Skip to content

Supporting GDPR compliance in clinical research

Sponsors are responsible for selecting and overseeing clinical research service providers that process personal data on their behalf. CR.GDPR provides a recognised framework to help sponsors understand how participating service providers have aligned their relevant processing activities with the requirements of the EUCROF GDPR Code of Conduct for Service Providers in Clinical Research.

CR.GDPR supports a more consistent approach to GDPR compliance across clinical research by providing practical guidance for service providers acting as data processors under a service contract.

Why does CR.GDPR matter to sponsors?

Clinical research is increasingly delivered through a network of CROs and specialist service providers, each responsible for processing personal data in support of clinical studies. Interpreting GDPR requirements consistently across different organisations and European jurisdictions can be challenging.

CR.GDPR has been developed to provide a common framework for applying GDPR requirements within clinical research. By adhering to the Code, service providers demonstrate their commitment to implementing the requirements of the EUCROF GDPR Code of Conduct for Service Providers in Clinical Research and maintaining high standards of data protection.

For sponsors, this can support:

How sponsors can use CR.GDPR

Sponsors may use CR.GDPR as part of their supplier assessment and oversight activities.

The scheme provides access to information about participating organisations through the Public Registry and establishes a common GDPR framework developed specifically for clinical research service providers.

Sponsors can use the Public Registry to identify organisations participating in the scheme and understand their current status within the adherence process.

Public Registry

The CR.GDPR Public Registry provides information about organisations participating in the adherence scheme.

The Registry is intended to provide transparency regarding organisations that have engaged with the CR.GDPR adherence process.

Compliance Marks

Organisations that successfully complete the adherence process may become eligible to display a CR.GDPR Compliance Mark in accordance with the rules of the scheme.

The Compliance Mark demonstrates that the organisation has achieved the relevant level of adherence under the CR.GDPR framework.

Compliance Marks are valid for three years.

A common framework across Europe

CR.GDPR is the first transnational GDPR Code of Conduct for Service Providers in Clinical Research, applicable across all 27 European Union Member States.

The Code was approved by the French Data Protection Authority (CNIL) following the opinion of the European Data Protection Board (EDPB) and is monitored by the Code’s Supervisory Committee (COSUP).