Art. 4 Directive 2019/790: Why Legal Coverage Means Nothing Without Operational Readiness
Most organisations that invoke Art. 4 of Directive (EU) 2019/790 have read the provision. Fewer have stress-tested what happens when someone asks them to prove they were actually within it at the moment of processing.
That gap — between legal awareness and operational traceability — is where TDM projects routinely fail. Not in court, but in practice: audits, procurement reviews, partner due diligence, regulator enquiries. The legal right exists. The evidence that it was exercised correctly, often does not.
This post is not about what Art. 4 says. It is about what it requires you to be able to demonstrate.
The Provision Does Not Protect Processing — It Protects Lawful Processing
Art. 4 grants an exception to copyright and related rights for Text and Data Mining carried out for any purpose, by any person who has lawful access to the relevant content. That is the core of it. But "lawful access" is not a binary state. It is a condition that must be verified per source, per moment of access, per type of content processed.
A source that was publicly accessible in January may have modified its terms by March. A dataset compiled from public sources may include a subset that, at retrieval time, was behind a session-based restriction. An automated processing pipeline has no inherent awareness of any of this. The legal exception does not move backwards in time to cure a flawed access event.
This means that claiming TDM coverage after the fact — without records of when each source was accessed and under what conditions — is weaker than most legal teams assume.
Opt-Out Is a Constraint That Must Be Tracked, Not Assumed Away
The Directive permits rightholders to opt out of the Art. 4 exception using machine-readable means. The practical expectation is that these reservations are expressed via robots.txt or equivalent metadata fields. What that creates, in operational terms, is a moving compliance boundary.
Opt-out signals can appear, change or disappear at any time. A source that published no reservation last quarter may have added one this week. If your TDM pipeline does not re-check opt-out status at each processing cycle — or at minimum at each new batch — you have no reliable basis to claim that the exception applied throughout.
This is not a hypothetical edge case. It is a structural property of the open web. Sources update their terms and their machine-readable signals independently of your processing schedule. Compliance at time T does not guarantee compliance at time T+1.
What "Lawful Access" Looks Like in an Instrumented Pipeline
The practical implication is that Art. 4 compliance is an engineering property before it is a legal one. The legal framework sets the conditions; the infrastructure either tracks those conditions or it does not.
An instrumented pipeline — one that is genuinely defensible — records, at minimum:
- Source-level access conditions at the moment of processing: whether the source was publicly accessible, whether any opt-out signal was present, and the specific timestamp of the access event.
- Content provenance metadata: which source, which version, at what point in time.
- Opt-out check logs: evidence that reservations were checked and respected, not simply assumed absent.
- Scope boundaries: what was processed for TDM purposes versus what was merely traversed or indexed.
None of this requires exotic infrastructure. It requires deliberate design. Most pipelines that were built for operational efficiency rather than legal traceability lack several of these layers.
The Asymmetry Between Claiming and Proving
There is a systematic asymmetry in how TDM exceptions work in practice. Invoking the exception costs nothing: any organisation can assert that its processing falls within Art. 4. Proving it — to a regulator, a counterparty, a court — requires documentation that must have been generated at the time of processing. It cannot be reconstructed afterwards.
This asymmetry matters more as TDM outputs become economically significant. When the analysis derived from public data feeds business decisions, informs AI training pipelines, or enters commercial agreements, the question of whether the underlying processing was legally sound becomes material. And the answer depends on records that either exist or do not.
Organisations that treat Art. 4 as a legal opinion — something you obtain once and rely on indefinitely — are building on an assumption that will not survive scrutiny under realistic conditions.
Jurisdiction Still Matters Inside the EU Framework
Art. 4 is a harmonised provision, but harmonisation is not uniformity. Member States transposed the Directive with varying degrees of precision. The interaction between Art. 4 and national copyright law — particularly around database rights, sui generis protections, and press publisher rights under Art. 15 — differs across jurisdictions.
If your TDM pipeline draws from sources across multiple EU Member States, the applicable constraints are not identical. A processing decision that is clearly within Art. 4 coverage in one jurisdiction may interact with a national-level provision in another that introduces additional conditions. This is not hypothetical complexity for large deployments. It is the baseline reality for anyone processing the public universe of the internet at scale.
Cross-border TDM is the norm, not the exception. Legal readiness for it means mapping not just Art. 4, but the national layer beneath it, per territory where sources originate.
Operational Readiness Is the Real Competitive Differentiator
The organisations that can move fastest in TDM-based analysis are not necessarily those with the broadest legal opinions. They are the ones whose infrastructure was designed to document compliance as a by-product of normal operation — so that demonstrating lawful processing is not a reactive effort but a continuous output of the pipeline itself.
At TrawlingWeb, the processing of the public universe of the internet is structured precisely around this principle: access conditions, opt-out signals and provenance metadata are part of the operational layer, not an afterthought. That is what makes the derived analysis defensible — not just useful.
The question worth asking about any TDM project is not "does Art. 4 cover this?" That question is usually easy. The harder question is: "can we show, for every source and every processing cycle, that it did?"
If the answer requires reconstruction rather than retrieval, the operational readiness is not where it needs to be.