Source: OJ L, 2025/2050, 9.10.2025

Current language: EN

Article 10 Content of a reasoned request


Summary What does Article 10 of the Data access for vetted researchers say?

This article sets out the mandatory content of a reasoned request — the formal document that the Digital Services Coordinator of establishment submits to a data provider to initiate data access.

It builds directly on Articles 8 and 9, as it requires the reasoned request to incorporate the access modalities determined under Article 9 and the application summary prepared under Article 8.

The article also addresses two specific scenarios: the discretionary inclusion of vetted researchers' personal details, and the additional requirements triggered when the data access involves transferring personal data outside the EU.

Important points:

  • The Digital Services Coordinator of establishment must ensure every reasoned request includes defined start and end dates for data access, the agreed access modalities, and a summary of the data access application.
  • The Digital Services Coordinator of establishment may include the names and contact details of vetted researchers in the reasoned request, but only where necessary to enable access.
  • Where the data access involves a transfer of personal data to a third country or international organisation, the reasoned request must reference an appropriate transfer mechanism to ensure compliance with GDPR.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. A reasoned request shall contain at least the following elements:

      1. the date by which the data provider shall give access to the data requested and the date on which such access shall be terminated;

      2. the access modalities determined pursuant to Article 9;

      3. the summary of the data access application referred to in Article 8 point (g).

    1. The Digital Services Coordinator of establishment may include in the reasoned request the names and contact details of all vetted researchers mentioned in the data access application where this is necessary to enable access to the requested data, in accordance with the access modalities specified in the reasoned request.

    1. If providing access involves a transfer of personal data to a third country or international organisation within the meaning of Chapter V of Regulation (EU) 2016/679, the reasoned request shall include information on the need to put in place or refer to an appropriate transfer mechanism to ensure compliance with Regulation (EU) 2016/679.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod