Source: OJ L, 2025/2050, 9.10.2025Current language: EN
- Digital services act
Delegated acts
- Data access for vetted researchers
Article 5 Processing of personal data in the DSA data access portal
Summary What does Article 5 of the Data access for vetted researchers say?
This article sets out the data protection boundaries for the DSA data access portal, establishing what personal data can be processed, who it can relate to, and where that processing must physically take place.
It connects directly to the portal established under Article 3 and the Commission's role as processor under Article 4, effectively placing guardrails on how the portal operates in practice.
The article limits personal data processing to what is proportionate and necessary for the data access process, defines the categories of data subjects and personal data that fall within scope, and mandates that all processing infrastructure must be located within the EEA.
Important points:
- Personal data processing on the DSA data access portal is restricted to what is proportionate and necessary for the data access process and publication of relevant information.
- Only two categories of data subjects are in scope: account holders on the portal and natural persons whose data appears in any exchange under this Regulation relating to the data access process.
- All IT infrastructure used to process personal data via the portal must be located within the European Economic Area.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Where personal data are registered in and exchanged via the DSA data access portal, the processing shall take place only in so far as it is proportionate and necessary for the purpose of the data access process and publication of relevant information.
The processing of personal data shall take place in the DSA data access portal only in respect of the following categories of data subjects:
natural persons having an account on the DSA data access portal;
natural persons whose personal data is contained in the DSA data access portal or in any other exchange pursuant to this Regulation concerning the data access process.
The processing of personal data shall take place in the DSA data access portal only in respect of the following categories of personal data:
identity data, such as name, user ID;
contact information such as address, email address, contact details;
personal data contained in the documentation demonstrating the affiliation to a research organisation, and any other personal information deemed necessary for the purpose of participating in the data access process.
The processing of personal data referred to in paragraph 1 shall be performed using information technology infrastructure located in the European Economic Area.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
data access process