Privacy AI
Regulatory

Health data compliance, handled.

Tell us what you need. We'll tell you what it takes and how long, before you commit.

Contact us

Summary

Safety reporting personal data is among the most legally sensitive activities in clinical research, combining mandatory pharmacovigilance timelines with GDPR data-minimisation, lawfulness and cross-border transfer requirements. This article explains how EU Clinical Trials Regulation 536/2014, GDPR Article 9 and national frameworks such as France's MR-001 interact when sponsors report suspected unexpected serious adverse reactions (SUSARs). It also examines the reputational and regulatory consequences when transparency obligations are delayed, drawing lessons applicable to any sponsor operating investigator-initiated or multi-site international studies.

Contact us

The iliomad Framework for Safety Reporting Data Protection

Safety reporting in clinical trials generates personal data at every stage: from the initial adverse event notation by an investigator, through the coded narrative transmitted to a sponsor, to the unblinded case-safety report submitted to a competent authority. Each step triggers distinct legal obligations under multiple overlapping instruments.

iliomad applies a four-layer compliance framework to safety reporting personal data:

  1. Lawfulness layer: confirm the legal basis and the applicable special-category ground under GDPR Article 9.
  2. Minimisation layer: ensure that only the data strictly necessary for the pharmacovigilance purpose is processed and transferred.
  3. Transfer layer: validate that every outbound transmission of identifiable or pseudonymous safety data satisfies Chapter V GDPR.
  4. Transparency layer: verify that participant information notices and informed consent forms (ICFs) accurately disclose safety reporting flows.

This framework applies whether the trial is a commercial Phase III study under EU Clinical Trials Regulation 536/2014 (EU CTR) or an investigator-initiated study with a lighter oversight pathway.

What Is Safety Reporting Personal Data in the Context of EU Clinical Trials?

Safety reporting personal data refers to any information relating to an identified or identifiable trial participant that is processed for the purpose of detecting, recording, evaluating and communicating adverse events, serious adverse events (SAEs) and suspected unexpected serious adverse reactions (SUSARs) during or after a clinical trial. Under EU CTR 536/2014, Article 41, sponsors must report SUSARs electronically to the EudraVigilance database within seven days for fatal or life-threatening cases and fifteen days for all others.

Because safety reports routinely contain diagnosis codes, treatment descriptions, medical history and, in some configurations, directly identifying data such as patient initials and dates of birth, they constitute special-category health data within the meaning of GDPR Article 9(1). Their processing therefore requires not only a lawful basis under GDPR Article 6 but also an explicit derogation under Article 9(2), most commonly Article 9(2)(i) (public interest in the area of public health) or Article 9(2)(j) (scientific research purposes subject to Article 89 safeguards).

What GDPR Obligations Govern Adverse Event and SUSAR Reporting?

GDPR obligations for adverse event reporting require sponsors to establish a lawful basis, minimise the personal data transmitted, implement pseudonymisation where practicable, and reflect the reporting flows transparently in participant-facing documents. These obligations do not disappear simply because reporting is legally mandated: mandatory reporting under EU CTR 536/2014 supports the Article 6(1)(c) legal basis (compliance with a legal obligation), but the data minimisation principle under GDPR Article 5(1)(c) still applies to every field included in the report.

Lawful Basis and Special-Category Derogation

A sponsor acting as data controller (a role defined in GDPR Article 4(7) as the entity that determines the purposes and means of processing) must document its legal basis before safety reporting commences, not retrospectively. For most EU-based interventional trials, the combination of Article 6(1)(c) (legal obligation) and Article 9(2)(i) or (j) is appropriate. Sponsors operating under Article 9(2)(j) must additionally comply with the proportionality and safeguarding conditions set out in GDPR Article 89(1), which include pseudonymisation and data-access controls.

Data Minimisation in SUSAR Narratives

SUSAR narratives submitted to EudraVigilance or to national competent authorities must contain sufficient clinical detail to enable medical assessment, but that requirement does not justify including surplus identifiers. The European Medicines Agency's guidance on good pharmacovigilance practices (GVP Module VI, revised 2017) recommends that case identifiers be limited to a patient number or code rather than full name or national identification number. Sponsors should audit their safety database configurations to confirm that export templates respect this principle.

Records of Processing Activities

Under GDPR Article 30, sponsors must maintain a record of processing activities (ROPA) that captures safety reporting as a distinct processing activity, specifying the categories of data processed, the recipients (including regulatory authorities and contract research organisations acting as data processors), the retention periods and the transfer safeguards. Failure to maintain an accurate ROPA is an enforcement risk independent of any underlying safety event.

DPO Involvement

A Data Protection Officer (DPO), defined in GDPR Article 37 as the designated expert responsible for advising the controller and monitoring GDPR compliance, must be consulted when safety reporting systems are designed or reconfigured. Because safety databases such as Argus or Veeva Vault Safety process special-category health data at scale, a Data Protection Impact Assessment (DPIA) under GDPR Article 35 is mandatory before their deployment.

How Do Cross-Border Data Transfers Affect Safety Reporting Timelines?

Cross-border safety data transfers can delay SUSAR reporting unless transfer mechanisms are pre-validated: a sponsor that discovers a fatal event at a site in a third country and then realises it has no executed Standard Contractual Clauses (SCCs) in place with that site will face a conflict between the EU CTR's seven-day clock and GDPR Chapter V compliance. The safest approach is to execute data processing agreements (DPAs) and SCCs before the first patient is enrolled.

Third-Country Transfers and the SUSAR Timeline

When a clinical site is located outside the European Economic Area (EEA), for example in the United States, China or Japan, any transmission of safety data from that site to an EU-based sponsor or contract research organisation (CRO) constitutes a restricted transfer under GDPR Chapter V. The standard mechanism is the European Commission's updated SCCs (Implementing Decision 2021/914, published 4 June 2021), which must be supplemented by a Transfer Impact Assessment (TIA) evaluating the legal framework of the third country.

The case of HuidaGene's CRISPR trial in China, reported by STAT News in August 2026, illustrates what can happen when oversight gaps in a third country intersect with inadequate transparency frameworks. The trial proceeded under China's investigator-initiated trial pathway, which permits hospital-based studies to advance with limited government oversight. When adverse events occurred, disclosure was significantly delayed, which, had EU-linked sponsors or data recipients been involved, would have triggered potential violations of both EU CTR Article 41 reporting timelines and GDPR Article 5(1)(a) (the principle of transparency). The lesson for EU and UK sponsors is that due diligence on a site's local regulatory framework must precede any cross-border data flow arrangement.

Investigator-Initiated Studies and Oversight Gaps

An investigator-initiated trial (IIT) is a clinical study in which the principal investigator, rather than a pharmaceutical company, acts as the sponsor and assumes regulatory accountability. IITs conducted in jurisdictions with lighter oversight frameworks may not systematically feed safety data into EudraVigilance or equivalent databases, creating information asymmetries. EU-based academic sponsors running IITs with non-EEA sites should ensure that their clinical site agreements explicitly allocate responsibility for adverse event reporting and specify the personal data transmission protocols required to meet EU CTR and GDPR obligations simultaneously.

Focus: National Authority Positions on Safety Reporting Personal Data

Focus: The Example of France (CNIL and MR-001)

France requires sponsors conducting interventional clinical trials to operate under the Méthodologie de Référence MR-001, issued by the Commission Nationale de l'Informatique et des Libertés (CNIL), the French supervisory authority. MR-001 authorises the processing of personal health data for research purposes without an individual CNIL authorisation, provided the sponsor complies with MR-001's conditions, including data minimisation requirements and specific rules on the re-use of safety data. Safety reporting flows must be described in the trial protocol's data protection section (commonly referred to as Protocol Section 13) and reflected in the ICF. Sponsors that deviate from MR-001 conditions must apply for a specific CNIL authorisation, which can add several months to the site-opening timeline.

Focus: The Example of the United Kingdom (ICO)

In the United Kingdom, the Information Commissioner's Office (ICO) is the competent supervisory authority. Post-Brexit, UK GDPR (retained in domestic law by the Data Protection Act 2018) applies to safety reporting in UK clinical trials, with the Medicines and Healthcare products Regulatory Agency (MHRA) as the competent authority for EU CTR-equivalent oversight. Sponsors transferring SUSAR data from UK sites to EEA recipients must use the International Data Transfer Agreement (IDTA) or the Addendum to the European Commission SCCs, published by the ICO in March 2022. The ICO has confirmed in its guidance on health and social care data that safety reporting constitutes processing in the substantial public interest, supporting a Schedule 1 condition under the Data Protection Act 2018.

Focus: The Example of Germany (BfDI and Länder Authorities)

Germany operates a dual supervisory structure: the Federal Commissioner for Data Protection and Freedom of Information (BfDI) oversees federal bodies, while Länder data protection authorities supervise sponsors and sites within their territory. The Paul-Ehrlich-Institut (PEI) and the Bundesinstitut für Arzneimittel und Medizinprodukte (BfArM) are the competent authorities for clinical trial authorisation. German law (BDSG, section 27) permits scientific research processing under conditions broadly aligned with GDPR Article 89, but sponsors must document the specific safeguards applied to safety databases. Safety narratives transferred outside Germany to non-EEA countries require the full SCC plus TIA package.

Focus: The Example of China (NMPA and Investigator-Initiated Pathways)

China's National Medical Products Administration (NMPA) regulates commercially sponsored clinical trials, but investigator-initiated studies conducted within hospital research programmes may operate under institutional review board approval without NMPA registration. This creates a material gap: adverse events may not be centrally reported, and no equivalent of EudraVigilance exists. For EU or UK sponsors considering data partnerships or licence agreements with Chinese trial sponsors, this gap is a transfer risk. Any personal safety data flowing from a Chinese site to the EEA must be assessed under GDPR Chapter V, and the absence of an adequacy decision for China (as of the date of this article) means that SCCs and a TIA are mandatory. The TIA must assess China's Cybersecurity Law (2017), Data Security Law (2021) and Personal Information Protection Law (PIPL, 2021), all of which permit government access to personal data under broad national security provisions, a factor that materially affects the TIA outcome.

Focus: The Example of the United States (FDA and 21 CFR Part 312)

The United States Food and Drug Administration (FDA) requires sponsors to report IND safety reports under 21 CFR Part 312.32, with a fifteen-day window for unexpected fatal or life-threatening adverse drug experiences. When a US site participates in an EEA-sponsored trial, safety data transfers from the US to the EEA do not require SCCs (because the transfer flows into the EEA, not out of it), but the reverse flow triggers GDPR Chapter V obligations. Sponsors should note that the FDA's clinical trial data-protection requirements under 21 CFR Part 11, which governs electronic records and signatures, are distinct from GDPR and require separate compliance mapping.

Comparison: Safety Reporting Obligations Across Key Instruments

Table 1: Safety reporting triggers and their data protection implications across the EU, UK and US frameworks.
Instrument Reporting Trigger Timeline Personal Data Rule Supervisory Body
EU CTR 536/2014, Article 41 SUSAR (fatal or life-threatening) 7 days Pseudonymisation recommended; EudraVigilance submission EMA and national competent authorities
EU CTR 536/2014, Article 41 SUSAR (non-fatal) 15 days Pseudonymisation recommended; EudraVigilance submission EMA and national competent authorities
GDPR Article 5(1)(a) Any safety data processing Ongoing (transparency principle) Accurate and transparent processing required Lead supervisory authority under Article 56
GDPR Article 35 New safety database deployment Before processing begins DPIA mandatory for large-scale health data DPO and supervisory authority (if high residual risk)
MR-001 (CNIL, France) Interventional trial in France Compliance before site opening Data minimisation and specific retention rules CNIL
21 CFR Part 312.32 (FDA, US) Unexpected fatal adverse drug experience 15 calendar days Electronic records under 21 CFR Part 11 FDA
ICO IDTA (UK, post-Brexit) Transfer of safety data from the UK to a non-adequate country Before first transfer Transfer Impact Assessment (TIA) required ICO

How iliomad Supports Sponsors with Safety Reporting Compliance

iliomad provides end-to-end data protection support for clinical trial sponsors and CROs, covering DPIA preparation for safety databases, SCC and TIA packages for non-EEA site transfers, Protocol Section 13 drafting, DPO services and representation before the CNIL, ICO and other EEA supervisory authorities.

If your trial involves investigator-initiated sites, non-EEA data flows or a safety database requiring GDPR validation, contact our clinical trials data protection team to understand the scope of work and timelines before you commit.

Explore iliomad's Clinical Trials Data Protection Services

Contact us

FAQs

Our frequently questions

What is the legal basis for processing safety reporting personal data under GDPR?

For most EU clinical trials, the legal basis is GDPR Article 6(1)(c) (compliance with a legal obligation) combined with Article 9(2)(i) (public interest in public health) or Article 9(2)(j) (scientific research), supported by proportionate safeguards under Article 89(1). Sponsors should confirm the applicable derogation with their DPO before trial initiation.

When is a DPIA required for a clinical trial safety database?

A DPIA under GDPR Article 35 is required whenever a sponsor deploys a new safety database that processes special-category health data at scale, involves systematic monitoring of participants or uses profiling to assess drug safety signals. The DPIA must be completed and documented before the system processes any participant data.

Do SCCs apply when transferring SUSAR data from an EU sponsor to a CRO in India or Japan?

es. Because neither India nor Japan has a full adequacy decision covering clinical trial data flows (Japan's adequacy decision under GDPR Article 45 applies to transfers from the EEA to Japan under specific conditions, and sponsors should verify its scope for safety data), sponsors must rely on the European Commission's SCCs (Decision 2021/914) supplemented by a TIA. The TIA must assess the local legal framework's government access provisions.

Can a sponsor delay a SUSAR report while waiting for SCCs to be executed?

No. The EU CTR 536/2014 reporting timelines are absolute regulatory obligations and cannot be suspended for contractual reasons. Sponsors must execute SCCs and DPAs before the first patient is enrolled, precisely to avoid this conflict. If a transfer mechanism is absent, the sponsor should seek legal advice on emergency derogations under GDPR Article 49, which are narrow and intended for exceptional situations only.

What are the consequences of delayed adverse event disclosure from a GDPR perspective?

Delayed disclosure of a serious adverse event can violate GDPR Article 5(1)(a) (transparency), Article 5(1)(f) (integrity and confidentiality) and, where the delay involves a personal data breach, the 72-hour notification obligation under GDPR Article 33. In addition to regulatory fines under Article 83, delayed disclosure exposes the sponsor to reputational damage and potential suspension of the clinical trial by competent authorities under EU CTR Article 77.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
Diagram showing GDPR data flow between a clinical trial sponsor, a CRO acting as data processor, and cloud infrastructure, with a data breach alert icon overlaid
August 17, 2026
Regulations & Guidelines
GDPR
Clinical Trials
Regulation
Data Breach & Cybersecurity

CRO data protection: managing third-party and cloud infrastructure risk in clinical research

Understand CRO data protection obligations under GDPR and EU CTR 536/2014. Learn how to manage third-party vendor risk, cloud infrastructure breaches and DPA requirements.

Diagram illustrating the site-to-vendor data transfer chain in a clinical trial, showing the study site as the entity responsible for standard contractual clauses rather than the sponsor
August 14, 2026
ICF
Clinical Trials
DPIA
Testimonial
Regulations & Guidelines

ICF Data Protection Language for Site-to-Vendor Transfers: Attributing SCCs to the Correct Entity

Learn how to correctly attribute international transfer safeguards in clinical trial ICFs. Avoid the common error of referencing sponsor SCCs for site-to-vendor data flows.

Abstract illustration of interconnected nodes representing clinical trial data flows, regulatory frameworks and AI partnerships across global jurisdictions.
August 14, 2026
Clinical Trials
Data Breach
AI
Healthtech

Weekly News Digest: Clinical Trial Oversight, Health Data Breaches and AI Regulation

This week: China tightens IIT oversight, 23andMe fine uncollectable, Snowflake guilty plea, Novo Nordisk-AWS AI deal, child safety AI bills and more health data breach news.