CROs & Clinical Service Providers

A contract research organisation or clinical service provider is a processor for most of its sponsors, a controller for its own staff and investigator databases, and sometimes a joint controller for site-facing activities. It receives a different data processing agreement, a different security questionnaire and a different audit request from every sponsor — and the sponsors' DPOs increasingly expect answers within days.

The obligations under Art. 28 and 32 GDPR, the UK GDPR, HIPAA where US sponsors are involved, and the sponsor-specific requirements flowing from the EU Clinical Trials Regulation are the same for every study. What differs is the paperwork. A CRO that has documented its processing once — roles, sub-processors, transfers, security measures, breach procedure — turns every new sponsor onboarding into a formality.

iliomad works with CROs, laboratories, imaging and eClinical vendors and clinical supply companies to build that single framework and, where useful, to act as their DPO or EU/UK representative.

Contact us

What a CRO has to get right

Sponsors delegate the work but not the accountability, so they audit. The obligations below are the ones that appear in every sponsor DPA and every qualification audit.

A processor framework that fits every sponsor

Art. 28(3) GDPR lists the clauses every DPA must contain; sponsors add their own. A CRO needs a master processor position — standard DPA, sub-processor list, transfer mechanisms, security annex — that it can offer proactively and reconcile quickly against sponsor paper. iliomad drafts it and reviews incoming sponsor DPAs against it — see contractual review.

Sub-processors, sites and international transfers

Laboratories, imaging centres, EDC and IRT providers and cloud hosts are sub-processors that must be authorised and flowed down. Transfers to US sponsors or vendors need EU SCCs, the UK Addendum or the Data Privacy Framework, plus a transfer impact assessment. iliomad maintains the sub-processor register and the transfer file that sponsors ask to see.

Security measures and Art. 32 evidence

Sponsors' qualification audits test the security measures promised in the DPA: access control, encryption, logging, business continuity, incident response. ISO 27001 certification helps but is not required; documented and tested measures are. iliomad prepares the security annex and the evidence pack — see cybersecurity for life sciences.

Breach notification within the sponsor's deadline

Art. 33(2) GDPR requires a processor to notify the controller without undue delay; sponsor DPAs typically shorten this to 24 or 48 hours. A CRO needs a breach procedure that detects, assesses and notifies within that window across all studies. iliomad writes and tests the procedure and provides ENISA-based severity assessment.

Own-controller activities: investigators, staff, business contacts

Investigator databases, site feasibility data, staff records and business contacts are processed by the CRO as controller, with their own privacy notices, records and retention rules. These are the activities most often missed in a processor-focused organisation. iliomad covers them in the record of processing and the notices.

Being audited and being a differentiator

Sponsors increasingly select CROs on compliance maturity. A CRO that can hand over a complete data protection file, name its DPO and its EU/UK representative, and pass a qualification audit without remediation wins the study. iliomad supports the audit and, where the CRO is outside the EU or the UK, acts as its representative.

How iliomad Health Data can help you

iliomad Health Data works with CROs and clinical service providers of every size, from specialist regional CROs to global providers, and sits on the sponsor side of the table for more than thirty life-sciences companies. That double perspective is what makes our processor frameworks pass sponsor audits first time. Engagements range from a one-off framework build to a full DPO and representative mandate.

Master processor framework and standard DPA
Sponsor DPA and clinical trial agreement review
Sub-processor and transfer register
Security annex and qualification-audit support
Breach procedure and severity assessment
DPO and EU/UK representative mandate

FAQs

Our frequently questions

No items found.