In this article
Health data compliance, handled.
Tell us what you need. We'll tell you what it takes and how long, before you commit.
Contact usSummary
This article addresses the common mistakes in attributing Standard Contractual Clauses (SCCs) in ICFs for clinical trials, particularly when transfers occur from study sites to vendors. It emphasizes the importance of accurately describing data transfer safeguards in compliance with GDPR to avoid consent invalidation and operational issues.
Informed consent forms (ICFs) used in clinical trials frequently contain errors in the attribution of international data transfer safeguards. Specifically, ICFs drafted on behalf of a sponsor often reference the sponsor's own Standard Contractual Clauses (SCCs) when describing transfers that, in legal and operational reality, originate from the study site to a third-party vendor. This article explains the compliance gap, the applicable legal framework and the recommended practice for all future ICF drafting.
What are Standard Contractual Clauses and why does their attribution in an ICF matter?
Standard Contractual Clauses (SCCs) are pre-approved contractual mechanisms adopted by the European Commission under Article 46(2)(c) of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter GDPR) that allow controllers and processors to transfer personal data to third countries without an adequacy decision. The current SCCs were adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 and replaced all prior sets of model clauses.
In a clinical trial, an ICF is the document through which a participant is informed, prior to enrolment, of the nature of all processing activities that will affect their personal data, including any international transfers of that data. Article 13(1)(f) of the GDPR requires the data controller to inform data subjects, at the time their data is collected, of any intended transfers to third countries and of the existence or absence of an adequacy decision, or, where transfers are based on Article 46 safeguards, of the appropriate safeguards and the means by which to obtain a copy of them.
Attributing the wrong safeguard mechanism to the wrong entity is therefore not a matter of drafting style. It is a failure to fulfil the transparency obligation imposed by Article 13 GDPR, and it risks invalidating the consent and the transparency notice simultaneously.
What compliance gap arises when a sponsor's SCCs are cited for site-to-vendor transfers?
The compliance gap arises because the sponsor's SCCs do not cover transfers in which the sponsor is not a party to the relevant data-exporter role. Where a study site collects and transmits participant data directly to a vendor (for example, an electronic patient-reported outcome provider, a central laboratory or a biomarker analysis platform), the legal relationship in that transfer chain is between the study site, acting as data exporter, and the vendor, acting as data importer. The sponsor may act as a data controller for the overall study, but it is not the data exporter in that specific transfer.
A real-world compliance review identified precisely this situation in the context of a German-language ICF for a clinical oncology programme. The ICF draft, prepared by the compliance team, referenced the sponsor's documented SCC agreements as the transfer safeguard for all international data flows. However, a closer review of the actual transfer architecture confirmed that the sponsor had not executed SCC agreements that extended to the site-to-vendor relationship. The sponsor was not the data importer in those transfers, and therefore the SCCs the sponsor held were legally irrelevant to them. The applicable safeguard, if any, would need to be put in place by the study site as data exporter.
This finding had two consequences: first, an identified compliance gap under Article 13(1)(f) GDPR, because participants were being informed of a safeguard that did not apply to their data; second, an impact on operational delivery, because the ICF required immediate amendment before it could be used at any German investigational site.
Focus: The Example of Germany
Germany presents a particularly stringent environment for clinical trial data protection. The Bundesdatenschutzgesetz (BDSG), the German Federal Data Protection Act, supplements the GDPR at national level and is enforced by sixteen Länder-level data protection authorities as well as the Federal Commissioner for Data Protection and Freedom of Information (BfDI). German ethics committees, which review ICFs under both the GDPR and the EU Clinical Trials Regulation 536/2014 (EU CTR), have a well-documented practice of scrutinising transfer-related language with care. An ICF that references a sponsor's SCCs for transfers to which the sponsor is not a party is likely to be queried or rejected during the ethics committee review process. Under Article 28 of Regulation (EU) No 536/2014, the sponsor is responsible for ensuring that the ICF contains accurate information about all relevant aspects of the trial, including data transfers. An inaccurate transfer description therefore also engages the sponsor's obligations under the EU CTR, not only its obligations under the GDPR.
How should transfer safeguards be described in a clinical trial ICF when the study site is the data exporter?
When the study site is the entity that transfers participant data to a vendor located in a third country, the ICF should attribute responsibility for the appropriate safeguards to the study site, not to the sponsor. This is the legally accurate position and the one that satisfies Article 13(1)(f) GDPR.
In practical terms, this means that the relevant ICF section should state, in substance, that the study site will put in place appropriate safeguards, such as Standard Contractual Clauses, before transferring participant data to vendors located outside the European Economic Area (EEA). The specific mechanism need not always be named with precision in the ICF, provided the language is accurate and participants are directed to a contact point from whom they may obtain further details. However, where SCCs are named, they must be attributed to the correct exporting entity.
The following table contrasts the two drafting approaches and their legal effect:
| Drafting approach | Entity referenced | Legally accurate? | Compliance risk |
|---|---|---|---|
| ICF states that the sponsor has SCCs in place for all international transfers | Sponsor | No — where sponsor is not the data exporter for site-to-vendor flows | Breach of Article 13(1)(f) GDPR; potential ICF invalidation |
| ICF states that the study site will put in place appropriate safeguards for transfers to vendors | Study site | Yes — where the site is the data exporter | Compliant with Article 13(1)(f) GDPR and Article 28 EU CTR 536/2014 |
| ICF states that the sponsor has SCCs covering transfers where the sponsor is contractually the data exporter to that vendor | Sponsor | Yes — only where sponsor holds and executes the relevant SCC agreement | Compliant, provided the transfer architecture is verified |
Source: iliomad Health Data
The key principle is that the description in the ICF must match the actual transfer architecture. Before finalising any ICF that references SCCs, the drafting team should confirm, by reference to the data flow map and the executed agreements, which entity holds the SCC in the relevant transfer relationship.
What is the recommended practice for ICF drafting teams going forward?
The recommended practice is to conduct a transfer architecture review at the outset of ICF drafting for every study and every country, rather than assuming that a sponsor's existing SCC portfolio covers all transfers associated with the study.
The following steps reflect best practice:
Step 1: Map the actual data flows. For each category of participant data and each vendor to whom that data flows, identify the data exporter (the entity that initiates the transfer) and the data importer (the entity in the third country that receives the data). This mapping should distinguish clearly between flows from the sponsor to vendors and flows from the study site to vendors.
Step 2: Confirm which entity holds the relevant transfer safeguard. Where a vendor is located in a third country, confirm whether it is the sponsor or the study site that has executed the applicable SCCs or alternative Article 46 GDPR mechanism with that vendor. Do not assume that a sponsor's general SCC programme covers site-to-vendor transfers unless the executed agreements expressly reflect this.
Step 3: Draft the ICF transfer language to reflect step 1 and step 2 accurately. Where the study site is the data exporter for certain flows, attribute the responsibility for safeguards to the study site. Where the sponsor is the data exporter, attribute the safeguards to the sponsor. Where both relationships exist within a single study, the ICF may need to address each category of transfer separately.
Step 4: Document the review. Record the conclusions of the transfer architecture review in the study's data protection documentation, such as the Record of Processing Activities maintained pursuant to Article 30 GDPR or the Data Protection Impact Assessment (DPIA) conducted pursuant to Article 35 GDPR. This documentation supports accountability under Article 5(2) GDPR and provides an audit trail for supervisory authorities and ethics committees.
Step 5: Apply this approach consistently across studies. Once a transfer architecture approach has been agreed and validated for a particular study programme, apply the same logic to all country-specific ICF adaptations unless the transfer structure changes. Any change to the vendor landscape or the contractual arrangements should trigger a reassessment of the ICF transfer language.
Focus: The Example of Germany (Continued Operational Implications)
In Germany, the operational impact of miscategorised transfer language extends beyond the ethics committee review. German investigational sites, which typically act as independent data controllers or joint controllers for clinical trial data under the BDSG and the GDPR, may themselves be subject to audit by their Länder data protection authority. If the ICF in use at the site attributes transfer safeguards to the sponsor rather than to the site, and the site is in fact the data exporter, the site could be found to be operating without a valid transfer mechanism for those flows. Under Article 83(4) GDPR, infringements of Article 13 may attract administrative fines of up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. Responsibility for such a finding could fall on the study site, the sponsor or both, depending on the controller and processor arrangements in the clinical site agreement.
For expert support with ICF drafting, transfer architecture mapping, DPIA preparation and clinical trial data protection compliance across EU member states, contact iliomad's clinical trials data protection team.
FAQs
Our frequently questions
Standard Contractual Clauses (SCCs) are pre-approved contractual mechanisms adopted by the European Commission under Article 46(2)(c) of the GDPR that allow controllers and processors to transfer personal data to third countries without an adequacy decision. In a clinical trial, the ICF must inform participants of any international data transfers and the safeguards in place, as required by Article 13(1)(f) GDPR. Attributing the wrong SCC to the wrong entity is not a drafting style issue — it is a failure of the transparency obligation under Article 13 GDPR, which risks invalidating both the consent and the transparency notice simultaneously.
The compliance gap arises because the sponsor's SCCs do not cover transfers where the sponsor is not the data exporter. When a study site transfers participant data directly to a vendor (e.g., a central laboratory or biomarker platform), the legal relationship is between the study site as data exporter and the vendor as data importer — not the sponsor. Citing the sponsor's SCCs in this context means participants are being informed of a safeguard that does not legally apply to their data, breaching Article 13(1)(f) GDPR and potentially requiring immediate ICF amendment before the document can be used at any investigational site.
When the study site is the entity transferring participant data to a third-country vendor, the ICF must attribute responsibility for the appropriate safeguards to the study site — not the sponsor. The ICF should state, in substance, that the study site will put in place appropriate safeguards (such as SCCs) before transferring data outside the EEA. Where SCCs are named specifically, they must be attributed to the correct exporting entity. The key principle is that the ICF description must always match the actual, verified transfer architecture, confirmed against the data flow map and executed agreements before the ICF is finalised.
Yes, but only under specific conditions. A sponsor's SCCs can cover site-to-vendor transfers only where the sponsor has executed SCCs directly with the relevant vendor and the contractual structure confirms that the sponsor — not the study site — is the data exporter in that transfer relationship. This requires the SCC agreement to have been concluded before the transfer takes place and to be accurately reflected in the ICF. Teams must not assume that a sponsor's general SCC programme automatically covers site-to-vendor transfers unless the executed agreements expressly state this.
Best practice for ICF drafting teams involves five key steps: (1) Map all actual data flows, identifying the data exporter and importer for each vendor relationship and distinguishing sponsor-to-vendor from site-to-vendor flows. (2) Confirm which entity — sponsor or study site — holds the executed transfer safeguard for each flow. (3) Draft ICF transfer language that accurately reflects steps 1 and 2, attributing safeguards to the correct entity for each category of transfer. (4) Document the transfer architecture review in the study's ROPA (Article 30 GDPR) or DPIA (Article 35 GDPR) to support accountability. (5) Apply this approach consistently across all country-specific ICF adaptations, reassessing whenever the vendor landscape or contractual arrangements change.
Incorrect transfer language in an ICF carries significant legal and operational risks. Under Article 83(4) GDPR, infringements of Article 13 — which includes inaccurate transfer disclosures — can attract administrative fines of up to €10 million or 2% of total worldwide annual turnover. In Germany specifically, ethics committees routinely scrutinise transfer-related ICF language, and an inaccurate description is likely to be queried or rejected during review. German investigational sites acting as independent or joint controllers may also face direct audits from Länder data protection authorities. Liability can fall on the study site, the sponsor, or both, depending on the controller and processor arrangements set out in the clinical site agreement. The EU CTR (Regulation 536/2014) further compounds this, as Article 28 requires sponsors to ensure ICFs contain accurate data transfer information.
Find out how iliomad can help your company.
Only visible in production
We'll get back to you as soon as possible.

CRO data protection: managing third-party and cloud infrastructure risk in clinical research
Understand CRO data protection obligations under GDPR and EU CTR 536/2014. Learn how to manage third-party vendor risk, cloud infrastructure breaches and DPA requirements.

Weekly News Digest: Clinical Trial Oversight, Health Data Breaches and AI Regulation
This week: China tightens IIT oversight, 23andMe fine uncollectable, Snowflake guilty plea, Novo Nordisk-AWS AI deal, child safety AI bills and more health data breach news.

Data processing agreement (DPA) clinical trials: cloud vendor risk and GDPR obligations
Learn how a robust data processing agreement protects clinical trial data in cloud environments, covering GDPR obligations, MFA clauses and vendor risk assessment.


