In this article
Health data compliance, handled.
Tell us what you need. We'll tell you what it takes and how long, before you commit.
Contact usSummary
The MR-001 methodology issued by CNIL provides clinical trial sponsors with a legal framework for processing sensitive health data in France. Understanding its requirements, particularly in relation to GDPR Articles 32 and 34, is crucial to avoid costly penalties and ensure compliance during clinical trials.
France operates one of the most detailed health data authorisation frameworks in the European Union. For clinical trial sponsors opening investigator sites on French territory, the Méthodologie de Référence MR-001 (hereinafter MR-001), issued by the Commission Nationale de l'Informatique et des Libertés (CNIL, the French data protection authority), establishes the specific legal pathway for processing personal health data in interventional research. A formal enforcement decision issued on 21 July 2026 and published by the CNIL on 3 September 2026, imposing a €500,000 fine on Hôpital Privé de la Loire, underscores precisely how costly non-compliance with the technical and notification obligations that underpin this framework can become.
This article explains what MR-001 requires, how it interacts with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the EU Clinical Trials Regulation 536/2014, which corrective actions the CNIL currently prioritises, and what practical steps sponsors should take before and during a French clinical site activation.
What is MR-001 and why does it matter for clinical trial sponsors?
MR-001 is the CNIL's reference methodology for interventional clinical research involving human participants: it is a pre-approved legal basis that allows sponsors and investigator sites to process sensitive health data without filing an individual authorisation request, provided every condition set out in the methodology is met. Understanding its scope is the starting point for any sponsor planning to include French sites in a multicentre or global clinical programme.
The GDPR classifies health data as a special category of personal data under Article 9, whose processing is prohibited in principle unless a specific exception applies. In France, Article 66 of the Loi Informatique et Libertés (French Data Protection Act, as amended) designates the CNIL as the competent authority to issue methodologies that constitute such an exception for health research. MR-001 covers interventional studies within the meaning of the EU Clinical Trials Regulation 536/2014, where the sponsor meets the CNIL's conditions on data minimisation, retention periods, access controls, participant information and cross-border transfers.
When a sponsor relies on MR-001, it commits, by declaration, to comply with every requirement in the methodology. A failure to do so is not merely an administrative irregularity: it constitutes a breach of Article 32 GDPR (security of processing) or Article 34 GDPR (communication of a breach to data subjects), as the Hôpital Privé de la Loire decision illustrates. The CNIL's restricted committee found that the hospital, which processed health data under comparable obligations, had not implemented virtual private network (VPN) access controls, multi-factor authentication (MFA) or real-time anomaly detection, thereby exposing the records of 524,867 patients and 202,246 trusted third parties to an external attacker.
How does MR-001 align with GDPR Articles 32 and 34?
MR-001 aligns directly with Articles 32 and 34 GDPR by translating the regulation's general security and notification obligations into sector-specific requirements calibrated for clinical research environments. Sponsors who understand this alignment can build a compliance architecture that satisfies both the methodology and the underlying regulation simultaneously.
Article 32 GDPR: security of processing
Article 32 GDPR requires controllers and processors to implement technical and organisational measures appropriate to the risk, including, where relevant, pseudonymisation, encryption and the ability to ensure ongoing confidentiality and integrity of processing systems. MR-001 operationalises these requirements by mandating that access to the computerised patient record system (Dossier Patient Informatisé, or DPI) be restricted to members of the care or research team directly involved in the trial, with individual authenticated accounts and traceable access logs.
The Hôpital Privé de la Loire decision provides a precise illustration of what the CNIL considers a failure of Article 32 compliance:
- Absence of VPN for external users (including liberal doctors accessing the DPI remotely).
- Absence of MFA, enabling an attacker to exploit a single set of compromised credentials.
- No concept of care team implemented in the access control policy, so that one account gave access to the entire patient population rather than only those patients assigned to that user.
- No real-time or near-real-time detection of abnormal activity, allowing the attacker to extract a large volume of data over several days without triggering any alert.
For a clinical trial sponsor relying on MR-001, each of these gaps would constitute a direct breach of the methodology's access control and security logging requirements, in addition to the breach of Article 32 GDPR itself.
Article 34 GDPR: communication of a breach to data subjects
Article 34 GDPR requires the controller to communicate a personal data breach to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. MR-001 reinforces this obligation by specifying that the sponsor must inform participants of any incident affecting their data.
In the Hôpital Privé de la Loire case, the hospital notified the patients whose data had been compromised but failed to inform the 202,246 trusted third parties (relatives or other individuals designated as emergency contacts) whose personal data was equally exposed. The CNIL's restricted committee found this omission to constitute a standalone infringement of Article 34 GDPR. For sponsors, this is a critical reminder: the notification obligation extends to every identifiable individual whose data is affected, not only the principal research participants.
Focus: the example of France and the CNIL's enforcement posture
The CNIL is one of Europe's most active data protection authorities in the health sector. The Hôpital Privé de la Loire decision of 21 July 2026, published on 3 September 2026, is the latest in a series of enforcement actions targeting healthcare controllers that process large volumes of sensitive data without adequate technical safeguards. The regulator explicitly noted that basic security hygiene, specifically VPN access control and MFA, could have materially hindered the attack, a statement that serves as a direct policy signal to any organisation relying on MR-001 or any other CNIL methodology. The fine of €500,000 was calibrated against the number of individuals affected, the sensitivity of the data and the hospital's financial capacity. The CNIL also ordered remediation within a period of three to fifteen months, depending on the type of measure required.
Focus: the example of investigator sites in multicentre EU trials
In a multicentre clinical trial operating under EU Clinical Trials Regulation 536/2014, French investigator sites are subject to MR-001 in addition to the pan-European ethics and regulatory framework. The sponsor, acting as data controller (or joint controller with the site, depending on the contractual structure), must ensure that the site's information systems meet MR-001's access control requirements. Practical due diligence should include a documented review of the site's DPI configuration, confirmation that MFA is enabled for all remote access accounts and verification that the site has a functioning anomaly detection mechanism. These checks should be embedded in the Clinical Trial Agreement (CTA) and reflected in the Data Processing Agreement required under Article 28 GDPR.
Focus: the example of cross-border data transfers involving French health data
When a sponsor transfers pseudonymised or identifiable clinical data from France to a third country, for instance to a contract research organisation (CRO) or a central laboratory located outside the European Economic Area, MR-001 imposes specific transfer conditions. The transfer must rely on one of the mechanisms listed in Chapter V GDPR: Standard Contractual Clauses (SCCs) adopted by the European Commission under Article 46(2)(c) GDPR, an adequacy decision, or binding corporate rules. The sponsor must also conduct a transfer impact assessment where the destination country does not offer essentially equivalent protection. Failure to document this analysis is treated by the CNIL as a breach of the methodology, irrespective of whether an actual incident has occurred.
What are the practical compliance obligations under MR-001 for sponsors?
MR-001 imposes a defined set of obligations that sponsors must address before the first patient is enrolled at a French site. Meeting these obligations systematically reduces both the risk of enforcement action and the operational disruption that a data breach or CNIL investigation would cause.
The table below compares the core obligations under MR-001 with the corresponding GDPR provisions and the typical implementation measures expected at site level.
| MR-001 obligation | Corresponding GDPR provision | Implementation measure |
|---|---|---|
| Declaration of commitment to the CNIL before processing begins | Article 6 and Article 9 GDPR (lawfulness of processing) | Submission of the MR-001 declaration by the sponsor prior to site activation |
| Access restricted to the care or research team | Article 32 GDPR (security of processing) | Role-based access control configured in the DPI; care team lists maintained and audited |
| Individual authenticated accounts with MFA for remote access | Article 32 GDPR | VPN with MFA enforced for all external users including external investigators |
| Real-time or near-real-time anomaly detection | Article 32 GDPR | Security information and event management (SIEM) system or equivalent alerting mechanism |
| Retention limited to the period necessary for the research purpose | Article 5(1)(e) GDPR (storage limitation) | Retention schedule documented in the record of processing activities and in the trial protocol |
| Participant information notice in plain language | Articles 13 and 14 GDPR (transparency) | Data protection section included in the Informed Consent Form (ICF), reviewed by the ethics committee |
| Breach notification to all affected individuals | Article 34 GDPR | Notification procedure covering patients and all other data subjects, including trusted third parties |
| Data Processing Agreement with each processor | Article 28 GDPR | CTA and DPA in place before any site data is processed by a third party |
| Transfer mechanism for exports outside the EEA | Articles 44 to 49 GDPR | SCCs or adequacy decision documented; transfer impact assessment filed internally |
Focus: the example of the Data Protection Officer appointment
Under Article 37(1)(c) GDPR, any organisation that processes special categories of data on a large scale is required to appoint a Data Protection Officer (DPO). A sponsor running a multicentre trial with French sites and processing health data from hundreds or thousands of participants is very likely to meet this threshold. The DPO must be involved from the outset of the trial design, reviewing the protocol's data protection section, the ICF, the record of processing activities and any transfer mechanism documentation. Sponsors established outside France but operating French sites also have the option of designating a local representative under Article 27 GDPR, which the CNIL recommends for entities without a legal establishment in France.
Focus: the example of the informed consent form under MR-001
The Informed Consent Form is the primary transparency instrument for clinical trial participants in France. Under MR-001, the ICF must contain a dedicated data protection section that identifies the controller, describes the legal basis for processing (reference to MR-001 and Article 9(2)(j) GDPR for scientific research), specifies the categories of data collected, names any processors or joint controllers, explains transfer arrangements and sets out the participant's rights under Articles 15 to 22 GDPR. The ethics committee (Comité de Protection des Personnes, CPP) reviews this section as part of its opinion on the trial. Sponsors should allow sufficient time for CPP feedback, as requests for amendment to the data protection section are common and can delay site activation.
Building a sustainable MR-001 compliance programme
A sustainable compliance programme for MR-001 is one that is integrated into the sponsor's global data governance framework rather than treated as a country-specific formality. Sponsors who apply what iliomad refers to as a funnel approach, beginning with the most stringent framework (GDPR) and layering country-specific requirements on top, find that MR-001 compliance is easier to achieve and to audit because the underlying controls are already in place.
The key elements of such a programme are as follows. First, the sponsor's standard operating procedures should include a French site activation checklist that covers the MR-001 declaration, the DPA, the ICF data protection section and the technical security review. Second, the CTA with each French site should include contractual warranties regarding access control configuration, MFA deployment and incident notification timelines. Third, the sponsor's breach response plan should explicitly address the obligation to notify all categories of data subjects, not only enrolled participants, as the Hôpital Privé de la Loire case demonstrates. Fourth, the programme should be reviewed at least annually against any updates to MR-001 or to the CNIL's published guidelines, as the methodology has been revised on several occasions since its initial adoption.
The CNIL's 2026 enforcement decision is a clear signal that technical safeguards and notification obligations will be examined rigorously, even in settings where no prior complaint has been filed. Sponsors who treat MR-001 as a living compliance instrument rather than a one-time declaration are significantly better positioned to withstand scrutiny.
Need expert guidance on MR-001 compliance, clinical trial data protection or CNIL declarations for your French investigator sites? Iliomad's clinical trials data protection team supports sponsors and CROs at every stage of the trial lifecycle. Contact us to discuss your programme.
FAQs
Our frequently questions
A sustainable MR-001 compliance programme should be embedded within the sponsor's global data governance framework rather than approached as a standalone country-level formality. Key measures include establishing a French site activation checklist covering the MR-001 declaration, the Data Processing Agreement, the ICF data protection section and a technical security review of site systems; incorporating contractual warranties in the Clinical Trial Agreement regarding access controls, MFA deployment and incident notification timelines; ensuring the breach response plan covers all categories of affected data subjects, including enrolled participants and third parties whose data may be stored in site systems; appointing a Data Protection Officer where required under Article 37(1)(c) GDPR and involving the DPO from protocol design onwards; and reviewing the programme at least annually against CNIL updates to MR-001 and related guidance, given that the methodology has been revised several times since its initial adoption.
When a sponsor transfers clinical data, whether pseudonymised or identifiable, from France to a country outside the European Economic Area, the transfer must comply with Chapter V GDPR. This may require reliance on an adequacy decision, Standard Contractual Clauses adopted by the European Commission, binding corporate rules or another valid transfer mechanism. Where the transfer relies on a mechanism that requires an assessment of the destination country's legal framework, the sponsor should also document the relevant transfer risk assessment and any supplementary measures considered necessary. As part of MR-001 compliance, sponsors should therefore map data flows originating from French sites and ensure that appropriate transfer safeguards are in place before personal data is transferred outside the EEA.
Under MR-001, the Informed Consent Form (ICF) must contain a dedicated data protection section that covers several mandatory elements: identification of the data controller; the legal basis for processing (referencing MR-001 and Article 9(2)(j) GDPR for scientific research purposes); the categories of personal data collected; the identity of any processors or joint controllers involved; details of any data transfers outside the EEA and the applicable transfer mechanism; and a full explanation of participant rights under Articles 15 to 22 GDPR. This section is reviewed by the ethics committee (Comité de Protection des Personnes, CPP) as part of its trial opinion. Sponsors should build sufficient time into their site activation timeline to accommodate CPP requests for amendments to the data protection section, as these are common and can delay the start of the study.
MR-001 requires investigator sites to implement appropriate technical and organisational safeguards in line with Article 32 GDPR. These measures include restricting access to patient and study systems to authorised members of the care or research team, using individual authenticated accounts, securing remote access through appropriate controls such as VPN and multi-factor authentication, maintaining traceable access logs, and implementing monitoring mechanisms capable of detecting unusual or unauthorised activity.
Recent CNIL enforcement also illustrates the importance of these safeguards. In its 2026 enforcement action against Hôpital Privé de la Loire, the CNIL highlighted deficiencies in remote-access security and monitoring that contributed to a large-scale data breach. Sponsors should therefore ensure, as part of site qualification and activation, that French investigator sites have appropriate security measures in place and that any identified gaps are addressed before study data is processed.
MR-001 gives practical effect to several GDPR security and breach-management obligations in the context of clinical research. In particular, Article 32 GDPR requires appropriate technical and organisational measures to protect personal data, which may include measures such as role-based access controls, individual authentication, secure remote access and appropriate monitoring capabilities. Article 34 GDPR may require communication of a personal data breach to affected individuals where the breach is likely to result in a high risk to their rights and freedoms. In an MR-001 context, sponsors should therefore ensure that security controls are appropriately implemented and that breach response procedures are capable of identifying and addressing all categories of affected data subjects whose personal data may be involved.
MR-001 is a reference methodology issued by the CNIL (France's data protection authority) that provides a pre-approved legal basis for processing sensitive health data in interventional clinical research. Instead of filing an individual authorisation request, sponsors and investigator sites can rely on MR-001 provided they meet every condition set out in the methodology. It applies to interventional studies within the meaning of EU Clinical Trials Regulation 536/2014. When a sponsor opens investigator sites on French territory, it must commit by declaration to comply with all MR-001 requirements before the first patient is enrolled — making it a mandatory compliance step for any multicentre or global clinical programme that includes French sites.
Find out how iliomad can help your company.
Only visible in production
We'll get back to you as soon as possible.

ICF Boilerplate and Open-Access Database Disclosures: What Clinical Trial Sponsors Must Know
Learn how US site ICF boilerplate on commercial products and open-access genetic databases affects sponsor data governance, Common Rule compliance and GDPR obligations.

iliomad Weekly Digest: DPO Conflicts, Bulk Data Rules, Healthcare Cyber Incidents and AI Transparency
This week: CNIL on DPO conflicts of interest, DOJ bulk data rule for life sciences, wave of healthcare ransomware attacks, Uber's €825m GDPR fine and AI disclosure demands.

CRO data protection: managing third-party and cloud infrastructure risk in clinical research
Understand CRO data protection obligations under GDPR and EU CTR 536/2014. Learn how to manage third-party vendor risk, cloud infrastructure breaches and DPA requirements.


