In this article
Health data compliance, handled.
Tell us what you need. We'll tell you what it takes and how long, before you commit.
Contact usSummary
This article discusses the implications of including institutional boilerplate in informed consent forms for clinical trials. It highlights compliance risks associated with the US Common Rule and GDPR, emphasizing the crucial differences between mandatory disclosures for commercial products and open-access database clauses that could alter data governance frameworks.
US academic investigator sites routinely insert institutional boilerplate paragraphs into sponsor-issued informed consent forms (ICFs). When those insertions expand the scope of data sharing beyond what the sponsor's data governance framework anticipates, they create compliance risk across multiple regulatory instruments: the US Common Rule (45 CFR Part 46), the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and, for studies with EU sites, the EU Clinical Trials Regulation (EU CTR, Regulation (EU) No 536/2014). This article explains why two recurring categories of site boilerplate require different sponsor responses, and what governance controls can prevent the issue from propagating across study amendments.
What Is Site ICF Boilerplate and Why Does It Create Compliance Risk?
Site ICF boilerplate refers to standardised paragraphs that an investigator site's Institutional Review Board (IRB) or legal department requires to be included in every informed consent form executed at that site, regardless of the sponsor's own template. Boilerplate insertions are common in US academic medical centres and are generally permissible under 45 CFR § 46.116, provided they do not conflict with the sponsor's regulatory strategy or expand the scope of data processing beyond what participants have been informed of at the protocol level.
The compliance risk arises not from the existence of boilerplate but from its content and, critically, from whether the sponsor's review process catches material expansions before consent is administered. Two categories of boilerplate appear with particular frequency and require distinct handling.
The 'Possible Commercial Products' Paragraph
The 'Possible Commercial Products' disclosure is a required element under 45 CFR § 46.116(b)(7), which mandates that consent documents state whether the research could lead to commercial products and whether participants will share in any resulting profit. This category of boilerplate is a mandatory Common Rule disclosure, not an optional site preference, so sponsors should accept it without amendment. Objecting to or deleting this paragraph would place the site's IRB-approved consent process in breach of the Common Rule and would expose the sponsor to regulatory criticism from the US Department of Health and Human Services Office for Human Research Protections (OHRP).
Sponsors should therefore pre-emptively include equivalent language in their master ICF templates for US sites. Doing so reduces the likelihood that sites will insert non-harmonised versions that vary in wording across the study, which complicates regulatory submission packages and audit trails.
How Does an 'Additional Studies' or Open-Access Database Paragraph Differ in Risk Profile?
An open-access database disclosure paragraph materially expands the scope of data sharing beyond a coded-data construct and must be escalated to the sponsor before execution. Unlike the commercial-products disclosure, a paragraph committing to deposit participants' genetic and health information into a publicly accessible scientific repository does not merely satisfy an existing regulatory requirement; it creates a new and distinct data-sharing pathway that may conflict with the sponsor's privacy notices, data management plan and, where EU participants are involved, the lawful basis relied upon under GDPR Article 9(2).
The distinction is critical because it determines who bears accountability for the expanded processing.
| Feature | ‘Possible Commercial Products’ paragraph | Open-Access Database paragraph |
|---|---|---|
| Regulatory basis | 45 CFR § 46.116(b)(7) (Common Rule mandatory element) | No single mandatory instrument; varies by funder policy |
| Sponsor action required | Accept without amendment | Escalate; assess compatibility with data governance framework |
| GDPR relevance (EU participants) | Low (commercial disclosure only) | High (new data sharing pathway; may alter lawful basis) |
| ICH E6(R3) GCP implication | Minimal | May require protocol amendment and IRB/IEC re-review |
| Risk to coded-data construct | None | Material: open-access deposit may re-identify participants |
| Propagation risk across sites | Low (standardised requirement) | High: site-specific approval may be misapplied to other sites |
A coded-data construct is a data governance arrangement under which participant data is pseudonymised at source and shared with the sponsor only in a form that prevents direct identification, with the linkage code held solely by the site. Depositing genetic data into an open-access repository undermines this construct because genomic information is inherently re-identifying: a 2013 study published in Science demonstrated that whole-genome sequences can re-identify individuals even from summary statistics.
Focus: The US Common Rule and the Open-Access Database Question
The Common Rule (45 CFR Part 46), which governs federally funded human subjects research in the United States, does not by itself mandate deposit of data into open-access repositories. However, the National Institutes of Health (NIH) Data Management and Sharing Policy, effective 25 January 2023, requires that NIH-funded research maximise the appropriate sharing of scientific data. Academic sites funded by NIH may therefore insert open-access database language to satisfy their institutional obligations under that policy, conflating a funder requirement with a consent requirement.
Sponsors operating under industry funding are not automatically subject to the NIH Data Sharing Policy. When a site inserts language that reflects its own institutional funder obligations into a sponsor ICF, the sponsor must determine whether accepting that language commits it to obligations it has not agreed to contractually and whether those obligations are compatible with its own data protection impact assessment (DPIA), as required under GDPR Article 35 for large-scale processing of genetic data.
Why Must the Sponsor, Not the Site, Make the Determination on Open-Access Language?
The sponsor holds primary accountability as data controller under GDPR Article 4(7) and as the entity responsible for the investigational product under EU CTR Article 2(14). Because the sponsor defines the purpose and means of data processing across the trial, any expansion of those purposes requires the sponsor's explicit authorisation. A site's claim that identical language was approved in a prior study protocol is not sufficient justification for extending that approval to a new study or to additional sites.
This principle is reinforced by ICH E6(R3) Good Clinical Practice (GCP), the international standard for clinical trial conduct published by the International Council for Harmonisation, which requires that all information given to participants be consistent with the approved protocol and that any deviation be documented and justified. A site-by-site patchwork of open-access database commitments that have not been reviewed against the current protocol constitutes a deviation under ICH E6(R3) Section 4.8.
Furthermore, under GDPR Article 9(2)(j), processing of special category data (including genetic data as defined in GDPR Article 4(13)) for scientific research purposes requires not only a lawful basis but also suitable and specific measures to safeguard the rights of the data subject, as elaborated in GDPR Article 89(1). Committing to open-access deposit without assessing whether the repository itself provides equivalent safeguards may breach this requirement.
Focus: The EU Dimension for Multinational Trials
For trials operating under EU CTR 536/2014, the Clinical Study Report and associated data sets submitted to the European Medicines Agency (EMA) are subject to their own publication and access framework under EMA Policy 0070. Sponsors must ensure that site-level open-access commitments in US ICFs do not conflict with the data publication schedule or the anonymisation standards applied under EMA Policy 0070, which uses a risk-based approach to redaction. A commitment to deposit raw genetic data into a third-party open-access database before EMA publication review could pre-empt the sponsor's obligations under that policy.
What Governance Controls Should Sponsors Implement?
Sponsors should establish a tiered ICF boilerplate review process that categorises site insertions by risk level and routes them to the appropriate decision-maker before IRB approval is sought. Effective governance requires four controls working in concert.
First, the sponsor's master ICF template for US sites should pre-populate the mandatory Common Rule disclosures at 45 CFR § 46.116(b)(1) through (b)(9), including the commercial-products paragraph. Pre-population reduces the likelihood of non-harmonised site versions entering the consent package.
Second, the clinical operations team should maintain a boilerplate registry: a tracked log of site-specific insertions, the study and site to which each insertion applies, the date of sponsor authorisation and the name of the authorising function. This registry prevents a single-site approval from being misapplied, whether deliberately or inadvertently, across other sites or subsequent study phases. The risk of misapplication is particularly acute in multi-cohort studies where the same site participates in more than one protocol, as the real-world practice reviewed for this article illustrates.
Third, any insertion that commits to data sharing beyond the sponsor's data governance framework must be routed to the sponsor's Data Protection Officer (DPO), a role mandated under GDPR Article 37 for organisations processing special category data on a large scale, for assessment of compatibility with the existing DPIA and processing records maintained under GDPR Article 30.
Fourth, the clinical trial agreement (CTA) executed with each investigator site should include an express provision prohibiting the site from making data-sharing commitments in consent documents that have not been pre-authorised in writing by the sponsor. This contractual control operates alongside, and does not replace, the regulatory controls described above.
Implementing these controls at study set-up, rather than during conduct, avoids the operational disruption of retrospective consent re-administration and the reputational risk of disclosing to regulators that material consent deviations were identified mid-study.
Sponsors and CROs navigating ICF review, site agreement drafting and GDPR compliance for multinational clinical trials are invited to explore iliomad's Clinical Trials Data Protection services, where our team provides protocol-specific guidance on consent frameworks, DPIA preparation and investigator site agreement drafting tailored to EU and US regulatory requirements.
FAQs
Our frequently questions
Sponsors should establish clear governance controls at study set-up to manage consent language and prevent unauthorised expansion of data uses. This includes ensuring that master ICF templates contain the mandatory disclosures applicable to the relevant jurisdiction, maintaining a controlled record of site-specific language and approvals, and subjecting any proposed data-sharing language that falls outside the existing governance framework to appropriate privacy review. Where the proposed processing may materially affect the study’s data protection assessment, the sponsor should consider whether existing RoPA and DPIA documentation requires review or update. Clinical trial agreements should also make clear that investigator sites may not introduce additional data-sharing commitments into consent materials without prior sponsor approval.
For multinational clinical trials conducted under EU Clinical Trials Regulation 536/2014, publication of clinical trial information through the EMA is subject to the applicable EMA transparency framework, including requirements relating to the disclosure and protection of personal and commercially confidential information. A site-level commitment to place raw genetic data in a third-party open-access repository should therefore be assessed carefully against the sponsor’s broader regulatory and publication strategy.
From a GDPR perspective, the use and disclosure of genetic data for scientific research must also be supported by an appropriate legal basis and accompanied by suitable safeguards in accordance with Articles 9 and 89 GDPR. Before any commitment to open-access deposition is included in study documentation, the sponsor should therefore assess the nature of the repository, the level of access provided, the safeguards applied, and the consistency of the proposed disclosure with the study’s existing data protection framework.
No. The Common Rule (45 CFR Part 46) does not itself mandate open-access data deposit. However, academic sites funded by the NIH may insert open-access database language to satisfy obligations under the NIH Data Management and Sharing Policy (effective 25 January 2023), which requires maximising the appropriate sharing of scientific data. Sponsors operating under industry funding are not automatically subject to this NIH policy. When a site inserts language reflecting its own funder obligations into a sponsor ICF, the sponsor must assess whether accepting that language creates contractual obligations it has not agreed to, and whether those obligations are compatible with its GDPR Article 35 DPIA for large-scale genetic data processing.
An open-access database provision introduces a separate and potentially significant data-sharing activity by allowing participants’ genetic and health information to be deposited in a repository accessible beyond the immediate study team. This should be assessed against the sponsor’s existing privacy notices, data management arrangements and the lawful basis relied upon for processing special-category data under Article 9 GDPR.
Particular care is required for genomic data, which may remain capable of contributing to re-identification even where direct identifiers have been removed. As the sponsor generally determines the purposes and means of the relevant processing, any material expansion of the intended use or disclosure of participant data should be reviewed and expressly approved by the sponsor before the ICF is finalised.
Sponsors should accept the 'Possible Commercial Products' paragraph without amendment. It is a mandatory disclosure under 45 CFR § 46.116(b)(7) of the US Common Rule, which requires consent documents to state whether research could lead to commercial products and whether participants will share in any resulting profit. Objecting to or deleting this paragraph would place the site's IRB-approved consent process in breach of the Common Rule and expose the sponsor to regulatory criticism from OHRP. Sponsors are advised to pre-emptively include equivalent language in their master ICF templates for US sites to avoid non-harmonised versions appearing across the study.
Site ICF boilerplate refers to standardised language that an investigator site, IRB or local legal function may require to be included in informed consent forms in addition to the sponsor’s master template. The principal compliance consideration is not the use of boilerplate itself, but whether the proposed language introduces any material change to the scope, purpose or disclosure of personal data that has not been reviewed and approved by the sponsor.
In practice, two categories commonly warrant particular attention: provisions addressing the potential development of commercial products from study materials or data, and provisions relating to the disclosure or deposit of data in open-access databases. These should be reviewed separately because they may raise different privacy, transparency and governance considerations.
Find out how iliomad can help your company.
Only visible in production
We'll get back to you as soon as possible.

MR-001 CNIL: what clinical trial sponsors must know about French health data compliance
Understand MR-001 CNIL obligations for clinical trial sponsors in France, from Article 32 security requirements to breach notification and cross-border data transfers.

iliomad Weekly Digest: DPO Conflicts, Bulk Data Rules, Healthcare Cyber Incidents and AI Transparency
This week: CNIL on DPO conflicts of interest, DOJ bulk data rule for life sciences, wave of healthcare ransomware attacks, Uber's €825m GDPR fine and AI disclosure demands.

CRO data protection: managing third-party and cloud infrastructure risk in clinical research
Understand CRO data protection obligations under GDPR and EU CTR 536/2014. Learn how to manage third-party vendor risk, cloud infrastructure breaches and DPA requirements.


