Source: OJ L, 2025/2050, 9.10.2025

Current language: EN

Article 15 Data sharing and data documentation


Summary What does Article 15 of the Data access for vetted researchers say?

This article sets out the practical obligations of data providers once a reasoned request has been acted upon.

It governs how data providers must behave throughout the active phase of data access — from notifying the relevant Digital Services Coordinator when access begins and ends, to supporting vetted researchers with the contextual information they need to make use of the data.

Crucially, the article also places clear limits on what data providers can and cannot demand of vetted researchers during this process, tying any permissible conditions back to what was explicitly set out in the reasoned request under Article 10.

Important points:

  • Data providers are required to notify the Digital Services Coordinator of establishment within three working days of both granting and terminating access to data.
  • Data providers must supply vetted researchers with supporting documentation (such as codebooks and changelogs) to enable proper use of the data, but must flag to the Digital Services Coordinator if doing so risks a significant vulnerability to their services.
  • Data providers must not impose data management requirements or personal data processing conditions on vetted researchers beyond those explicitly stated in the reasoned request.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Data providers shall notify the Digital Services Coordinator of establishment within three working days of the fact:

      1. that access to the requested data has been provided to vetted researchers, in accordance with the reasoned request;

      2. that the access for the vetted researchers has been terminated.

    1. Data providers shall provide vetted researchers with any additional information needed to access and understand the requested data, such as codebooks, changelogs and architectural documentation. In cases where the provision of such information may result in a significant vulnerability of the data provider’s services, the data provider shall notify the Digital Services Coordinator of establishment of that risk and, where possible, propose alternative information.

    1. When providing access to data, data providers shall not impose on vetted researchers data management requirements such as archiving, storage, refresh and deletion requirements, or limitations to the use of standard analytical tools, that may hinder the performance of the relevant research, unless such requirements or limitations are explicitly mentioned in the reasoned request.

    1. Where personal data are processed, data providers shall not impose on vetted researchers any conditions in relation to the processing of the shared personal data other than those specified in the reasoned request.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod