Source: OJ L, 2025/2050, 9.10.2025

Current language: EN

Article 5 Processing of personal data in the DSA data access portal


Summary What does Article 5 of the Data access for vetted researchers say?

This article sets out the data protection boundaries for the DSA data access portal, establishing what personal data can be processed, who it can relate to, and where that processing must physically take place.

It connects directly to the portal established under Article 3 and the Commission's role as processor under Article 4, effectively placing guardrails on how the portal operates in practice.

The article limits personal data processing to what is proportionate and necessary for the data access process, defines the categories of data subjects and personal data that fall within scope, and mandates that all processing infrastructure must be located within the EEA.

Important points:

  • Personal data processing on the DSA data access portal is restricted to what is proportionate and necessary for the data access process and publication of relevant information.
  • Only two categories of data subjects are in scope: account holders on the portal and natural persons whose data appears in any exchange under this Regulation relating to the data access process.
  • All IT infrastructure used to process personal data via the portal must be located within the European Economic Area.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Where personal data are registered in and exchanged via the DSA data access portal, the processing shall take place only in so far as it is proportionate and necessary for the purpose of the data access process and publication of relevant information.

    1. The processing of personal data shall take place in the DSA data access portal only in respect of the following categories of data subjects:

      1. natural persons having an account on the DSA data access portal;

      2. natural persons whose personal data is contained in the DSA data access portal or in any other exchange pursuant to this Regulation concerning the data access process.

    1. The processing of personal data shall take place in the DSA data access portal only in respect of the following categories of personal data:

      1. identity data, such as name, user ID;

      2. contact information such as address, email address, contact details;

      3. personal data contained in the documentation demonstrating the affiliation to a research organisation, and any other personal information deemed necessary for the purpose of participating in the data access process.

    1. The processing of personal data referred to in paragraph 1 shall be performed using information technology infrastructure located in the European Economic Area.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod