# iliomad Health Data > iliomad Health Data is a regulatory compliance consultancy that works only with life sciences companies. It acts as outsourced Data Protection Officer, EU, UK and Swiss data protection representative, and EU AI Act compliance partner for biotech and pharma sponsors, CROs, and HealthTech, MedTech and medical AI companies. iliomad delivers operational compliance rather than legal opinions: appointments, records of processing, DPIAs, contracts, training, and responses to audits, authorities and due diligence teams. This file lists the main pages of www.iliomadhealthdata.com, the canonical domain (iliomad.fr redirects to it). Last updated: 30 September 2026. Key facts: - Entities: iliomad Health Data SAS (France, EU entity) and iliomad Health Data UK Ltd (United Kingdom, Cambridge). - Operating since 2020, with CDPO-certified Data Protection Officers working under ISO 27001, ISO 27005 and ISO 9001 certified processes. - More than 30 life sciences clients under DPO, representative or AI mandates, and hands-on regulatory experience in more than 75 countries. - Frameworks covered: GDPR, UK GDPR, Swiss FADP, EU AI Act, EU Clinical Trials Regulation 536/2014, ICH GCP, MDR and IVDR, HIPAA, CCPA/CPRA, Canada PIPEDA, China PIPL, Australian Privacy Act, Turkish KVKK and VERBIS. - Clients: biotech and pharma sponsors, CROs, MedTech and IVD manufacturers, HealthTech and digital therapeutics companies, health data platforms, TechBio and medical AI companies, academic and hospital research. - Working languages: English and French. - Contact: https://www.iliomadhealthdata.com/get-in-touch ## Company - [Home](https://www.iliomadhealthdata.com): Overview of iliomad's compliance services for life sciences: data protection and EU AI Act compliance. - [About iliomad Health Data](https://www.iliomadhealthdata.com/about): Who iliomad is, its two entities, its certifications, the frameworks it implements and the organisations it works with. - [Compliance services overview](https://www.iliomadhealthdata.com/compliance-services): Hub page listing iliomad's outsourced compliance roles and project-based services for life sciences. - [Contact](https://www.iliomadhealthdata.com/get-in-touch): Contact form to reach the iliomad team. - [Careers](https://www.iliomadhealthdata.com/jobs): Open positions at iliomad Health Data. - [Terms of use and privacy policy](https://www.iliomadhealthdata.com/legal): iliomad's terms of use and privacy policy. ## Outsourced compliance roles - [Outsourced Data Protection Officer (Global DPO)](https://www.iliomadhealthdata.com/gdpr-services/data-protection-officer): Outsourced DPO for pharma, biotech and HealthTech companies, with GDPR, HIPAA and EU AI Act expertise across more than 75 countries. - [EU Data Protection Representative (Art. 27 GDPR)](https://www.iliomadhealthdata.com/gdpr-services/data-protection-representative): EU Article 27 GDPR representative for non-EU companies running clinical trials or processing personal data of people in the EU. - [UK Data Protection Representative (Art. 27 UK GDPR)](https://www.iliomadhealthdata.com/gdpr-services/uk-data-representative): UK GDPR Article 27 representative for non-UK pharma, biotech and MedTech companies. - [Swiss FADP Representative](https://www.iliomadhealthdata.com/gdpr-services/switzerland): Swiss FADP Article 14 representative for life sciences companies processing personal data of people in Switzerland. - [Global data governance and compliance](https://www.iliomadhealthdata.com/gdpr-services/global-data-governance-compliance-solutions): Outsourced data governance and GDPR compliance programmes for life sciences: records of processing, DPAs, breach management and privacy programmes. ## Data protection projects and assessments - [Data Protection Impact Assessments (DPIA)](https://www.iliomadhealthdata.com/gdpr-services/dpia): DPIAs for clinical trials and medical research that process patient data, based on iliomad's DPIA templates and methodology. - [Informed consent form (ICF) review](https://www.iliomadhealthdata.com/gdpr-services/icf-review): GDPR review of informed consent forms for clinical trials, covering the EU and national privacy wording expected by ethics committees. - [GDPR contract review](https://www.iliomadhealthdata.com/gdpr-services/contractual-review): GDPR contract review for sponsors, sites and vendors: allocation of roles, data processing agreements and transfers outside the EEA. - [Vendor assessment](https://www.iliomadhealthdata.com/gdpr-services/vendor-assessment): Assessment of CROs, laboratories, hosting and analytics vendors before they process patient data. - [Global privacy gap analysis](https://www.iliomadhealthdata.com/gdpr-services/gap-analysis): Privacy gap analysis for multi-regional studies against UK data protection law, HIPAA, Brazil's LGPD, Canada's PIPEDA and China's PIPL. - [European local regulations](https://www.iliomadhealthdata.com/gdpr-services/european-local-regulations): How each EU Member State applies the GDPR and which national requirements apply to clinical studies. - [GDPR quality assurance](https://www.iliomadhealthdata.com/gdpr-services/quality-assurance): A scalable GDPR quality assurance system for life sciences companies: documented compliance, data request procedures and breach policies. - [Data privacy training](https://www.iliomadhealthdata.com/gdpr-services/data-privacy-training): GDPR training for life sciences teams, from operational staff to management. - [Data privacy due diligence](https://www.iliomadhealthdata.com/gdpr-services/due-diligence-audits): Data privacy due diligence for life sciences financing rounds and acquisitions, with a remediation plan for the gaps found. - [Clinical data hosting](https://www.iliomadhealthdata.com/gdpr-services/clinical-data-hosting): Compliant hosting strategy for clinical data: choice of cloud provider, HDS and SecNumCloud certifications, and hosting country. - [UK Data Protection Act 2018](https://www.iliomadhealthdata.com/gdpr-services/uk-data-protection-act-): Compliance with the UK Data Protection Act 2018 and the UK GDPR for life sciences companies. - [HIPAA compliance](https://www.iliomadhealthdata.com/gdpr-services/hipaa): HIPAA for life sciences companies that handle protected health information in clinical trials or with US healthcare partners. - [CPRA compliance](https://www.iliomadhealthdata.com/gdpr-services/cpra): California Privacy Rights Act compliance for life sciences companies that handle sensitive personal data. ## AI for life sciences - [AI governance and AI Officer](https://www.iliomadhealthdata.com/gdpr-services/ai-officer): AI governance for life sciences teams that use LLMs, copilots and agents: AI policy, tool assessment, AI literacy and oversight under the EU AI Act. - [EU AI Act compliance for AI developers](https://www.iliomadhealthdata.com/gdpr-services/ai-compliance-services): EU AI Act compliance for providers of diagnostic, decision-support and medical device AI: classification, conformity assessment, documentation and post-market monitoring. - [EU AI Act representative](https://www.iliomadhealthdata.com/gdpr-services/ai-representative): EU AI Act representative for non-EU life sciences companies bringing AI systems to the European market. - [EU AI Act for healthcare and life sciences](https://www.iliomadhealthdata.com/gdpr-services/artificial-intelligence-): What the EU AI Act means for healthcare AI and how life sciences companies prepare for it. - [AI in clinical research](https://www.iliomadhealthdata.com/gdpr-services/clinical-research): Compliance for AI across the clinical research lifecycle, from drug discovery to post-market surveillance: EU AI Act, GDPR, MDR/IVDR and GCP. - [AI in healthcare](https://www.iliomadhealthdata.com/gdpr-services/healthcare): Regulatory compliance for healthcare AI in diagnostics, clinical decision support, precision medicine and telehealth. ## Sectors - [Clinical trials](https://www.iliomadhealthdata.com/gdpr-services/clinical-trials): GDPR compliance for clinical trial sponsors and CROs: ICF reviews, DPIAs, cross-border transfers and DPO services. - [Drug clinical trials](https://www.iliomadhealthdata.com/gdpr-services/drugs-clinical-trials): GDPR support for drug trial sponsors in the EU: clinical trial agreements, ICF review, DPO appointment and risk analysis. - [HealthTech and MedTech](https://www.iliomadhealthdata.com/gdpr-services/medical-devices): Data protection for MedTech, HealthTech and digital health companies: MDR/IVDR privacy requirements, DPIAs and vendor assessments. - [Health data platforms](https://www.iliomadhealthdata.com/gdpr-services/data-warehouse): Governance, security and regulatory compliance for health data warehouses and platforms used for research. ## Who we work with - [Biotech and pharma sponsors](https://www.iliomadhealthdata.com/gdpr-services/biotech-pharma-sponsors): Outsourced DPO, EU and UK representative and AI Act compliance for biotech and pharma sponsors running multi-country trials. - [HealthTech, MedTech and AI diagnostics](https://www.iliomadhealthdata.com/gdpr-services/healthtech-medtech-ai-diagnostics): Data protection and EU AI Act compliance for digital health platforms, medical device software and AI diagnostics. - [CROs and clinical service providers](https://www.iliomadhealthdata.com/gdpr-services/cro-clinical-service-providers): GDPR, UK GDPR and HIPAA compliance for CROs, central labs, eClinical vendors and clinical supply providers: processor frameworks and sponsor-ready DPAs. - [Founders and executives](https://www.iliomadhealthdata.com/gdpr-services/founders-executives): One fixed-fee mandate covering the DPO, representative and AI Officer roles, with a compliance file ready for due diligence and partnering. - [Clinical operations and regulatory affairs](https://www.iliomadhealthdata.com/gdpr-services/clinical-operations-regulatory-affairs): ICF and protocol review, study DPIAs, clinical trial agreements and vendor contracts delivered on study timelines. - [Legal, privacy and compliance leads](https://www.iliomadhealthdata.com/gdpr-services/legal-privacy-compliance-leads): Specialist support for in-house legal, privacy and compliance leads: EU and UK representation, DPIAs, gap assessments and AI Act readiness. - [Investors, incubators and accelerators](https://www.iliomadhealthdata.com/gdpr-services/investors-incubators-accelerators): Data protection and AI Act due diligence for life sciences investors, and portfolio compliance programmes for funds, incubators and accelerators. ## Regulations and guidelines - [Regulations and guidelines](https://www.iliomadhealthdata.com/regulations-and-guidelines): Summaries of the regulations and guidelines that govern personal data in life sciences. - [General Data Protection Regulation (GDPR)](https://www.iliomadhealthdata.com/regulations-and-guidelines/general-data-protection-regulation-gdpr): Overview of the GDPR and its obligations for organisations that process personal data. - [Artificial Intelligence Act (AI Act)](https://www.iliomadhealthdata.com/regulations-and-guidelines/artificial-intelligence-act-ai-act): Overview of the EU AI Act and its risk-based classification of AI systems. - [EU-U.S. Data Privacy Framework](https://www.iliomadhealthdata.com/regulations-and-guidelines/eu-u-s-data-privacy-framework): The EU adequacy decision for the United States and how it governs transfers of personal data to certified US organisations. - [Swiss-U.S. Data Privacy Framework](https://www.iliomadhealthdata.com/regulations-and-guidelines/swiss-u-s-data-privacy-framework): The framework for transfers of personal data from Switzerland to the United States. - [UK Extension to the EU-U.S. Data Privacy Framework](https://www.iliomadhealthdata.com/regulations-and-guidelines/uk-extension-to-the-eu-u-s-data-privacy-framework): The framework for transfers of personal data from the United Kingdom to the United States. - [Health data warehouses in France (entrepôts de données de santé)](https://www.iliomadhealthdata.com/regulations-and-guidelines/health-data-warehouse-hdw-the-french-guideline-to-centralize-health-data-for-multiple-purposes-reuse): The French CNIL framework for health data warehouses that centralise health data for reuse across multiple purposes. - [MR-001: conducting a clinical trial in France](https://www.iliomadhealthdata.com/regulations-and-guidelines/mr-001-the-french-guideline-to-conduct-a-clinical-trial-in-france): CNIL reference methodology MR-001 for processing personal data in interventional clinical research in France. - [MR-003: conducting a non-interventional study in France](https://www.iliomadhealthdata.com/regulations-and-guidelines/mr-003-the-french-guideline-to-conduct-a-non-interventional-study-in-france): CNIL reference methodology MR-003 for processing personal data in non-interventional studies in France. - [MR-004: conducting an observational study in France](https://www.iliomadhealthdata.com/regulations-and-guidelines/mr-004-the-french-guideline-to-conduct-an-observational-study-in-france): CNIL reference methodology MR-004 for processing personal data in observational studies in France. - [MR-006: access to public health data by a pharmaceutical company](https://www.iliomadhealthdata.com/regulations-and-guidelines/mr-006-the-french-guideline-to-access-to-health-public-data-by-a-pharmaceutical-company): CNIL reference methodology MR-006 governing access by pharmaceutical companies to French public health data. - [MR-008: access to national health databases by a pharmaceutical company](https://www.iliomadhealthdata.com/regulations-and-guidelines/mr-008-the-french-guideline-to-access-to-national-health-database-by-an-pharmaceutical-company): CNIL reference methodology MR-008 governing access by pharmaceutical companies to French national health databases. ## Guides and analysis - [GDPR Article 89 research: lawful basis and safeguards for clinical trials](https://www.iliomadhealthdata.com/post/gdpr-article-89-research-clinical-trials): How GDPR Article 89 allows processing of personal data for scientific research in clinical trials, and which safeguards such as pseudonymisation apply. - [Data transfer compliance in global clinical trials: a sponsor's guide](https://www.iliomadhealthdata.com/post/data-transfer-compliance-clinical-trials): Sponsor guide to international data transfers in global clinical trials under the GDPR, standard contractual clauses and local frameworks. - [MR-001 CNIL: what clinical trial sponsors must know about French health data compliance](https://www.iliomadhealthdata.com/post/mr-001-cnil-clinical-trial-compliance): What the CNIL MR-001 methodology requires from clinical trial sponsors processing health data in France, from security obligations to breach handling. - [Voluntary enrollment pauses in clinical trials: data protection obligations for sponsors](https://www.iliomadhealthdata.com/post/enrollment-pause-clinical-trials-participant-data-protection): Data protection obligations for sponsors when a clinical trial pauses enrolment: GDPR, informed consent documentation and safety reporting. - [ICF boilerplate and open-access database disclosures](https://www.iliomadhealthdata.com/post/icf-boilerplate-open-access-database-disclosures-clinical-trial): How US site boilerplate in informed consent forms on commercial use and open-access genetic databases affects sponsor data governance under the Common Rule and the GDPR. - [ICF data protection language for site-to-vendor transfers](https://www.iliomadhealthdata.com/post/icf-data-protection-site-to-vendor-scc-attribution-d9e00): How to attribute standard contractual clauses correctly in informed consent forms when data flows from study sites to vendors. - [Informed consent forms and ethnicity data](https://www.iliomadhealthdata.com/post/icf-ethnicity-data-justification-gdpr-mr-001-clinical-trials): Why ethics committees require a scientific justification for collecting ethnicity data in informed consent forms, under GDPR Article 9 and MR-001. - [CRO data protection: managing third-party and cloud infrastructure risk](https://www.iliomadhealthdata.com/post/cro-data-protection-vendor-risk-clinical-research): Data protection obligations of CROs under the GDPR and EU CTR 536/2014, and how to manage third-party and cloud vendor risk. - [Data processing agreements for clinical trials: cloud vendor risk](https://www.iliomadhealthdata.com/post/data-processing-agreement-dpa-clinical-trials-cloud-vendor-risk-3b2c1): What a data processing agreement must cover to protect clinical trial data hosted by cloud vendors under the GDPR. - [Safety reporting personal data in clinical trials](https://www.iliomadhealthdata.com/post/safety-reporting-personal-data-clinical-trials): GDPR obligations when processing personal data for safety reporting and pharmacovigilance in clinical trials, including cross-border disclosures. - [Pseudonymisation in clinical trials: CNIL enforcement clarifications](https://www.iliomadhealthdata.com/post/pseudonymisation-clinical-trials-cnil-enforcement-clarifications): What a 2026 CNIL enforcement action clarifies about the line between pseudonymisation and anonymisation of clinical trial data. - [Vendor GDPR in clinical trials: what the IQVIA CNIL ruling changes](https://www.iliomadhealthdata.com/post/vendor-gdpr-in-clinical-trials-what-the-iqvia-cnil-ruling-changes-for-sponsors-and-healthtech-companies): What the CNIL's 2026 IQVIA ruling, which treated supposedly anonymised health data as pseudonymous, changes for sponsors and HealthTech companies. - [EDPB anonymisation guidelines 2026 and clinical trial data](https://www.iliomadhealthdata.com/post/edpb-anonymisation-guidelines-2026-clinical-trials): How the EDPB Guidelines 02/2026 on anonymisation apply to clinical trial data, including the three-criteria test. - [DPIA for clinical trials: the EDPB harmonised template](https://www.iliomadhealthdata.com/post/dpia-clinical-trials-edpb-harmonised-template): How the EDPB's harmonised DPIA template, put to public consultation in April 2026, changes DPIAs for clinical trial sponsors. - [Human intervention in automated decision-making: the EDPS checklist](https://www.iliomadhealthdata.com/post/edps-adm-checklist-gdpr-clinical-trials): What the EDPS checklist on human intervention in automated decision-making means for sponsors and CROs using automated tools in clinical trials. - [Governing AI-assisted data flows in clinical trials under the GDPR](https://www.iliomadhealthdata.com/post/data-protection-in-clinical-trials-governing-ai-assisted-data-flows-under-gdpr): How sponsors govern AI-assisted data flows in clinical trials under the GDPR: legal bases, CRO oversight and cross-border transfers. - [CTIS data protection: joint controllership and sponsor responsibilities](https://www.iliomadhealthdata.com/post/ctis-data-protection-joint-controllership-gdpr-obligations): Data protection obligations in the Clinical Trials Information System under EU CTR 536/2014 and the GDPR, including the joint controllership arrangement. - [The Clinical Trials Information System (CTIS) and data privacy](https://www.iliomadhealthdata.com/post/the-clinical-trial-information-system-ctis-and-data-privacy-a-guide-for-clinical-trial-sponsors): Guide for sponsors on CTIS transparency rules and the protection of personal data in submitted documents. - [Data protection strategies for Phase III clinical trials](https://www.iliomadhealthdata.com/post/data-protection-strategies-for-phase-iii-clinical-trials): Data protection strategies for multi-country Phase III trials: GDPR obligations, local authorisations and ethics committee oversight. - [Applying the GDPR to clinical trials conducted in Europe](https://www.iliomadhealthdata.com/post/applying-the-gdpr-to-clinical-trials-conducted-in-europe-deciphering-the-regulatory-requirements): What US biotech companies must put in place to apply the GDPR when running clinical trials in the EU. - [Clinical trials in Europe: compliance of data transfers outside the EU](https://www.iliomadhealthdata.com/post/clinicaltrials-conducted-in-europe-compliance-of-data-transfers-outside-the-ue): Rules governing transfers of clinical trial data outside the European Economic Area. - [Impacts of the GDPR on clinical trials](https://www.iliomadhealthdata.com/post/gdpr-applied-to-clinical-trials): How the GDPR has changed the way clinical trial data is governed and processed since 2018. - [Writing a clinical trial consent form: patient data protection challenges](https://www.iliomadhealthdata.com/post/consent-form-in-a-clinical-trial-what-are-the-challenges-for-the-protection-of-patient-data): The data protection information a clinical trial informed consent form must contain, and the challenges of drafting it. - [Data mapping and data flows in clinical trials](https://www.iliomadhealthdata.com/post/importance-of-data-mapping-and-data-flow-in-clinical-trials): Why data mapping and data flow diagrams are central to GDPR compliance in clinical trials. - [ICH-GCP and the GDPR in clinical trials](https://www.iliomadhealthdata.com/post/adequacy-of-ich-gcp-guidelines-and-gdpr): Similarities and differences between ICH-GCP and the GDPR in clinical trials. - [Scientific research and the GDPR: secondary use of data](https://www.iliomadhealthdata.com/post/scientific-research-and-the-gdpr-challenges-and-opportunities-in-secondary-data-use): GDPR conditions for the secondary use of clinical trial data in scientific research. - [Data protection representatives in EU and UK clinical trials](https://www.iliomadhealthdata.com/post/navigating-compliance-the-essential-role-of-data-protection-representatives-in-eu-and-uk-clinical-trials): The role of the EU and UK data protection representative in clinical trials run by sponsors established outside those territories. - [GDPR and biotechnology: subcontracting compliance](https://www.iliomadhealthdata.com/post/gdpr-and-biotechnology-the-challenge-of-subcontracting-compliance): How biotech and MedTech sponsors keep control of GDPR compliance when they subcontract trial activities. - [Clinical trial privacy requirements in China](https://www.iliomadhealthdata.com/post/navigating-privacy-requirements-for-clinical-trials-across-jurisdictions-focus-on-china): Data protection requirements for clinical trials in China, including the PIPL, GCP-2020 and cross-border transfer rules. - [Clinical trial data protection compliance in Australia](https://www.iliomadhealthdata.com/post/strategic-guide-clinical-trial-privacy-compliance-in-australia): Clinical trial data protection in Australia for international sponsors, under the Privacy Act and OAIC oversight. - [VERBIS registration and standard contractual clauses in Turkey](https://www.iliomadhealthdata.com/post/verbis-registration-and-standard-contractual-clauses-in-turkey-a-complete-guide-for-life-sciences-companies-conducting-clinical-trials): VERBIS registration and standard contractual clauses for life sciences companies running clinical trials in Turkey. - [US regulatory requirements for AI-powered medical devices](https://www.iliomadhealthdata.com/post/navigating-us-regulatory-requirements-for-ai-powered-medical-devices-a-comprehensive-guide-to-fda-hipaa-and-irb-compliance): Guide for EU HealthTech companies entering the US with AI medical devices: FDA oversight, HIPAA, state laws and IRB review. - [EU AI Act for healthcare: what life sciences companies need to know](https://www.iliomadhealthdata.com/post/eu-ai-act-for-healthcare-what-life-sciences-companies-need-to-know-before-august-2026): EU AI Act compliance roadmap for biotech, pharma and MedTech: high-risk classification, MDR/IVDR overlap and key deadlines. - [Life sciences and the challenges of large language models](https://www.iliomadhealthdata.com/post/life-sciences-meet-the-challenges-of-large-language-models-and-foundation-models): Data protection challenges raised by large language models and foundation models in life sciences. - [AI and privacy constraints](https://www.iliomadhealthdata.com/post/ai-and-privacy-constraints): Data protection questions raised by artificial intelligence in medical research. - [Data protection and ethical challenges of AI in health, part 1](https://www.iliomadhealthdata.com/post/addressing-the-data-protection-and-ethical-challenges-posed-by-ai-in-health---part-i): The data protection and ethical challenges raised by AI in diagnostics, personalised treatment and patient monitoring. - [Data protection and ethical challenges of AI in health, part 2](https://www.iliomadhealthdata.com/post/ai-part-2): A comparison of US and EU approaches to regulating AI in life sciences. - [Data protection challenged by artificial intelligence](https://www.iliomadhealthdata.com/post/data-protection-challenged-by-artificial-intelligence-are-we-heading-towards-regulation-becoming-unavoidably-obsolete): Whether data protection law can keep pace with artificial intelligence in healthcare. - [Healthcare data warehouses: regulatory opportunities and restrictions](https://www.iliomadhealthdata.com/post/healthcare-data-warehouses-regulatory-opportunities-and-restrictions): Regulatory opportunities and constraints for healthcare data warehouses under the CNIL framework in France. - [Data sovereignty and data hosting for life sciences](https://www.iliomadhealthdata.com/post/new-concerns-for-the-life-science-industry-data-sovereignty-and-data-hosting): What data sovereignty and health data hosting requirements mean for life sciences companies in Europe. - [Cyber insurance for the life sciences industry](https://www.iliomadhealthdata.com/post/comprehensive-cyber-insurance-for-life-sciences-industry): What cyber insurance covers and why it matters for life sciences companies. ## Case studies, interviews and press - [Use case: Roche France observational study](https://www.iliomadhealthdata.com/post/iliomad-use-case-1-interview-with-quentin-lasbleiz-medical-manager-at-roche-france-on-data-protection-matters-concerning-an-observational-study): How iliomad supported Roche France on data protection for an observational study within its Ambition Autonomie project. - [Use case: CNIL authorisation for the Institut du Cancer de Montpellier](https://www.iliomadhealthdata.com/post/iliomad-is-deligthed-to-have-supported-the-icm---institut-du-cancer-de-montpellier-in-their-cnils-authorization-process): iliomad supported the Institut du Cancer de Montpellier in obtaining CNIL authorisation for the APAD-ECO study. - [Use case: partnership with MedTech Law LLC](https://www.iliomadhealthdata.com/post/iliomad-use-case-2-interview-with-roger-cepeda-founder-of-medtech-law-llc): Partnership announcement and interview with Roger Cepeda, founding attorney of MedTech Law LLC. - [Interview: Paul Chilo, SOPHiA GENETICS](https://www.iliomadhealthdata.com/post/interview-paul-chilo-director-of-governance-risk-compliance-at-sophia-genetics---sophia-unity): Interview with Paul Chilo, Director of Governance, Risk and Compliance at SOPHiA GENETICS. - [Interview: Nijta on speech and voice data](https://www.iliomadhealthdata.com/post/data-protection-addressing-noise-speech-and-voice-concerns): Interview with Brij Mohan Lal Srivastava, co-founder and CEO of Nijta, on protecting speech and voice data in AI. - [iliomad in BioPharma Dive](https://www.iliomadhealthdata.com/post/iliomad-health-data-showcased-in-biopharma-dive): iliomad's article on what US trial sponsors should know about the GDPR, published in BioPharma Dive. ## Resources - [Resource center](https://www.iliomadhealthdata.com/ressource-center): Guides, cheat sheets and brochures on data protection for life sciences. - [GDPR guide for life sciences](https://www.iliomadhealthdata.com/resource-center/gdpr-guide): Practical GDPR guide for pharma, biotech and clinical research: legal bases, data subject rights and international transfers. - [DPIA for EU clinical trials: cheat sheet](https://www.iliomadhealthdata.com/resource-center/dpia-cheat-sheet-eu-clinical-trials): Cheat sheet on the key steps of a data protection impact assessment for EU clinical trials. - [ICH GCP and GDPR: a visual comparison](https://www.iliomadhealthdata.com/resource-center/ich-gcp-and-gdpr-a-visual-comparaison): Side-by-side comparison of ICH GCP and GDPR requirements for clinical trial sponsors. - [Mandatory GDPR information in informed consent forms](https://www.iliomadhealthdata.com/resource-center/mandatory-gdpr-information-informed-consent-forms-icf): The GDPR information that must appear in informed consent forms for clinical trials. - [Health data warehouse guide (French)](https://www.iliomadhealthdata.com/resource-center/health-data-warehouse-guide-french): Guide to the French framework for health data warehouses and the related GDPR and CNIL requirements. - [iliomad services brochure](https://www.iliomadhealthdata.com/resource-center/privacy-solutions-for-life-sciences-brochure): Overview of iliomad's data protection and AI Act services for pharma, biotech and HealthTech. - [Glossary](https://www.iliomadhealthdata.com/glossary): More than 200 definitions of data protection, clinical research and EU AI Act terms for life sciences. - [Articles and news](https://www.iliomadhealthdata.com/news): All iliomad articles, guides and news. - [Newsletter archive](https://www.iliomadhealthdata.com/newsletters): Archive of iliomad's newsletter on compliance news for life sciences. - [Events](https://www.iliomadhealthdata.com/events): Events where iliomad speaks or takes part. ## Glossary: key terms - [Data Protection Officer (DPO)](https://www.iliomadhealthdata.com/glossary/data-protection-officer-dpo): The Data Protection Officer (Art. 37-39 GDPR): when appointment is mandatory, tasks, independence, and why most life sciences companies need an outsourced DPO. - [Data Protection Representative (DPR)](https://www.iliomadhealthdata.com/glossary/data-protection-representative-dpr): The Data Protection Representative (Art. 27 GDPR, Art. 3 UK GDPR, Art. 14 FADP) is mandatory for non-EU/UK/Swiss sponsors and HealthTech companies processing local residents' data. - [General Data Protection Regulation (GDPR)](https://www.iliomadhealthdata.com/glossary/gdpr-general-data-protection-regulation): The GDPR (Regulation (EU) 2016/679) is the EU's data protection law, applicable since 25 May 2018, with extraterritorial reach. - [UK GDPR](https://www.iliomadhealthdata.com/glossary/uk-gdpr): The UK GDPR is the retained version of the EU GDPR applicable in the United Kingdom since 1 January 2021, alongside the Data Protection Act 2018 and as amended by the Data (Use and Access) Act 2025. - [Swiss Federal Act on Data Protection (FADP / revFADP)](https://www.iliomadhealthdata.com/glossary/swiss-federal-act-on-data-protection-fadp): The revised Swiss Federal Act on Data Protection (revFADP), in force since 1 September 2023, aligns Swiss law with the GDPR while keeping distinct features. - [EU Artificial Intelligence Act (AI Act)](https://www.iliomadhealthdata.com/glossary/ai-act): The EU AI Act (Regulation (EU) 2024/1689) is the first horizontal law on AI, with risk-based obligations for providers and deployers. - [High-risk AI system](https://www.iliomadhealthdata.com/glossary/high-risk-ai-system): A high-risk AI system under the EU AI Act (Art. 6, Annex I and III) faces the full compliance regime: risk management, data governance, documentation, human oversight and conformity assessment. - [Provider and deployer (AI Act roles)](https://www.iliomadhealthdata.com/glossary/provider-and-deployer-ai-act): The EU AI Act allocates obligations along the value chain to providers, deployers, importers, distributors and authorised representatives. - [Authorised representative (EU AI Act)](https://www.iliomadhealthdata.com/glossary/ai-act-authorised-representative): Under Art. 22 EU AI Act, providers of high-risk AI systems established outside the EU must appoint an authorised representative in the Union before placing systems on the market. - [AI Officer](https://www.iliomadhealthdata.com/glossary/ai-officer): An AI Officer is the person or external function responsible for an organisation's AI governance and compliance with the EU AI Act, GDPR and sector rules. - [AI literacy (Art. 4 EU AI Act)](https://www.iliomadhealthdata.com/glossary/ai-literacy): AI literacy is the obligation under Art. 4 EU AI Act, applicable since 2 February 2025, for providers and deployers to ensure their staff have sufficient skills and understanding to use AI systems responsibly. - [Fundamental rights impact assessment (FRIA)](https://www.iliomadhealthdata.com/glossary/fundamental-rights-impact-assessment-fria): A fundamental rights impact assessment (Art. 27 EU AI Act) is required from certain deployers of high-risk AI systems before first use. - [Data Protection Impact Assessment (DPIA)](https://www.iliomadhealthdata.com/glossary/data-protection-impact-assessment-dpia): A DPIA (Art. 35 GDPR) is a mandatory risk assessment for high-risk processing such as clinical trials, health platforms and AI on health data. - [Transfer impact assessment (TIA)](https://www.iliomadhealthdata.com/glossary/transfer-impact-assessment-tia): A transfer impact assessment (TIA) documents whether the law and practice of a third country undermine the safeguards of SCCs or BCRs, as required since Schrems II. - [Standard contractual clauses (SCC)](https://www.iliomadhealthdata.com/glossary/standard-contractual-clauses-scc): The EU standard contractual clauses (Decision 2021/914) are the main mechanism for transferring personal data to third countries. - [EU-US Data Privacy Framework (DPF)](https://www.iliomadhealthdata.com/glossary/eu-us-data-privacy-framework): The EU-US Data Privacy Framework (adequacy decision of 10 July 2023) allows transfers to self-certified US organisations without SCCs. - [Data processing agreement (DPA)](https://www.iliomadhealthdata.com/glossary/data-processing-agreement-dpa): A data processing agreement (Art. 28(3) GDPR) is the mandatory contract between a controller and a processor, setting instructions, security, sub-processors, assistance, audits and deletion. - [Controller](https://www.iliomadhealthdata.com/glossary/controller): The controller (Art. 4(7) GDPR) determines the purposes and means of processing. - [Processor](https://www.iliomadhealthdata.com/glossary/processor): A processor (Art. 4(8) GDPR) processes personal data on behalf of the controller under Art. 28 instructions. - [Joint controllers](https://www.iliomadhealthdata.com/glossary/joint-controllers): Joint controllers (Art. 26 GDPR) jointly determine the purposes and means of processing and must allocate responsibilities in a transparent arrangement. - [Sub-processor](https://www.iliomadhealthdata.com/glossary/sub-processor): A sub-processor is a processor engaged by another processor under Art. 28(2) and (4) GDPR, requiring the controller's authorisation and flow-down of obligations. - [Pseudonymisation](https://www.iliomadhealthdata.com/glossary/pseudonymisation): Pseudonymisation (Art. 4(5) GDPR) replaces identifiers with codes while keeping the key separate. - [Anonymisation](https://www.iliomadhealthdata.com/glossary/anonymization): Anonymisation renders personal data irreversibly non-identifiable, taking it outside the GDPR. - [Key-coded data (coded data)](https://www.iliomadhealthdata.com/glossary/key-coded-data): Key-coded or coded data is pseudonymised data in which identifiers are replaced by a code, with the key held separately, typically by the investigator site. - [Scientific research purposes (Art. 89 GDPR)](https://www.iliomadhealthdata.com/glossary/scientific-research-purposes): Processing for scientific research purposes benefits from a compatibility presumption, the Art. 9(2)(j) exception and possible derogations from rights, subject to Art. 89 safeguards. - [Secondary use of health data](https://www.iliomadhealthdata.com/glossary/secondary-use-of-health-data): Secondary use means processing health data for a purpose other than the one it was collected for, such as research, innovation or policy. - [Sponsor](https://www.iliomadhealthdata.com/glossary/sponsor): Sponsor under Art. 2(2)(14) CTR 536/2014: the entity responsible for initiating, managing and financing a clinical trial. - [Contract research organisation (CRO)](https://www.iliomadhealthdata.com/glossary/contract-research-organisation-cro): A contract research organisation (CRO) performs outsourced clinical trial activities for sponsors. - [Clinical Trials Regulation (CTR) 536/2014](https://www.iliomadhealthdata.com/glossary/clinical-trials-regulation-ctr): The EU Clinical Trials Regulation 536/2014, fully applicable since 31 January 2025, harmonises authorisation and conduct of clinical trials through CTIS. - [Clinical Trials Information System (CTIS)](https://www.iliomadhealthdata.com/glossary/clinical-trials-information-system-ctis): CTIS is the single EU portal for clinical trial applications, assessment and supervision under CTR 536/2014. - [Informed consent](https://www.iliomadhealthdata.com/glossary/informed-consent): Informed consent in clinical trials (Art. 2(2)(21) and Art. 29 CTR 536/2014, ICH GCP): content, process, and why it is distinct from consent as a GDPR legal basis. - [Electronic informed consent (eConsent)](https://www.iliomadhealthdata.com/glossary/econsent): eConsent uses electronic systems to inform participants and capture their consent to take part in a clinical trial. - [Data concerning health](https://www.iliomadhealthdata.com/glossary/data-concerning-health): Data concerning health (Art. 4(15) GDPR) is broadly defined and is a special category of personal data. - [Genetic data](https://www.iliomadhealthdata.com/glossary/genetic-data): Genetic data (Art. 4(13) GDPR) is a special category of personal data covering inherited or acquired genetic characteristics. - [HIPAA (Health Insurance Portability and Accountability Act)](https://www.iliomadhealthdata.com/glossary/hipaa): HIPAA is the US federal law protecting health information held by covered entities and their business associates. - [Protected health information (PHI)](https://www.iliomadhealthdata.com/glossary/protected-health-information-phi): Protected health information (PHI) is individually identifiable health information held by a HIPAA covered entity or business associate. - [Software as a Medical Device (SaMD)](https://www.iliomadhealthdata.com/glossary/software-as-a-medical-device-samd): Software as a Medical Device (SaMD) is software with a medical purpose that is not part of a hardware device. - [Medical Device Regulation (MDR)](https://www.iliomadhealthdata.com/glossary/medical-device-regulation-mdr): The Medical Device Regulation (EU) 2017/745 governs CE marking, clinical investigation and post-market surveillance of medical devices, including software. - [European Health Data Space (EHDS)](https://www.iliomadhealthdata.com/glossary/european-health-data-space-ehds): The European Health Data Space (Regulation (EU) 2025/327) creates EU-wide rules for patient access to electronic health data and for secondary use through health data access bodies. - [NIS2 Directive](https://www.iliomadhealthdata.com/glossary/nis2-directive): The NIS2 Directive (2022/2555) imposes cybersecurity risk management and 24/72-hour incident reporting on essential and important entities, including healthcare, pharma manufacturers and medical device makers. ## Optional - [Artificial intelligence (domain overview)](https://www.iliomadhealthdata.com/domain/artificial-intelligence): AI is ushering in a transformative era for life sciences, where its data-centric nature places data privacy squarely at the heart of critical considerations - [Health data warehouses (domain overview)](https://www.iliomadhealthdata.com/domain/data-warehouses): Data warehouses are experiencing rapid growth due to their immense benefits to medical research, making adherence to regulatory requirements absolutely essential. - [Health data strategy (domain overview)](https://www.iliomadhealthdata.com/domain/data-strategy): As the volume of data, managed by companies, continues to grow, mastering data usage and control has evolved into a significant endeavor. - [Health data due diligence (domain overview)](https://www.iliomadhealthdata.com/domain/due-diligence): Integrating data privacy into due diligence is now a pivotal step, acting as a proactive shield against future regulatory pitfalls. - [Third-party risk management (domain overview)](https://www.iliomadhealthdata.com/domain/third-party-risk-management): Medical research significantly depends on third parties, ranging from data hosting to central labs and CROs. - [Weekly digest: AI governance failures, UK regulatory reform and healthcare cybersecurity](https://www.iliomadhealthdata.com/post/weekly-digest-ai-governance-uk-reform-healthcare-cybersecurity-september-2026): The ICO becomes the Information Commission, Medicare AI prior authorisation failures, FDA trial pilots and a surge of healthcare ransomware. - [Weekly digest: AI governance, data breaches and regulatory shifts in health and life sciences](https://www.iliomadhealthdata.com/post/weekly-digest-ai-governance-data-breaches-regulatory-shifts-health-life-sciences): A EUR 403 million DPC fine against Google, HIPAA settlements, UK ICO updates and Medicare AI failures. - [Weekly digest: DPO conflicts, bulk data rules, healthcare cyber incidents and AI transparency](https://www.iliomadhealthdata.com/post/weekly-digest-dpo-conflicts-bulk-data-rule-healthcare-cyber-ai-transparency): CNIL guidance on DPO conflicts of interest, the DOJ bulk data rule for life sciences and healthcare ransomware attacks. - [Weekly digest: clinical trial oversight, health data breaches and AI regulation](https://www.iliomadhealthdata.com/post/weekly-digest-clinical-trials-health-data-ai-regulation-august-2026): China tightens oversight of investigator-initiated trials, the 23andMe fine, the Snowflake guilty plea and AI partnerships in pharma. - [Weekly digest: AI triage, biopharma workbenches and EU-US data transfers](https://www.iliomadhealthdata.com/post/ai-triage-biopharma-privacy-data-transfers-weekly-digest): NHS AI triage, Anthropic's Claude Science, privacy risks in medical AI models, MHRA GxP guidance, the EDPS automated decision-making checklist and EU-US data flows. - [Weekly digest: US legislative shifts, AI privacy risks and EU cloud sovereignty](https://www.iliomadhealthdata.com/post/health-data-ai-privacy-eu-cloud-sovereignty-weekly-digest): A proposed US ban on health data brokers, a Supreme Court FTC ruling affecting EU-US data flows, AI privacy risks and EU cloud sovereignty disputes. - [Weekly digest: healthcare cyber breaches, AI regulation and genetic data enforcement](https://www.iliomadhealthdata.com/post/weekly-digest-healthcare-cyber-breaches-ai-regulation-genetic-data-enforcement): Ransomware linked to patient mortality, the FDA-EMA AI framework, Germany's KI-MIG and the EU-US Data Privacy Framework under review. - [EU Digital Omnibus simplifies AI Act obligations; Rhode Island enacts AI healthcare laws](https://www.iliomadhealthdata.com/post/eu-digital-omnibus-ai-rhode-island-healthcare-ai-laws-july-2026): Regulation (EU) 2026/1744 simplifies EU AI Act obligations, while Rhode Island enacts three laws on AI in healthcare. - [Weekly digest: EU AI Act prohibitions, GDPR enforcement and clinical trial developments (June 2026)](https://www.iliomadhealthdata.com/post/weekly-digest-eu-ai-act-prohibitions-gdpr-enforcement-and-clinical-trial-developments----week-of-22-june-2026): EU AI Act simplification, prohibited healthcare AI practices, California AB 2575, FDA enforcement and GDPR updates. - [Weekly digest: shadow AI, EDPB templates, EHDS and global reform (June 2026)](https://www.iliomadhealthdata.com/post/privacy-ai-regulation-digest-week-16-june-2026): Shadow AI risks, EDPB breach and DPIA templates, the European Health Data Space and Canada's replacement for PIPEDA. - [NHS data stolen in the Synnovis ransomware attack published by hackers](https://www.iliomadhealthdata.com/post/uks-nhs-says-hackers-have-published-data-stolen-in-ransomware-attack): The NHS confirmed that data stolen in the ransomware attack on pathology provider Synnovis was published online. - [ICO to fine NHS vendor Advanced over the LockBit ransomware attack](https://www.iliomadhealthdata.com/post/uk-data-watchdog-to-fine-nhs-vendor-advanced-for-security-failures-prior-to-lockbit-ransomware-attack): The ICO's planned fine against NHS software vendor Advanced for security failures before the LockBit ransomware attack. - [The European Health Data Space passes its final step in Parliament](https://www.iliomadhealthdata.com/post/the-european-health-data-space-overcomes-its-final-obstacle-in-parliament): The European Parliament's final approval of the European Health Data Space regulation and what it harmonises. - [Colorado enacts the first neurodata protection law](https://www.iliomadhealthdata.com/post/first-neurodata-law): Colorado became the first US state to explicitly protect neural data, with a law enacted in April 2024. - [FTC updates the Health Breach Notification Rule for health apps](https://www.iliomadhealthdata.com/post/ftc-finalizes-changes-to-the-health-breach-notification-rule): The FTC's updated Health Breach Notification Rule clarifies its application to health apps and expands the content of breach notices. - [European Parliament adopts the AI Act](https://www.iliomadhealthdata.com/post/european-parliament-adopts-ai-act): The European Parliament approved the AI Act in plenary on 13 March 2024. - [EU poised to enact sweeping AI rules](https://www.iliomadhealthdata.com/post/eu-poised-to-enact-sweeping-ai-rules): News ahead of the European Parliament's March 2024 vote on the AI Act. - [AI Act: main elements of the provisional agreement](https://www.iliomadhealthdata.com/post/eu-regulation-act-officially-adopted): The main changes introduced by the provisional agreement on the EU AI Act compared with the Commission proposal. - [US executive order on Americans' bulk sensitive personal data](https://www.iliomadhealthdata.com/post/executive-order-preventing-access-to-americans-bulk-sensitive-personal-data): The US executive order authorising the DOJ and other agencies to restrict access to Americans' bulk sensitive personal data. - [Opening of the Belgian Health Data Agency](https://www.iliomadhealthdata.com/post/opening-of-the-belgian-health-data-agency): Belgium opened its Health Data Agency on 17 January 2024 to improve access to health data for secondary use. - [CNIL recommendation: AI providers and legal responsibilities](https://www.iliomadhealthdata.com/post/cnils-recommendation-ai-providers-legal-responsibilities): How the CNIL qualifies AI system providers under the GDPR: controller, joint controller or processor. - [CNIL five-year data breach review](https://www.iliomadhealthdata.com/post/cnils-five-year-data-breach-review): The CNIL's report summarising five years of personal data breach notifications in France. - [23andMe data breach: DNA Relatives feature affected](https://www.iliomadhealthdata.com/post/data-breach-23andme-dna-relatives-feature-affected): The 23andMe security breach affecting its DNA Relatives feature and the genetic and ancestry data exposed. - [The Bletchley Declaration at the AI Safety Summit](https://www.iliomadhealthdata.com/post/the-bletchley-declaration-ai-safety-summit): The Bletchley Declaration published by the United Kingdom at the AI Safety Summit in November 2023. - [Scalable extraction of training data from production language models](https://www.iliomadhealthdata.com/post/scalable-extraction-of-training-data-from-production-language-models): Research by Google DeepMind and university teams on how outsiders can extract training data from production language models. - [Apple Watch qualified by the FDA for use in clinical trials](https://www.iliomadhealthdata.com/post/apple-pushes-into-clinical-trials-with-new-fda-nod-for-apple-watch): The FDA qualified the Apple Watch AFib History feature as a Medical Device Development Tool usable in clinical trials. - [iliomad launches its UK entity](https://www.iliomadhealthdata.com/post/iliomad-is-launching-its-uk-entity): Announcement of iliomad's UK entity and the reasons for expanding into the United Kingdom. - [iliomad at Medi'Nov Lyon 2024](https://www.iliomadhealthdata.com/post/medinov-lyon-april-3-4-2024): iliomad's participation in the Medi'Nov MedTech congress in Lyon on 3 and 4 April 2024. - [510(k) premarket notification](https://www.iliomadhealthdata.com/glossary/510-k): 510(k) is the FDA premarket notification route for most Class II medical devices, based on substantial equivalence to a predicate device. - [Accountability](https://www.iliomadhealthdata.com/glossary/accountability): Accountability under Art. 5(2) GDPR requires controllers to demonstrate compliance, not merely achieve it. - [Accuracy](https://www.iliomadhealthdata.com/glossary/accuracy): The GDPR accuracy principle (Art. 5(1)(d)) requires personal data to be accurate and kept up to date. - [Ad hoc services](https://www.iliomadhealthdata.com/glossary/ad-hoc-services): Ad hoc data protection services are one-off, scoped engagements (DPIA, contract review, gap analysis) as opposed to a recurring DPO or DPR mandate. - [Adequacy decision](https://www.iliomadhealthdata.com/glossary/adequacy-decision): An adequacy decision (Art. 45 GDPR) allows personal data to flow from the EEA to a third country without further safeguards. - [Adverse event](https://www.iliomadhealthdata.com/glossary/adverse-event): Adverse event (AE) definition under EU CTR 536/2014 and ICH GCP, and how AE data is handled as health data under the GDPR in clinical trials. - [Analysis Data Model (ADaM)](https://www.iliomadhealthdata.com/glossary/analysis-data-model-adam): ADaM is the CDISC standard for analysis-ready clinical trial datasets submitted to FDA and other regulators. - [Appropriate safeguards](https://www.iliomadhealthdata.com/glossary/appropriate-safeguards): Appropriate safeguards under Art. 46 GDPR (SCCs, BCRs, codes of conduct) allow data transfers to third countries without an adequacy decision. - [Article 29 Working Party (WP29)](https://www.iliomadhealthdata.com/glossary/article-29-working-party): The Article 29 Working Party (WP29) was the EU advisory body on data protection until 2018, replaced by the EDPB. - [Artificial intelligence (AI)](https://www.iliomadhealthdata.com/glossary/artificial-intelligence): Definition of artificial intelligence under the EU AI Act (Art. 3(1)) and what it means for pharma, MedTech and clinical research using machine learning on health data. - [Automated individual decision-making](https://www.iliomadhealthdata.com/glossary/automated-individual-decision): Automated individual decision-making under Art. 22 GDPR: when decisions based solely on automated processing are prohibited, the exceptions, and the interplay with the EU AI Act. - [Auxiliary medicinal product](https://www.iliomadhealthdata.com/glossary/auxiliary-medicinal-product): Auxiliary medicinal product (formerly non-investigational medicinal product) under Art. 2(2)(8) EU CTR 536/2014: definition, examples and documentation requirements. - [Best-in-class drugs](https://www.iliomadhealthdata.com/glossary/best-in-class-drugs): A best-in-class drug is a follow-on product judged superior within an established mechanism of action. - [Binding corporate rules (BCR)](https://www.iliomadhealthdata.com/glossary/binding-corporate-rules): Binding corporate rules (Art. 47 GDPR) are approved intra-group policies enabling international transfers within a multinational. - [Biobank](https://www.iliomadhealthdata.com/glossary/biobank): A biobank stores biological samples and associated data for future research. - [Biometric data](https://www.iliomadhealthdata.com/glossary/biometric-data): Biometric data under Art. 4(14) GDPR: definition, when it becomes special category data, and examples in clinical research and digital health (voice, gait, retinal imaging). - [Biotechnology](https://www.iliomadhealthdata.com/glossary/biotechnology): Biotechnology (biotech) uses living systems and biological processes to develop medicines, diagnostics and therapies. - [Broad consent](https://www.iliomadhealthdata.com/glossary/broad-consent): Broad consent allows participants to agree to future research within a defined framework, without knowing each specific study. - [Business associate agreement (BAA)](https://www.iliomadhealthdata.com/glossary/business-associate-agreement-baa): A business associate agreement (BAA) is the HIPAA-mandated contract between a covered entity and a vendor handling PHI (45 CFR 164.504(e)). - [Central imaging](https://www.iliomadhealthdata.com/glossary/central-imaging): Central imaging in clinical trials: independent blinded review of scans by a core lab. - [Central laboratory](https://www.iliomadhealthdata.com/glossary/central-laboratory): A central laboratory analyses biological samples from all sites in a clinical trial. - [Clinical outcome assessment (COA)](https://www.iliomadhealthdata.com/glossary/clinical-outcome-assessment-coa): A clinical outcome assessment (COA) measures how a patient feels, functions or survives. - [Clinical research](https://www.iliomadhealthdata.com/glossary/clinical-research): Clinical research covers interventional trials, observational studies, registries and secondary data use involving human participants. - [Clinical study](https://www.iliomadhealthdata.com/glossary/clinical-study): Clinical study definition under Art. 2(2)(1) EU CTR 536/2014: any investigation in humans intended to establish the effects, adverse reactions or pharmacokinetics of a medicinal product. - [Clinical trial](https://www.iliomadhealthdata.com/glossary/clinical-trial): Clinical trial definition under EU CTR 536/2014 and ICH GCP, the phases, the actors (sponsor, investigator, CRO) and how the GDPR applies to trial data. - [Clinical trial agreement (CTA)](https://www.iliomadhealthdata.com/glossary/clinical-trial-agreement-cta): A clinical trial agreement (CTA) is the contract between sponsor (or CRO) and investigator site governing conduct, budget, liability and data protection roles. - [Clinical trial phases](https://www.iliomadhealthdata.com/glossary/clinical-trial-phases): The phases of clinical trials (Phase 0 to IV) explained: objectives, participant numbers and typical duration, with the data protection issues specific to each phase. - [Clinical trial site](https://www.iliomadhealthdata.com/glossary/clinical-trial-site): A clinical trial site is the hospital, clinic or research centre where a trial is conducted under an investigator. - [Clinician-reported outcome (ClinRO)](https://www.iliomadhealthdata.com/glossary/clinician-reported-outcome-clinro): A clinician-reported outcome (ClinRO) is a clinical outcome assessment based on a trained healthcare professional's observation and judgement. - [Chemistry, Manufacturing and Controls (CMC)](https://www.iliomadhealthdata.com/glossary/cmc-chemistry-manufacturing-and-controls): CMC (Chemistry, Manufacturing and Controls) is the quality section of a drug regulatory dossier covering composition, manufacturing process and specifications. - [CNIL (Commission nationale de l'informatique et des libertés)](https://www.iliomadhealthdata.com/glossary/cnil): The CNIL is the French data protection authority, known for its reference methodologies (MR-001 to MR-008) governing health research and for active enforcement on cookies and security. - [Codes of conduct](https://www.iliomadhealthdata.com/glossary/codes-of-conduct): Codes of conduct (Art. 40 and 41 GDPR) are sector-approved sets of rules that help demonstrate compliance and can serve as a transfer tool. - [Consent](https://www.iliomadhealthdata.com/glossary/consent): Consent as a GDPR legal basis (Art. 4(11), 6(1)(a), 7 and 9(2)(a)): conditions of validity, withdrawal, and why it is rarely the right basis for clinical trial data. - [Cookies](https://www.iliomadhealthdata.com/glossary/cookies): Cookies and similar tracking technologies: the ePrivacy consent rule, exemptions, GDPR interplay and what pharma, MedTech and HealthTech websites must do to be compliant. - [Cross-border processing](https://www.iliomadhealthdata.com/glossary/cross-border-processing): Cross-border processing (Art. 4(23) GDPR) triggers the one-stop-shop mechanism and the lead supervisory authority. - [Data Act](https://www.iliomadhealthdata.com/glossary/data-act): The EU Data Act (Regulation (EU) 2023/2854), applicable since 12 September 2025, gives users of connected products access to the data they generate and regulates B2B data sharing and cloud switching. - [Data Governance Act (DGA)](https://www.iliomadhealthdata.com/glossary/data-governance-act): The Data Governance Act (Regulation (EU) 2022/868) regulates reuse of protected public-sector data, data intermediation services and data altruism. - [Data management plan (DMP)](https://www.iliomadhealthdata.com/glossary/data-management-plan-dmp): A clinical data management plan (DMP) documents how trial data will be collected, validated, cleaned, coded, locked and archived. - [Data minimisation](https://www.iliomadhealthdata.com/glossary/data-minimization): The data minimisation principle (Art. 5(1)(c) GDPR): personal data must be adequate, relevant and limited to what is necessary. - [Data monitoring committee (DMC)](https://www.iliomadhealthdata.com/glossary/data-monitoring-committee-dmc): A data monitoring committee (DMC or DSMB) independently reviews accumulating safety and efficacy data during a clinical trial. - [Data protection authority (DPA)](https://www.iliomadhealthdata.com/glossary/data-protection-authority): A data protection authority is the independent national regulator enforcing the GDPR (CNIL, ICO, AEPD, Garante…). - [Data protection by default](https://www.iliomadhealthdata.com/glossary/data-protection-by-default): Data protection by default (Art. 25(2) GDPR) requires that, out of the box, only necessary personal data is processed. - [Data protection by design](https://www.iliomadhealthdata.com/glossary/data-protection-by-design): Data protection by design (Art. 25(1) GDPR) requires privacy to be built into systems and processes from the outset. - [Data quality](https://www.iliomadhealthdata.com/glossary/data-quality): Data quality in data protection law refers to the Art. 5 GDPR principles (accuracy, minimisation, storage limitation). - [Data retention](https://www.iliomadhealthdata.com/glossary/data-retention): Data retention rules for clinical trial and health data: GDPR storage limitation, the 25-year trial master file rule under CTR 536/2014, and building a retention schedule. - [Data subject](https://www.iliomadhealthdata.com/glossary/data-subject): The data subject is the identified or identifiable natural person to whom personal data relates (Art. 4(1) GDPR). - [Data subject access request (DSAR)](https://www.iliomadhealthdata.com/glossary/data-subject-access-request-dsar): A data subject access request (DSAR) is a request to exercise the right of access under Art. 15 GDPR. - [International data transfer](https://www.iliomadhealthdata.com/glossary/data-transfer): International data transfers under Chapter V GDPR: adequacy, SCCs, BCRs, derogations and transfer impact assessments. - [De-identification (HIPAA)](https://www.iliomadhealthdata.com/glossary/de-identification): De-identification under HIPAA (45 CFR 164.514) removes identifiers so that health information is no longer PHI, via Safe Harbor (18 identifiers) or Expert Determination. - [Decentralised clinical trial (DCT)](https://www.iliomadhealthdata.com/glossary/decentralised-clinical-trial-dct): A decentralised clinical trial (DCT) moves trial activities to participants' homes using telemedicine, eConsent, wearables, home nursing and direct-to-patient drug shipment. - [Differential privacy](https://www.iliomadhealthdata.com/glossary/differential-privacy): Differential privacy is a mathematical framework that adds calibrated noise so that the output of an analysis does not reveal whether any individual's data was included. - [Early termination of a clinical trial](https://www.iliomadhealthdata.com/glossary/early-termination-of-a-clinical-trial): Early termination of a clinical trial under Art. 2(2)(28) CTR 536/2014: definition, notification duties in CTIS, and what happens to participants' data after termination. - [Electronic case report form (eCRF)](https://www.iliomadhealthdata.com/glossary/electronic-case-report-form-ecrf): An eCRF is the electronic form used to record protocol-required data for each trial participant in an EDC system. - [Electronic clinical outcome assessment (eCOA)](https://www.iliomadhealthdata.com/glossary/electronic-clinical-outcome-assessment-ecoa): eCOA is the electronic capture of clinical outcome assessments (ePRO, eClinRO, eObsRO, ePerfO) via tablets, smartphones or wearables. - [Electronic data capture (EDC)](https://www.iliomadhealthdata.com/glossary/electronic-data-capture-edc): An EDC system is the validated software platform that hosts eCRFs and manages clinical trial data collection, queries and audit trails. - [Electronic health record (EHR)](https://www.iliomadhealthdata.com/glossary/electronic-health-record-ehr): An electronic health record (EHR) is a longitudinal digital patient record maintained by healthcare providers. - [Encryption](https://www.iliomadhealthdata.com/glossary/encryption): Encryption converts data into unreadable ciphertext without the key, and is named in Art. 32 GDPR as a security measure. - [End of a clinical trial](https://www.iliomadhealthdata.com/glossary/end-of-a-clinical-trial): End of a clinical trial under Art. 2(2)(26) CTR 536/2014: last visit of the last subject, CTIS notification and results deadlines, and the start of the 25-year archiving period. - [Enterprise](https://www.iliomadhealthdata.com/glossary/enterprise): Enterprise (Art. 4(18) GDPR) and group of undertakings (Art. 4(19)): why these definitions matter for binding corporate rules, fines calculated on group turnover and intra-group transfers. - [Ethics committee](https://www.iliomadhealthdata.com/glossary/ethics-committee): An ethics committee (research ethics committee, IRB, CPP) independently reviews clinical research to protect participants. - [European Data Protection Board (EDPB)](https://www.iliomadhealthdata.com/glossary/european-data-protection-board-edpb): The EDPB is the EU body of national data protection authorities ensuring consistent GDPR application. - [European Data Protection Supervisor (EDPS)](https://www.iliomadhealthdata.com/glossary/european-data-protection-supervisor-edps): The EDPS is the data protection authority for EU institutions and agencies under Regulation (EU) 2018/1725, including EMA and CTIS. - [European Medicines Agency (EMA)](https://www.iliomadhealthdata.com/glossary/european-medicines-agency-ema): The EMA is the EU agency evaluating medicines for centralised authorisation and coordinating pharmacovigilance, CTIS and clinical data publication. - [Explicit consent](https://www.iliomadhealthdata.com/glossary/explicit-consent): Explicit consent is the heightened form of consent required for special category data (Art. 9(2)(a) GDPR), automated decisions and transfers under Art. 49. - [Fairness and transparency](https://www.iliomadhealthdata.com/glossary/fairness-and-transparency): Fairness and transparency under Art. 5(1)(a) GDPR: what the principles require in practice, from information notices to avoiding dark patterns, in clinical research and digital health. - [Federated learning](https://www.iliomadhealthdata.com/glossary/federated-learning): Federated learning trains AI models across multiple institutions without pooling raw data: only model updates are exchanged. - [First-in-class drugs](https://www.iliomadhealthdata.com/glossary/first-in-class-drugs): A first-in-class drug uses a new and unique mechanism of action to treat a condition. - [Filing system](https://www.iliomadhealthdata.com/glossary/filing-system): A filing system (Art. 4(6) GDPR) is any structured set of personal data accessible by specific criteria. - [Food and Drug Administration (FDA)](https://www.iliomadhealthdata.com/glossary/food-and-drug-administration-fda): The FDA is the US federal agency regulating drugs, biologics and medical devices. - [General-purpose AI model (GPAI)](https://www.iliomadhealthdata.com/glossary/general-purpose-ai-model-gpai): General-purpose AI models (Art. 3(63), 51-56 EU AI Act) are models such as large language models trained on broad data and capable of many tasks. - [Genetically modified organism (GMO)](https://www.iliomadhealthdata.com/glossary/genetically-modified-organism-gmo): GMO definition under Directive 2001/18/EC and its relevance to gene therapy and vaccine clinical trials: environmental risk assessment and interplay with CTR 536/2014. - [Global public health security](https://www.iliomadhealthdata.com/glossary/global-public-health-security): Global public health security covers the collective measures to prevent, detect and respond to cross-border health threats. - [Good clinical practice (GCP)](https://www.iliomadhealthdata.com/glossary/good-clinical-practice-gcp): Good clinical practice (ICH E6(R3), Art. 2(2)(30) CTR 536/2014) is the international ethical and scientific quality standard for clinical trials. - [Health data warehouse (HDW)](https://www.iliomadhealthdata.com/glossary/health-data-warehouse): A health data warehouse (entrepôt de données de santé) centralises health data from multiple sources for secondary use in research and innovation. - [Human oversight (AI Act)](https://www.iliomadhealthdata.com/glossary/human-oversight): Human oversight (Art. 14 and 26 EU AI Act) requires high-risk AI systems to be designed and used so that natural persons can understand, monitor, override and stop them. - [Human subjects protection review board](https://www.iliomadhealthdata.com/glossary/human-subjects-protection-review-board): A human subjects protection review board, known as an IRB in the US or an ethics committee in Europe, reviews and monitors research involving people. - [Investigational Medicinal Product Dossier (IMPD)](https://www.iliomadhealthdata.com/glossary/impd-investigational-medicinal-product-dossier): The IMPD is the quality, non-clinical and clinical dossier on an investigational medicinal product submitted with a clinical trial application in CTIS. - [In Vitro Diagnostic Regulation (IVDR)](https://www.iliomadhealthdata.com/glossary/in-vitro-diagnostic-regulation-ivdr): The In Vitro Diagnostic Regulation (EU) 2017/746 governs IVD devices, including genetic tests and companion diagnostics, with risk classes A to D and performance studies. - [Incapacitated subject](https://www.iliomadhealthdata.com/glossary/incapacitated-subject): An incapacitated subject (Art. 2(2)(19) CTR 536/2014) cannot give informed consent and is protected by specific conditions in Art. 31. - [Information Commissioner's Office (ICO)](https://www.iliomadhealthdata.com/glossary/information-commissioners-office-ico): The Information Commissioner's Office (ICO) is the UK's data protection regulator, enforcing the UK GDPR, Data Protection Act 2018 and PECR. - [Inspection](https://www.iliomadhealthdata.com/glossary/inspection): Inspection under Art. 2(2)(31) CTR 536/2014: official review of documents, facilities and records by a competent authority. - [Institutional Review Board (IRB)](https://www.iliomadhealthdata.com/glossary/institutional-review-board-irb): An Institutional Review Board (IRB) is the US ethics committee reviewing research with human subjects under the Common Rule and FDA regulations. - [Interactive response technology (IRT)](https://www.iliomadhealthdata.com/glossary/interactive-response-technology-irt): IRT (interactive response technology) systems manage randomisation, drug supply and unblinding in clinical trials. - [Interactive web response system (IWRS)](https://www.iliomadhealthdata.com/glossary/interactive-web-response-system-iwrs): An IWRS is a web-based system for randomisation, drug supply and unblinding in clinical trials, successor to telephone IVRS and now part of IRT/RTSM platforms. - [Investigational medicinal product (IMP)](https://www.iliomadhealthdata.com/glossary/investigational-medicinal-product): Investigational medicinal product (IMP) under Art. 2(2)(5) CTR 536/2014: the tested product, placebo or reference. - [Investigational New Drug (IND) application](https://www.iliomadhealthdata.com/glossary/investigational-new-drug-ind): An IND is the FDA submission (21 CFR Part 312) required before a drug can be tested in humans in the US. - [Investigator](https://www.iliomadhealthdata.com/glossary/investigator): Investigator under Art. 2(2)(15) CTR 536/2014: the individual responsible for conducting a clinical trial at a site. - [Investigator's brochure (IB)](https://www.iliomadhealthdata.com/glossary/investigators-brochure): The investigator's brochure (Art. 2(2)(23) CTR 536/2014, ICH GCP section 7) compiles clinical and non-clinical data on the IMP for investigators. - [ISO/IEC 27001 (information security management)](https://www.iliomadhealthdata.com/glossary/iso-iec-27001): ISO/IEC 27001 is the international standard for information security management systems (ISMS), widely expected of vendors handling health data. - [ISO/IEC 42001 (AI management system)](https://www.iliomadhealthdata.com/glossary/iso-iec-42001): ISO/IEC 42001:2023 is the first certifiable international standard for an AI management system (AIMS). - [k-anonymity](https://www.iliomadhealthdata.com/glossary/k-anonymity): k-anonymity is a privacy model ensuring each record is indistinguishable from at least k-1 others on quasi-identifiers. - [Key (cryptographic key and pseudonymisation key)](https://www.iliomadhealthdata.com/glossary/key): In data protection, a key is the secret used for encryption or the mapping table linking pseudonyms to identities. - [Kinetics (pharmacokinetics and pharmacodynamics)](https://www.iliomadhealthdata.com/glossary/kinetics): Kinetics in drug development refers to the time course of drug concentration and effect in the body (PK/PD). - [Large language model (LLM)](https://www.iliomadhealthdata.com/glossary/large-language-model-llm): Large language models (LLMs) are generative AI systems trained on vast text corpora to produce and understand language. - [Lawfulness](https://www.iliomadhealthdata.com/glossary/lawfulness): Lawfulness under Art. 5(1)(a) and Art. 6 GDPR: every processing needs a legal basis, and special category data needs an Art. 9 exception. - [Legal basis for processing](https://www.iliomadhealthdata.com/glossary/legal-basis-for-processing): The six legal bases of Art. 6(1) GDPR explained, plus the Art. 9(2) exceptions for health data, and which bases sponsors, CROs and HealthTech companies should rely on. - [Legally designated representative](https://www.iliomadhealthdata.com/glossary/legally-designated-representative): Legally designated representative under Art. 2(2)(20) CTR 536/2014: the person authorised to consent on behalf of an incapacitated subject or a minor. - [Legitimate interest](https://www.iliomadhealthdata.com/glossary/legitimate-interest): Legitimate interest (Art. 6(1)(f) GDPR) is a flexible legal basis requiring a three-step balancing test. - [Legitimate interest assessment (LIA)](https://www.iliomadhealthdata.com/glossary/legitimate-interest-assessment-lia): A legitimate interest assessment (LIA) documents the three-part test required to rely on Art. 6(1)(f) GDPR: purpose, necessity and balancing. - [Storage limitation (limited storage periods)](https://www.iliomadhealthdata.com/glossary/limited-storage-periods): Storage limitation (Art. 5(1)(e) GDPR) requires personal data to be kept in identifiable form no longer than necessary. - [Local site investigator](https://www.iliomadhealthdata.com/glossary/local-site-investigator): A local site investigator conducts a multicentre clinical trial at one specific site under the coordinating investigator. - [Main establishment](https://www.iliomadhealthdata.com/glossary/main-establishment): Main establishment (Art. 4(16) GDPR) is the place of central administration in the EU, or where decisions on purposes and means are taken. - [Natural history study](https://www.iliomadhealthdata.com/glossary/natural-history-study): A natural history study tracks the course of a disease over time without intervention, often in rare diseases, to inform trial design and serve as an external control. - [Observational study](https://www.iliomadhealthdata.com/glossary/observational-study): An observational (non-interventional) study assesses outcomes without assigning treatment. - [Observer-reported outcome (ObsRO)](https://www.iliomadhealthdata.com/glossary/observer-reported-outcome-obsro): An observer-reported outcome (ObsRO) is a clinical outcome assessment reported by a parent, caregiver or other non-clinician observer. - [One-stop-shop mechanism and lead supervisory authority](https://www.iliomadhealthdata.com/glossary/one-stop-shop-mechanism): The one-stop-shop mechanism (Art. 56 and 60 GDPR) lets organisations engaged in cross-border processing deal with a single lead supervisory authority at their main establishment. - [Orphan drug designation (ODD)](https://www.iliomadhealthdata.com/glossary/orphan-drug-designation-odd): Orphan drug designation (Regulation (EC) 141/2000 in the EU; Orphan Drug Act in the US) grants incentives for rare-disease medicines. - [Patient-reported outcome (PRO)](https://www.iliomadhealthdata.com/glossary/patient-reported-outcome-pro): A patient-reported outcome (PRO) is a clinical outcome assessment reported directly by the patient without interpretation. - [Performance outcome (PerfO)](https://www.iliomadhealthdata.com/glossary/performance-outcome-perfo): A performance outcome (PerfO) is a clinical outcome assessment based on a standardised task performed by the patient, such as a walk test or cognitive test. - [Personal data](https://www.iliomadhealthdata.com/glossary/personal-data): Personal data (Art. 4(1) GDPR) is any information relating to an identified or identifiable natural person. - [Personal data breach](https://www.iliomadhealthdata.com/glossary/personal-data-breach): A personal data breach (Art. 4(12) GDPR) is a security incident leading to destruction, loss, alteration, unauthorised disclosure of or access to personal data. - [Pharmacokinetics (PK)](https://www.iliomadhealthdata.com/glossary/pharmacokinetics-pk): Pharmacokinetics (PK) studies the absorption, distribution, metabolism and excretion of drugs. - [Pharmacovigilance](https://www.iliomadhealthdata.com/glossary/pharmacovigilance): Pharmacovigilance is the science and activities relating to the detection, assessment, understanding and prevention of adverse effects of medicines. - [Population pharmacokinetics (pop PK)](https://www.iliomadhealthdata.com/glossary/population-pharmacokinetics-pop-pk): Population pharmacokinetics (pop PK) uses non-linear mixed-effects modelling to characterise variability in drug exposure across patients. - [Principal investigator (PI)](https://www.iliomadhealthdata.com/glossary/principal-investigator): The principal investigator (Art. 2(2)(16) CTR 536/2014) leads the investigator team at a clinical trial site. - [Principles of data protection](https://www.iliomadhealthdata.com/glossary/principles-of-data-protection): The seven principles of Art. 5 GDPR (lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability) explained for life sciences. - [Privacy](https://www.iliomadhealthdata.com/glossary/privacy): Privacy is the fundamental right to be free from unwarranted intrusion and to control information about oneself (Art. 7 EU Charter, Art. 8 ECHR). - [Privacy by design](https://www.iliomadhealthdata.com/glossary/privacy-by-design): Privacy by design is the approach of embedding privacy into systems and processes from the outset, formalised in Art. 25 GDPR as data protection by design. - [Privacy-enhancing technologies (PETs)](https://www.iliomadhealthdata.com/glossary/privacy-enhancing-technologies-pets): Privacy-enhancing technologies (PETs) such as pseudonymisation, encryption, differential privacy, federated learning and synthetic data protect personal data while preserving utility. - [Privacy notice (information notice)](https://www.iliomadhealthdata.com/glossary/privacy-notice): A privacy notice or information notice is the document through which a controller meets its Art. 13 and 14 GDPR transparency duties. - [Processing](https://www.iliomadhealthdata.com/glossary/processing): Processing (Art. 4(2) GDPR) covers any operation performed on personal data, from collection to erasure. - [Profiling](https://www.iliomadhealthdata.com/glossary/profiling): Profiling (Art. 4(4) GDPR) is automated processing to evaluate personal aspects of a person, such as health or behaviour. - [Protocol](https://www.iliomadhealthdata.com/glossary/protocol): The clinical trial protocol (Art. 2(2)(22) CTR 536/2014, ICH E6) describes objectives, design, methodology and organisation. - [Purpose limitation](https://www.iliomadhealthdata.com/glossary/purpose-limitation): Purpose limitation (Art. 5(1)(b) GDPR) requires specified, explicit and legitimate purposes and restricts incompatible further use. - [Qualified Person for Pharmacovigilance (QPPV)](https://www.iliomadhealthdata.com/glossary/qualified-person-for-pharmacovigilance-qppv): The QPPV is the EU-resident individual responsible for a marketing authorisation holder's pharmacovigilance system (Art. 104 Directive 2001/83/EC, GVP Module I). - [Quality management system (QMS)](https://www.iliomadhealthdata.com/glossary/quality-management-system-qms): A quality management system (QMS) is the documented framework of processes, procedures and responsibilities through which an organisation ensures quality and compliance. - [Quasi-identifier](https://www.iliomadhealthdata.com/glossary/quasi-identifier): A quasi-identifier is an attribute (age, sex, postcode, dates, rare diagnosis) that does not identify a person alone but can when combined with others. - [Query (clinical data query)](https://www.iliomadhealthdata.com/glossary/query-clinical-data-query): A data query is a formal question raised on a clinical trial data point that appears inconsistent, missing or implausible, resolved by the site through an audit-trailed workflow in the EDC. - [Randomised clinical trial (RCT)](https://www.iliomadhealthdata.com/glossary/randomised-clinical-trials): A randomised clinical trial allocates participants to treatment groups by chance, minimising bias. - [Randomisation and trial supply management (RTSM)](https://www.iliomadhealthdata.com/glossary/randomization-and-trial-supply-management-rtsm): RTSM systems combine randomisation, treatment assignment and investigational product supply management in clinical trials. - [Real-world data (RWD)](https://www.iliomadhealthdata.com/glossary/real-world-data-rwd): Real-world data (RWD) is health data collected outside conventional clinical trials, from EHRs, claims, registries and wearables. - [Real-world evidence (RWE)](https://www.iliomadhealthdata.com/glossary/real-world-evidence-rwe): Real-world evidence (RWE) is clinical evidence derived from the analysis of real-world data. - [Recipient](https://www.iliomadhealthdata.com/glossary/recipient): Recipient (Art. 4(9) GDPR) is any body to which personal data is disclosed, whether a third party or not, excluding authorities acting in a particular inquiry. - [Record of processing activities (RoPA)](https://www.iliomadhealthdata.com/glossary/record-of-processing-activities): The record of processing activities (Art. 30 GDPR) is the mandatory inventory of processing maintained by controllers and processors. - [Restriction of processing](https://www.iliomadhealthdata.com/glossary/restriction-of-processing): Restriction of processing (Art. 4(3) GDPR) means marking stored personal data to limit its future processing. - [Right not to be subject to solely automated decision-making](https://www.iliomadhealthdata.com/glossary/right-not-to-be-subject-to-a-decision-based-solely-on-automated-processing-2): Art. 22 GDPR gives data subjects the right not to be subject to solely automated decisions with legal or similarly significant effects. - [Right of access](https://www.iliomadhealthdata.com/glossary/right-of-access): The right of access (Art. 15 GDPR) lets data subjects obtain confirmation of processing, a copy of their data and information about it, within one month. - [Right of information](https://www.iliomadhealthdata.com/glossary/right-of-information): The right of information (Art. 12-14 GDPR) obliges controllers to tell data subjects who processes their data, why and how. - [Right of rectification](https://www.iliomadhealthdata.com/glossary/right-of-rectification): The right of rectification (Art. 16 GDPR) allows data subjects to have inaccurate data corrected and incomplete data completed. - [Right to data portability](https://www.iliomadhealthdata.com/glossary/right-to-data-portability): The right to data portability (Art. 20 GDPR) lets individuals receive and transmit data they provided, processed by automated means under consent or contract. - [Right to erasure ("right to be forgotten")](https://www.iliomadhealthdata.com/glossary/right-to-erasure): The right to erasure (Art. 17 GDPR) applies in defined circumstances and is subject to exceptions, including for scientific research and legal obligations. - [Right to object](https://www.iliomadhealthdata.com/glossary/right-to-object): The right to object (Art. 21 GDPR) allows data subjects to oppose processing based on public interest or legitimate interests, and absolutely for direct marketing. - [Right to restriction of processing](https://www.iliomadhealthdata.com/glossary/right-to-restriction-of-processing): The right to restriction (Art. 18 GDPR) lets data subjects require that their data be stored but not otherwise processed in four situations. - [Rights of the data subject](https://www.iliomadhealthdata.com/glossary/rights-of-the-data-subject): The eight data subject rights under Chapter III GDPR (information, access, rectification, erasure, restriction, portability, objection, automated decisions): overview, deadlines and research limitations. - [Security breach (security incident)](https://www.iliomadhealthdata.com/glossary/security-breach): A security breach or incident is any event compromising the confidentiality, integrity or availability of information. - [Security of processing](https://www.iliomadhealthdata.com/glossary/security-of-processing): Security of processing (Art. 32 GDPR) requires appropriate technical and organisational measures proportionate to the risk. - [Sensitive data](https://www.iliomadhealthdata.com/glossary/sensitive-data): "Sensitive data" is the common name for the special categories of personal data in Art. 9 GDPR: health, genetic, biometric data and others. - [Serious adverse event (SAE)](https://www.iliomadhealthdata.com/glossary/serious-adverse-event): Serious adverse event (SAE) under Art. 2(2)(33) CTR 536/2014: death, life-threatening event, hospitalisation, disability or congenital anomaly. - [Source data verification (SDV) and source documents](https://www.iliomadhealthdata.com/glossary/source-data-verification-sdv): Source data verification (SDV) compares clinical trial data in the eCRF with original source documents such as medical records. - [Special categories of personal data](https://www.iliomadhealthdata.com/glossary/special-categories-of-personal-data): Special categories of personal data (Art. 9 GDPR) include health, genetic and biometric data. - [Start of a clinical trial](https://www.iliomadhealthdata.com/glossary/start-of-a-clinical-trial): Start of a clinical trial under Art. 2(2)(25) CTR 536/2014 is the first act of recruitment of a potential subject. - [Study Data Tabulation Model (SDTM)](https://www.iliomadhealthdata.com/glossary/study-data-tabulation-model-sdtm): SDTM is the CDISC standard for organising clinical trial data into domains for regulatory submission to FDA, PMDA and others. - [Subject (clinical trial participant)](https://www.iliomadhealthdata.com/glossary/subject): Subject under Art. 2(2)(17) CTR 536/2014: an individual who participates in a clinical trial as recipient of an investigational product or as control. - [Supervisory authority](https://www.iliomadhealthdata.com/glossary/supervisory-authority): A supervisory authority (Art. 51 GDPR) is the independent public body monitoring GDPR compliance in each Member State. - [Supplementary measures](https://www.iliomadhealthdata.com/glossary/supplementary-measures): Supplementary measures are additional technical, contractual or organisational safeguards required when a transfer impact assessment shows that SCCs or BCRs alone are insufficient (EDPB Recommendations 01/2020). - [Synthetic data](https://www.iliomadhealthdata.com/glossary/synthetic-data): Synthetic data is artificially generated data that mimics the statistical properties of real datasets. - [Technical and organisational measures (TOMs)](https://www.iliomadhealthdata.com/glossary/technical-and-organisational-measures-toms): Technical and organisational measures (TOMs) are the safeguards controllers and processors must implement under Art. 24, 25, 28 and 32 GDPR. - [Temporary halt of a clinical trial](https://www.iliomadhealthdata.com/glossary/temporary-halt-of-a-clinical-trial): Temporary halt of a clinical trial (Art. 2(2)(27) CTR 536/2014): an interruption not provided in the protocol, with intention to resume. - [Third country](https://www.iliomadhealthdata.com/glossary/third-country): A third country under the GDPR is any country outside the EU and EEA, including the UK, Switzerland and the US. - [Third party](https://www.iliomadhealthdata.com/glossary/third-party): Third party (Art. 4(10) GDPR) means any person or body other than the data subject, controller, processor and their authorised staff. - [Trial master file (TMF)](https://www.iliomadhealthdata.com/glossary/trial-master-file-tmf): The trial master file (TMF) is the collection of essential documents that allows a clinical trial to be reconstructed and evaluated. - [Unexpected serious adverse reaction (SUSAR)](https://www.iliomadhealthdata.com/glossary/unexpected-serious-adverse-reaction): Unexpected serious adverse reaction (Art. 2(2)(34) CTR 536/2014) and SUSAR expedited reporting to EudraVigilance within 7 or 15 days. - [Validation (computerised system validation, CSV)](https://www.iliomadhealthdata.com/glossary/validation-computerised-system-validation-csv): Computerised system validation (CSV) is the documented process demonstrating that a GxP system consistently does what it is intended to do (21 CFR Part 11, EU Annex 11, GAMP 5, EMA 2023 guideline). - [Vendor assessment (third-party risk management)](https://www.iliomadhealthdata.com/glossary/vendor-assessment): Vendor assessment is the process of evaluating and monitoring suppliers that process personal data or support regulated activities, as required by Art. 28 GDPR, ICH GCP and NIS2. - [Vital interests (Art. 6(1)(d) GDPR)](https://www.iliomadhealthdata.com/glossary/vital-interests): Vital interests is the GDPR legal basis for processing necessary to protect a person's life, used only when no other basis applies (Art. 6(1)(d), 9(2)(c)). - [Vulnerable participants (vulnerable subjects)](https://www.iliomadhealthdata.com/glossary/vulnerable-participants): Vulnerable participants are people whose capacity or circumstances limit free and informed consent: minors, incapacitated adults, pregnant women, emergency patients, prisoners, dependants. - [Wearables and digital health technologies (DHT)](https://www.iliomadhealthdata.com/glossary/wearables-and-digital-health-technologies): Wearables and digital health technologies (DHT) collect continuous physiological and behavioural data in trials and care. - [Withdrawal (of consent and from a clinical trial)](https://www.iliomadhealthdata.com/glossary/withdrawal-of-consent): Withdrawal covers a participant leaving a clinical trial (Art. 28(3) CTR) and withdrawing consent as a GDPR legal basis (Art. 7(3)). - [World Health Organization (WHO)](https://www.iliomadhealthdata.com/glossary/world-health-organization-who): The World Health Organization (WHO) is the UN agency for international public health, and the source of the ICTRP trial registry requirements and the International Health Regulations. - [XAI (explainable artificial intelligence)](https://www.iliomadhealthdata.com/glossary/xai-explainable-artificial-intelligence): XAI (explainable AI) covers methods that make AI model outputs understandable to humans. - [Yellow Card scheme (UK)](https://www.iliomadhealthdata.com/glossary/yellow-card-scheme): The Yellow Card scheme is the UK MHRA system for reporting suspected adverse drug reactions, medical device incidents and defective medicines. - [Zero-knowledge proof](https://www.iliomadhealthdata.com/glossary/zero-knowledge-proof): A zero-knowledge proof lets one party prove a statement is true without revealing anything else, and is one of the privacy-enhancing technologies. - [Zero trust architecture](https://www.iliomadhealthdata.com/glossary/zero-trust-architecture): Zero trust is a security model that verifies every user, device and request continuously, assuming no implicit trust inside the network (NIST SP 800-207).