Privacy Notice
Effective date: 15 July 2026
This privacy notice sets out who we are and how and why we collect, store, use and share personal information. It also explains your rights in relation to your personal information and how to contact us or supervisory authorities if you have a complaint.
Who we are
We are COSUP, the Supervisory Committee of the EUCROF GDPR Code of Conduct for Service Providers in Clinical Research (CR.GDPR). The European CRO Federation (EUCROF) is the “Code Owner” for CR.GDPR and is an organisation based in the Netherlands that represents the interests of Contract Research Organisations in Europe.
Information collection and legal basis
When you contact us
When you choose to contact us we will keep records of your interactions with us.
We keep contact details and information on our interactions with you to manage and monitor implementation of CR.GDPR.
When your organisation submits an application for adherence
When your organisation submits an application dossier for adherence to the CR.GDPR, we will collect the name, job title and contact details of the person submitting the request as these are necessary for the performance of a contract between us as described in the Terms of Use. We may also collect details of anyone named in the application, and may require further details about particular employees.
For example, if your organisation has a Data Protection Officer (DPO) we may need to understand their qualifications and suitability for the role as part of our assessment of adherence to CR.GDPR.
If your organisation applies for Level 2 Adherence to the CR.GDPR, we will collect information about other employees in your organisation. This may include names, contact information, job titles and interview notes taken as part of the audit process, including any correspondence related to the audit.
Submitting an application to the COSUP requires the COSUP to perform its legal obligations, accredited by the CNIL, to assess and monitor the compliance of the Candidate CRO or Code Member with the CR.GDPR.
COSUP Members
As a Member of COSUP, we collect personal information necessary for your activities on behalf of COSUP and to ensure that the COSUP meets its legal obligations as an accredited body. These may include the following.
- Your name
- Contact details
- Professional qualifications and experience
- Records of meetings you have attended
- Correspondence with other COSUP Members
- Your use of our systems
- Payment details for expenses or any paid activity you complete for COSUP.
When you visit our website
We collect information about when you view and interact with the website. This includes information about your operating system, browser version, domain name and IP address, and the details of any website you were on before coming to our site.
We use a cookie management tool which has information on all the cookies we use. We use this information to monitor, improve and administer the website and the services we provide, and to measure and manage our marketing efforts.
Purposes of the processing and retention
Purposes
We may use your information as necessary and appropriate to:
- administrate and conduct the activities of the COSUP;
- comply with our legal obligations;
- enforce our legal rights;
- protect the rights of third parties;
- assess the adherence of organisations who are Candidate CROs or Code Members; or
- make sure the CR.GDPR is being implemented appropriately.
Retention
We will only keep your information as long as necessary for the fulfilment of the purposes outlined above, except if otherwise required by applicable laws or legal orders.
Information sharing
We may need to share information we have collected with the CNIL and other relevant data protection authorities as part of their oversight of the COSUP and in accordance with the procedures of the COSUP.
If, as part of our work, we discover any evidence of criminal activity or serious wrongdoing, we may be required to share this information with the relevant authorities.
Service providers
We use a variety of service providers to help run our business. We have agreements with all providers that contain obligations on the other organisation to safeguard your information and to only use your information to provide their service.
Legal requirement
We will disclose your personal information if we, in good faith, believe that we are required to do so by law, regulation or the order of court or other legitimate government body.
Third-party links and websites
Our site contains links to third-party websites and services. This privacy notice does not apply to them. We recommend you read their privacy notices to understand how they handle your personal information.
Security and data location
We aim to take all reasonable steps to protect your personal information.
Our service providers are based in different locations in the European Union, or countries with an EU adequacy decision, such as Switzerland and the United Kingdom.
If a transfer of personal information outside of these areas becomes necessary, we will make sure that any transfer is protected by an appropriate legal safeguard, which in most cases will be standard contractual clauses, which can be made available on request.
Your rights and choices
You have several different rights with regard to your personal information. Some rights only apply in certain circumstances or to certain information. There are also exemptions from some rights in some circumstances. If you want to make a rights request, or a data protection complaint, please contact: rco@crgdpr.org.
Access
You are entitled to know what personal information we hold about you and to receive a copy of it.
Correction
You are entitled to correct personal information we hold about you that is inaccurate.
You will need to provide us with evidence of the correct information.
Deletion
In certain circumstances you are entitled to ask us to delete the personal information we hold about you.
We will not be able to delete certain information, such as where we are legally obliged to keep it or where we need to keep it for legitimate business reasons such as accounts and records. This includes record keeping necessary to demonstrate that the CR.GDPR is being implemented appropriately.
Objection
In certain circumstances you are entitled to object to us processing your personal information.
If you want to object to marketing please use the unsubscribe link in emails, or contact us to opt out of phone and postal marketing. To make sure we respect your request we have to keep your contact details on a suppression list.
However, in other circumstances we may need to continue processing your information where we have strong and legitimate reasons to do so.
Restriction
In certain circumstances you are entitled to ask us to restrict our processing of your personal information.
You can ask us to do this if:
- you dispute the accuracy of your personal information;
- you believe that our processing is unlawful but you prefer restriction to deletion;
- we no longer need the information but you need it for legal reasons; or
- you have objected to our processing and we are still dealing with this objection.
Portability
In certain circumstances you are entitled to receive the personal information you have provided us in a structured, commonly used and machine-readable format.
Complaints
You can make a data protection complaint in good faith at any time without fear of retribution.
You may also complain to our lead regulator, the Commission Nationale de l’Informatique et des Libertés (CNIL).
Address: 3 Place de Fontenoy, 75007 Paris, France.
Telephone: +33 (0) 1 53 73 22 22
Website: cnil.fr
How to contact us
You can contact the Risk and Compliance Officer of the COSUP at rco@crgdpr.org.
Changes to our privacy notice
We will use personal information as described in the privacy notice in effect when the information was collected from you or as authorised by you, or the notice in force during any continued use of our website. Subject to any applicable consent requirements, or if required by law, we reserve the right to change the terms of this privacy notice at any time. We will reflect any changes to this privacy notice on this page with a new effective date. We encourage you to review this privacy notice regularly for any changes and we will update you if any significant changes are made to how we process data.

