Electronic informed consent (eConsent)
Electronic informed consent (eConsent) is the use of electronic systems and processes, such as tablets, web portals, videos, interactive modules and electronic signatures, to convey information to potential participants and to document their informed consent to participate in a clinical trial, either at the site or remotely as part of a decentralised trial. Well-designed eConsent improves comprehension through multimedia and knowledge checks, creates complete audit trails, facilitates re-consent after protocol amendments and supports remote enrolment.
Regulatory acceptance is broad but conditional. In the EU, Art. 29 CTR 536/2014 requires consent to be written, dated and signed, and the Commission, EMA and HMA recommendation paper on decentralised elements (2022) confirms that electronic means may be used where national law allows; acceptance of remote consent and of the type of electronic signature (simple, advanced or qualified under the eIDAS Regulation) varies between Member States, and some require a wet-ink signature or a witnessed video interview. The FDA and Office for Human Research Protections issued joint guidance on eConsent in 2016 and accept electronic signatures compliant with 21 CFR Part 11. The UK Health Research Authority and MHRA have published a joint statement supporting eConsent with clear conditions.
eConsent platforms process personal data that is directly identifying (name, signature, contact details, often a photo or identity check) alongside the subject number, which makes them one of the few trial systems holding the link between identity and pseudonym outside the site. The platform vendor is a processor, usually to the sponsor but sometimes to the site, and its hosting location determines transfer requirements; access to identifying data must be restricted so that the sponsor sees only completion status and version, not identities. The DPIA should address identity verification methods (which may involve biometric data), retention of the signed form for 25 years under Art. 58 CTR, device security in bring-your-own-device settings and accessibility for incapacitated or vulnerable participants. Note that eConsent to participate remains distinct from consent as a GDPR legal basis; the electronic form must still carry the Art. 13 GDPR information as a transparency measure.
