob Ohme, Ulrike Klinger, and Claes de Vresse outline the different data access options available to researchers and the challenges that keep the DSA’s framework from reaching its potential.
We also were represented at the 2025 CITR Summit in Berlin, where we coordinated with other researchers to bring about the DSA Data Access Task Force (already mentioned above). Shortly afterwards, we hosted the first DSA40 Data Access Days, welcoming around 100 researchers, regulators, and platform representatives. On the first day, we looked back on the experiences with access to public data – and forward to what the access to publicly available data may bring. Day two was reserved for researchers to start preparing data access applications for non-public data with the help of data protection & data engineering experts. If you want to know more, you can find a summary, including recordings of the expert talks on day one, on our website.
Meanwhile, Meta and the Center for Open Science had quietly updated the information on their Instagram Data Access Pilot for Well-being research, announcing which research projects had passed stage 2 of the registration process. Conditioned on the users’ consent, the selected projects will get access to information about user accounts (like join date and follower counts), content production (like timestamps and content types), consumption behaviour (like session start and end times or content views), content interactions, and the use of safety and control features. Find out more on the project page.
DSA Addendum
September was also the month in which Google, in an act of malicious semi-compliance, erased 7 years of political advertising and messaging on YouTube, Google Search and for display ads in EU member states. The move followed Google’s decision to exit the EU political advertising market entirely ahead of the Transparency and Targeting of Political Advertising (TTPA) regulation. Still, this does not absolve platforms of their DSA obligations, including the duty to mitigate systemic risks to civic discourse. We’ve asked for transparency. We got: nothing.
In other news, the Seventh Chamber of the General Court ruled against Zalando, which had argued that its designation as a VLOP was incorrect and drew into question the European Commission’s methodology for determining recipients of the service. For more legal details and other cases, see the latest issue of Martin’s DSA Newsletter.
Key Harms and Risks
In September the European Commission issued an information request on financial scams to Apple, Booking.com, Google and Microsoft. Little did they know that only two months later, Jeff Horwitz at Reuters would write about internal documents at Meta, which showed that the platform projected that 10% of its 2024 revenue would come from ads for scams and banned goods. While complaints ensued in both the US and the EU, the Commission is yet to initiate proceedings.
October
Everything Data Access
On 29 October 2025, the delegated act (DA) finally went into effect, allowing researchers to submit access applications for non-public data via the DSA data access portal. The expectations were high, considering that CnaM had released the results of a researcher survey to “better understand the needs, challenges and expectations” a month prior. Out of the 116 respondents, 54% (~60) indicated that they planned to submit a data access application within the first 3 months after the delegated act came into force. Such a volume promised that the regulators’ capacities would be fully utilised, if not exceeded. But the flood of applications never materialised. After all, the data was collected before the DA was published or the Data Access Portal was live, which meant that back then researchers had no clear idea of the level of preparation or input required for an application.
The DA also included another obligation for VLOPSEs to provide easily findable and accessible” data catalogues, describing their “data assets, their data structures and metadata” (Rec. 7 DA). Unfortunately, the initial offerings do not seem to meet these criteria. In fact, it was Alexander Hohlfeld who first tracked down all the catalogues, adding them to his DSA database (also a great resource for risk assessment and audit reports!), before the Commission dedicated a page to them on the data access portal in November. Stay tuned for more news on a more structured analysis coming soon!
But October was not only dedicated to non-public data access. In fact, at the end of the month, the European Commission announced that it had preliminarily found TikTok and Meta in breach of their transparency obligations under the DSA. Among the violations identified by the Commission were “burdensome procedures and tools”, which aligned well with researcher experiences, who had long complained about overly complex forms and limited access available through the platforms’ offerings (esp. regarding TikTok’s Virtual Computation Environment and Meta’s Content Library). LK, the Collaboratory’s coordinator, elaborated on these frustrations in this article for the Science magazine.
Fittingly, Mozilla also published their report on Fairer Terms for Data Access under Art. 40(12) DSA. If you could never be bothered to actually read the platform’s terms, this report is for you. Written by AWO, it goes through all the platforms’ terms, identifies and groups problematic passages and concludes that platforms are restricting researchers by, among others, imposing overly strict qualification criteria and management obligations, rate/quota limits, publication-related obligations, indemnity and liability clauses, and limiting access methods (incl. scraping). And, to top it off, they also included a model data sharing agreement, which unfortunately has not been adopted yet. Never lose hope, they say.
We also started a little experiment in October that we had been quietly preparing alongside Mozilla and AlgorithmWatch for months: On the birthday of the Digital Services Act, we coordinated a group of over 20 researchers and institutions to send out requests for public data to multiple social media platforms, asking for access to their Top 1000 most viral posts for each day. Platform responses differed but eventually we were rejected by all. So, we returned to our drawing boards, to refine our request. No matter the outcome, if you agree that the most viewed content should be disclosed by platforms, you can sign this petition. Given that YouTube ended its Trending Page, mid 2025, researchers from the University of Illinois, published a dataset documenting the trending videos with for snapshots per day for 2022-2025 – a great basis for analysis while we attempt to make the current trends available to the public again. Also, TikTok added two parameters to their API documentation that should allow researchers to filter the videos returned by the API by view and comment count. Not quite what we asked for but better than nothing – assuming the functionality actually does what it’s supposed to, which it currently doesn’t.
With the DSA’s data access framework slowly taking shape, Columbia World Projects and the Hertie School for Digital Governance released the “Building Capacity for Data Access, Analysis + Accountability” report, distilling a set of convenings of the Columbia-Hertie Working Group. It identifies current gaps in social media data access and lays out where public and private funders can meet these opportunities to support democratic institutions and norms worldwide. Given that the funding landscape of research data access has not significantly improved since, it’s still a highly relevant read.
DSA Addendum
In related news, the Open Terms Archive also started to track the DSA Systemic Risk Assessment Reports after a successful Hackathon at the Conservatoire National des Arts et Métiers in October. This somewhat machine readable dataset can now be used by anyone who wants to start some engineering around or analysis of the reports. We are already excited for the outcome.
November
Everything Data Access
In November, we joined the Mozilla Festival in Barcelona for the latest installment of the community meetup and to support the launch of the Better Access: Data for the Common Good report, which LK co-authored as part of an expert group. The report, which was led and published by Peter Chapman and Leticia Bode at the Knight Georgetown Institute, outlines different information environments, high-influence public platform data within those environments, and three complementary mechanisms that platforms should enable for meaningful data access. If you have not read it yet, we highly recommend you do! The release of the report was also accompanied by a series on Tech Policy Press, for which LK and Mark Scott wondered “How To Stabilize Researcher Data Access?”. LK also showed up in the Tech Policy Press Podcast alongside Peter Chapman and Brandi Guerkink to discuss why independent researchers need better access to platform data.
November also saw the first report on the most prominent and recurrent systemic risks as well as mitigation measures by the European Board for Digital Services, made up of the national DSCs and the Commission. It combines the platforms’ risk assessments inputs by CSOs and academic literature and is a great starting point to get an idea of all the different topics data access-enabled research could contribute to.
Still, while the report lists a whole set of examples, it’s still far from clear what is (and what isn’t) a systemic risk. The Court of Justice of the European Union provided some clarification in its ruling against Amazon, which was recently analysed on the DSA Observatory’s blog. Amazon had put forth a very narrow idea of systemic risk, limited to the sort of risk posed by highly interconnected financial institutions, and based on this claimed that “marketplaces do not give rise to systemic risks since they are not part of a ‘system’, unlike financial institutions”. The court did not buy this and instead clarified with reference to Rec. 76 that it’s the platforms’ reach (distributing information to a significant share of the EU population) which lies at the heart of their due diligence obligations as it “may cause societal risks, different in scope and impact from those caused by smaller platforms”. What commentators have missed so far is that Amazon also challenged researcher data access: the e-commerce giant, supported by the German registered association for e-commerce and mail order businesses (bevh), had claimed that researcher data access would infringe on the rights to the protection of confidential information and personal data enshrined in Article 7 and 8 of the EU Charter of Fundamental Rights respectively. But the CJEU made clear: Article 40(4) and (12) DSA do “not constitute a disproportionate interference” with these rights.
But November was also the month of the Digital Omnibus Proposal, which suggested substantial revisions to GDPR and AI Act under the banner of “simplification.” The response was mixed to say the least, with critics highlighting the extent to which the proposal represented US big tech lobbying positions. And while its broad implications for research were discussed on Tech Policy, it was Natali Helber at University of Amsterdam, who raised a more specific concern: the proposed amendment to Article 12(5) GDPR would allow controllers to refuse or charge fees for data access requests deemed an “abuse” of data rights — directly threatening individual data access and thus research methods that rely on voluntary data donations. We responded by coordinating an open letter, signed by over 230 researchers from 25 countries and nearly 100 institutions, urging EU policymakers to reject the amendment as contradicting existing EU commitments to evidence-based policymaking and independent research. As it turns out, we are not the only ones: joint opinion by the European Data Protection Board and the European Data Protection Supervisor also mentions “clarifying what qualifies as an abuse of rights is welcome, but it should not be linked to the exercise of the right to access for purposes other than data protection.” In a draft of the first compromise text from February 2026, the Council had stepped back from the most egregious changes suggested by the European Commission (like changing the definition of personal data) but the supposed change to Art. 12(5) remained. While the limitation to only data protection-related purposes was dropped, and suggested a more narrow specification that data controllers could make use of the existing options for refusal or fees “also where an abusive intention on the part of the data subject submitting those requests can be demonstrated by the controller.” Still, with discussions in parliament only starting in May and Ireland taking over the Council’s presidency in July, this discussion is far from over. We’ll keep you in the loop on further developments.
DSA Addendum
Also in November, the European Commission launched its long-anticipated Democracy Shield alongside an EU Strategy for Civil Society, designed to protect EU democratic processes from foreign interference and disinformation. The initiative drew criticism, including from the parliament, for centering coordination and voluntary measures over enforcement — reaffirming the voluntary Code of Conduct on Disinformation as the main forum for developing a DSA incidents and crisis protocol as one of the most actionable planned outcomes.
Key Harms and Risks
After pressure from both France and Germany on the European Commission following the sale of child-like sex dolls and banned weapons on Shein, the Commission sent an information request to Shein, suspecting the platform of the sale of illegal goods in November 2025. Four months later (February 2026) it launched an investigation into the e-commerce platform, alleging that Shein was not only selling illegal products but also were in breach of the DSA in terms of addictive design and lacking transparency of the recommender systems.
December
Everything Data Access
The dominant topic in December was the 120 million € fine the European Commission imposed on Elon Musk’s X for non-compliance with the DSA – the first big DSA enforcement action against a US company. In its communications the European Commission highlighted three points: the deceptive design of X’s ‘blue checkmark’, the lack of transparency regarding X’s ads repository, and X’s obstructive behaviour against researchers requesting access to data.
The clash between Europe’s “digital rulebook” and US geopolitical and geoeconomic interests was highlighted by the fine’s coincidence with the release of the US National Security Strategy, which pledged to resist European “national and transnational regulations that undermine creativity and industriousness,” criticized “censorship of free speech and the suppression of political opposition”, and encouraged action against “hostile economic practices.” And although, experts quickly pointed out that the fine was “not about speech or ‘censorship’”, it took only two months until the Republican members of the House Judiciary Committee to publish a report claiming exactly that (it marked the second Republican-led attempt to attach the ‘censorship’ label to the DSA – we discussed the first one, published in July 2025, briefly in our last newsletter). While the first report had leaked information about the Commission’s stakeholder workshop, this report published at the end of January leaked a redacted version of the X decision, alongside a whole set of documents and emails, drastically misreading it to fit the ‘censorship’ frame.
But the leaked decision also provided some helpful clarifications about the Commission’s understanding of researcher data access, which Oliver Marsh from AlgorithmWatch and our Collaboratory’s own LK Seiling summarised for Tech Policy Press:
- Researchers that meet the requirements in Art. 40(8b-e) must be allowed to scrape
- ‘Systemic risks’ should be interpreted broadly, and can be covered by large array of research fields and methodologies
- Access to publicly accessible data under Art. 40(12) should be free of charge
- Platforms should not impose restrictive quotas for access to the requested data
- Researchers do not need an affiliation to request and receive data
- Researchers do not need to be located in the EU or affiliated to an EU organisation to receive access
As was to be expected, X, X.AI Holdings, and Musk personally challenged the fine in front of the EU General Court in February. All cases raise objections regarding the procedural fairness underlying the fine – and claim that the Commission “misinterprets and misapplies Article 40(12) DSA” and fails to provide enough evidence that X was and is in infringement of the data access provision. It’s unclear how strong X’s defense is in the non-procedural aspects of the case, given that only one month after opposing the Commission with regard to the design of its service’s interface, X submitted remedies relating to the blue checkmark. In any case, we’ll keep you updated on any further developments!
Also, on 22 May 2026, 113 days after the initial press release, the European Commission quietly uploaded their version of the fine to their supervision and enforcement overview, which included some passages that X had previously redacted. Most notably the amount of requests X had received by 8 May 2024: 276 out of which it had made a decision for 255 applications, 12 of which (4.7%) were accepted.
Another piece of news that broke on 5 December, the day of the X decision, was that the European Commission accepted TikTok’s commitments on advertising transparency. In the recently published full document, TikTok has, for the next five years, committed to simplifying researcher access (reducing required fields), expanding searchable ad data and targeting information, improving search functionality, and reducing update delays (data should be provided with a maximum delay of one day), with implementation phased over 2–12 months.
As of 8 December 2025, SOMAR, the Social Media Archive at University of Michigan, which used to handle all data access requests to Meta, stopped handling access requests announcing that “all applications for Meta Content Library and API access are now managed via Meta’s own application portal,” the Research Tools Manager. This also resulted in a change of the information researchers needed to provide, finally removing researchers’ birthdates and mobile number from the form. The provided information is now independently reviewed by CASD, a French consortium for secure research data access. If researchers also choose to access the requested data via Meta’s API, they now have the choice between Meta’s own Secure Research Environment and SOMAR’s Virtual Data Enclave, the latter of which charges a $1,000 setup and onboarding fee plus a monthly fee of $371 for each researcher. See the official platform comparison page for a full comparison.
The Collaboratory’s year came to an end with a presentation that LK gave together with David Wegman at DATALAB in Aarhus University on the last day of the 39th Chaos Communication Congress. They spoke about the different ways researchers can access data from platforms and how it can be used to surface new insights, drawing on data collected from 1064 Danes as a case study.
DSA Addendum
2025 experienced another lowlight on Christmas Eve when the Trump administration imposed visa bans on 5 Europeans associated with the development, enforcement, or use of the DSA:
- Thierry Breton, former European Commissioner for Internal Market
- Anna-Lena von Hodenberg and Josephine Ballon of the German NGO and trusted flagger HateAid
- Imran Ahmed, the British CEO of the US-based Center for Countering Digital Hate
- Clare Melford, co-founder of the Global Disinformation Index
The move followed threats by the U.S. Secretary of State Marco Rubio in May 2025 to ban foreign nationals the US deemed to be censoring Americans. The bans were strongly criticised by European leaders of government as well as the European Parliament. Thus far, the bans have not been reversed.
January
Everything Data Access
Probably the biggest news item relating directly to data access in January was Whatsapp’s designation as a VLOP, which opened the platform up for researcher data access under the DSA. The Meta Content Library now allows qualified researchers to access updates from the last 30 days in WhatsApp channels that are verified or have a minimum of 100 followers.
DSA Addendum
Also in January, Poland’s President Karol Nawrocki vetoed the DSA’s national implementation bill, echoing American talking points of “administrative censorship,” effectively skirting the Polish parliament. This makes Poland one of six EU member states facing ongoing infringement proceedings by the European Commission for failing to designate and/or fully empower their DSC. Currently the Urząd Komunikacji Elektronicznej, the Polish Office of Electronic Communications, is only temporarily appointed and partially empowered to fulfil the functions of Poland’s DSC following a resolution of the Council of Ministers in May 2025.
Unrelated to the DSA but still relevant for platform regulation: TikTok’s US operation was restructured into a TikTok USDS Joint Venture LLC, a new legal entity with a majority stake of American investors, many of which have close ties to Trump, in order to comply with an executive order requiring divestiture from Chinese ownership concerns. While the new owners are overseeing data protection, algorithm security, content moderation, and software assurance within the United States, the recommendation algorithm seems to be subject to oversight and assurance mechanisms that may include auditing, licensing, and retraining arrangements.
Key Harms and Risks
While there was some reporting on “sexually suggestive, AI-generated children” on TikTok mid December, the topic became the dominant risk discussed throughout January, as grok was used for the mass generation of non-consensual intimate imagery (discussed in our first newsletter) on Elon Musk’s X platform. In 2025, the platform had already been identified as a key distribution platform for synthetic intimate image abuse and there had already been reports of grok users attempting to generate CSAM. According to its 2024 systemic risk report, X has an incident response protocol for such events, which it previously activated when synthetic intimate images of Taylor Swift were spread on the platform in January 2024. However, this time protocol was not activated. Instead, the platform’s owner further popularised, and later tried to monetise the functionality before seemingly shutting it down after an overwhelming international response, including the European Commission launching a formal investigation into X’s risk assessment and mitigation and French prosecutors raiding the X office in Paris.
For now, grok seems to have stopped creating synthetic intimate images of women and children. Still, the platform continues to be used as a means of distributing non-consensual intimate imagery.
February
Everything Data Access
The 17th was the key day for data access in February, for three separate reasons:
First, the Berlin Court of Appeal ruled that the CSO Democracy Reporting International (DRI) is entitled to receive publicly accessible data from X under the DSA. Previously, X had refused their application for data access submitted to monitor the Hungarian elections – and so DRI, supported by Gesellschaft für Freiheitsrechte (GFF), sued them in front of the Berlin Regional Court. Initially, however, the court rejected the lawsuit, declaring that it did not have jurisdiction (contradicting an earlier ruling by a different judge). But DRI and GFF appealed this first-instance decision in front of the Higher Regional Court of Berlin, which overruled the previous decision and thus confirmed “lack of data access as a tort,” meaning that the harm researchers suffer by not being able to access data occurs in the member state and can therefore be litigated there also. This is important because such cases would otherwise have to be litigated in the member state the platform is registered in (Ireland), which is expensive and would greatly increase the burden for researchers to appeal platform decisions. You can find an English translation of all rulings here. One important detail is that the court explicitly ordered X to grant data access without quota restrictions, which is a good sign for researchers currently limited by such quotas.
Second, on the same day, 170 work days after the initial press release, the European Commission quietly released the decision and commitments relating to their investigation of AliExpress’ potential violations of the DSA, including its data access provisions. Apart from information about the monitoring trustee overlooking the platform’s commitments, the decision provides some insights into the behind-the-scenes back and forth between the Commission and AliExpress, as well as some additional details on the specific commitments. These are our top three noteworthy highlights:
- Scraping is allowed by including an “exception to the restrictions on data access and use in the AliExpress Terms of Use” for researchers that meet the criteria in Art. 40(8b-d) DSA and comply with specific terms for researchers AliExpress may set. The European Commission had pushed for similar exemptions vis-a-vis X.
- Next to “(near) real time” access to readily-available datasets to qualified researchers (provided through an API for example), AliExpress is also supposed to provide additional customised datasets and other statistical data for the research purposes denied in Art. 40(12) upon researcher request. While the text does not provide examples, this could potentially include aggregated data on the most-viewed products.
- AliExpress has committed to “gradually expand the available datasets” based on frequent requests by researchers. While it remains to be seen, how this develops in practice, the fact that the scope of the data available through API could grow in the future offers an additional incentive to researchers to ask for data that is public but not yet easily accessible.
Finally, 17 February also marked the second and last day of “The DSA and Platform Regulation Conference”, which featured two sessions on access to platform data. The conference was organised by the DSA Observatory, which is run by the Institute for Information Law (IViR) at the University of Amsterdam. If you have not watched it yet, we’d recommend you take a look at the keynote by Prabhat Agarwal (the Acting Director of DG CONNECT, leading the DSA’s enforcement and strategic development), which not only gave insights in the roadmap for the future of DSA implementation but also addressed the (American) elephant in the room: “Don’t let yourself be scared. We at the Commission stand by the European civil society organizations that have been threatened, and we stand by our teams as well.” From his mouth to the ears of Ursula von der Leyen!
DSA Addendum
February also marked the end of a second year of the DSA being in force. A perfect chance to put the censorship claims from across the Atlantic to the test against the actual data. And as it turns out, the data submitted by platforms to the Statements of Reasons database tells a different story: Since its application, out of the 165 million content moderation decisions appealed by users, roughly 30 % (165 million) have been reversed. And as the conservative German newspaper, WELT, showed 99,8 % of moderation decisions by platforms are voluntary, 0,09 % are based on notices by third parties and notices by all trusted flaggers only informed 560 moderation decisions, which amounts to 0,0008 %.
Key Harms and Risks
In February the discussion around addictive platform design started heating up, as multiple lawsuits alleging addictive design patterns in Meta, YouTube, TikTok, and Snap made their way through the courts, putting the tech industry’s engagement-maximizing practices under renewed legal scrutiny. This allowed for interesting comparisons between what platforms had published in their DSA risk report and the internal documents that emerged as part of US litigation. While Meta and YouTube were found to have harmed young users with addictive design in March (TikTok and Snap had previously settled), the European Commission preliminarily found TikTok’s addictive design – including features like infinite scroll, autoplay, push notifications, and a highly personalised recommender system – in breach of the Digital Services Act. According to its findings, TikTok had neither conducted adequate risk assessments nor put in place adequate risk mitigation measures. Effectively, the Commission seems to require TikTok to change the basic design of its service, which could have wide-reaching consequences for all platforms, if successful. While child protection did not play an explicit role in the Commission’s preliminary findings, the mention of existing parental controls failing and the mention of “effective ‘screen time breaks’, including during the night” already gave a preview of the Commission’s push towards child safety online later in the year (see April).
On another note, if “AI chatbots” are ever designated VLOSEs, we’re already looking forward to investigations into similar design patterns, which are already actively being documented.
March
Everything Data Access
After a hectic start to the year, March was a fairly quiet time for data access. While there was some commotion around the first negative responses to access applications under Art. 40(4), we only documented two relevant events apart from that:
- The latest round of reports under the Code of Conduct on Disinformation was published, revealing improved data access to application ratios for the platforms that reported them (YouTube and TikTok). Looking at the overall numbers, it’s somehow not surprising that LinkedIn withdrew from the data access reporting commitments early last year.
- Between 17 and 19 March, the Social Media Access Days took place at the German National Library in Frankfurt. Especially on days 2 and 3, data access played a big role with various presentations (pdfs linked in programme) and a workshop on how to prepare Art. 40(4) applications. LK and Sophia from the Collaboratory also took part, talked about the links between the X fine and the data in the Collaboratory’s data access tracker, and gave a sneak preview on how they are planning to analyse the platform’s data catalogues. Find their slides here.
DSA Addendum
In broader DSA terms, March brought with it the first harmonised transparency reports. After two years of unstandardised, only partially machine readable reports, platforms now have to use a machine-readable template, which allows for easier comparison between the reports made to the Statements of Reasons database and the aggregated numbers in the transparency reports.
Also in March, Meta’s Oversight Board published a policy advisory opinion that warned of human rights risks connected to an indiscriminate global rollout of community notes, casting doubt on the assumption that the feature would be a meaningful intervention against misinformation. A week later, Platformer exclusively reported on the company’s plans to stop funding for the Oversight Board after 2028, having already significantly cut available funding.
Key Harms and Risks
In March, there was noteworthy discussion around recommender algorithms, which are not a harm or risk per sé but a potential risk factor, which may influence risk formation on platforms: LinkedIn updated its ranking system, moving from multiple retrieval sources to scoring based on large language models. This decision was not unprecedented. In fact, on X users have had the choice to have their following timeline be ranked by grok since November 2025. In March, Bluesky also started to offer similar functionality that leveraged large language models for feed customisation – much to the dismay of the platform’s user base.
Apart from such changes in the design, March was unfortunately once again dominated by news about technology-facilitated gender-based violence (GBV). And unfortunately, none of the cases was previously unknown.
An AI Forensics report documents a “structured, monetized, and largely automated ecosystem of abuse” on Telegram. Users in Italy and Spain used Telegram to engage in various sorts of violence, where “sharing of non-consensual intimate images rarely occurs as an isolated practice, but forms part of a wider ecosystem” of GBV, including incitations to rape or offering/seeking women to rape. Similar ‘rape chat groups’ had alread been uncovered on German Telegram channels in 2024 but March 2026 also saw reporting on similar groups in Poland.
Relatedly, the AI Forensics report also documented the distribution of links to nudifying apps, which enable the creation of sexualised deepfakes of people against their consent using image generation technologies. In April, both Google’s and Apple’s App Stores still offered such apps, although they violated their own policies. In May the European Parliament and Council agreed on a provisional agreement under the Digital Omnibus on AI, which targets companies developing AI systems for the creation of sexual deepfakes and users creating such content without consent, starting 2 December. According to AlgorithmWatch, data access requests to X aimed at analysing the distribution of such apps through the social network have been rejected, however if you find websites or apps which create non-consensual sexualized deepfakes of real people, you can report them here.
April
April was even more quiet than March when it came to data access-related news. However, this was the month where the discussion around child protection through age verification finally came to a head. But let’s rewind shortly to get the full picture.
DSA Addendum & Key Harms and Risks
After a call for evidence, multiple stakeholder workshops, and a targeted public consultation, the European Commission published guidelines on the protection of minors in July 2025. Applicable to all providers of online platforms which can be accessed by minors, the guidelines are firmly rooted in the DSA’s risk-based approach, requiring platforms to assess and mitigate risks of minors accessing the services and potential negative or positive impact on their privacy, safety and security (see also the OECD’s 5Cs risk typology). To that end, the guidelines outline various ways through which platforms should embed child safety into their operations, including governance, tools for guardians, user support and reporting functionality, as well as specific measures regarding the design of the service. Those include setting defaults of children’s accounts to the highest privacy, safety and security settings, avoiding addictive or persuasive design, responsible recommender systems and commercial practices, as well as age assurance (through means of age estimation or age verification) – as a central measure at the top of the list. Alongside the guidelines, the Commission also presented the prototype of an age verification app developed by a consortium of German and Swedish IT companies, which is supposed to enable users to prove that they are above a specified age threshold without disclosing additional personal information.
The app thus represents a hybrid model situated between the platform-based model (implemented by many US states) and the device-based model – both of which are advocated for by different major online platforms. Rather than requiring websites to collect users’ identity data directly or entrusting age verification to operating-system providers, the app is supposed to rely on privacy-preserving age attestations issued through a trusted public digital identity infrastructure.
The developments continued after the summer of 2025 when the Commission sent requests for information to Snapchat, YouTube, Apple App Store and Google Play in October, requiring them to provide information on their age verification systems and measures to prevent them from accessing illegal products or harmful material. On the same day, it also updated the EU age-verification app and coordinated with the national DSCs to conduct targeted compliance checks for those (non-VLOPSE) platforms identified as posing the greatest risk for children.
As internal documents attesting Meta’s knowledge of severe harms to children facilitated by its platforms were unsealed as part of court cases in November, the discussion on social media’s risks to children intensified further. And while the scientists gathering at an ECAT workshop as well as the research published by CDT highlighted the complexity and heterogeneity of the issue, as well as the difficulty of translating such nuance into enforceable regulatory standards at scale, policy-makers appeared increasingly receptive to more categorical interventions targeting minors’ access to social media services.
In fact, Australia became the first country to ban social media for children under 16 in December, establishing a global reference point for categorical age-based regulation. It did not take long for other countries in Europe to start moving on social media bans also. In January a proposal for a similar ban was approved in the UK’s upper house, followed by France accelerating the procedure for passing similar legislation, kicking off an EU-wide discussion of age limits for social media, resulting in 10 EU countries proposing or being close to proposing such bans in March 2026 – with only Estonia openly opposing such a move, with the Estonian education minister stating that a ban would not “actually solve the problems” as “kids will find very quickly the ways to go around and to still use social media” (a claim corroborated by Australian teens).
While EU member states discussed social media bans, the Commission continued to move on the child protection measures in the DSA throughout the first quarter of 2026, including an action plan against cyberbullying, the opening of an investigation into Snapchat’s compliance with the DSA’s child protection rules, and preliminary findings that Meta and Pornhub, Stripchat, XNXX and XVideos were in breach of the DSA by allowing minors to access their services. But with the advance of national proposals, the threat of fragmentation caused by member states implementing their own age verification measures prompted the Commission to urge national rollouts of its age verification app, which by mid-April was no longer framed as a blueprint but as “technically ready” by the European Commission president Ursula von der Leyen, inviting everyone to check the open source code. Following this invitation, privacy experts investigated the app and found that it would store sensitive data unprotected on the user’s phone, heavily relied on Google maintained technology, and allowed bypassing of its biometric authentication features. While the announcement allowed the developers to address some of the vulnerabilities, it did make the launch seem somewhat rushed and has not created much excitement for adoption amongst member states. With the final recommendations from the Special panel on child safety online still outstanding, the Commission president made it clear in her keynote at the European Summit on Artificial Intelligence and Children that “without pre-empting the panel’s findings, [she] believe[s] we must consider a social media delay.”
May
Everything Data Access
May marked a partial return of movement on the data access front. The European Commission held a roundtable on data access for vetted researchers, inviting all VLOPSEs and the DSCs to discuss access to non-public data. While the specific details of the meeting were not disclosed, it signalled that Article 40(4) access is moving forward and we can probably expect some more decisions during summer.
However, we should not be overly excited by these developments, considering that the implementation of researcher data access is increasingly unfolding in a politically constrained environment. So while the Board and VLOPSEs meet for one roundtable, the European Commission is simultaneously setting up a structured EU–US mechanism to coordinate the application and enforcement of the DSA and DMA. Formally described as a non-binding consultation framework, the planned committee effectively embeds US actors into enforcement-adjacent processes. And this is not counting the coordinated pressure other US-aligned actors are putting on the European Parliament, with efforts increasingly shifting from outright repeal of the DSA to strategies aimed at constraining enforcement and weakening implementation in practice. Still, it’s too early for despair. We’re keeping our fingers crossed for (and are actively working towards) promising applications that will hopefully soon result in the first reasoned request!
DSA Addendum
In parallel, we saw more enforcement at the national as the Irish DSC moved forward with two new investigations into Meta focusing on the use of dark patterns and user modification options for their recommender algorithms. CnaM had previously already started to investigate TikTok and LinkedIn with regard to the platforms’ reporting mechanisms.
Also in May, the European Commission launched a targeted consultation for the draft guidelines on trusted flaggers. Stakeholders with relevant experience and expertise are invited to submit their responses by 26 June.
Our Summer Reading List
The State of (DSA) Data Access
- Bekavac, L., & Mayer, S. (2026). Auditing Meta and TikTok Research API data access under Article 40(12) of the Digital Services Act [Preprint]. arXiv.
- Peters, Y., & Weller, K. (2026). Little mentioning, moderate attention, great relevance: The quality of online platform data in the Digital Services Act. Platforms & Society, 3, 1–17.
- Kazaz, J., & Klingová, K. (2025). Access to data for researchers: A state of play 2025. GLOBSEC.
- Santini, R. M., Leal, H., Salles, D., Belisário, A., Mattos, B., & Pinho, D. (2026). Data not found: Social media data transparency for information integrity. NetLab UFRJ & Minderoo Centre for Technology and Democracy.
- Pierri, F., Araujo, T., Kruikemeier, S., Lorenz-Spreen, P., Vanden Abeele, M. M. P., Vandenbosch, L., Gonçalves-Sa, J., & Grabowicz, P. A. (2025). Research opportunities and challenges of the EU’s Digital Services Act [Preprint]. arXiv.
- Tavishi, A., & Shobhit S. (2025). Platform transparency under the EU’s Digital Services Act: Opportunities and challenges for the Global South. Centre for Communication Governance, National Law University Delhi.
- Darius, P., Breuer, J., Kruschinski, S., Loecherbach, F., Riedl, J., & Stier, S. (2026). Election research in the age of regulated data access under the EU Digital Services Act. Internet Policy Review, 15(1).
Conceptualising Data Access
- Botero Arcila, B., Ramaciotti, P., & Cabale, E. (2026). Seeing in the dark: Towards a broad construction of the access to data provisions of the DSA. Internet Policy Review, 15(1).
- Stalla-Bourdillon, S., & Lieutaud, M. (2026). Data accessibility as a platform affordance: The shaping of research possibilities on online platforms with prospective legal methods. [Preprint]. SSRN.
Methodological Considerations
- Stravato Emes, C. (2026). Auditing risks of platforms in use under the DSA: A case for user-side observability. [Preprint]. SSRN.
- Chen, Y., Kmetty, Z., Iñiguez, G., & Omodei, E. (2025). The public that engages invisibly: What visible engagement fails to capture in online political communication. Communication Methods and Measures, 19(4), 294–312.
- Oswald, L., Schulz, W., Hertwig, R., Lazer, D., & Stier, S. (2025). The tip of the iceberg: How the social media production–consumption gap distorts public opinion for citizens and researchers [Preprint]. SocArXiv.
- Di Bona, G., Fraxanet, E., Komander, B., Lo Sasso, A., Morini, V., Vendeville, A., Falkenberg, M., & Galeazzi, A. (2026). Sampled social media data risk biased and inconsistent estimates of online social phenomena [Preprint]. OSF Preprints.
The Role of Social Media Research
- Scharfbillig, M., Lewandowsky, S., Altay, S., Van Alstyne, M., Kozyreva, A., Hertwig, R., Lorenz-Spreen, P., DiResta, R., Valenzuela, S., Egidy, S., Quattrociocchi, W., & Orben, A. (2026). Fractured reality: How democracy can win the global struggle over the information space (JRC144603). Publications Office of the European Union.
- Lewandowsky, S. (2026). Internet platforms must be held accountable for their actions. Science, 391(6785), eaee9835.
- Bak-Coleman, J., West, J., O’Connor, C., & Bergstrom, C. T. (2026). Industry influence in high-profile social media research [Preprint]. arXiv.
- Heiss, R., & Freiling, I. (2026). Addressing social media platforms’ influence on academic research. Humanities and Social Sciences Communications, 13, Article 192.
- Citron, D. K., & Waldman, A. E. (2025). The evolution of trust and safety. [Preprint]. SSRN.
- Moran, R. E., Schafer, J., Bayar, M., & Starbird, K. (2025). The end of trust and safety?: Examining the future of content moderation and upheavals in professional online safety efforts. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems (pp. 1–14). ACM.
On Various Risks and Risk Factors
- Goldin, I., & Vogel, T. (2010). Global governance and systemic risk in the 21st century: Lessons from the financial crisis. Global Policy, 1(1), 4–15.
- Forum on Information and Democracy. (2026). Strengthening information integrity on climate change and the environment.
- Correia de Carvalho, M., & Griffin, R. (2026). Who speaks and who is heard? Civil society participation and participatory justice in DSA systemic risk management. DSA Observatory.
- Packin, N. G., & Rabinovitz, S. (2026). Prediction markets as a public health threat. Science, 392(6795), 257–260.
- Entrena-Serrano, C. (2025). Watch, scroll, repeat: How interface design shapes consumptive curation affordances on TikTok. Social Media + Society, 11(3).
- Eyal, N. (2014). Hooked: How to build habit-forming products. Portfolio/Penguin.
- boyd, d. (2015). Blame society, not the screen time. The New York Times.
