← Red Threads

DSA research access: the decision-maker is identifiable; a GDI approval is not established

Bounded official-source check closed on 9 September 2026. Two original HTML responses retained: one substantive Commission FAQ and the public portal's application shell. No login, application, data query or live platform experiment. Root independently owns the adopted Article 40 and delegated-rule reading; this lane reports explanatory guidance and the actual public-record boundary.

The operational route described by the Commission

The [Joint Research Centre / European Centre for Algorithmic Transparency FAQ](http[local research file] published 3 July 2025, shows an update of 29 October 2025. It distinguishes public-data access under Article 40(12) from vetted non-public access under 40(4). Both require commercial independence, disclosed research funding, proportionate research and security/privacy safeguards; vetting adds research affiliation and public, free results. Locators: questions on access/conditions, reader lines 33–52.

The DSC where the platform provider is established makes the final decision and issues a reasoned request. The researcher's home DSC may assess and forward an application (90–96). The FAQ describes an 80-working-day response, with explained extension (139–145); this is not a guaranteed data-delivery date. The establishment DSC specifies access conditions case by case, potentially using a secure environment rather than transferring data (130–138). A provider may seek amendments or mediation, but the DSC retains the decision (154–167). Public-data refusal feedback can inform Commission systemic enforcement; the FAQ says it will not opine on individual cases (80–84).

These are described powers and conditions, not an exercised decision concerning GDI. The Commission's explanatory text should be reconciled with root's operative-law reading rather than substituted for it. One question heading says the delegated act was adopted in June 2025, while the body dates adoption to July; no June date is adopted here.

What became publicly inspectable in this session

The FAQ's question on other researchers' outcomes says public overviews of reasoned requests and amendments are intended to appear in the [DSA data access portal](http[local research file] (149–150). This is narrower than a promise that every application, rejection or private exchange is public. Root's independent reading of delegated Regulation 2025/2050 Article 11 identifies topic, provider, requested data and access modality as overview fields; researcher and funder names are not mandatory fields. An exact-name search is consequently a particularly weak exclusion test. This legal detail is cross-lane input, not an additional legal-text read by this worker.

The FAQ's actual link opened /home. The official reader returned zero lines. One ordinary GET returned HTTP 200 and 45,880 bytes of an application shell, with only the title in text extraction and no anchor links. No overview rows were inspected. No application index was enumerated, searched through a logged-in interface, exported or reverse-engineered. A retained shell is not evidence that the portal has no records, or that its intended public summaries require login. This transport branch was closed after the two ordinary methods.

GDI / AI4TRUST request or approval status

No publicly identifiable official approval or reasoned request for GDI or AI4TRUST was acquired. That is an evidence limit, not a finding that neither has applied, qualified or obtained data. The exact indexed-name checks were:

site:data-access.dsa.ec.europa.eu "GDI"; site:data-access.dsa.ec.europa.eu "AI4TRUST"; site:data-access.dsa.ec.europa.eu "Disinformation Index"; "Global Disinformation Index" "vetted" "approved"; site:cnam.ie "AI4TRUST"; site:cnam.ie "Global Disinformation Index"; and site:bundesnetzagentur.de "GDI" "researcher".

These returned no matching official named request/approval in the displayed results. The broader query returned historical Commission policy references and commentary, neither of which is a vetting record. Earlier discovery queries and the search boundary are recorded in the manifest. Search indexing is incomplete; a request may name a principal researcher, research institution or project variant rather than either searched label. This was not a search of every DSC or a complete public register.

The already accepted GDI retrospective describes a 2024 Article 40 application and refusal. It does not supply the original application, a DSC determination or a paragraph-specific legal route. Its date alone must not be recast as an application under the mechanism that the FAQ says became operational on 29 October 2025. Conversely, this run does not invalidate that historical self-report. The exact procedural channel remains a missing fact.

Horizon participation and financial support do not constitute a research-access determination. Nor do any previously documented platform data collections establish which legal channel supplied them. The selected sources do not establish trusted-flagger status for GDI or AI4TRUST; no inference between that separate status and researcher access is made. Commercial independence is an application condition requiring assessment, not a finding in this packet that a particular legal entity satisfies or fails it.

The next discriminating record

An issued reasoned-request overview, matched to this research through provider, topic, data and modality plus corroborating applicant or decision records, would establish a concrete authority step. The public overview need not name the applicant, so a name match alone cannot be the retrieval criterion. The associated vetting decision and specified access conditions would show what was authorized. Actual provider fulfilment or delivery confirmation would be a further step. A grant record or a statement that research used platform data cannot replace this sequence.

Known expected holders are the establishment DSC, the principal researcher and the provider. The portal is the stated publication channel for reasoned-request overviews. For the reported 2024 refusal, the application and platform response remain the direct records needed to distinguish public-data access, another platform scheme and a government-vetted request. No holder was contacted, and no next branch was opened.

Custody and reading scope

gates-faq.html and gates-faq.derived.txt: full substantive FAQ reader-read, questions from DSA introduction through stakeholder input, plus publication/update fields (official-reader lines 3–184). Original HTML retained; its links and date/footer fields inspected locally. This is a 29 October 2025 updated explanation captured on 9 September 2026, not a complete current enforcement-case inventory.

gates-portal.html and gates-portal.derived.txt: application-shell response and title only. No substantive public request index read. gates-transport.json preserves actual requests, timestamps, statuses and hashes. gates-captures.json states each source's limits and the exact search coverage. No original decision, reasoned request, refusal correspondence or data-delivery receipt was acquired.