CNIL consultation: In 2024, the French data protection authority (CNIL) launched a broad public consultation aimed at revising its health data reference frameworks.
These documents govern the processing of personal data in healthcare and health research, including studies involving medical devices (MDs) and digital medical devices (DMDs) that collect or process health data.
This revision directly concerns all stakeholders conducting clinical research with medical devices, whether industrial sponsors, research institutions, or digital health developers.
The objective is clear: adapt the CNIL framework to rapid changes in research practices, the multiplication of data sources, and the growing role of digital and connected medical devices.
Why the CNIL consultation directly affects medical devices
Research involving medical devices increasingly relies on data generated by:
- connected devices and sensors,
- embedded software,
- analytical platforms,
- real-world data and post-market studies.
All of these datasets qualify as health data, which are considered sensitive personal data under the GDPR and the French Data Protection Act (Loi Informatique et Libertés).
CNIL reference frameworks and methodologies define the practical rules that determine:
- prior formalities and declarations,
- data retention periods,
- patient information requirements,
- conditions for data reuse in medical device trials.
With the full application of Regulation (EU) 2017/745 (MDR), it has become necessary to align CNIL frameworks with new categories of clinical investigations, including post-market studies, real-world evidence studies, and decentralized research models.
The choices made in the revised reference frameworks — applicable methodologies (MR), risk levels, and authorization requirements — will have a direct impact on regulatory burden, timelines, and operational feasibility for clinical research involving medical devices.
The CNIL consultation on health reference frameworks: a turning point
In December 2024, the CNIL published the summary of contributions received during its public consultation on health reference frameworks.
Stakeholders included healthcare institutions, manufacturers, researchers, and associations, with a shared conclusion: existing reference frameworks must evolve to reflect:
- new digital research practices,
- the rapid expansion of connected medical devices,
- the integration of artificial intelligence,
- the increasing complexity of research projects,
- the development of large-scale health databases.
The CNIL has announced the creation of working groups in 2025 to revise existing reference methodologies and health data frameworks.
Consequences for clinical research involving medical devices
Choosing the applicable regulatory framework
Sponsors conducting research involving medical devices will need to determine whether their study falls under:
- an existing Reference Methodology (e.g. MR-001 for research with consent, MR-003 for research without consent), or
- a new or updated framework resulting from the CNIL revision.
If no framework applies, a specific CNIL authorization remains mandatory.
In such cases, the CNIL issues its decision within a two-month timeframe.
Data governance and security requirements
Any research project involving a medical device processing health data must include:
- a Data Protection Impact Assessment (DPIA) when risk is high,
- appropriate technical and organizational security measures,
- detailed documentation of data processing activities,
- GDPR-compliant subcontractor management,
- clear procedures for informing data subjects and exercising their rights.
https://www.cnil.fr/fr/quelles-formalites-pour-les-traitements-de-donnees-de-sante
A specific focus on digital medical devices (DMDs)
In addition to CNIL requirements, digital medical devices may also fall under the Interoperability and Security Reference Framework for Digital Medical Devices (DMN) published by the French Digital Health Agency.
https://industriels.esante.gouv.fr/sites/default/files/media/document/REF_IS_DMN_FR_V1.2.2_0.pdf
This framework is separate from CNIL methodologies, but complementary.
It ensures that digital medical devices are compliant both technically and regulatorily, particularly regarding cybersecurity and interoperability.
Implications for clinical investigations under the MDR
For clinical investigations conducted under Regulation (EU) 2017/745, compliance with CNIL reference frameworks or methodologies remains a prerequisite whenever:
- the device collects data via an application, sensor, or platform,
- data are transferred to an analysis system,
- sensitive data are combined to assess safety or performance.
The data controller must therefore articulate:
- MDR obligations for medical devices,
- GDPR and data protection requirements,
- applicable CNIL reference frameworks.
What impact for manufacturers in the coming months?
The revision of CNIL reference frameworks may:
- modify authorized data retention periods,
- clarify pseudonymization and anonymization requirements,
- strengthen DPIA obligations,
- redefine subcontracting rules,
- integrate new types of processing related to digital medical devices.
Manufacturers and sponsors will need to closely monitor CNIL publications in 2025 and adapt their internal procedures, patient information notices, and impact assessments accordingly.
Conclusion: a moving framework for rapidly evolving practices
CNIL reference frameworks play a strategic role in health research, as they secure the legal basis for data processing while simplifying procedures when conditions are met.
For medical device stakeholders — whether digital or non-digital — the ongoing CNIL consultation marks a major transition.
The framework will evolve, and adapting to it will be essential to ensure compliance, data security, and transparency in clinical research projects.






