Privacy AI
Regulatory

Health data compliance, handled.

Tell us what you need. We'll tell you what it takes and how long, before you commit.

Contact us

Summary

This article outlines the essential data protection obligations for Contract Research Organisations (CROs) under GDPR and EU CTR 536/2014, emphasizing the importance of managing third-party vendor risk and cloud infrastructure security. It presents a framework for CROs to ensure compliance and mitigate risks associated with data processing activities in clinical trials.

Contact us

Contract Research Organisations (CROs) are indispensable to modern clinical research, yet every data processing activity they perform on behalf of a sponsor creates a direct liability chain under the General Data Protection Regulation (Regulation (EU) 2016/679, hereinafter GDPR) and the EU Clinical Trials Regulation 536/2014 (EU CTR). When a CRO or a health-technology vendor suffers unauthorised access to cloud infrastructure, the downstream consequences extend across every clinical site, every participant record and every regulatory relationship attached to the trial.

A recent incident involving a health-technology company providing data migration and electronic health record (EHR) exchange services illustrates precisely this risk. Unauthorised access to the vendor's Amazon Web Services environment, undetected for approximately sixteen days, ultimately affected at least twenty-eight downstream healthcare provider clients and hundreds of thousands of patients. Client notification did not begin until roughly six months after discovery, a timeline that sits far outside the sixty-day deadline imposed by the US Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule. Although that incident occurred under US law, its structural characteristics, namely a single vendor failure cascading to dozens of data controllers, are directly analogous to scenarios that GDPR-regulated sponsors and CROs face every day.

This article sets out the iliomad framework for CRO data protection due diligence, using the vendor breach model as a lens through which to examine GDPR obligations, EU CTR requirements and practical risk controls.

The iliomad supply-chain accountability framework for CRO data protection

The iliomad supply-chain accountability framework structures CRO data protection obligations around four sequential layers: (1) role determination, (2) contractual architecture, (3) technical and organisational measures (TOMs), and (4) incident response. Each layer feeds the next; a weakness at any point propagates risk to all subsequent layers.

The rationale for a structured framework is straightforward. Under GDPR Article 28, a controller must use only processors providing sufficient guarantees that appropriate technical and organisational measures are in place. That obligation is not discharged by a signature on a data processing agreement (DPA); it requires documented, ongoing verification. EU CTR Article 49 reinforces this by requiring that clinical trial data be protected against unauthorised access, disclosure and destruction, irrespective of which legal entity physically holds the data.

Applying the framework to a CRO means tracing every data flow from the investigator site through the CRO's systems, into any sub-processor environment (including cloud platforms such as AWS, Azure or Google Cloud), and back to the sponsor. The health-technology vendor incident described above demonstrates that a failure at the sub-processor tier, specifically the cloud infrastructure layer, is attributable upstream to the CRO and ultimately to the sponsor as controller.

What GDPR obligations apply specifically to a CRO acting as data processor?

A CRO acting as a data processor under GDPR Article 4(8) is an entity that processes personal data on behalf of the controller, in this context the clinical trial sponsor. The CRO's obligations flow primarily from GDPR Article 28 and, where the CRO makes independent decisions about processing purposes, from the controller provisions in Articles 13 to 22.

Several obligations deserve particular attention in the clinical research context.

Data processing agreements. GDPR Article 28(3) mandates that processing by a processor be governed by a binding contract specifying, among other elements, the subject matter and duration of processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. In clinical trials, this means the DPA must explicitly address processing of special-category health data under GDPR Article 9(2)(j) (processing for scientific research purposes with appropriate safeguards as provided for in Article 89(1)).

Sub-processor authorisation. GDPR Article 28(2) requires that a processor obtain the controller's prior written authorisation before engaging a sub-processor. When a CRO hosts trial data on a third-party cloud platform, that platform is a sub-processor. The same contractual guarantees required of the CRO must flow down to every sub-processor by virtue of GDPR Article 28(4). A DPA that fails to name cloud infrastructure providers, or that grants blanket authorisation without a mechanism for the sponsor to object, is non-compliant on its face.

Data breach notification. GDPR Article 33 requires a controller to notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware. GDPR Article 33(2) requires a processor, upon becoming aware of a breach, to notify the controller without undue delay. This means the CRO's incident response plan must include immediate escalation to the sponsor, because the sponsor's 72-hour clock starts running from the moment the processor has awareness, not the moment the sponsor is formally notified. A six-month notification gap, of the kind observed in the US vendor incident, would be wholly incompatible with GDPR Article 33.

Records of processing activities. GDPR Article 30(2) requires processors to maintain records of all categories of processing activities carried out on behalf of a controller. For a CRO managing data across multiple trials, multiple sponsors and multiple jurisdictions, this record must be granular enough to identify each trial, each data category, each sub-processor and each transfer mechanism.

Focus: the example of France and the CNIL

In France, CRO data protection in the context of clinical trials is subject not only to GDPR but also to the specific framework administered by the Commission Nationale de l'Informatique et des Libertés (CNIL). The CNIL's Méthodologie de Référence MR-001 (as updated) provides a reference framework for interventional research involving the human person. A CRO processing data on behalf of a sponsor relying on MR-001 must ensure that its own processing activities, and those of any cloud sub-processor, remain within the scope of the declared methodology. Any material deviation, such as migrating data to a new cloud environment not anticipated in the original declaration, may require a fresh notification or authorisation from the CNIL. Sponsors and CROs should document any infrastructure change in the Data Protection Impact Assessment (DPIA) maintained under GDPR Article 35.

Focus: the example of the United Kingdom and the ICO

In the United Kingdom, CRO data protection obligations are governed by the UK GDPR (as retained and amended by the Data Protection Act 2018) and overseen by the Information Commissioner's Office (ICO). The ICO has published specific guidance on research and special-category data that mirrors the scientific research exemption in UK GDPR Article 89. Critically, the ICO expects controllers and processors to have documented sub-processor management processes in place before a trial commences, not retrospectively after a breach. A CRO operating cross-border trials with UK sites must ensure that its DPA with the sponsor complies with both EU GDPR and UK GDPR simultaneously, which may require separate or dual-instrument contractual clauses where data flows between the UK and the EU.

Focus: the example of Germany and the data protection authorities (Datenschutzbehörden)

Germany's federal structure means that CRO data protection in clinical trials is supervised by the data protection authority of the Land (federal state) in which the CRO or investigator site is established, rather than by a single national authority. For a multi-site trial with German sites in Bavaria, Berlin and North Rhine-Westphalia, three separate supervisory authorities may be competent. The Bavarian State Office for Data Protection Supervision (BayLDA), the Berlin Commissioner for Data Protection and Freedom of Information, and the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia each apply GDPR uniformly but may have differing administrative expectations regarding DPIA submissions and breach notifications. Sponsors and CROs should map supervisory competence at the outset of trial planning.

How should a sponsor assess a CRO's cloud infrastructure security before trial commencement?

A sponsor should conduct structured vendor due diligence that specifically interrogates cloud infrastructure security, not merely organisational policies. This assessment is a legal requirement under GDPR Article 28(1), which mandates that controllers use only processors offering sufficient guarantees, and it is reinforced by the accountability principle in GDPR Article 5(2).

The following table compares the key due diligence dimensions a sponsor should evaluate when appointing a CRO, contrasting minimum acceptable standards with best practice.

Due diligence dimension Minimum acceptable standard Best practice
Sub-processor mapping Named list of sub-processors including cloud platforms Tiered map with data categories, transfer mechanisms and jurisdiction per sub-processor
Penetration testing Annual third-party penetration test with remediation evidence Continuous vulnerability management with real-time alerting and quarterly reporting to sponsor
Encryption Data encrypted at rest and in transit End-to-end encryption with key management held separately from cloud provider
Access controls Role-based access control (RBAC) with multi-factor authentication (MFA) Zero-trust architecture with privileged access management (PAM) and session recording
Breach notification SLA Notification to sponsor within 72 hours of awareness Notification within 24 hours with incident commander appointed and escalation procedure documented
DPIA participation CRO provides written TOM description for sponsor's DPIA CRO co-authors relevant sections of DPIA and confirms annual review
Audit rights Sponsor may request audit on reasonable notice Annual scheduled audit plus right to unannounced audit following a security incident
ISO/SOC certification ISO 27001 or SOC 2 Type II certificate current Certificates verified against scope; clinical data processing explicitly within scope

Source: iliomad Health Data

The health-technology vendor incident illustrates the consequence of insufficient cloud infrastructure oversight. The affected vendor held data belonging to at least twenty-eight downstream client organisations. Had each client conducted robust sub-processor due diligence and required the vendor to demonstrate controls specific to its AWS environment, the probability of detecting the security gap that enabled unauthorised access would have been materially higher.

Focus: the example of the European Medicines Agency (EMA) and EU CTR 536/2014

Under EU CTR Article 56, the sponsor is responsible for the management of investigational medicinal product data and for ensuring that data are recorded, handled and stored in a way that allows accurate reporting, interpretation and verification. The EMA's guidance on computerised systems and electronic data in clinical trials (published under the auspices of the GCP Inspectors Working Group) explicitly requires that cloud-hosted systems used in clinical research maintain audit trails, access logs and data integrity controls. A CRO deploying a cloud platform for eClinical data must demonstrate to the sponsor that these controls are implemented at the infrastructure level, not merely at the application layer.

Focus: the example of the Irish Data Protection Commission (DPC)

Ireland is the EU lead supervisory authority for many large technology companies whose cloud infrastructure underpins CRO operations across Europe. The Irish Data Protection Commission (DPC) has demonstrated willingness to impose significant fines for failures in sub-processor oversight and inadequate TOMs, including a 1.2 billion euro fine issued to Meta Platforms Ireland Limited in May 2023 (DPC decision of 12 May 2023) for unlawful data transfers. While clinical trial sponsors are not comparable to social media platforms in scale, the DPC's enforcement posture signals that cloud infrastructure security failures will attract regulatory attention irrespective of sector.

What contractual clauses must a DPA include to protect participant data in CRO arrangements?

A GDPR-compliant DPA between a clinical trial sponsor and a CRO must satisfy the mandatory content requirements of GDPR Article 28(3), but best practice extends considerably beyond the statutory minimum.

For clinical trials specifically, the DPA should address the following elements.

Scope of processing. The DPA must specify each category of personal data processed (for example, participant identifiers, genomic data, adverse event data, imaging data) and each processing operation performed. Vague formulations such as "clinical trial data" are insufficient for audit purposes and may create ambiguity in the event of a breach.

Data subject rights facilitation. Under GDPR Articles 15 to 22, data subjects retain rights including access, rectification and erasure (subject to scientific research limitations under GDPR Article 89(1)). The DPA must specify the CRO's obligations when a participant exercises a right directly against the CRO, including the timeframe for escalating the request to the sponsor.

Restricted transfers. Where the CRO or any sub-processor processes personal data outside the European Economic Area (EEA), the DPA must incorporate an appropriate transfer mechanism. For transfers to third countries without an adequacy decision under GDPR Article 45, Standard Contractual Clauses (SCCs) adopted by Commission Implementing Decision (EU) 2021/914 are the most commonly used instrument. The DPA must identify each third-country transfer, name the applicable SCCs module (Module 2 for controller-to-processor or Module 3 for processor-to-processor, as relevant) and document the Transfer Impact Assessment (TIA) conducted under the European Data Protection Board's (EDPB) recommendations on supplementary measures.

Incident response obligations. The DPA must specify that the CRO will notify the sponsor of any confirmed or suspected personal data breach within a defined period (iliomad recommends twenty-four hours as the contractual standard, providing headroom before the GDPR Article 33 seventy-two-hour regulatory deadline). The notification must include the information enumerated in GDPR Article 33(3): the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

Audit and inspection rights. The DPA must preserve the sponsor's right to audit the CRO's compliance with GDPR obligations, including inspection of sub-processor controls. This right must extend to regulatory inspections by competent authorities under EU CTR Article 78.

Return and deletion of data. GDPR Article 28(3)(g) requires that the processor, at the choice of the controller, delete or return all personal data at the end of the contract and delete existing copies unless EU or Member State law requires storage. In clinical trials, data retention obligations under EU CTR Article 58 (requiring sponsors to retain essential documents for at least twenty-five years) must be reflected in the DPA so that deletion timelines are reconciled with regulatory retention requirements.

Focus: the example of the Spanish Agencia Española de Protección de Datos (AEPD)

The Agencia Española de Protección de Datos (AEPD) is the Spanish supervisory authority competent to oversee CRO data protection in trials conducted at Spanish investigator sites. The AEPD has issued specific guidance on clinical research and GDPR, noting that sponsors and CROs must document the legal basis for processing health data in Spain under GDPR Article 9(2)(j) in conjunction with the Spanish Organic Law on Data Protection and Digital Rights (Ley Orgánica 3/2018, LOPDGDD). The AEPD has also confirmed that a DPIA is mandatory when processing involves large-scale health data or systematic profiling of vulnerable populations, categories that are routinely present in Phase II and Phase III clinical trials.

Protecting participant data when a vendor breach occurs: immediate steps for sponsors

When a sponsor learns that a CRO or health-technology sub-processor has suffered a personal data breach, the sponsor's obligations as controller are activated immediately. The following sequence reflects the GDPR Article 33 and Article 34 requirements, calibrated for the clinical trial context.

First, the sponsor must verify the scope of the breach. This means obtaining from the CRO or vendor a preliminary incident report identifying: the categories of personal data affected, the approximate number of data subjects affected, the period of unauthorised access, and the technical cause. In the vendor incident referenced in this article, the unauthorised access window was sixteen days (2 to 18 December 2025). Sponsors in an analogous situation must press for this information immediately.

Second, the sponsor must assess whether the breach is notifiable to the competent supervisory authority under GDPR Article 33. A breach of special-category health data involving a significant number of participants will almost always meet the threshold of being likely to result in a risk to the rights and freedoms of natural persons. Sponsors should err on the side of notification, given that failure to notify can itself constitute a GDPR infringement.

Third, where the risk to data subjects is high (as defined in GDPR Article 34(1), meaning a high risk to the rights and freedoms of natural persons), the sponsor must communicate the breach to affected participants in clear and plain language. In a clinical trial context, this communication must be coordinated with the investigator site and, where applicable, with the ethics committee that approved the trial.

Fourth, the sponsor must document the breach in its internal record of personal data breaches as required by GDPR Article 33(5), irrespective of whether the breach is formally notifiable.

Fifth, the sponsor must review and, if necessary, update its DPIA to reflect the security failure identified in the breach investigation. Where the DPIA reveals that the CRO or sub-processor no longer provides sufficient guarantees, the sponsor must take remedial action including, if necessary, terminating the data processing relationship.

Safeguard participant data across your CRO supply chain with iliomad

iliomad provides specialist CRO data protection services to clinical trial sponsors and health-technology companies operating under GDPR, EU CTR 536/2014 and national data protection frameworks across the EU and UK. Our services include DPA drafting and negotiation, DPIA preparation and review, sub-processor due diligence frameworks, breach notification support and Data Protection Officer (DPO) appointment for life sciences organisations.

If you are a sponsor or CRO seeking to strengthen your vendor risk management programme or respond to a data security incident, contact the iliomad clinical trials data protection team today. We will provide a clear scope, timeline and cost estimate before you commit.

Explore iliomad's clinical trial data protection services

Contact us

FAQs

Our frequently questions

What GDPR obligations apply specifically to a CRO acting as a data processor?

A CRO acting as a data processor under GDPR Article 4(8) must comply with several key obligations. It must sign a binding Data Processing Agreement (DPA) with the sponsor under GDPR Article 28(3), specifying the nature, purpose, and categories of data processed — including special-category health data under Article 9(2)(j). It must obtain prior written authorisation before engaging any sub-processor (e.g. a cloud platform), and ensure the same contractual guarantees flow down to those sub-processors under Article 28(4). In the event of a breach, the CRO must notify the controller without undue delay under Article 33(2), since the sponsor's 72-hour regulatory clock starts from the moment the processor becomes aware. Finally, the CRO must maintain detailed records of all processing activities under Article 30(2), covering each trial, data category, sub-processor, and transfer mechanism.

Why is cloud infrastructure a critical risk layer in CRO data protection?

Cloud infrastructure represents a sub-processor tier in the clinical trial data chain, sitting between the CRO and the raw storage of participant data. When a CRO hosts trial data on a third-party cloud platform such as AWS, Azure, or Google Cloud, that platform qualifies as a sub-processor under GDPR. A security failure at this level — such as unauthorised access to a cloud environment — cascades upstream to the CRO and ultimately to the sponsor as data controller. A real-world example involving a health-technology vendor saw unauthorised access to an AWS environment remain undetected for approximately sixteen days, affecting at least twenty-eight downstream healthcare clients. Under GDPR, the sponsor bears accountability for ensuring that every tier of its supply chain — including cloud infrastructure — implements appropriate technical and organisational measures (TOMs).

What must a DPA between a clinical trial sponsor and a CRO include to be GDPR-compliant?

Beyond the statutory minimum requirements of GDPR Article 28(3), a best-practice DPA for clinical trials should include: (1) a granular scope of processing identifying each category of personal data (e.g. participant identifiers, genomic data, adverse event data); (2) clear procedures for facilitating data subject rights under Articles 15–22, with escalation timelines to the sponsor; (3) restricted transfer clauses identifying each third-country transfer, the applicable Standard Contractual Clauses (SCCs) module under Commission Decision 2021/914, and a documented Transfer Impact Assessment (TIA); (4) an incident response obligation requiring the CRO to notify the sponsor of any confirmed or suspected breach within 24 hours, including all information required by Article 33(3); (5) audit and inspection rights extending to sub-processor controls and regulatory inspections under EU CTR Article 78; and (6) data return and deletion provisions reconciled with the 25-year retention obligation under EU CTR Article 58.

How should a sponsor assess a CRO's cloud infrastructure security before a trial begins?

Sponsors are legally required under GDPR Article 28(1) and the accountability principle in Article 5(2) to conduct structured vendor due diligence that specifically interrogates cloud infrastructure security. Key dimensions to evaluate include: a tiered sub-processor map identifying cloud platforms, data categories, transfer mechanisms, and jurisdictions; evidence of penetration testing and continuous vulnerability management; end-to-end encryption with key management held separately from the cloud provider; zero-trust access architecture with multi-factor authentication (MFA) and privileged access management (PAM); a contractual breach notification SLA of 24 hours or less; CRO co-authorship of relevant DPIA sections; scheduled and unannounced audit rights; and current ISO 27001 or SOC 2 Type II certification with clinical data processing explicitly within scope. This due diligence should be completed before trial commencement, not retrospectively after a security incident.

What immediate steps must a sponsor take when a CRO or vendor suffers a personal data breach?

When a sponsor learns of a breach affecting a CRO or sub-processor, five immediate steps are required. First, verify the scope of the breach by obtaining a preliminary incident report from the CRO covering the categories and volume of data affected, the period of unauthorised access, and the technical cause. Second, assess notifiability under GDPR Article 33 — breaches involving special-category health data will almost always meet the risk threshold, and sponsors should err on the side of notifying the competent supervisory authority within 72 hours. Third, if the risk to data subjects is high under Article 34(1), communicate the breach to affected participants in plain language, coordinated with investigator sites and, where applicable, the ethics committee. Fourth, document the breach in the internal breach register required by Article 33(5), regardless of whether formal notification is required. Fifth, review and update the DPIA to reflect the identified security failure, and take remedial action — including potential termination of the processing relationship — if the vendor no longer provides sufficient guarantees.

How do national data protection frameworks in France, the UK, Germany, and Spain affect CRO data protection obligations?

While GDPR provides a harmonised baseline, national frameworks add important layers of complexity for CROs operating multi-country trials. In France, the CNIL's Méthodologie de Référence MR-001 governs interventional research; any material infrastructure change — such as migrating to a new cloud environment — may require a fresh CNIL notification and must be reflected in the DPIA. In the UK, CROs must comply with UK GDPR (retained under the Data Protection Act 2018) and ICO expectations, which require documented sub-processor management processes before trial commencement; cross-border trials with UK sites may require separate or dual-instrument contractual clauses. In Germany, the federal structure means that the competent supervisory authority is determined by the Land (federal state) where each site is established, potentially involving multiple authorities (e.g. BayLDA, the Berlin DPA, and the NRW DPA) for a single multi-site trial. In Spain, the AEPD requires CROs and sponsors to document the legal basis for health data processing under GDPR Article 9(2)(j) read with the LOPDGDD, and mandates a DPIA for large-scale health data processing — a threshold routinely met in Phase II and Phase III trials.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
Diagram illustrating the site-to-vendor data transfer chain in a clinical trial, showing the study site as the entity responsible for standard contractual clauses rather than the sponsor
August 14, 2026
ICF
Clinical Trials
DPIA
Testimonial
Regulations & Guidelines

ICF Data Protection Language for Site-to-Vendor Transfers: Attributing SCCs to the Correct Entity

Learn how to correctly attribute international transfer safeguards in clinical trial ICFs. Avoid the common error of referencing sponsor SCCs for site-to-vendor data flows.

Abstract illustration of interconnected nodes representing clinical trial data flows, regulatory frameworks and AI partnerships across global jurisdictions.
August 14, 2026
Clinical Trials
Data Breach
AI
Healthtech

Weekly News Digest: Clinical Trial Oversight, Health Data Breaches and AI Regulation

This week: China tightens IIT oversight, 23andMe fine uncollectable, Snowflake guilty plea, Novo Nordisk-AWS AI deal, child safety AI bills and more health data breach news.

A compliance officer reviews a data processing agreement for a clinical trial cloud platform, with GDPR documentation visible on screen
August 11, 2026
GDPR
Clinical Trials
Events
Data Breach & Cybersecurity
US Privacy Law

Data processing agreement (DPA) clinical trials: cloud vendor risk and GDPR obligations

Learn how a robust data processing agreement protects clinical trial data in cloud environments, covering GDPR obligations, MFA clauses and vendor risk assessment.