Bay Street Wire
Tech & BusinessOpinion

The Enforcement Gap: How Big Tech Treats the DSA's Data Mandates as Optional

Portrait of Diana Vasquez
Diana Vasqueztech policy & regulationJul 25AI
The Enforcement Gap: How Big Tech Treats the DSA's Data Mandates as Optional

AI-generated image · Bay Street Wire

European researchers are hitting a wall of obfuscation and technical hurdles, suggesting that without strict enforcement, the Digital Services Act's transparency requirements are a paper tiger.

The Digital Services Act (DSA) was designed to pull back the curtain on the algorithmic black holes of social media, granting vetted researchers access to the data necessary to study systemic risks. But two years into the law's implementation, a troubling pattern has emerged: the platforms are not merely complying with the law; they are interpreting it in ways that make compliance practically impossible for the academic community.

As a rules-of-the-game analyst, I see this as a fundamental enforcement crisis. The legal scope of the DSA is broad, but the actual mechanism of delivery is being throttled by the very companies it aims to regulate. When platforms treat legal mandates as suggestions, the law ceases to be a guardrail and becomes a suggestion box.

**The Romanian Case Study**

Nothing illustrates the stakes of this data deadlock more clearly than the 2024 presidential election in Romania. According to reporting from Ars Technica, TikTok accounts that had previously focused on fashion or manicures suddenly pivoted to promoting Calin Georgescu, a politician with hard-line views on immigration and anti-Semitic tropes. Georgescu, who had previously polled in the single digits, won the first round of the election with 23 percent of the vote.

Adriana Iamnitchi, chair of computational social sciences at Maastricht University, attempted to use the DSA to investigate how pro-Georgescu content was being monetized through livestreamed political content and hidden influencer marketing. Iamnitchi and her team applied for access to TikTok's Application Programming Interface (API) on October 28, 2025. TikTok denied the request, claiming the researchers failed to meet security requirements, explain their commercial interests, or prove they were established researchers.

Two months later, TikTok admitted to taking action against more than 27,000 fake accounts in a coordinated network run by a third-party "fake engagement vendor" that promoted Georgescu and the Alliance for the Union of Romanians (AUR). While TikTok claimed it did not know the origin or operator of the network, declassified Romanian intelligence indicated that Russia allegedly coordinated the campaign and that Georgescu benefited from preferential treatment and massive exposure on the platform. Iamnitchi believes her team could have identified who profited from and created the content had TikTok granted the data access.

**The Architecture of Obfuscation**

The friction is not accidental; it is systemic. Researchers describe a landscape of "obstacles, obfuscation," and legal battles. Duncan Allen, a research officer at Democracy Reporting International (DRI) in Germany, notes that platforms have systematically dismantled public access tools. Meta replaced its CrowdTangle tool with content libraries, while X paywalled its API data, requiring academics to pay hundreds of dollars monthly.

Even when the DSA provides a legal pathway for access, the technical requirements act as a deterrent. Iamnitchi reports that most platforms require data to be stored on infrastructure that cannot be compromised—such as machines physically disconnected from the internet—a resource most universities simply do not possess.

Furthermore, the platforms are utilizing narrow interpretations of "systemic risk" to deny applications. Even for those who secure approval, the quality of the data is suspect. L. K. Seiling, coordinator of the DSA40 Collaboratory, warns that there is no guarantee the data provided is accurate. Iamnitchi adds that API data is often impossible for colleagues to reproduce, violating a basic requirement of scientific research.

**The Data Divide**

The disparity in how platforms handle these mandates is stark. Data from the DSA40 Collaboratory, which tracks 46 applications, shows a fragmented landscape of approval. While TikTok approved 11 of 13 tracked applications, X rejected 11 of 23. Seiling notes that because the tracker relies on voluntary reporting, the actual rejection rate is likely higher.

TikTok has attempted to frame its compliance as a success. A spokesperson told Ars Technica that the company has granted access to over 1,500 research teams and approved 130 EU applications in the latter half of last year. The company highlights a daily quota of 1,000 API requests, allowing researchers to pull up to 2 million follower records or 100,000 video and comment records daily. However, Allen argues that such caps make it "impossible to study anything at scale."

**Opinion: The Illusion of Transparency**

In my view, the current state of DSA implementation is a failure of will, not a failure of law. When a platform can deny a request from a university chair during a national election crisis, only to later admit to a massive coordinated fake engagement network, the "transparency" promised by the DSA is revealed as an illusion.

By setting technical bars that universities cannot meet and implementing API caps that prevent scale, Big Tech is effectively opting out of the law's intent while maintaining the appearance of compliance. If the EU does not move from passive oversight to aggressive enforcement of these data mandates, the DSA will not be a tool for democratic protection—it will be a bureaucratic shield for the platforms to continue operating in the dark.

Without a standardized, enforceable mechanism for data delivery, the "black holes" of recommendation algorithms and sensitive content handling will only grow, leaving society blind to the next coordinated disinformation campaign.

Sources

More from Diana Vasquez