GDPR and health data in clinical research: key points to watch

Picture of Maurice Bagot D'arc

Maurice Bagot D'arc

ENT surgeon, head and neck surgeon, specialized in ENT oncology, legal compensation for bodily injury, and pharmaceutical marketing, with over 30 years of experience in Medical Affairs serving the healthcare industries and 15 years of surgical practice.

GDPR and health data are now inseparable from the conduct of clinical research. Medical history, laboratory results, imaging, genetic data, treatments, adverse events and data generated by connected devices are all particularly sensitive information. Their use is essential for research, but it must comply with a strict framework. In France, data protection is one of the regulatory aspects that must be anticipated when setting up a clinical trial. The European Clinical Trials Regulation notably includes, in Part II of the application dossier, elements relating to compliance with personal data protection requirements.

GDPR and health data: why is enhanced protection required?

Health data fall within the special categories of personal data protected under Article 9 of the GDPR. Their processing therefore requires the identification of a legal basis under Article 6, together with a condition allowing the processing of sensitive data. One point requires particular attention in clinical research: a participant’s consent to take part in a clinical trial should not automatically be confused with the legal basis used to process their personal data. The sponsor must document its analysis and clearly define the responsibilities of the different parties involved: data controller, possible joint controllers and processors.

GDPR and health data: identify the applicable reference methodology

In France, health research is subject, with certain exceptions, to specific formalities with the CNIL. The MR-001 and MR-003 reference methodologies were updated in 2026. MR-001 notably covers research requiring consent to participate in the research or to undergo a specific procedure, while MR-003 applies to research that does not require such consent. Before a project begins, it is therefore essential to check that it fully complies with the requirements of the applicable methodology. Otherwise, an authorisation request to the CNIL may be required. This is a key step in ensuring GDPR and health data compliance from the outset of the study.

Limit collection to data that are genuinely necessary

The principle of data minimisation is one of the main points of vigilance regarding GDPR and health data. The protocol should only provide for the collection of information necessary to meet the defined scientific objectives. Each variable collected must be justified, the purposes must be clearly specified and retention periods defined. Particular attention is required when data may be reused for secondary analyses, future research or projects involving artificial intelligence. The fact that information might prove useful at a later stage is not, in itself, sufficient justification for collecting it systematically.

Pseudonymisation and security: essential safeguards

Pseudonymisation is an essential measure in clinical research, but it does not turn information into anonymous data. As long as re-identification remains possible using additional information, the GDPR continues to apply. Security measures must be proportionate to the risks and should include access-right management, access traceability, backups, encryption where appropriate and procedures for handling data breaches. The 2026 versions of MR-001 and MR-003 also include a dedicated security appendix. In particular, they provide for multi-factor authentication for research tools accessible via the web from 1 January 2027. These requirements reinforce the importance of addressing GDPR and health data throughout the study lifecycle.

GDPR and health data: provide clear information to participants

Transparency remains a fundamental principle. Participants must understand what data are collected, why they are collected, who may access them, how long they will be retained and which rights they may exercise. This information must be clear, accessible and understandable, rather than buried in overly legalistic wording. The 2026 updates to the reference methodologies also take greater account of digital information methods, in line with the development of decentralised trials and digital patient pathways.

Anticipate international data transfers

Multicentre trials frequently involve CROs, central laboratories, ePRO/eCOA platforms, hosting providers or analytical teams located in different countries. Accurate mapping of data flows is therefore essential. Any transfer outside the European Economic Area must be governed in accordance with the GDPR, taking into account the destination country, the safeguards available and, where necessary, additional measures. This assessment should be carried out before processing begins and updated whenever providers, tools or data flows change. For international studies, GDPR and health data considerations should therefore be integrated into vendor selection and contracting as early as possible.

GDPR and health data: build compliance in from the design stage

Compliance should not be checked only at the time of the regulatory submission. A “privacy by design” approach makes it possible to integrate data protection requirements from the drafting of the protocol through to the choice of digital tools and selection of service providers. The record of processing activities must be kept up to date, and a Data Protection Impact Assessment (DPIA) must be carried out when processing is likely to result in a high risk to individuals’ rights and freedoms. The DPO, clinical, legal, data and security teams therefore need to work together.

Key points to remember

To manage the issues surrounding GDPR and health data in clinical research, teams should verify the qualification of the processing activity, the applicable reference methodology, data minimisation, retention periods, security measures, participant information, contracts with service providers and international transfers. Documentation is equally important: compliance is not enough; organisations must also be able to demonstrate it. In an increasingly digital and international research environment, data protection has become a genuine marker of clinical project quality, alongside methodological robustness and participant safety.

Useful sources and links

If you would like to receive regularly our articles and recent news, please subscribe here.

Other articles to consult

Participez au webinaire

Présentation de BluePharm Academy : Les modules de formation de BluePharm