Source: OJ L, 2025/2050, 9.10.2025Current language: DE
- Digital services act
Delegated acts
- Data access for vetted researchers
Artikel 5 Verarbeitung personenbezogener Daten im DSA-Datenzugangsportal
Summary What does Article 5 of the Data access for vetted researchers say?
This article sets out the data protection boundaries for the DSA data access portal, establishing what personal data can be processed, who it can relate to, and where that processing must physically take place.
It connects directly to the portal established under Article 3 and the Commission's role as processor under Article 4, effectively placing guardrails on how the portal operates in practice.
The article limits personal data processing to what is proportionate and necessary for the data access process, defines the categories of data subjects and personal data that fall within scope, and mandates that all processing infrastructure must be located within the EEA.
Important points:
- Personal data processing on the DSA data access portal is restricted to what is proportionate and necessary for the data access process and publication of relevant information.
- Only two categories of data subjects are in scope: account holders on the portal and natural persons whose data appears in any exchange under this Regulation relating to the data access process.
- All IT infrastructure used to process personal data via the portal must be located within the European Economic Area.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Werden personenbezogene Daten im DSA-Datenzugangsportal registriert und über dieses Portal ausgetauscht, so erfolgt die Verarbeitung nur insoweit, wie dies verhältnismäßig und für die Zwecke des Datenzugangsprozesses und der Veröffentlichung einschlägiger Informationen erforderlich ist.
Die Verarbeitung personenbezogener Daten darf im DSA-Datenzugangsportal nur in Bezug auf die folgenden Kategorien betroffener Personen erfolgen:
natürliche Personen, die ein Konto im DSA-Datenzugangsportal haben,
natürliche Personen, deren personenbezogene Daten im DSA-Datenzugangsportal oder in einem anderen Informationsaustausch gemäß dieser Verordnung in Bezug auf den Datenzugangsprozess enthalten sind.
Die Verarbeitung personenbezogener Daten darf im DSA-Datenzugangsportal nur in Bezug auf die folgenden Kategorien personenbezogener Daten erfolgen:
Identitätsdaten wie Name, Benutzerkennung,
Kontaktinformationen wie Anschrift, E-Mail-Adresse, Kontaktdaten,
personenbezogene Daten, die in den Unterlagen enthalten sind, aus denen der Anschluss an eine Forschungsorganisation hervorgeht, sowie sonstige personenbezogene Informationen, die für die Zwecke der Teilnahme am Datenzugangsprozess als notwendig betrachtet werden.
Die in Absatz 1 genannte Verarbeitung personenbezogener Daten erfolgt mithilfe von IT-Infrastrukturen, die sich im Europäischen Wirtschaftsraum befinden.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
Datenzugangsprozess
(En. data access process)