Source: OJ L, 2025/2050, 9.10.2025

Current language: SV

Artikel 15 Datadelning och datadokumentation


Summary What does Article 15 of the Data access for vetted researchers say?

This article sets out the practical obligations of data providers once a reasoned request has been acted upon.

It governs how data providers must behave throughout the active phase of data access — from notifying the relevant Digital Services Coordinator when access begins and ends, to supporting vetted researchers with the contextual information they need to make use of the data.

Crucially, the article also places clear limits on what data providers can and cannot demand of vetted researchers during this process, tying any permissible conditions back to what was explicitly set out in the reasoned request under Article 10.

Important points:

  • Data providers are required to notify the Digital Services Coordinator of establishment within three working days of both granting and terminating access to data.
  • Data providers must supply vetted researchers with supporting documentation (such as codebooks and changelogs) to enable proper use of the data, but must flag to the Digital Services Coordinator if doing so risks a significant vulnerability to their services.
  • Data providers must not impose data management requirements or personal data processing conditions on vetted researchers beyond those explicitly stated in the reasoned request.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Dataleverantörer ska inom tre arbetsdagar underrätta samordnaren för digitala tjänster i etableringslandet om följande:

      1. Att utvalda forskare har fått åtkomst till begärda data i enlighet med den motiverade begäran.

      2. Att utvalda forskares åtkomst har upphört.

    1. Dataleverantörerna ska förse utvalda forskare med all ytterligare information som behövs för att de ska få åtkomst till och förstå begärda data, såsom kodböcker, ändringsloggar och arkitekturdokumentation. Om tillhandahållandet av sådan information kan leda till en betydande sårbarhet för dataleverantörens tjänster ska dataleverantören underrätta samordnaren för digitala tjänster i etableringslandet om denna risk och, om möjligt, föreslå alternativ information.

    1. När dataleverantörer ger åtkomst till data får de inte ålägga utvalda forskare krav på datahantering, såsom arkivering, lagring, uppdatering och radering, eller begränsa användningen av standardiserade analysverktyg, som kan hindra att den relevanta forskningen utförs, såvida inte sådana krav eller begränsningar uttryckligen nämns i den motiverade begäran.

    1. Vid behandling av personuppgifter ska dataleverantörer inte ålägga utvalda forskare några andra villkor för behandlingen av de delade personuppgifterna än de som anges i den motiverade begäran.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod