Privacy AI
Regulatory

Health data compliance, handled.

Tell us what you need. We'll tell you what it takes and how long, before you commit.

Contact us

Summary

GDPR Article 89 allows the processing of personal data for scientific research in clinical trials, provided that proper safeguards such as pseudonymisation are in place. This regulation works alongside Article 9(2)(j) for processing special category health data, facilitating research while ensuring data protection across the EU.

Contact us

Summary: GDPR Article 89 provides the legal mechanism that allows sponsors, contract research organisations and academic institutions to process personal data for scientific research purposes, provided they implement appropriate technical and organisational safeguards. The provision works alongside a lawful basis under Article 9(2)(j) for special category health data and permits Member States to restrict certain data subject rights where necessary to protect research integrity. Understanding the precise conditions attached to Article 89, including the principle of data minimisation and the pseudonymisation requirement, is essential for any organisation conducting clinical trials in the European Union.

What does GDPR Article 89 actually permit for research organisations?

GDPR Article 89 of Regulation (EU) 2016/679 (the General Data Protection Regulation) grants Member States the power to provide derogations from several data subject rights when personal data is processed for scientific or historical research purposes, statistical purposes, or archiving in the public interest, subject to the condition that appropriate safeguards are in place. The provision does not create a standalone lawful basis; it operates as a modulating rule that limits or restricts rights already established elsewhere in the Regulation.

For clinical trial sponsors, Article 89 is the gateway through which national legislators have carved out workable exemptions from rights such as access (Article 15), rectification (Article 16), restriction of processing (Article 18) and the right to object (Article 21). Without those derogations, a participant could theoretically exercise a right that would compromise the statistical validity of a study or unblind a randomised controlled trial, undermining the scientific integrity on which regulatory submission depends.

The provision is reinforced by Article 9(2)(j), which provides an explicit condition for processing special category data, including health data and genetic data, for scientific research purposes where the processing is based on Union or Member State law. Taken together, Articles 89 and 9(2)(j) form the twin pillars on which EU clinical research data protection law is built.

Focus: the example of France

France implements Article 89 primarily through the Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978, as amended) and through the reference methodologies published by the Commission Nationale de l'Informatique et des Libertés (CNIL), the French data protection authority. The most relevant instrument for interventional clinical trials is the Méthodologie de Référence MR-001, which permits the processing of health data without individual CNIL authorisation where the sponsor follows its prescribed framework. MR-001 sets out conditions on data retention, pseudonymisation, security measures and the role of the Data Protection Officer (DPO), translating the abstract requirements of Article 89 into an operational checklist that sponsors can follow.

Focus: the example of Germany

Germany transposes Article 89 through Section 27 of the Bundesdatenschutzgesetz (BDSG), the Federal Data Protection Act. Section 27 permits the processing of personal data for scientific research without the data subject's consent where the public interest in the research clearly outweighs the data subject's interest in exclusion. The German approach imposes a strict necessity test and requires pseudonymisation as soon as the research purpose allows it. The supervisory authorities of the individual Länder, such as the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) for private-sector entities in Bavaria, supervise compliance and may issue guidance specific to multicentre trials conducted within their territory.

Focus: the example of the United Kingdom

Following the UK's departure from the EU, the UK GDPR (retained in domestic law by the European Union (Withdrawal) Act 2018) preserves an equivalent of Article 89 at Schedule 2 and Paragraph 26 of the Data Protection Act 2018. The Information Commissioner's Office (ICO) has published research-specific guidance confirming that the scientific research exemption applies to clinical trials, provided sponsors implement pseudonymisation and limit access to identified data. The UK framework diverges from the EU in that the ICO does not operate a reference methodology equivalent to MR-001, placing greater responsibility on sponsors to document their own safeguards within a Data Protection Impact Assessment (DPIA).

What safeguards must be in place under Article 89?

The safeguards required by Article 89 are not exhaustively defined in the Regulation itself; instead, Recital 156 of the GDPR states that those safeguards should ensure that technical and organisational measures are in place to respect the principle of data minimisation. Two safeguards are explicitly referenced in the text of Article 89(1): pseudonymisation and the aggregation of data where possible. All further measures are left to Union or Member State law and to the controller's own risk assessment.

In practice, a clinical trial sponsor seeking to rely on Article 89 will typically need to demonstrate the following:

  1. A documented lawful basis, either Article 6(1)(e) (public task) or Article 6(1)(f) (legitimate interests), combined with the Article 9(2)(j) condition for health data.
  2. Pseudonymisation of participant data at the earliest opportunity, typically through a coded identifier assigned by the investigator site and held under a separate key by the sponsor or a trusted third party.
  3. Access controls limiting identifiable data to personnel with a direct need, such as safety reviewers conducting pharmacovigilance assessments.
  4. A DPIA completed before the trial commences, as required by Article 35 of the GDPR, given that the systematic processing of health data at scale is likely to result in a high risk to the rights of data subjects.
  5. Contractual arrangements, typically Standard Contractual Clauses (SCCs) adopted by the European Commission under Article 46(2)(c) of the GDPR, governing data transfers to third countries such as the United States where the sponsor's data processing infrastructure is located.
  6. Retention schedules aligned with regulatory obligations, including Article 58 of EU Clinical Trials Regulation 536/2014 (EU CTR), which requires the retention of trial master file (TMF) documentation for at least 25 years after the conclusion of the trial.
Safeguard Article 89 requirement Practical implementation in clinical trials
Pseudonymisation Explicitly required where possible Coded participant IDs held at site; sponsor retains only pseudonymous data
Data minimisation Recital 156 Protocol limits data collection to variables defined in the statistical analysis plan
Access restriction Implied by proportionality Role-based access in the electronic data capture (EDC) system
DPIA Article 35 triggers apply Mandatory prior to trial launch given large-scale health data processing
Retention limits Member State law and EU CTR 536/2014 Schedules aligned to 25-year TMF obligation and local requirements
Third-country transfer safeguards Article 46 GDPR SCCs between EU sponsor and non-EU CRO or data platform provider

How do data subject rights interact with Article 89 derogations?

Data subject rights are not eliminated by Article 89; they are restricted only to the extent necessary and only where Member State law has enacted a specific derogation. The table below maps the rights most commonly affected in clinical trials against the conditions under which a derogation may be lawful.

Data subject right GDPR article Article 89 derogation permitted? Condition for derogation
Right of access Article 15 Yes Where access would render the research purpose impossible or seriously impair it
Right to rectification Article 16 Yes Where accuracy of historical or scientific record must be preserved
Right to erasure Article 17 Yes Where erasure would render the research impossible or seriously impair it
Right to restriction Article 18 Yes Subject to Member State law
Right to object Article 21 Yes Where processing is necessary for a task carried out in the public interest
Right to data portability Article 20 No Article 20 does not apply to processing based on Article 6(1)(e)

‍

Sponsors must nonetheless handle requests from participants in good faith. Even where a derogation is technically available, the European Data Protection Board (EDPB), which is the independent body that ensures consistent application of the GDPR across the EU, has emphasised in its guidelines on data subject rights that controllers should communicate clearly with data subjects about the reasons why a right is being restricted and the period for which the restriction applies.

Focus: the example of Belgium

Belgium provides a useful example of a Member State that has enacted detailed research derogations. The Belgian Data Protection Act of 30 July 2018 transposes Article 89 at Articles 186 to 191, permitting restrictions on the rights of access, rectification and erasure where the research would otherwise be rendered impossible. The Belgian Data Protection Authority (Gegevensbeschermingsautoriteit, GBA) has indicated in its published guidance that sponsors conducting multicentre trials in Belgium should document the specific scientific justification for each derogation they rely upon, rather than asserting Article 89 as a blanket exemption.

Focus: the example of the Netherlands

The Dutch implementation, through the Uitvoeringswet Algemene Verordening Gegevensbescherming (UAVG) of 2018, similarly restricts the right of erasure and the right of access where the research purpose would be seriously impaired. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) has specifically noted that clinical trials falling within the scope of EU CTR 536/2014 benefit from a degree of regulatory alignment because the ethics committee review process and the competent authority authorisation required under the EU CTR already constitute a form of structured oversight that supports the research legitimacy required by Article 89.

Building a compliant Article 89 framework for your trial programme

A robust Article 89 compliance framework for clinical research rests on four interconnected elements: governance, documentation, contractual architecture and ongoing monitoring.

Governance begins with the appointment of a DPO. Under Article 37(1)(c) of the GDPR, organisations that carry out large-scale processing of special category data, which includes health data processed in clinical trials, are required to appoint a DPO. The DPO must be involved from the protocol design stage, reviewing the DPIA and advising on the lawful basis, rather than being consulted only at the point of regulatory submission.

Documentation must include a Record of Processing Activities (ROPA) under Article 30 of the GDPR, a completed DPIA under Article 35, and evidence that pseudonymisation is applied to the processing chain. Where the trial is conducted in France, the sponsor must also complete the MR-001 reference commitment or seek an individual CNIL authorisation where the trial falls outside the scope of MR-001.

The contractual architecture must address the relationship between the sponsor as data controller and the contract research organisation (CRO) as data processor, formalised through a Data Processing Agreement (DPA) under Article 28 of the GDPR. Where data is transferred outside the European Economic Area (EEA), the DPA must incorporate the SCCs published by the European Commission in Implementing Decision 2021/914 of 4 June 2021, supplemented by a Transfer Impact Assessment (TIA) where the destination country does not offer an adequate level of protection.

Ongoing monitoring should include periodic review of the DPIA, particularly at protocol amendments, and alignment with any updated EDPB guidelines. The EDPB's September 2026 plenary session, recapped by the CNIL on 23 September 2026, adopted draft guidelines on GDPR administrative fines that are open for public consultation until 13 November 2026. Those guidelines introduce a five-step methodology for supervisory authorities assessing enforcement action, reinforcing the importance of documented and demonstrable safeguards of precisely the kind required by Article 89.

Take the next step with iliomad

iliomad specialises in clinical trial data protection across the EU, UK and beyond. Whether you need a DPO with life sciences expertise, a DPIA tailored to your trial protocol, or contractual frameworks that satisfy both Article 89 and EU CTR 536/2014 requirements, our team can support you from protocol design through to regulatory submission.

Explore our clinical trials data protection services to understand how we can help your organisation build a compliant and inspection-ready research programme.

Contact us

FAQs

Our frequently questions

How do Belgium and the Netherlands approach Article 89 derogations for clinical research?

Belgium and the Netherlands offer instructive examples of detailed national implementations. In Belgium, the Data Protection Act of 30 July 2018 transposes Article 89 at Articles 186–191, permitting restrictions on access, rectification, and erasure rights where research would otherwise be rendered impossible. The Belgian Data Protection Authority (GBA) requires sponsors to document the specific scientific justification for each derogation rather than citing Article 89 as a blanket exemption. In the Netherlands, the UAVG of 2018 restricts the rights of erasure and access where the research purpose would be seriously impaired. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) has noted that clinical trials under EU CTR 536/2014 benefit from regulatory alignment, as the ethics committee review and competent authority authorisation already constitute structured oversight supporting the research legitimacy required by Article 89.

What are the four key elements of a compliant Article 89 framework for clinical trials?

A robust Article 89 compliance framework for clinical research rests on four interconnected elements. (1) Governance: Appoint a Data Protection Officer (DPO) as required under Article 37(1)(c) of the GDPR for large-scale processing of health data. The DPO must be involved from protocol design stage, not just at regulatory submission. (2) Documentation: Maintain a Record of Processing Activities (ROPA) under Article 30, a completed DPIA under Article 35, and evidence of pseudonymisation. Trials in France must also complete the MR-001 reference commitment or seek individual CNIL authorisation. (3) Contractual architecture: Formalise the sponsor–CRO relationship via a Data Processing Agreement (DPA) under Article 28. For transfers outside the EEA, incorporate SCCs from Implementing Decision 2021/914, supplemented by a Transfer Impact Assessment (TIA). (4) Ongoing monitoring: Periodically review the DPIA — especially at protocol amendments — and align with updated EDPB guidelines.

How do France, Germany, and the UK implement Article 89 for clinical trials?

Each jurisdiction transposes Article 89 differently. In France, the Loi Informatique et Libertés and the CNIL's Méthodologie de Référence MR-001 allow sponsors to process health data without individual CNIL authorisation, provided they follow a prescribed framework covering retention, pseudonymisation, security, and DPO responsibilities. In Germany, Section 27 of the BDSG permits processing without consent where the public interest in the research clearly outweighs the data subject's interest in exclusion, subject to a strict necessity test and pseudonymisation requirements enforced by Länder-level supervisory authorities. In the UK, the equivalent of Article 89 is preserved through Schedule 2 and Paragraph 26 of the Data Protection Act 2018 under the UK GDPR. Unlike France, the ICO does not operate a reference methodology, placing greater responsibility on sponsors to document their own safeguards within a DPIA.

How do data subject rights interact with Article 89 derogations?

Article 89 derogations do not eliminate data subject rights — they restrict them only to the extent necessary and only where Member State law has enacted a specific derogation. Rights most commonly affected in clinical trials include access, rectification, restriction of processing, and the right to object. Even where a derogation is technically available, the European Data Protection Board (EDPB) has emphasised that controllers must handle requests in good faith, communicate clearly with data subjects about why a right is being restricted, and specify the period for which the restriction applies. Sponsors should never assert Article 89 as a blanket exemption but instead document the specific scientific justification for each derogation relied upon, as recommended by authorities such as the Belgian Data Protection Authority (GBA).

What safeguards must be in place under Article 89?

Article 89 does not exhaustively define the required safeguards, but Recital 156 of the GDPR states they should ensure technical and organisational measures that respect data minimisation. The two safeguards explicitly referenced in Article 89(1) are pseudonymisation and data aggregation where possible. In practice, clinical trial sponsors relying on Article 89 should demonstrate: (1) a documented lawful basis under Article 6(1)(e) or 6(1)(f), combined with Article 9(2)(j) for health data; (2) pseudonymisation of participant data at the earliest opportunity using coded identifiers; (3) access controls limiting identifiable data to personnel with a direct need; (4) a completed Data Protection Impact Assessment (DPIA) under Article 35 before the trial begins; (5) Standard Contractual Clauses (SCCs) for data transfers to third countries; and (6) retention schedules aligned with regulatory obligations, including the 25-year minimum under EU CTR 536/2014.

What does GDPR Article 89 actually permit for research organisations?

GDPR Article 89 grants Member States the power to provide derogations from several data subject rights when personal data is processed for scientific or historical research, statistical purposes, or archiving in the public interest — provided appropriate safeguards are in place. It is not a standalone lawful basis but a modulating rule that restricts rights established elsewhere in the Regulation. For clinical trial sponsors, it enables exemptions from rights such as access (Article 15), rectification (Article 16), restriction of processing (Article 18), and the right to object (Article 21). It works in tandem with Article 9(2)(j), which permits the processing of special category data — including health and genetic data — for scientific research under Union or Member State law. Together, Articles 89 and 9(2)(j) form the twin pillars of EU clinical research data protection law.

What contractual framework is needed when a sponsor transfers clinical trial data outside the EEA?

When personal data from an EU-based clinical trial is transferred to a third country — such as to a US-based CRO or data platform provider — sponsors must use Standard Contractual Clauses (SCCs) published by the European Commission in Implementing Decision 2021/914. These SCCs must be incorporated into the Data Processing Agreement (DPA) formalised between the sponsor (as data controller) and the CRO (as data processor) under Article 28 of the GDPR. Where the destination country does not offer an adequate level of data protection, a Transfer Impact Assessment (TIA) must also be conducted to supplement the SCCs.

Is a Data Protection Impact Assessment (DPIA) mandatory for clinical trials under GDPR?

Yes. A DPIA is mandatory before a clinical trial commences, as required by Article 35 of the GDPR. This is because the systematic, large-scale processing of health data in clinical trials is considered likely to result in a high risk to the rights and freedoms of data subjects — one of the key triggers for a DPIA. The DPIA must be reviewed periodically, particularly at protocol amendments, and should be completed with the involvement of the Data Protection Officer (DPO) from the protocol design stage, not only at the point of regulatory submission.

How do France, Germany, and the UK implement GDPR Article 89 for clinical research?

Each jurisdiction takes a distinct approach. France relies on the Loi Informatique et Libertés and the CNIL's Méthodologie de Référence MR-001, which allows sponsors to process health data without individual CNIL authorisation if they follow a prescribed framework. Germany transposes Article 89 through Section 27 of the BDSG, applying a strict necessity test and mandatory pseudonymisation. The UK preserves an equivalent provision through Schedule 2 of the Data Protection Act 2018 and the UK GDPR, but unlike France, the ICO does not operate a reference methodology — placing greater responsibility on sponsors to self-document safeguards within their own DPIA.

Are data subject rights completely eliminated by Article 89 derogations in clinical trials?

No. Data subject rights are not eliminated — they are restricted only to the extent necessary and only where Member State law has enacted a specific derogation. For example, the right of access may be restricted where it would render the research impossible, and the right to erasure may be limited where it would seriously impair the study. However, the right to data portability cannot be derogated under Article 89. Sponsors must still handle participant requests in good faith, clearly communicating the reasons for any restriction and the period during which it applies, as emphasised by the European Data Protection Board (EDPB).

What safeguards are required under GDPR Article 89 for clinical trials?

Article 89 explicitly requires pseudonymisation and data aggregation where possible. In practice, clinical trial sponsors must also: (1) document a lawful basis under Article 6(1)(e) or 6(1)(f) combined with Article 9(2)(j) for health data; (2) apply access controls limiting identifiable data to personnel with a direct need; (3) complete a Data Protection Impact Assessment (DPIA) before the trial starts; (4) put Standard Contractual Clauses (SCCs) in place for data transfers to third countries; and (5) align retention schedules with regulatory obligations, including the 25-year retention requirement under EU Clinical Trials Regulation 536/2014.

What does GDPR Article 89 permit for clinical research organisations?

GDPR Article 89 grants Member States the power to provide derogations from several data subject rights — including access (Article 15), rectification (Article 16), restriction of processing (Article 18), and the right to object (Article 21) — when personal data is processed for scientific research purposes. It does not create a standalone lawful basis but works as a modulating rule alongside Article 9(2)(j), which explicitly permits processing of special category health and genetic data for scientific research. Together, these two provisions form the legal foundation for clinical trial data processing in the EU.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
Abstract digital graphic showing interconnected nodes representing AI governance, data protection enforcement and clinical regulation across healthcare and life sciences sectors
September 23, 2026
Healthtech
Regulations & Guidelines
Data Breach & Cybersecurity
GDPR
Data Breach

Weekly Digest: AI Governance, Data Breaches and Regulatory Shifts in Health and Life Sciences

This week: Google's €403m DPC fine, Gemini's autonomous hack, Medicare's WISeR AI failures, HIPAA settlements, UK ICO rebrand and more. iliomad weekly digest.

A data protection officer reviewing updated informed consent documentation and protocol amendments following a voluntary enrollment pause in a phase 3 clinical trial
September 21, 2026
DPIA
Clinical Trials
Testimonial
EU Privacy Law
Regulations & Guidelines

Voluntary enrollment pauses in clinical trials: data protection obligations for sponsors

When a clinical trial enrollment pause occurs, sponsors face urgent GDPR, ICF and safety-reporting obligations. Learn what participant data protection requires.

Illustrated weekly digest header showing a digital shield, a DNA helix and a regulatory document, representing AI governance, clinical trial reform and healthcare data protection themes for September 2026
September 16, 2026
Regulations & Guidelines
Events
GDPR
Regulation
AI

iliomad Weekly Digest: AI Governance Failures, UK Regulatory Reform and Healthcare Cybersecurity Surge

This week: ICO becomes the Information Commission, Medicare AI prior-auth failures, FDA pilots accelerate trials, and ransomware hits 3.5 million patient records.