Executive summary
On 16 July 2026, the European Commission announced that it had accepted X’s action plan concerning transparency obligations and researchers’ access to data under the Digital Services Act.
The plan follows a Commission decision finding X in breach of the DSA and imposing a fine in December 2025. X committed to improve its advertising repository and researcher-access procedures. An independent external audit is expected after implementation.
The European Board for Digital Services had considered the proposed changes only partially adequate and viewed the audit measures—and therefore the overall plan—as insufficient. The Commission nevertheless accepted the plan after clarifying points to be addressed during implementation.
This creates a precise institutional question: what does acceptance mean when a consulted oversight body has found the plan insufficient?
Acceptance is not completed compliance
The Commission’s announcement describes a staged process:
- a breach decision;
- proposed corrective measures;
- consultation with the Board;
- acceptance of the action plan;
- a six-month implementation period;
- an external audit;
- Commission monitoring and possible further action.
The acceptance decision therefore appears to approve a route toward compliance, not certify that the underlying infringements have already been remedied.
Public communication should preserve this distinction.
Core forensic question
Which legal and evidentiary threshold did the Commission apply when it accepted a plan that the Board considered insufficient?
A reviewable file should explain:
- the Board’s specific objections;
- the additional clarifications obtained;
- whether the plan itself was amended;
- which obligations remain unfulfilled until implementation;
- the conditions attached to acceptance;
- the consequences of delayed or incomplete implementation.
Expected evidence matrix
| Issue | Evidence needed |
|---|---|
| Advertising repository | Search tests, completeness checks, update speed and API performance |
| Researcher applications | Processing times, approval rates, refusal reasons and appeal paths |
| Data access | Availability, cost, technical usability and restrictions |
| Audit independence | Selection, mandate, conflicts safeguards and access to underlying systems |
| Implementation | Milestones, deadlines and verified completion records |
| Board concerns | Published opinion and Commission response to each concern |
| Enforcement | Conditions, monitoring actions and consequences for non-compliance |
Researcher access in practice
Formal availability of data is not the same as effective access.
A meaningful evaluation should measure:
- how many eligible researchers apply;
- how long screening takes;
- how many applications are approved or refused;
- whether refusal reasons are specific and reviewable;
- whether data formats are usable;
- whether access is free in practice;
- whether contractual terms restrict lawful research;
- whether scraping of public data is technically blocked;
- whether researchers can reproduce platform-risk findings.
Advertising repository test
The repository should be evaluated against real research tasks:
- Can users search by advertiser, content and targeting criteria?
- Are removed or expired advertisements retained as required?
- Are political or issue advertisements identifiable?
- Are targeting and reach data complete?
- Does the API return the same information as the public interface?
- Can independent researchers detect missing records?
- Are updates timely enough to support election monitoring?
Quantitative-formalism risks
Potentially misleading indicators include:
- number of advertisements in the repository without a completeness estimate;
- number of approved researchers without the number of applicants;
- average response time without distribution or delayed cases;
- number of API calls without evidence of data quality;
- completion of an audit without publishing findings or methodology;
- acceptance of a plan presented as proof of compliance.
Alternative explanations
The Commission may accept a plan that is not yet fully implemented when it contains enforceable commitments and a credible path to correction.
The Board’s opinion is consultative within the described process, and the Commission may lawfully reach a different assessment. Additional clarifications may have resolved some concerns.
However, where the final decision differs from an expert body’s assessment, transparency requires a reasoned explanation of the divergence.
Preliminary finding
The case illustrates the difference between procedural acceptance and substantive outcome.
The action plan should be assessed after implementation through independent tests of repository completeness, researcher access, audit quality and corrective results. Until then, the correct description is that X has an accepted remediation plan—not that compliance has been demonstrated.
Recommended Civic Forensics modules
- Analysis of Institutional Conduct
- Document Comparison
- Quantitative Claims Module
- Detector of Quantitative Formalism
- Expected Evidence Trace Plan
- Institutional Integrity Index
Source
European Commission, Commission accepts X ’s action plan to comply with Digital Services Act, 16 July 2026: https://digital-strategy.ec.europa.eu/en/news/commission-accepts-xs-action-plan-comply-digital-services-act
Limitations
This analysis is based on the Commission’s public announcement. It does not independently assess the confidential action plan, the Board’s complete opinion, X’s technical systems or the future external audit.