The Lawxy Times
On 1 October 2026 the European Commission announced that regulators may access ChatGPT data under the Digital Services Act. The announcement clarifies that such access is permissible only when necessary, proportionate and compliant with data‑protection rules. AI providers operating in the EU must now prepare for regulator and vetted‑researcher data requests, facing risk of non‑compliance. The statement does not resolve whether private user conversations are included.
Full News Breakdown
The European Parliament’s inquiry by MEP Christine Anderson into the scope of regulator‑initiated data requests triggered a Commission clarification. The Commission affirmed that the regulatory framework allows data access for compliance monitoring, but left the precise reach regarding private conversations open. It set out a three‑part safeguard test – necessity, proportionality and data‑protection compliance – that must be satisfied before any request is honoured.
Case Name: Commission statement on regulator access to ChatGPT data
Date: 1 October 2026
Citation: Official Statement, European Commission, 2026
EU Instruments / UK Legislation Cited: Digital Services Act, General Data Protection Regulation
Key Provisions: DSA Art. 29 (risk‑assessment and mitigation), DSA Art. 30 (audit and data‑access), GDPR Art. 6 (lawfulness of processing), GDPR Art. 9 (special‑category data)
Primary Legal Issue: Scope of regulator‑initiated data access for generative‑AI services under the DSA while respecting GDPR safeguards
Applicant/Plaintiff Arguments: MEP Anderson argued that regulator access would breach privacy and exceed the powers granted by the DSA.
Respondent/Defendant Arguments: The Commission contended that the DSA expressly permits limited data access for compliance purposes, provided the three‑part safeguard test is met.
Court's Reasoning: Not applicable; the Commission based its view on the text of the DSA and the data‑protection principles of the Regulation.
Holding: Regulators may request data from AI services under the DSA, subject to necessity, proportionality and data‑protection safeguards.
Operative Order: AI providers must establish procedures to receive, evaluate and securely transmit data in response to qualified regulator or vetted‑researcher requests.
Practical Outcome: Providers face an immediate compliance obligation to design technical and organisational measures for lawful data disclosure.
How Does This Affect You?
Before the Commission’s clarification, the legal basis for regulator‑driven data extraction from generative‑AI platforms was uncertain. The statement now confirms that such extraction is allowed, but only when the three‑part safeguard test is satisfied. This removes ambiguity for supervisory authorities and creates a concrete, proportionate‑test‑driven duty for AI providers, while leaving the exact treatment of private user conversations unresolved. The implications are explored below for lawyers, students and businesses.
For Lawyers & Advocates
Amend service‑level agreements with AI vendors to include a clause obliging the provider to comply with regulator‑initiated data requests that satisfy the necessity‑proportionate‑safeguard test.
Update internal data‑mapping inventories to identify which datasets fall within the scope of DSA Art. 29 and can be lawfully disclosed, reducing the risk of inadvertent over‑disclosure.
Draft standard operating procedures for responding to regulator or vetted‑researcher requests, specifying verification steps, data minimisation measures and documentation of the proportionality assessment.
Leverage the Commission’s three‑part test as a defensive argument in disputes where a regulator’s request is alleged to be excessive, citing the explicit safeguard requirements.
Advise clients on the residual risk that private conversation data may still be deemed inaccessible, prompting the need for additional privacy‑by‑design safeguards in product development.
For Law Students
The case illustrates how EU regulators interpret ancillary powers within a regulatory framework that balances market oversight with fundamental rights.
The core doctrinal distinction concerns the interplay between a sector‑specific regime (the DSA) and the overarching data‑protection regime (the Regulation).
The decision is particularly relevant for the study of:
EU regulatory competence in the digital single market
Data‑protection law and the principle of proportionality
Administrative law: limits on supervisory authority powers
Comparative analysis of sector‑specific versus general‑purpose legislation
Risk‑assessment obligations for very‑large online platforms
Comparable cases include Schrems II (C‑311/18, CJEU 2020) and Google Spain (C‑131/12, CJEU 2014). Comparing them shows how the Court balances fundamental rights against cross‑border data flows, illuminating the doctrinal tension between market‑regulation objectives and privacy protections.
For Businesses
Cloud‑based AI service providers must implement a secure data‑request portal that logs regulator identifiers, request timestamps and the proportionality assessment, or risk enforcement action.
Companies that embed ChatGPT‑like tools in customer‑facing applications should revise their privacy notices to disclose the possibility of regulator‑mandated data disclosure under the three‑part test.
Boards of directors of large tech firms should commission a gap analysis of current data‑retention policies against the DSA’s risk‑assessment obligations, ensuring that any data earmarked for possible regulator access is stored in a readily extractable format.
Enterprises handling special‑category data through generative‑AI must conduct a DPIA that explicitly addresses regulator‑access scenarios, otherwise they may face fines for non‑compliance with the data‑protection safeguards.
Key Takeaways
Regulators now have a clarified, conditional right to request data from generative‑AI services under the DSA, subject to a necessity‑proportionate‑data‑protection test.
Service‑level agreements and internal SOPs must be updated to incorporate verification and proportionality steps before any data is disclosed.
Supervisory authorities can issue data‑access orders only after demonstrating that the three‑part safeguard test is satisfied; they cannot rely on a blanket request power.
Watch for the European Parliament’s upcoming amendment proposal to DSA Art. 29, expected in early 2027, which may tighten the proportionality threshold.
In‑house counsel should audit AI‑related contracts and data‑handling procedures before the end of Q2 2027 to ensure compliance with the new regulator‑access framework.
Source: ChatGPT data access under EU digital rulebook subject to safeguards, Commission says

