For Service Providers & CROs
How to apply, how to adhere, and what CR.GDPR does for you
CR.GDPR is the EUCROF GDPR Code of Conduct for clinical research service providers acting as data processors on behalf of sponsors. It provides a recognised framework for demonstrating GDPR compliance through requirements developed specifically for the clinical research sector. Organisations within scope can apply for adherence through the Code’s Supervisory Committee (COSUP), which oversees the assessment and ongoing monitoring of compliance.
How to Apply & Adherence Levels | Benefits | FAQ | Fee Breakdown | Fees at a glance
How to Apply
Adherence Scheme 1: Self-declaration and review
- Create & complete an organisational profile on the Code’s Public registry and fill in a compliance questionnaire tailored to what services your organisation provides (“Compliance Dossier”).
- Submit your compliance dossier to the Code’s Supervisory Body (COSUP) for review.
- COSUP will review the compliance dossier and issue its resolution within 6-8 weeks and add the CRO to the public registry.
Adherence Scheme 2: Audit
- Once you have obtained a Level 1 Compliance Mark, the COSUP will organise an audit of your organisation to verify compliance.
- The COSUP auditor will create an audit plan
- Candidate CRO will receive the audit plan and be requested to confirm agreement to the proposed process.
- COSUP auditors, responsible for assessing legal and technical compliance, will audit the Candidate CROs in accordance with the audit plan.
- Upon audit completion, the COSUP auditors will report the audit results to the rest of the COSUP Members.
- COSUP will communicate the final decision to the Candidate CRO and add the CRO to the public registry.
Adherence Benefits
Adherence Routes and Fees
Organisations within the scope of the EUCROF CR.GDPR Code of Conduct may apply for either a Level 1 Compliance Mark or a Level 2 Compliance Mark. Both Compliance Marks are valid for three years. To continue as a Code Adherent and retain the right to display the Compliance Mark, an organisation must renew its adherence every three years.
Standard adherence fees
The following fees apply to all Code Adherents, whether they select the Level 1 or Level 2 route. Fees are based on the total number of employees within the organisation worldwide. Please note: Organisations following the Level 2 route pay audit expenses in addition to these standard adherence fees.
* Fees from Year 4 onwards are subject to inflation.
After the renewal fee is paid in Year 7, annual maintenance fees would apply in Years 8 and 9. The next renewal fee would then be payable in Year 10. The same three-year cycle would continue thereafter.
Additional Level 2 audit expenses
Organisations following the Level 2 route pay audit expenses in addition to the standard adherence fees.
The base audit unit tariff is €1,500.
The audit costs shown above are estimates. The final cost will depend on:
- the size of the organisation;
- the number of services included in the assessment;
- the number of auditors required; and
- the number of audit days needed.
Fee Information at a glance:
- Level 1 and Level 2 are two different evaluation routes.
- Both Compliance Marks are valid for three years.
- Organisations must renew their adherence every three years to continue displaying the Compliance Mark.
- Standard application, maintenance and renewal fees apply to both Level 1 and Level 2 organisations.
- Level 2 organisations pay separate audit expenses in addition to the standard fees.
- A Level 1 organisation is not obligated to move to Level 2 at renewal.

