Big Tech Accused of Stonewalling European Social Media Researchers

FIRST SEEN 2026-07-29 · VERSION 20260729_rev01 · COMPARED WITH 20260725_rev01

Full text changes — 20260725_rev01 to 20260729_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1DSA denials
2
3Researchers say TikTok, X, and Meta aren't providing data they're legally required to.
4
5In the final weeks before Romania's presidential vote in November 2024, [TikTok](https://www.wired.com/tag/tiktok/) accounts that had previously spent years posting about manicures or fashion suddenly started promoting a little-known politician named Calin Georgescu.
6
7His posts, espousing hard-line views on immigration and anti-Semitic tropes, were viewed 120 million times before the vote. Georgescu, who had previously been polling in the single digits, stunned observers by winning the election's first round with 23 percent of the vote.
8
9In the Netherlands, Adriana Iamnitchi was watching closely. As chair of computational social sciences at Maastricht University, she leads the research into disinformation campaigns. She wanted to know how pro-Georgescu content was being monetized on TikTok through hidden influencer marketing and livestreamed political content.
10
11On October 28, 2025, a month before Georgescu won the first round, she and her team applied for access to TikTok's Application Programming Interface (API) under the EU's recent Digital Services Act (DSA).
12
13Their request was denied. TikTok said they had failed to prove they were established researchers or to explain their commercial interests or to meet security requirements, Iamnitchi [wrote in a blog post](https://dsa-observatory.eu/2026/03/12/if-at-first-you-dont-succeed-reflections-on-a-rejected-art-40-dsa-data-access-request/).
14
15But two months later, [TikTok flagged 116k accounts as potentially compromised](https://newsroom.tiktok.com/continuing-to-protect-the-integrity-of-tiktok-during-romanian-elections) before taking action against more than 27,000 fake accounts in a coordinated network run by a third-party "fake engagement vendor" that was promoting Georgescu and his party, the Alliance for the Union of Romanians (AUR). TikTok said it did not know who operated the network or where it originated.
16
17The first round of voting was annulled and in the runoff in May 2025, independent candidate and former Bucharest mayor Nicușor Dan beat AUR's George Simion, who took over the party after [Georgescu was barred](https://www.ccr.ro/wp-content/uploads/2025/09/Hotarare_7_2025.pdf) from running again. Georgescu said [on his YouTube channel](https://www.youtube.com/watch) that annulling the 2024 results was "practically a formalized coup d'état" by Romania's Constitutional Court.
18
19[Declassified Romanian intelligence](https://www.presidency.ro/files/userfiles/Documente%20CSAT/Document%20CSAT%20SRI%20II.pdf) showed he "benefited" from massive exposure and preferential treatment by TikTok and that Russia had allegedly coordinated the online campaign to elect Georgescu.
20
21Calin Georgescu
22
23Credit: Getty
24
25Calin Georgescu Credit: Getty
26
27Iamnitchi believes her team might have been able to identify who created and profited from the pro-Georgescu content had they gained access to the data. "If you are a scholar interested in how social media shapes society, the past years have been tough," she [wrote.](https://dsa-observatory.eu/2026/03/12/if-at-first-you-dont-succeed-reflections-on-a-rejected-art-40-dsa-data-access-request/) "When you need data to investigate that impact, and that data is privately held, it can become practically impossible to research this space."
28
29Iamnitchi is one of several misinformation researchers who told WIRED that, despite being legally entitled to obtain platform data under EU law, they face obstacles, obfuscation, and, in some cases, court battles to obtain it. Last year the law was broadened to increase researcher access, but it's the implementation, not the scope of the law itself, that researchers say is the issue.
30
31In recent years, social media companies shut down public access tools like [Meta's](https://www.wired.com/tag/meta/) CrowdTangle and replaced them [with content libraries](https://transparency.meta.com/researchtools/other-data-catalogue/crowdtangle/), or, like X, paywalled their [API data](https://docs.x.com/x-api/introduction), forcing academics to pay "hundreds of dollars a month," said Duncan Allen, a research officer at Democracy Reporting International (DRI) in Germany. Researchers say that without API access, what Iamnitchi describes as the "black holes" in what society knows about how these platforms recommend content or handle reports regarding sensitive content will only grow.
32
33Others, like TikTok, cap how many posts any researcher account can pull each day, which Allen said can make it "impossible to study anything at scale."
34
35[The DSA](https://www.eu-digital-services-act.com/Digital_Services_Act_Article_40.html) was meant to solve this by allowing vetted researchers at credible institutions to have access to API data if they could show it would help in studying systemic risks, from illegal content to threats to fundamental rights. But two years after the law took effect, researchers say they struggle to meet its security requirements and face narrow interpretations from platforms of what qualifies as a systemic risk.
36
37Application forms differ by platform, but most require data to be stored on infrastructure that cannot be compromised-such as a machine physically disconnected from the Internet-a resource most universities lack, Iamnitchi said.
38
39Even for researchers who secure approval, "there's no guarantee that the data is good," said L. K. Seiling, coordinator of the [DSA40 Collaboratory](https://dsa40collaboratory.eu/), a German initiative that tracks 46 DSA applications. API data is often difficult for a colleague to reproduce, so a researcher's work cannot be checked for errors, which Iamnitchi said is a "basic requirement of science."
40
41[DSA40 data](https://dsa40collaboratory.eu/) shows that of 46 tracked applications, 20 were approved and 14 rejected. But approval rates vary widely: TikTok approved 11 of 13 applications, while X rejected 11 of 23. The true rejection rate is likely higher because the tracker relies on voluntary reporting, Seiling said.
42
43"There's no structured advantage for researchers to use this pathway," Seiling said. "Data access as it's set up right now tries to disincentivize researchers."
44
45A TikTok spokesperson told WIRED the company has given more than 1,500 research teams access to its tools, approved 130 applications in the EU in the second half of last year, and that its daily quota of 1,000 API requests lets researchers pull up to 100,000 video and comment records a day, or up to 2 million follower records. TikTok said it considers its research tools compliant with the DSA but "would welcome further public guidance."
46
47A Meta spokesperson said CrowdTangle covered only a fraction of the company's public data, while the Meta Content Library and API that replaced it are "the most comprehensive research tools to date." They cover Facebook, Instagram, WhatsApp Channels, and Threads with "robust privacy protections," and qualified nonprofit researchers, including journalists, can apply.
48
49There are few workarounds. Iamnitchi and Allen said they resort to scraping on the platforms that allow it, a time-consuming process that exports website data into spreadsheets. Even with sophisticated tools, scraping "is not very comprehensive," Allen said. It cannot capture an account's complete follower list, making coordinated disinformation networks difficult to map.
50
51One way to challenge a rejected request is to take the platforms to court. Allen said DRI and the Society for Civil Rights applied for access to X's API in April 2024 to study political discourse ahead of Germany's federal election. X rejected the request in November, prompting DRI to sue in February 2025.
52
53The court ruled X should have granted access, in what DRI believed could become a precedent-setting case. But months later the organization was back in court after X denied access for research ahead of Hungary's election. That case nearly collapsed when a Berlin court ruled the researchers should have sued in Ireland, where X is based. [DRI won on appeal](https://freiheitsrechte.org/en/themen/freiheit-im-digitalen-zeitalter/x).
54
55"EU law is still not uniformly applied," he said, reflecting on the Hungarian case. "It's cost us a lot of time and energy, and there is an ongoing calculus of whether or not it's worth having these lawsuits every time we apply for data access."
56
57In December 2025, the European Commission imposed its first DSA penalty, [fining X €120 million](https://digital-strategy.ec.europa.eu/en/news/commission-fines-x-eu120-million-under-digital-services-act) ($137 million) partly for creating "unnecessary barriers" to researcher access that "effectively undermin\[e\] research into several risks in the European Union."
58
59On February 20, 2026, X appealed, [calling the investigation](https://x.com/GlobalAffairs/status/2024803983093629298) "incomplete and superficial" and accusing the EU of "systemic breaches of rights of defence and basic due process requirements."
60
61Last week, the [commission accepted X's action plan](https://digital-strategy.ec.europa.eu/en/news/commission-accepts-xs-corrective-measures-terminate-breaches-dsa) to fix the researcher screening process, provide data free of charge, cut processing times, and lift restrictions on data scraping. X has six months to put these changes in place.
62
63Allen called the plan "a step in the right direction" but remains skeptical about how it will be implemented. He wants X to be more specific about how it will improve the vetting process used to determine whether researchers qualify for API access under the DSA.
64
65The EU, having said in another DSA [investigation](https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2503) that Meta and TikTok "may have put in place burdensome procedures and tools for researchers to request access to public data," leaving them with partial or unreliable data, started [meeting with platforms](https://digital-strategy.ec.europa.eu/en/news/commission-holds-roundtable-data-access-vetted-researchers) in May to work on a new standard for vetting researchers.
66
67Late last year, [the commission](https://digital-strategy.ec.europa.eu/en/news/commission-adopts-delegated-act-data-access-under-digital-services-act) also expanded researchers' access to nonpublic platform data to study risks including illegal content, financial scams, and recommender systems. Researchers say the new provisions have yet to be tested, but they are cautiously optimistic.
68
69The new regulations on nonpublic data could force X to release an account's full follower list. This gives disinformation researchers a much clearer view of how coordinated attacks spread online, because they can use this data to map out which accounts interact or follow one another and how they amplify content, Allen says.
70
71_This story originally appeared on [wired.com](https://www.wired.com/story/european-researchers-want-to-study-social-medias-harms-but-cant-get-the-data/)._
72
73Wired.com is your essential daily guide to what's next, delivering the most original and complete take you'll find anywhere on innovation's impact on technology, science, business and culture.
74
75[2 Comments](https://arstechnica.com/tech-policy/2026/07/big-tech-accused-of-stonewalling-european-social-media-researchers/)
76
771.