Art. 4 Directive 2019/790: What the TDM Exception Actually Permits in Practice
Most organisations that rely on public data analysis have heard of Article 4 of Directive (EU) 2019/790. Far fewer have tested what it actually allows — or, more precisely, where it stops covering you.
That gap between knowing the label and understanding the operational boundary is where real risk lives. Legal teams tend to read Article 4 in terms of liability exposure. Data teams tend to ignore it entirely. Neither approach is adequate when the core of your product or research pipeline depends on processing publicly accessible content at scale.
This post is not a legal interpretation. It is a practical map of what Article 4 enables, what conditions attach to that enablement, and what happens when those conditions are not met.
What Article 4 Actually Says — Stripped of Abstractions
Article 4 of Directive (EU) 2019/790 establishes a copyright and database-right exception for Text and Data Mining carried out by any person — not just research organisations — provided that the works or content being processed have been lawfully accessed and that rights holders have not expressly reserved those rights in an appropriate manner.
Three elements define the boundary:
Lawful access: The content must be reachable through means that do not require bypassing technical restrictions. Access through open, publicly indexed sources falls within this framing. Access that requires circumventing authentication or paywalls does not.
No opt-out in place: Rights holders may reserve their rights explicitly — most commonly via
robots.txtdirectives or equivalent machine-readable signals. When a reservation exists and is detectable, Article 4 does not apply.Copies are instrumental: Temporary reproductions made in the course of TDM are covered. Storing and distributing the original content is not. The output of TDM — derived signals, aggregated patterns, structured datasets — is what the exception protects, not the intermediate copy of the source material.
These three conditions are not optional. They are the legal architecture of the exception.
The Opt-Out Mechanism: More Operational Than It Appears
The rights reservation clause is the element most frequently underestimated by data teams. Article 4 explicitly allows rights holders to opt out — and when they do, any TDM operation on that content loses its legal cover.
In practice, this means that a compliant TDM pipeline must:
- Read and honour machine-readable reservation signals at the point of access, not as an afterthought.
- Maintain a record of which sources carry active reservations and update that record as source policies change.
- Exclude opted-out sources from processing before analysis begins — not after.
This is not a passive obligation. It requires active source governance: a maintained inventory of sources, their access conditions, and their reservation status. Sources that had no opt-out in place six months ago may have one today. A static source list is a compliance liability.
The operational implication is significant. Source qualification is not a one-time setup task. It is a recurring process that must be embedded in the infrastructure, not delegated to a legal review that happens once a year.
Derived Output vs. Reproduced Content: The Distinction That Defines Everything
Article 4 covers the process, not the product as stored source material. This distinction is central to how compliant TDM workflows are designed.
What is covered: the analytical process that reads, processes, and extracts structured signals from lawfully accessed content. Frequency patterns, sentiment shifts, entity co-occurrence, topic clustering — these are derived outputs. They represent the result of analysis, not a reproduction of the source.
What is not covered: retaining verbatim content, distributing original text, or building systems whose value proposition rests on storing and serving the source material rather than the derived insight.
This is precisely why TrawlingWeb's architecture is built around derived analysis — not around redistribution of third-party content. The output of the pipeline — mentions, signals, structured trend data — is an original analytical product, not a mirror of any underlying source. That architectural choice is not incidental. It is a direct response to the legal framework Article 4 establishes.
Where Organisations Fail the Article 4 Test Without Knowing It
Several failure modes appear consistently in how organisations implement TDM pipelines in ways that undermine their Article 4 compliance:
Ignoring reservation signals in real time. Many pipelines process sources at scale without a live check against opt-out signals. If a rights holder adds a reservation between one crawl cycle and the next, the pipeline may continue processing that source in non-compliant mode for weeks.
Retaining intermediate copies beyond what processing requires. Article 4 covers temporary reproductions made in the course of TDM. Retaining full-text copies of source material beyond what the analytical process needs — for example, for human review or redistribution — falls outside the exception.
Applying TDM to content behind paywalls or authentication barriers. Lawful access is a precondition, not a legal formality. Content that requires credentials, subscription, or circumventing technical protection measures is not covered, regardless of how the analysis is framed.
Treating Article 4 as a blanket licence. Article 4 is a conditional exception, not a general authorisation. Each source, each access method, and each output type needs to be evaluated against the conditions it sets. A pipeline that processes some sources compliantly and others not does not benefit from Article 4 coverage across the board.
Building for Compliance Before You Build for Scale
The practical lesson from Article 4 is sequencing. Compliance architecture must come before scale decisions — not after.
Organisations that invest in source governance, opt-out monitoring, and derived-output design from the beginning build pipelines that can scale without accumulating legal exposure. Organisations that scale first and address compliance later typically discover that retrofitting a large pipeline to meet Article 4 conditions is far more expensive than designing for it from the start.
The question is not whether to comply. The question is whether your infrastructure is built in a way that makes compliance measurable and maintainable as the scope of your TDM operations grows.
That is an infrastructure question as much as a legal one. And it is worth asking before your next source expansion, not after.
For a closer look at how TrawlingWeb structures its data processing operations within the framework of Art. 4 Directive (EU) 2019/790 and Art. 67 bis LPI, visit trawlingweb.com.