A recognised GDPR Code of Conduct for clinical research service providers.
CR.GDPR provides a practical framework for demonstrating GDPR compliance for organisations acting as data processors in clinical research. Supporting consistent GDPR compliance across all 27 EU Member States.
For CROs & Service Providers
Understand whether the Code applies to your organisation and how to become an Adherent.
For Sponsors
Learn how CR.GDPR helps assess GDPR maturity across clinical research suppliers.
About the Code
Who is Covered?
Clinical research service providers acting as data processors for sponsors under a service contract. Find out more
What is covered?
23 classes of services that a CRO can deliver. Access list here
Whose data are covered?
Patients & healthcare professionals
What geographical area?
27 European Union Member States
Development & Maintenance
Want to know more?
You can download a user guide, the full code or a reader’s version via the button below.

