Issue #171

How a $145M Fine Opened X's Researcher Data

Even with a legal right to it, a professor couldn't get TikTok's data—until a massive fine cracked open X's instead.

BusinessHow a $145M Fine Opened X's Researcher Data

The day a TikTok account suddenly started pushing a politician

Ahead of Romania’s presidential election in November 2024, TikTok accounts that had spent years posting nothing but nail art and fashion content suddenly started pushing an obscure politician: Călin Georgescu. His posts, from a candidate who’d been polling in the single digits, racked up 120,000,000 views before the vote — and he came out on top in the first round with 23% of the vote.

Adriana Iamnitchi, a professor at Maastricht University in the Netherlands, wanted to study this. Who made this content, and how did they monetize it? So she requested data from TikTok under a right guaranteed by EU law. She was refused.

She already had the legal right to demand the data — she just never got it. In a separate case involving X, a roughly ₩200,000,000,000 (~$145M) fine was followed by a remediation plan promising to fix the platform’s researcher-access process. And Korea, where you live, hasn’t even gotten to the stage of writing researcher access rights into law yet.

What ₩200 Billion Bought

On July 15th, the European Commission accepted X’s remediation plan. The gist: streamline the vetting process for qualified researchers and sharply cut processing times, provide data free of charge, and revise the terms of service that had contractually barred researchers from independently collecting public data. The deadline for implementation is six months, subject to an independent external audit.

Let’s count how long it took to get here. In April 2023, X was designated a Very Large Online Platform1, and that December the EU opened a formal investigation. Then, on December 5th, 2025, the Commission fined X €120 million — roughly ₩200 billion (~$144 million) — the first penalty issued under the Digital Services Act2.

There were three grounds for the fine, though the one most widely reported was the “deceptive blue-check design.” But the other two are today’s subject: an opaque ad repository that made verification impossible, and a failure to provide researchers with access to public data. X’s terms, in particular, had prohibited qualified researchers from independently collecting data at all.

X didn’t simply concede, either. On February 20th of this year, X appealed the decision, arguing the investigation had been incomplete and superficial and that the EU had violated its rights of defense and due process. The appeal and the negotiations over the remediation plan proceeded in parallel even after the fine was imposed. The remediation plan came only after that.

To sum up: 2 years and 7 months elapsed between the start of the investigation and the acceptance of the remediation plan. In that span, Romania’s presidential election was annulled and a rerun had to be held. Whether X’s plan actually translates into real data access won’t be clear until the implementation deadline passes. And it doesn’t resolve the TikTok research request I mentioned earlier, either.

The Law Was Already There — So Why Couldn’t Researchers Get the Data?

It’s not that there was no law to see the data by. The EU’s law was, by global standards, ahead of its time.

Article 40 of the Digital Services Act formally enshrines the right of vetted researchers to access platform data. The provision allows researchers to request data if they’re studying systemic risks — things like the spread of illegal content or distortion of electoral processes. In July 2025, a delegated act3 laying out detailed procedures was adopted, and when it took effect that October, the scope expanded to include even non-public internal data. A data access portal for applications was also set up.

But here’s what actually happened in practice.

First, the security requirements didn’t match universities’ reality. Most platforms require data to be stored on “tamper-proof infrastructure” — meaning equipment physically disconnected from the internet. Not many universities have facilities like that.

Second, approval rates varied wildly by platform. Of 46 applications tracked by Germany’s DSA40 collective, 20 were approved and 14 were denied — but TikTok approved 11 of 13 requests, while X denied 11 of 23. The group’s organizers note, though, that since this tracking relies on researchers voluntarily reporting their own cases, the actual denial rate is likely higher.

Third, even getting approved was no guarantee the data would actually be usable. Data received via API is often difficult for fellow researchers to reproduce. Reproducibility is a basic condition of science, and here it was on shaky ground.

And there’s one more problem that’s proven the hardest to solve — a “data catch-22” that even the delegated act couldn’t fix. Researchers have to specify exactly what data they need in their applications. But to know what you need, you first have to see what’s inside. And there’s no reliable way to confirm whether the list of data a platform submits is actually complete. In the end, pinning down what data you need requires first knowing what exists internally — but there’s no channel to find that out.

lockThat left two paths. Scraping4 whatever the platform allows on-screen, or litigation. In fact, a German research organization applied for X’s data in April 2024, was denied, and filed suit in February 2025. The court ruled that X should have granted access — but this time, the case hit a new wall over research into Hungary’s elections. A Berlin court ruled that the suit should have been filed in Ireland, where X’s headquarters is located, nearly killing the case before it was overturned on appeal. It’s only natural that people are starting to doubt whether risking a lawsuit every single time you apply is really a sustainable way to do this.

Of course, it’s worth hearing the platforms’ side too. TikTok says it has provided tools to more than 1,500 research teams and approved 130 requests in the EU in the second half of last year alone. It says researchers can access up to 100,000 video and comment records, with a daily cap of 1,000 API requests. Meta counters that while CrowdTangle only covered a fraction of its public data, its replacement, the Content Library, is the most comprehensive research tool it has ever released. And it’s true that privacy protection and platform security are legitimate constraints.

One more thing worth noting. On X’s current remediation plan, the Digital Services Board — made up of regulators from member states — issued an opinion that it was, on the whole, inadequate. Yet the Commission accepted the plan anyway, saying it would strengthen enforcement oversight instead. In other words, a plan its own regulatory advisory body deemed insufficient went through as-is. Whether researchers actually get their hands on the data six months from now remains to be seen.

So Where Does Korea Stand

This month, Korea also rolled out a system that imposes disinformation-response and transparency obligations on platforms.

On July 7th, the amended enforcement decree of the Information and Communications Network Act (Korea’s core internet regulation law) cleared the State Council meeting, and the very next day, on the 8th, the Broadcasting Media Communications Commission designated and notified the platforms subject to it. They are Naver, Kakao, Nate, DCInside (a large Korean online community), and Google, Meta, X, and TikTok. The targets are social media, online communities, and video-sharing services with an average of 1,000,000 or more daily users. Search engines and open markets were included at the legislative notice stage, but they were dropped from the final version.

Here are the obligations these operators now bear: set up procedures for receiving and processing disinformation reports; establish self-governing operational policies; publish transparency reports. They’re required to sign agreements with fact-checking organizations that comply with the code of principles of the International Fact-Checking Network, and a transparency center has been set up to support this.

This is where the difference from the EU shows up. In Korea’s system, the verifying parties are the platforms themselves and the designated fact-checking organizations. The platform writes its own report, and the partnered organization judges the veracity of individual pieces of information. By contrast, this amendment includes no legal pathway for independent researchers to directly access the raw data.

In the Romania case, it was TikTok itself that ultimately exposed the existence of the manipulation network. Two months later, it classified 116,000 accounts as suspicious and announced that it had taken action against more than 27,000 fake accounts. But TikTok also stated that it didn’t know who ran the network or where it had originated. When all you have is the platform’s own self-reporting with no external verification, that’s the limit of what we can know.

So how would a researcher in Korea today go about studying opinion-manipulation patterns on a domestic platform? With no legal basis to compel access, three options remain: forming an individual cooperative relationship with the platform, scraping publicly visible screens, or reading the reports the platform chooses to publish on its own. The first two depend entirely on the platform’s goodwill and terms of service, and the last amounts to nothing more than quoting whatever the platform has already announced. Unlike the friction EU researchers experienced—which at least left behind a “record of being denied”—here, the application itself never even gets off the ground.

Worth noting, too, is the divide between how public data and private platform data are treated. In June 2026, Korea promulgated the National Research Data Act, establishing that data produced through national R&D projects should, in principle, be made public. Data generated by the public sector is being opened up. But the data of private platforms—where public opinion is actually formed—remains outside that conversation entirely.

Oswarld’s Lens

I read this story less as regulatory news and more as a case of a system that was built but never actually used in the field.

There’s something I’ve confirmed over and over while building GTM strategy: there’s always a big gap between shipping a feature and that feature actually being used. When you open up an entitlement and nobody uses it, it’s usually not because the entitlement doesn’t exist — it’s because people drop off, one by one, at every step required to actually use it. If you draw the pathway the EU created as a funnel, it looks like this: know your right, write the application, meet the security requirements, wait for review, get approved, receive usable data. The process can stall at any point between application and data receipt. Those earlier figures — 20 approvals out of 46 cases — are a tally of application outcomes, not a number showing that half of applicants dropped off at the final stage. This needs to be treated like product operations: identify where the funnel breaks down at each step, and fix it there.

That’s why I look at implementation design more than whether a legal clause exists on paper. Are the requirements within the operational capacity of people on the ground? Is there a defined processing deadline? Is there any recourse against a denial besides litigation? In this X case, what actually moved X wasn’t Article 40, the rights provision — it was the fine. That means X only started saying it would improve data access once the cost of stonewalling became greater than the cost of cooperating.

One more thing, from someone who’s spent a career working with data: a number that can’t be verified from the outside isn’t a confirmed fact — it’s just a company’s claim. When a platform says “we deleted 27,000 fake accounts,” if there’s no third party who can verify that figure, all we actually have in hand is the company’s press statement. Worry about algorithms swaying elections keeps growing, yet the only party that can actually look inside that algorithm is the company that built it. This exact situation is playing out in Europe and Korea at the same time.

Closing

First, the EU wrote researcher data access into law, but on X it took more than two years for the process — investigation, sanctions, and finally acceptance of a remediation plan — to play out. Even with the right on the books, security requirements and review procedures meant researchers still couldn’t actually get the data.

Second, what pushed X to improve data access wasn’t the provision itself but a fine of ₩200 billion (~$144M). And that’s not the end of it: even the regulator’s own advisory body judged X’s remediation plan inadequate, so we’ll need to watch whether it’s actually implemented over the next six months.

Third, Korea imposed transparency obligations on 8 platforms this month, but independent researcher access wasn’t part of the design. What the EU case tells us is that writing a right into law isn’t enough — you have to look at the implementation design alongside it.

Have you ever designed or requested data access permissions inside your own organization? If you’ve had access approved on paper but couldn’t actually use it — or if you built something that made it actually work — tell me about it in the comments. Data access inside organizations and platform regulation share the same problem: having the right doesn’t mean you can actually use it. If enough stories come in, I’ll pull together the common threads in the next issue.


📨 If you have a colleague who works on platform regulation or data governance, pass this along to them.


The English draft matches the Korean source accurately with no distortions, omissions, or glossary violations. Only one minor issue: “Broadcasting Media Communications Commission” is a fictional/placeholder-looking Korean institution name that should be verified, but the translation approach (romanized with English descriptive title) is acceptable per the glossary rules since no official English name is provided in glossary.csv.

Your take shapes the next issue

What resonated most in this issue, or where has your experience been different?

Any registered reader can comment for free.

References & Further Reading

Primary sources

  • WIRED, “European Researchers Say Big Tech Is Blocking Access to Their Data”, 2026. ··· This is the article that sparked today’s piece. It carries direct quotes from Professor Iamnitchi and a DRI researcher, letting you see the friction on the ground that institutional documents alone don’t reveal.
  • European Commission, “Commission fines X €120 million under the Digital Services Act”, 2025.12.5. ··· This is the primary source for the fine decision. Worth checking the original to see exactly which provisions each of the three violations fell under.
  • European Commission, “Commission accepts X’s action plan to comply with Digital Services Act”, 2026.7.15. ··· This is the concrete list of corrective measures X committed to. You can use it as a checklist to verify implementation six months later.
  • Iamnitchi, A., “If at first you don’t succeed: reflections on a rejected Art. 40 DSA data access request”, DSA Observatory, 2026.3.12. ··· This is a firsthand account written by a rejected researcher. It’s the most concrete source available, laying out step by step exactly where the application process broke down.
  • Broadcasting Media Communications Commission (Korea), “Enforcement Decree and Guidelines of the Network Act on Preventing the Distribution of Illegal and False/Manipulated Information”, 2026.7. ··· This is the original text of Korea’s regulatory framework. Search for the word “researcher” in the list of obligations, and the point of today’s piece becomes immediately clear.

Background

Past issues worth reading alongside this one


Illustrated portrait of Kwangseob Ahn (Oswarld)

The author is Oswarld (Kwangseob Ahn). Current roles: Adjunct Professor at Sejong University, Strategy Consultant at INLEVEL9. Career, research, books, and recent work are kept current on the About page. Latest · July 2026: HEMA-2: A Consolidation-Aware Tri-Memory Architecture with Multi-Channel Scheduling for Lifelong Conversational AI.

📝 Glossary

Footnotes

  1. Very Large Online Platform (VLOP): A service with more than 45 million average monthly users in the EU. Landing on this list brings far heavier obligations — risk assessments, external audits, and providing data access to researchers.

  2. Digital Services Act (DSA): The EU’s law regulating online platforms, enacted in 2022. It’s notable for bundling together responses to illegal content, advertising transparency, and algorithmic accountability.

  3. Delegated act: A subordinate regulation where the higher-level law sets only broad principles, delegating detailed procedures to the Commission. Think of it as playing a role similar to an enforcement decree in Korea’s legal system.

  4. Scraping: A method of programmatically collecting content visible on webpages. Since it isn’t an official channel like an API, the scope of what can be gathered is limited — obtaining something like an account’s entire follower list, for instance, is difficult.