Adriana Iamnitchi’s team asked TikTok for data access on Oct. 28, 2025. They were told no. Two months later, TikTok itself flagged 116,000 accounts as potentially compromised and took action against more than 27,000 fake accounts in a coordinated network pushing a Romanian presidential candidate.
The researchers who might have traced who built and profited from that network never got to look.
That gap is the story. Not the fake accounts. The fact that the people legally entitled under EU law to study them couldn’t get in the door.
What happened in Romania, and how late everyone was
In the final weeks before Romania’s presidential vote in November 2024, TikTok accounts that had spent years posting about manicures or fashion abruptly pivoted to promoting a little-known politician named Calin Georgescu.
His posts, pushing hard-line views on immigration and anti-Semitic tropes, were viewed 120 million times before the vote. Georgescu had been polling in the single digits. He won the first round with 23 percent.
The network behind the boost was run by a third-party “fake engagement vendor” promoting Georgescu and his party, the Alliance for the Union of Romanians. TikTok said it did not know who operated the network or where it originated.
The first round was annulled. In the May 2025 runoff, independent candidate and former Bucharest mayor Nicușor Dan beat AUR’s George Simion, who took over the party after Georgescu was barred from running again. Georgescu said on his YouTube channel that annulling the 2024 results was “practically a formalized coup d’état” by Romania’s Constitutional Court.
Declassified Romanian intelligence showed he “benefited” from massive exposure and preferential treatment by TikTok, and that Russia had allegedly coordinated the online campaign to elect him.
The rejection letter
Iamnitchi chairs computational social sciences at Maastricht University in the Netherlands and leads its research into disinformation campaigns. She wanted to know how pro-Georgescu content was being monetized on TikTok through hidden influencer marketing and livestreamed political content.
Her team applied for TikTok API access under the EU's Digital Services Act. TikTok said they had failed to prove they were established researchers, or to explain their commercial interests, or to meet security requirements, Iamnitchi wrote in a blog post.
She believes her team might have identified who created and profited from the pro-Georgescu content had they gotten the data.
“If you are a scholar interested in how social media shapes society, the past years have been tough,” she wrote. “When you need data to investigate that impact, and that data is privately held, it can become practically impossible to research this space.”
The numbers behind the approval process
The DSA40 Collaboratory, a German initiative, tracks 46 DSA applications. Of those, 20 were approved and 14 rejected. The split by platform tells you more than the total: TikTok approved 11 of 13 applications. X rejected 11 of 23.
The real rejection rate is likely higher, because the tracker depends on voluntary reporting, said L. K. Seiling, the Collaboratory’s coordinator.
“There’s no structured advantage for researchers to use this pathway,” Seiling said. “Data access as it’s set up right now tries to disincentivize researchers.”
Approval isn’t the finish line either. “There’s no guarantee that the data is good,” Seiling said. API data is often difficult for a colleague to reproduce, so a researcher’s work can’t be checked for errors, which Iamnitchi said is a “basic requirement of science.”
A security requirement most universities can’t meet
Application forms differ by platform, but most require data to be stored on infrastructure that cannot be compromised, such as a machine physically disconnected from the Internet. Iamnitchi said most universities don’t have that.
Read that requirement next to the daily caps and the shape of the problem gets clearer. TikTok limits how many posts any researcher account can pull per day, which Duncan Allen, a research officer at Democracy Reporting International in Germany, said can make it “impossible to study anything at scale.”
Meta shut down CrowdTangle and replaced it with content libraries. X paywalled its API, forcing academics to pay “hundreds of dollars a month,” Allen said. Without API access, what Iamnitchi calls the “black holes” in what society knows about how platforms recommend content or handle sensitive-content reports only get bigger.
The platforms’ side
A TikTok spokesperson said the company has given more than 1,500 research teams access to its tools and approved 130 applications in the EU in the second half of last year. Its daily quota of 1,000 API requests lets researchers pull up to 100,000 video and comment records a day, or up to 2 million follower records. TikTok said it considers its research tools compliant with the DSA but “would welcome further public guidance.”
A Meta spokesperson said CrowdTangle covered only a fraction of the company’s public data, while the Meta Content Library and API that replaced it are “the most comprehensive research tools to date.” They cover Facebook, Instagram, WhatsApp Channels and Threads with “robust privacy protections,” and qualified nonprofit researchers, including journalists, can apply.
Scraping is the fallback, and it doesn’t work
Iamnitchi and Allen both resort to scraping on platforms that allow it, exporting website data into spreadsheets. It’s slow. And even with sophisticated tools, scraping “is not very comprehensive,” Allen said.
Here’s the specific failure: it can’t capture an account’s complete follower list. Without the follower graph, you can’t map a coordinated network. You can see the posts. You can’t see the machine.

Suing your way to a dataset
DRI and the Society for Civil Rights applied for X API access in April 2024 to study political discourse ahead of Germany’s federal election. X rejected the request in November. DRI sued in February 2025.
The court ruled X should have granted access, which DRI thought might be precedent-setting. Months later they were back in court after X denied access for research ahead of Hungary’s election. That case nearly collapsed when a Berlin court ruled the researchers should have sued in Ireland, where X is based. DRI won on appeal.
“EU law is still not uniformly applied,” Allen said of the Hungarian case. “It’s cost us a lot of time and energy, and there is an ongoing calculus of whether or not it’s worth having these lawsuits every time we apply for data access.”
That last sentence is the quiet cost. Every application now carries an implied litigation budget.
A €120 million fine and a six-month clock
In December 2025 the European Commission imposed its first DSA penalty, fining X €120 million ($137 million) partly for creating “unnecessary barriers” to researcher access that “effectively undermin[e] research into several risks in the European Union.”
X appealed on Feb. 20, 2026, calling the investigation “incomplete and superficial” and accusing the EU of “systemic breaches of rights of defence and basic due process requirements.”
Last week the commission accepted X’s action plan to fix the researcher screening process, provide data free of charge, cut processing times and lift restrictions on data scraping. X has six months to implement.
Allen called the plan “a step in the right direction” but is skeptical about implementation. He wants X to say specifically how it will improve the vetting process that decides who qualifies for API access.

The provision worth watching
The commission has said in a separate DSA investigation that Meta and TikTok “may have put in place burdensome procedures and tools for researchers to request access to public data,” leaving them with partial or unreliable data. It started meeting with platforms in May to build a new vetting standard.
Late last year it also expanded researcher access to nonpublic platform data covering illegal content, financial scams and recommender systems. Those provisions haven’t been tested yet.
The one to watch is follower data. New rules on nonpublic data could force X to release an account’s full follower list, Allen said, which would let researchers map which accounts interact with or follow one another and how they amplify content. That’s the exact capability scraping can’t deliver, and the exact capability Iamnitchi needed in Romania and didn’t have.
Two years after the DSA took effect, the law that was supposed to make this data available has produced 20 approvals, one fine under appeal and a running tab of legal fees. The DSA didn’t fail on paper. It’s failing at the intake form.