Art. 4 Directive 2019/790: Why TDM for Commercial Purposes Is Legally Sounder Than Most Teams Assume
There is a persistent assumption in legal and data teams alike: that Text and Data Mining on publicly accessible sources for commercial purposes sits in a legal grey zone. It does not. The framework is explicit, and it has been in force since 2019. The actual risk lies not in the activity itself, but in how poorly organizations understand the conditions that govern it.
Art. 4 of Directive (EU) 2019/790 establishes a general TDM exception — one that applies to any natural or legal person who has lawful access to a work or other subject matter. Unlike Art. 3, which is restricted to research organizations and cultural heritage institutions, Art. 4 carries no institutional gate. A commercial entity processing publicly accessible signals from the open web operates within this framework by default, provided the access itself is lawful and no valid opt-out mechanism has been invoked.
That combination — lawful access plus no opt-out — is where most analytical teams stop reading. It should be where the real operational work begins.
Lawful Access Is a Condition, Not a Formality
"Lawful access" is not a bureaucratic checkbox. It defines the entire perimeter of the exception. If the source being processed is publicly accessible — indexed, open, not behind an authentication wall — and the processing entity has not circumvented any technical access control, lawful access is established. This is the baseline.
What it does not cover: accessing content that requires credentials you do not hold, bypassing rate limits set as access controls, or processing material from sources that have explicitly excluded third-party processing through technical means. The line is functional, not contractual. Courts are increasingly reading Terms of Service as enforceable instruments, but the directive itself frames lawful access in terms of actual technical access conditions, not ToS language alone.
For teams doing analysis on the universe of public Internet sources, the practical implication is operational hygiene: document what you access, how you access it, and under what conditions. The exception does not require prior authorization. It does require that access is structurally lawful.
The Opt-Out Clause: Where Rightsholders Hold Real Power
Art. 4(3) introduces the mechanism that actually shifts the balance: rightsholders can reserve their works from TDM processing, provided that reservation is expressed "in an appropriate manner, such as machine-readable means in the case of content made publicly available online."
This is not a theoretical provision. Several major publishing ecosystems have already deployed robots.txt extensions and structured metadata directives explicitly invoking TDM opt-outs. When a valid opt-out is in place and machine-readable, the Art. 4 exception no longer applies to that source.
The implication is structural, not just legal. Any analytical infrastructure that treats all publicly accessible sources as interchangeable is operating on a flawed assumption. The composition of the accessible universe changes as publishers update their opt-out declarations. That change is not always announced. A source that was in scope six months ago may not be in scope today.
This is precisely where monitoring the opt-out landscape becomes an operational requirement, not an optional compliance exercise. The analytical output depends on knowing, at any given moment, which signals are within the legal perimeter.
Reproducibility vs. Derived Analysis: The Distinction That Matters
One area where legal and technical teams consistently diverge is in understanding what TDM actually produces under Art. 4. The exception covers the act of mining — the automated processing of text and data to extract patterns, trends, correlations, and derived insights. It does not authorize the reproduction or redistribution of the source content itself.
This distinction has direct product implications. Derived analysis — trend signals, mention patterns, sentiment distributions, entity co-occurrence maps — is the legitimate output of TDM under the directive. A database of verbatim content excerpts from third-party sources is a different legal object entirely, regardless of how it was assembled.
Organizations that conflate the two create a compliance exposure that the exception does not protect. The mining is covered. The reproduction is not.
At TrawlingWeb, the entire processing architecture is built around this distinction. What the infrastructure produces is analytical output derived from publicly accessible signals — not a content store, not a redistribution layer. That separation is not incidental. It is the structural condition that keeps the operation within the Art. 4 perimeter.
Cross-Jurisdictional Gaps Still Exist and They Are Not Symmetric
Directive 2019/790 required transposition by member states by June 2021. Most have done so. But transposition is not harmonization. Member states retained discretion in how they implemented certain provisions, and the opt-out regime in particular has been transposed with meaningful variation.
In the Spanish legal system, the equivalent framework appears under Art. 67 bis of the Ley de Propiedad Intelectual (LPI), which follows the directive closely but operates within a national enforcement context. For operations that touch sources across multiple EU jurisdictions — as most large-scale analysis of the public Internet does — the assumption that "EU compliance" is a single state is operationally wrong.
The practical exposure is not usually in the mining exception itself. It is in the interaction between the exception and national rules on database rights, neighboring rights, and enforcement mechanisms, which vary enough to require jurisdiction-specific assessment for high-volume or high-sensitivity use cases.
What Operationally Sound TDM Compliance Looks Like
Legal soundness under Art. 4 is not a one-time assessment. It is a process with at least three ongoing components:
Source perimeter review. The set of publicly accessible sources in scope should be reviewed against known opt-out declarations on a regular cadence. New declarations appear without notice. The perimeter is not static.
Access methodology documentation. The technical means by which sources are accessed — protocols, frequency, access controls respected — should be documented in a way that can demonstrate lawful access if challenged. This is internal governance, not public-facing compliance theater.
Output classification. Every analytical product derived from TDM should be classifiable as derived analysis, not content reproduction. If the output cannot be clearly separated from the source material by that test, the product design has a structural problem that legal framing cannot solve.
Art. 4 of Directive 2019/790 is not ambiguous in its intent. Commercial TDM on lawfully accessed public sources is a recognized, protected activity. What organizations consistently underestimate is the operational discipline required to stay within the conditions that make the exception work. The directive gives you the room. It does not do the compliance work for you. That part is an infrastructure and governance problem — and it is one worth solving properly before it becomes a litigation problem.
For more on how TrawlingWeb structures its processing within this legal framework, the product documentation outlines the analytical architecture in detail.