Skip to content

A recognised GDPR Code of Conduct for clinical research service providers.

CR.GDPR provides a practical framework for demonstrating GDPR compliance for organisations acting as data processors in clinical research. Supporting consistent GDPR compliance across all 27 EU Member States.

Approved by CNIL
Applicable across 27 EU Member States
Monitored by COSUP
Developed by EUCROF

For CROs & Service Providers

Understand whether the Code applies to your organisation and how to become an Adherent.

For Sponsors

Learn how CR.GDPR helps assess GDPR maturity across clinical research suppliers.

About the Code

Who is Covered?

Clinical research service providers acting as data processors for sponsors under a service contract. Find out more

What is covered?

23 classes of services that a CRO can deliver. Access list here

Whose data are covered?

Patients & healthcare professionals

What geographical area?

27 European Union Member States

Development & Maintenance

Development

CR.GDPR was developed by the European CRO Federation under Article 40 of the GDPR to provide practical guidance for clinical research service providers acting as data processors. It interprets GDPR requirements specifically for the clinical research sector, supporting a more consistent approach to data protection across Europe.

Approval

CR.GDPR was approved by CNIL (the French Data Protection Authority) on 12 September 2024 following the opinion of the European Data Protection Board (EDPB). It is the first transnational GDPR Code of Conduct for clinical research, applicable across all 27 European Union Member States.

Governance

CR.GDPR is independently monitored by the Code’s Supervisory Committee (COSUP), formally approved by CNIL as the accredited monitoring body. COSUP is responsible for assessing adherence applications, overseeing ongoing compliance and maintaining the integrity of the Code.

Development

CR.GDPR was developed by EUCROF under Article 40 of the GDPR to provide practical guidance for clinical research service providers acting as data processors. It interprets GDPR requirements specifically for the clinical research sector, supporting a more consistent approach to data protection across Europe.

Approval

CR.GDPR was approved by CNIL (the French Data Protection Authority) on 12 September 2024 following the opinion of the European Data Protection Board (EDPB). It is the first transnational GDPR Code of Conduct for clinical research, applicable across all 27 European Union Member States.

Governance

CR.GDPR is independently monitored by the Code’s Supervisory Committee (COSUP), formally approved by CNIL as the accredited monitoring body. COSUP is responsible for assessing adherence applications, overseeing ongoing compliance and maintaining the integrity of the Code.

Want to know more? 

You can download a user guide, the full code or a reader’s version via the button below.