Source: OJ L, 2025/2050, 9.10.2025

Current language: EN

Article 8 Prerequisites for formulating a reasoned request


Summary What does Article 8 of the Data access for vetted researchers say?

Article 8 sets out the criteria that the Digital Services Coordinator of establishment must evaluate when deciding whether to formulate a reasoned request for data access.

It directly feeds into the process established under Article 7, which gives the Digital Services Coordinator 80 working days to make that decision.

In essence, this article defines what a complete and credible data access application looks like, covering both the credentials of the researchers involved and the substance of the research itself, including the data sought, the risks involved, and the safeguards proposed.

Important points:

  • The Digital Services Coordinator of establishment is required to assess each applicant researcher's institutional affiliation, independence from commercial interests, and commitment to making results publicly available free of charge.
  • Applicant researchers must provide a detailed description of the data requested, the necessity of accessing it, the research timeframes, and the activities to be conducted with the data.
  • Applicant researchers must identify risks related to confidentiality, data security, and personal data protection, and describe the technical, legal, and organisational measures they will put in place to mitigate those risks.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

The Digital Services Coordinator of establishment shall decide whether a reasoned request can be formulated taking into account the following elements:

  1. for each applicant researcher:

    1. a confirmation of affiliation to a research organisation as defined in Article 2, point (1), of Directive (EU) 2019/790 of the European Parliament and of the Council(6);

    2. a declaration of independence from commercial interests relevant to the specific project for which the data are requested;

    3. a commitment to making their research results publicly available free of charge;

  2. information about funding supporting the research project for which the data are requested;

  3. a description of the data requested, including format, scope and, where possible, the specific attributes, relevant metadata and data documentation, also considering the information made available pursuant to Article 6(4) of this Regulation;

  4. information on the necessity and proportionality of the access to the data and the information on the time frames of the research for which the data are requested;

  5. information on the identified risks in terms of confidentiality, data security and personal data protection related to the data that would be accessed, a description of the technical, legal and organisational measures that will be put in place, including, where possible, suggested access modalities, to mitigate such risks when processing the requested data;

  6. a description of the research activities to be conducted with the requested data;

  7. a summary of the data access application containing the following elements:

    1. the research topic;

    2. the data provider from which data are requested;

    3. a description of the data requested, as referred to in point (c).

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod