X's Data Only Opened After a $170M Fine
The EU just issued its first-ever penalty for blocking researcher access to platform data
Opening
In November 2024, something strange happened ahead of Romania’s presidential election. TikTok accounts that had spent years posting nothing but nail art and fashion content suddenly started boosting an obscure politician: Călin Georgescu. His posts, from a candidate polling in the single digits, racked up 120 million views before the vote — and he came out on top in the first round with 23%.
Professor Adriana Iamnitchi at Maastricht University in the Netherlands wanted to study this. Who made this content, and how did they monetize it? So she requested data from TikTok under a right guaranteed by EU law. She was denied.
The law already existed. The data didn’t. To cut to the point: what finally closed this gap wasn’t a research paper or a petition — it was a fine of ₩200 billion (~$145 million). And wherever Reader lives, you’re likely still a step behind even that.
What a ₩200 Billion ($145 Million) Fine Bought
On July 15, the European Commission accepted X’s remediation plan. The gist: improve the vetting process for qualified researchers and drastically cut processing times, provide data free of charge, and revise the terms of service that had contractually banned researchers from independently collecting public data. The deadline for compliance is six months, subject to an external independent audit.
Let’s count how long it took to get here. In April 2023, X was designated a Very Large Online Platform1. That December, the EU opened a formal investigation. Then on December 5, 2025, the Commission fined X €120 million — roughly ₩200 billion (~$145 million) — the first penalty issued under the Digital Services Act2.
There were three grounds for the penalty. The one that made headlines was the “deceptive blue checkmark design.” But the other two are today’s subject: an opaque ad repository that made verification impossible, and a failure to provide researchers with access to public data. X’s terms specifically banned qualified researchers from independently collecting data at all.
X didn’t simply accept this. On February 20 of this year, X appealed the decision, arguing the investigation was incomplete and superficial and that the EU had violated its rights of defense and due process. So even after the fine, X kept fighting for nearly five more months. The remediation plan came only after that.
To sum up: two years and seven months passed between the launch of the investigation and the acceptance of the remediation plan. In that time, Romania’s presidential election was annulled and a re-run was held. Researchers won’t be able to see the data from that period until, at the earliest, the end of this year.
The Law Already Existed — So Why Didn’t the Door Open?
There’s an easy misunderstanding here: “we couldn’t see it because there was no law.” Not true. The law was ahead of the curve — arguably the most advanced in the world.
Article 40 of the Digital Services Act codifies qualified researchers’ right to access platform data. If you’re studying “systemic risks” — the spread of illegal content, or distortion of electoral processes, for instance — you can demand data. In July 2025, a delegated act3 laying out detailed procedures was adopted, and when it took effect that October, its scope expanded to include non-public internal data. A Data Access Portal was also launched as the application gateway.
But in practice, here’s what actually happened.
First, security requirements didn’t match what universities could realistically provide. Most platforms require data to be stored on “tamper-proof infrastructure” — meaning equipment physically disconnected from the internet. Few universities have facilities like that.
Second, approval rates varied wildly by platform. Of the 46 applications tracked by Germany’s DSA40 collective, 20 were approved and 14 rejected — but TikTok approved 11 of 13, while X rejected 11 of 23. That said, because this tracking relies on researchers voluntarily reporting their own cases, the group’s organizers say the real rejection rate is likely even higher.
Third, even approval didn’t guarantee usable data. Data received via API was often hard for a fellow researcher to replicate exactly. Reproducibility is a basic condition of science — and that condition was shaky.
And there’s one more, particularly ironic problem that not even the delegated act could solve: the “data catch-22.” Researchers must specify exactly what data they need in their application. But to know what you need, you first have to see what’s inside. And there’s no reliable way to check whether the data inventory a platform submits is even complete. You need to see it to know it, and know it to see it.
That left two paths: scraping4 — gathering whatever’s visible on-screen within what the platform allows — or lawsuits. In fact, a German research organization applied for data from X in April 2024, was rejected, and filed suit in February 2025. The court ruled that X should have granted access — but then hit another wall, this time over research into Hungarian elections. A Berlin court ruled the case should be heard in Ireland, where X’s headquarters are located, nearly killing the case before an appellate court reversed that decision. It’s no surprise researchers are asking whether risking a lawsuit every time you apply is really a sustainable approach.
Of course, the platforms’ side deserves a hearing too. TikTok says it has provided tools to more than 1,500 research teams and approved 130 requests in the EU alone in the second half of last year, with a cap of 1,000 API requests per day allowing access to up to 100,000 video and comment records. Meta counters that while its earlier tool, CrowdTangle, covered only a fraction of its public data, its replacement, the Content Library, is the most comprehensive research tool released to date. It’s also true that legitimate constraints exist — privacy protection and platform security among them.
One more thing worth noting: the European Board for Digital Services, made up of regulators from EU member states, gave an overall assessment that X’s remediation plan was inadequate. Yet the Commission accepted it anyway, saying it would strengthen implementation oversight. In effect, a plan that the regulators’ own advisory body deemed insufficient was approved as-is. Whether the door actually opens six months from now remains to be seen.
So Where Does Korea Stand?
Just this month, a similar resolution mechanism launched in Korea.
On July 7, the amended enforcement decree of the Act on Promotion of Information and Communications Network Utilization passed a Cabinet meeting, and the next day, July 8, the Korea Communications Standards Commission (KOCSC) designated and notified the platforms subject to it: Naver, Kakao, Nate, DC Inside, along with Google, Meta, X, and TikTok. The rules apply to social media, online communities, and video-sharing services with more than 1 million average daily users. Search engines and open marketplaces had been included during the legislative notice stage but were dropped from the final version.
The obligations these operators now carry: establish procedures for accepting and processing reports of disinformation, set up self-governance policies, and publish transparency reports. They’re also required to sign agreements with fact-checking organizations that comply with the International Fact-Checking Network’s Code of Principles, and a supporting Transparency Center has been established.
This is where the difference from the EU shows. In Korea’s system, the verifiers are the platforms themselves and designated fact-checking organizations. Platforms write their own reports, and partner organizations assess the veracity of individual pieces of information. There’s no legal pathway in this amendment for independent researchers to directly access the raw data.
Why does this matter? In the Romania case, it was TikTok itself that eventually revealed the existence of the manipulation network. Two months later, it classified 116,000 accounts as suspicious and announced it had taken action against more than 27,000 fake accounts. But TikTok also said it didn’t know who was operating the network or where it originated. When all you have is the platform’s own self-reporting, with no external verification, that’s the ceiling of what you can know.
So how would a researcher in Korea today study opinion-manipulation patterns on a domestic platform? With no legal basis to demand data, three options remain: form an individual cooperative relationship with the platform, scrape publicly visible content, or read the reports the platform publishes about itself. The first two depend entirely on the platform’s goodwill and terms of service; the last one isn’t verification — it’s just citation. Unlike EU researchers, who at least came away with a documented record of “we were rejected,” here the application doesn’t even get off the ground.
There’s one interesting asymmetry worth mentioning. In June 2026, Korea promulgated the National Research Data Act, establishing a principle that data produced through national R&D projects should be made public. Data generated by the public sector is being opened up. But data from the private platforms where public opinion is actually shaped remains entirely outside that conversation.
Oswald’s Lens
I read this story not as regulatory news, but as a textbook case of adoption failure.
Working on go-to-market strategy, I’ve confirmed the same thing over and over: there’s always a deep valley between shipping a feature and that feature actually getting used. When you grant permission and nobody uses it, it’s usually not because the permission doesn’t exist — it’s because each step in between drops people off, one at a time. If you draw the EU’s pathway as a funnel, it looks like this: know your right, write the application, meet the security requirements, wait for review, get approved, receive usable data. Drop-off starts as early as step two, and even at the final step, half the applicants leak out. If this were a product, that conversion rate would have triggered a redesign long ago.
That’s why I pay more attention to implementation design than to whether a legal clause exists. Are the requirements within reach of what’s actually feasible on the ground? Is there a defined processing deadline? Is there an appeals process for rejection besides going to court? In the X case, what actually made things move wasn’t the right enshrined in Article 40 — it was the cost of the fine. The door only opened once the cost of resistance exceeded the cost of cooperation.
As someone who’s worked with data, let me add one more thing. A number that can’t be verified isn’t information — it’s a claim. When a platform says “we deleted 27,000 fake accounts,” and there’s no third party who can check that figure, what we’re getting isn’t a fact — it’s a press release. The more we worry about algorithms swaying elections, the more we run into this paradox: the only people who can actually look inside the algorithm are the ones who built it. And that paradox is playing out on two continents at once, right now.
Closing
To sum up:
First, the EU was the first in the world to enshrine researcher data access as law — but for over two years, it simply didn’t function in practice. Even with the right in place, requirements and procedures blocked the door.
Second, what opened the door wasn’t the legal clause — it was a ₩200 billion (~$145 million) fine. And given that even the regulators’ own advisory body called X’s remediation plan inadequate, we’ll need to watch what happens in six months.
Third, Korea imposed transparency obligations on eight platforms this month, but independent researchers’ access rights are absent from the design. What the EU’s case tells us is that writing a right into law isn’t enough — you have to look at implementation design too.
Have you ever designed or requested data-access permissions inside your own organization? If you’ve had permission approved but couldn’t actually use it — or if, on the flip side, you built something that made it work smoothly — tell me in the comments. Data access within organizations and platform regulation turn out to share a remarkably similar structure, and if enough examples come in, I’ll pull the common threads together in a future issue.
💬 Share your experience with data-access permissions in the comments — I may feature it in a future issue. 📨 If you know a colleague working on platform regulation or data governance, pass this one along.
References & Further Reading
Primary sources
- WIRED, “European Researchers Say Big Tech Is Blocking Access to Their Data”, 2026. ··· The article that started today’s piece. It includes direct quotes from Professor Iamnitchi and a DRI researcher, capturing on-the-ground friction that policy documents alone don’t reveal.
- European Commission, “Commission fines X €120 million under the Digital Services Act”, 2025.12.5. ··· The primary source for the fine decision. Worth reading in the original to see exactly which provisions each of the three violations fell under.
- European Commission, “Commission accepts X’s action plan to comply with Digital Services Act”, 2026.7.15. ··· The concrete list of remediation measures X committed to. Useful as a checklist to compare against actual implementation six months from now.
- Iamnitchi, A., “If at first you don’t succeed: reflections on a rejected Art. 40 DSA data access request”, DSA Observatory, 2026.3.12. ··· A firsthand account written by a rejected researcher. It lays out, step by step, exactly where the application process broke down — the most concrete material available.
- Korea Communications Standards Commission, “Enforcement Decree and Guidelines under the Network Act on Preventing the Distribution of Illegal and False Manipulated Information,” 2026.7. ··· The original text of Korea’s system. Search the list of obligations for the word “researcher” and today’s argument becomes immediately clear.
Background
- European Commission, “Commission adopts delegated act on data access under the Digital Services Act”, 2025.7.2. ··· The detailed rules meant to make Article 40 actually function. Once you see how the system was designed, it becomes clearer why it still didn’t work.
- van de Kerkhof, J., “Unpacking the EU’s Digital Services Act Delegated Regulation on Data Access”, Tech Policy Press, 2025.7. ··· The clearest articulation of the “data catch-22” concept discussed in this piece. Also a good primer on the logic of institutional critique.
Related past issues
- How an Academic Publishing Platform Became Worth $6.7 Million After 35 Years of Independence ··· Covered ownership of academic infrastructure. Today’s piece is about failing to get the data to put into that infrastructure in the first place — the two connect naturally.
- China, Built by Isolation, Now Locks Its Own Doors ··· A story about a state locking the doors on data and technology. Today it’s a company doing the locking.
📝 Glossary
Footnotes
-
Very Large Online Platform (VLOP): A designation for services with more than 45 million average monthly users within the EU. Being placed on this list brings much heavier obligations — risk assessments, external audits, and providing data to researchers. ↩
-
Digital Services Act (DSA): The EU’s regulation for online platforms, enacted in 2022. It’s distinctive for bundling together illegal-content response, ad transparency, and algorithmic accountability in a single framework. ↩
-
Delegated act: A subordinate regulation where the parent law sets only the broad principles, delegating the detailed procedures to the Commission to work out separately. Roughly analogous to an enforcement decree in Korea’s legal system. ↩
-
Scraping: A method of programmatically gathering content visible on a webpage. Since it’s not an official channel like an API, the scope of what can be collected is limited — obtaining something like a full follower list for an account, for instance, is difficult. ↩


Your take shapes the next issue
Reply with your experience or perspective — the best responses feed into future issues.
Sign in to commentAny registered reader can comment — it takes 10 seconds.