Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

T

Technical and organisational measures (TOMs)

Technical and organisational measures (TOMs) is the GDPR's generic term for the safeguards that controllers and processors must implement to ensure and demonstrate compliance and to protect personal data. The phrase appears throughout the Regulation: in Art. 24 (responsibility of the controller), Art. 25 (data protection by design and by default), Art. 28 (guarantees required of processors), Art. 32 (security of processing) and Art. 89 (safeguards for research). Technical measures act on systems and data; organisational measures act on people and processes; both must be appropriate to the risk, taking into account the state of the art and the costs of implementation.

A typical TOM catalogue, structured along the lines of Annex II of the standard contractual clauses or ISO/IEC 27001 Annex A, covers: pseudonymisation and encryption; confidentiality controls such as physical access control, logical access management, role-based permissions and multi-factor authentication; integrity controls such as input logging, change management and audit trails; availability and resilience through backups, redundancy, disaster recovery and business continuity; procedures for regular testing, vulnerability management and penetration testing; incident and breach management; data minimisation, quality, retention and deletion; portability and secure erasure; staff confidentiality undertakings and training; vendor and sub-processor governance; and certification or adherence to codes of conduct.

TOMs must be documented, not merely implemented: in general terms in the record of processing activities (Art. 30(1)(g)), specifically in the annex to each data processing agreement, per actor in the DPIA, and in the transfer impact assessment where they serve as supplementary measures. In health and clinical research, regulators expect measures aligned with the CNIL security guide, ENISA health guidance, HDS hosting requirements and, for trial systems, 21 CFR Part 11 and the EMA computerised-systems guideline. iliomad's DPIA methodology scores each sponsor and vendor's TOMs on a three-point scale to identify where measures are acceptable, improvable or unacceptable.