In this article
Health data compliance, handled.
Tell us what you need. We'll tell you what it takes and how long, before you commit.
Contact usSummary
Clinical trial sponsors must ensure that technology vendors processing participant data comply with GDPR, particularly Article 28, by maintaining comprehensive audit logs and safeguarding participant rights. Gaps in logging can jeopardize breach notification obligations under Article 33, underscoring the need for stringent vendor audits to protect trial integrity and participant safety.
Summary: Sponsors conducting clinical trials must ensure that every technology vendor processing participant data maintains complete, tamper-evident audit logs and complies fully with Article 28 of the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). When a vendor's system cannot record or detect unauthorised access, the sponsor's ability to meet the 72-hour breach-notification deadline under Article 33 GDPR is critically undermined. Selecting, contracting and auditing vendors rigorously is therefore not optional; it is a core regulatory obligation with direct consequences for trial integrity and participant safety.
The Epic Systems incident reported by TechCrunch on 2 October 2026 (https://techcrunch.com/2026/10/02/medical-records-giant-epic-pauses-product-development-to-fix-security-bugs-that-risk-patients-data/) illustrates a vulnerability type that life sciences data-protection teams must treat as a primary risk scenario: an electronic health record platform whose deployment configurations could permit unauthorised access to patient data without generating any log entry. Because MyChart underpins access to records for more than 320 million patients across United States healthcare systems, the scale of potential undetected exposure is substantial. Although the breach involves a US vendor subject primarily to the Health Insurance Portability and Accountability Act (HIPAA), the governance lessons translate directly into the GDPR framework that European and globally active clinical trial sponsors must apply to every technology sub-processor they appoint.
This article sets out iliomad's structured approach to vendor GDPR compliance in clinical trials, covering sub-processor obligations, audit-trail requirements, Data Protection Impact Assessments (DPIAs) and breach-notification readiness.
What do Article 28 GDPR obligations actually require from clinical trial vendors?
Article 28 GDPR requires that a sponsor, acting as data controller, only appoints processors who provide sufficient guarantees to implement appropriate technical and organisational measures so that processing meets GDPR requirements and ensures the protection of data subjects' rights. In clinical trials, this means every technology vendor handling participant data, including electronic data capture (EDC) platforms, ePRO tools, randomisation systems and electronic trial master file (eTMF) solutions, must be bound by a written data processing agreement (DPA) before processing begins.
The DPA is not a formality. Under Article 28(3) GDPR, it must specify the subject matter, duration, nature and purpose of processing; the type of personal data and categories of data subject; and the obligations and rights of the controller. Critically, it must require the processor to maintain records of processing activities, assist the controller with security obligations under Article 32, and notify the controller without undue delay after becoming aware of a personal data breach. In clinical trial terms, Article 32 GDPR mandates that processing systems maintain the ability to ensure ongoing confidentiality, integrity, availability and resilience, and to restore access to data in a timely manner following an incident.
A vendor whose system cannot generate an audit trail of access events fails the Article 32 test regardless of any contractual assurance it may have provided.
Focus: the example of France and the CNIL's MR-001 framework
In France, clinical trial sponsors must comply with the Commission Nationale de l'Informatique et des Libertés (CNIL) Méthodologie de Référence MR-001, which governs the processing of health data for research involving human subjects. MR-001 imposes specific security requirements on data processors, including the obligation to maintain access logs and to implement traceability measures proportionate to the sensitivity of health data. A vendor configuration that suppresses log generation would constitute a direct breach of MR-001's security annex and would expose the sponsor to regulatory sanction, since the sponsor remains accountable as controller even when processing is delegated. The CNIL has the authority under Article 83 GDPR to impose administrative fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher.
Focus: the example of the United Kingdom and the ICO's expectations
In the United Kingdom, the UK GDPR (as retained and amended by the Data Protection Act 2018) mirrors the EU GDPR's Article 28 framework. The Information Commissioner's Office (ICO) has published guidance making clear that controllers must carry out due diligence on processors before appointment and must audit processor compliance on an ongoing basis. For clinical trials subject to the UK's Medicines and Healthcare products Regulatory Agency (MHRA) oversight, audit-trail integrity is additionally required under Good Clinical Practice (GCP) standards, specifically ICH E6(R3), which demands that all clinical trial data be attributable, legible, contemporaneous, original and accurate. A logging gap that prevents attribution of data access to a specific user at a specific time is incompatible with ICH E6(R3) and with UK GDPR Article 32 simultaneously.
How does a logging gap undermine breach notification obligations?
A logging gap directly prevents a sponsor from detecting a personal data breach, which in turn makes the 72-hour notification deadline under Article 33 GDPR impossible to meet from the moment an intrusion occurs. Article 33 GDPR requires the controller to notify the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a breach. Where a vendor's system produces no record of unauthorised access, the controller may never become aware of the breach at all.
This is precisely the risk that the Epic/MyChart situation illustrates. Epic's chief security officer acknowledged that certain MyChart deployment configurations could allow outsiders to access patient records without recording any intrusion in the software's logs. In a clinical trial context, an equivalent gap in an EDC system or patient portal would mean that a sponsor could not determine whether trial data had been accessed or altered, could not assess the risk to data subjects as required by Article 33(3) GDPR, and could not notify affected participants under Article 34 GDPR where the breach is likely to result in a high risk to their rights and freedoms.
The severity is compounded in oncology or rare disease trials, where re-identification of participants is feasible from a small dataset and where unauthorised disclosure of diagnosis or treatment data carries significant consequences for participants' insurance, employment and wellbeing.
Focus: the example of Germany and the BfArM's expectations for eTMF integrity
The Bundesinstitut für Arzneimittel und Medizinprodukte (BfArM), Germany's federal medicines authority, requires that electronic systems used in clinical trials maintain complete and unbroken audit trails under Section 13 of the German GCP Ordinance (GCP-V) and under the EU Clinical Trials Regulation 536/2014 (EU CTR), which applies to all trials authorised through the Clinical Trials Information System (CTIS). EU CTR Article 58 requires that trial master file systems retain records in a manner that allows complete reporting, interpretation and verification of the trial. A vendor system with logging gaps cannot satisfy this requirement.
Focus: the example of EU-level obligations under EU CTR 536/2014
Regulation (EU) No 536/2014 on clinical trials on medicinal products for human use establishes harmonised requirements across EU Member States for the conduct of clinical trials. Article 56 of EU CTR 536/2014 requires sponsors to maintain a trial master file throughout the trial and for a period of at least 25 years after its conclusion. The integrity of that file depends on systems that record every access, modification and deletion event. A vendor whose platform cannot guarantee this audit-trail completeness creates direct regulatory exposure for the sponsor, independently of any GDPR liability.
Comparing vendor obligations across key regulatory instruments
The table below summarises the core logging and audit-trail obligations that clinical trial vendors must satisfy under each relevant framework.
| Instrument | Jurisdiction | Relevant provision | Core logging obligation |
|---|---|---|---|
| GDPR (Regulation (EU) 2016/679) | EU/EEA | Articles 28, 32 | DPA required; processor must support breach detection and notification |
| UK GDPR / Data Protection Act 2018 | United Kingdom | Articles 28, 32 | Same as EU GDPR; ICO guidance requires ongoing processor audits |
| CNIL MR-001 | France | Security annex | Mandatory access logs; traceability proportionate to health data sensitivity |
| ICH E6(R3) GCP | Global | Section 5 (sponsor responsibilities) | Data must be attributable, legible, contemporaneous, original and accurate |
| EU CTR 536/2014 | EU/EEA | Articles 56, 58 | TMF must support complete verification; 25-year retention minimum |
| GCP-V (German GCP Ordinance) | Germany | Section 13 | Electronic systems must maintain complete and unbroken audit trails |
What should a DPIA cover when onboarding a clinical trial technology vendor?
A Data Protection Impact Assessment (DPIA), defined under Article 35 GDPR as a prior assessment of the impact of envisaged processing operations on the protection of personal data, is mandatory when processing is likely to result in a high risk to individuals. Clinical trial data involving health information, genetic data or data relating to vulnerable populations will almost always meet this threshold.
When the processing is delegated to a technology vendor, the DPIA must assess not only the vendor's stated security architecture but also the specific deployment configuration that will be used for the trial. The Epic/MyChart situation demonstrates that a platform may be secure by default yet expose participants to risk through a particular configuration chosen by the deploying organisation. Sponsors must therefore require vendors to provide configuration-specific security documentation and to confirm in writing which logging features are enabled for the sponsor's instance.
A DPIA conducted for vendor GDPR clinical trials compliance should address the following elements as a minimum:
- A description of the processing, including the categories of participant data, the systems involved and the vendor's role as processor or sub-processor.
- An assessment of the necessity and proportionality of the processing relative to the trial's scientific objectives.
- An assessment of risks to participants, including risks arising from logging gaps, configuration errors or vendor-side security vulnerabilities.
- The measures envisaged to address those risks, including contractual controls under Article 28, technical requirements for audit-trail completeness, penetration testing obligations and incident response timelines.
- Evidence that the vendor has been informed of and agrees to participate in any supervisory authority consultation under Article 36 GDPR, should the residual risk remain high after mitigating measures are applied.
Focus: the example of the Netherlands and the AP's DPIA guidance for health data processors
The Autoriteit Persoonsgegevens (AP), the Netherlands' data protection authority, has published sector-specific DPIA guidance for health data processing that requires controllers to verify processor security controls as part of the DPIA process, rather than treating processor assurances as conclusive. The AP's position aligns with Recital 81 GDPR, which states that the processor should be chosen on the basis of sufficient guarantees, particularly in terms of expert knowledge, reliability and resources. Sponsors operating trials through Dutch sites must document in their DPIA how they have verified, rather than simply assumed, that their vendors' logging and audit-trail functions are operational and complete.
Focus: the example of AI-assisted security testing in vendor assurance programmes
The Epic incident is significant not only for the vulnerability it exposed but for the mechanism that uncovered it: Anthropic's AI-based security-testing tool, internally referred to as Mythos, identified logging gaps that conventional security reviews had apparently not surfaced. This has direct implications for sponsor vendor assurance programmes. The EU AI Act (Regulation (EU) 2024/1689), which entered into application progressively from August 2024, classifies AI systems used in critical digital infrastructure management as high-risk under Annex III. AI security-testing tools used to assess health data platforms may fall within this classification, depending on their deployment context. Sponsors and vendors using AI tools for security assurance must therefore consider whether those tools themselves require conformity assessment and technical documentation under the EU AI Act, in addition to the GDPR controls applied to the systems being tested.
Building a sponsor-ready vendor governance framework
Sponsors require a repeatable, inspection-ready process for onboarding, monitoring and, where necessary, terminating clinical trial technology vendors. Based on iliomad's work with biotech and pharmaceutical sponsors across multiple jurisdictions, a compliant vendor governance framework for vendor GDPR clinical trials compliance comprises four operational layers.
Layer 1: pre-selection due diligence. Before signing any agreement, the sponsor must review the vendor's security architecture documentation, most recent penetration test results, audit-trail specifications and sub-processor list. Logging completeness and the ability to produce audit reports on demand must be confirmed in writing.
Layer 2: contractual controls. The DPA under Article 28 GDPR must include explicit provisions requiring the vendor to maintain complete access logs, to notify the sponsor within 24 hours of becoming aware of any actual or suspected security incident (to allow the sponsor to meet the 72-hour supervisory authority notification deadline under Article 33), and to permit the sponsor to conduct or commission audits of the vendor's security controls.
Layer 3: DPIA integration. The vendor's specific deployment configuration must be assessed within the sponsor's DPIA, not as an afterthought but as a core component of the risk assessment. Configuration changes during the trial must trigger a DPIA review.
Layer 4: ongoing monitoring. Sponsors must schedule periodic reviews of vendor security posture, require vendors to report any identified vulnerabilities that affect the sponsor's instance, and maintain documented evidence of these reviews in the trial master file to satisfy EU CTR 536/2014 Article 58 and ICH E6(R3) requirements.
Iliomad supports biotech and pharmaceutical sponsors, CROs and HealthTech organisations with end-to-end data protection compliance for clinical trials, including vendor due diligence, Article 28 DPA drafting, DPIA completion and regulatory representation across EU Member States and the United Kingdom. To discuss your vendor governance programme or to request a compliance review, visit our Clinical Trials Data Protection service page.
FAQs
Our frequently questions
Sponsors remain accountable as data controllers even when processing is fully delegated to a technology vendor. If a vendor's system fails to maintain adequate audit trails or logging, the sponsor faces direct regulatory exposure on multiple fronts. Under Article 83 GDPR, supervisory authorities such as the CNIL in France can impose administrative fines of up to €20 million or 4% of total worldwide annual turnover, whichever is higher. Beyond financial penalties, a sponsor may be unable to meet the 72-hour breach notification deadline under Article 33 GDPR, triggering additional enforcement action. Failures in audit-trail integrity can also constitute a breach of EU CTR 536/2014 and ICH E6(R3) GCP standards, potentially jeopardising trial authorisation, data acceptability for regulatory submissions, and the overall integrity of the trial. Selecting, contracting and auditing vendors rigorously is therefore a core regulatory obligation, not an optional governance measure.
A sponsor-ready vendor governance framework for GDPR compliance in clinical trials comprises four operational layers. Layer 1 — Pre-selection due diligence: before signing any agreement, sponsors must review the vendor's security architecture, penetration test results, audit-trail specifications and sub-processor list, confirming logging completeness in writing. Layer 2 — Contractual controls: the Article 28 DPA must explicitly require complete access logs, a 24-hour security incident notification to the sponsor (enabling the 72-hour supervisory authority deadline to be met), and the right to audit vendor security controls. Layer 3 — DPIA integration: the vendor's specific deployment configuration must be assessed as a core component of the DPIA, with configuration changes triggering a review. Layer 4 — Ongoing monitoring: sponsors must schedule periodic security posture reviews, require vendors to report vulnerabilities affecting the sponsor's instance, and retain documented evidence in the trial master file to satisfy EU CTR 536/2014 and ICH E6(R3).
Clinical trial vendors must satisfy audit-trail and logging obligations under several overlapping regulatory frameworks. ICH E6(R3) GCP requires all trial data to be attributable, legible, contemporaneous, original and accurate — meaning any logging gap that prevents attribution of data access to a specific user at a specific time is non-compliant. EU Clinical Trials Regulation 536/2014 (Articles 56 and 58) requires that trial master file systems support complete reporting, interpretation and verification of the trial, with a minimum 25-year retention period. In Germany, the GCP Ordinance (GCP-V, Section 13) mandates complete and unbroken audit trails. In France, CNIL MR-001 requires mandatory access logs and traceability proportionate to health data sensitivity. In the UK, the ICO requires ongoing processor audits, and the MHRA additionally enforces GCP audit-trail standards.
A Data Protection Impact Assessment (DPIA) is mandatory under Article 35 GDPR whenever processing is likely to result in a high risk to individuals — a threshold almost always met by clinical trial data involving health or genetic information. When processing is delegated to a vendor, the DPIA must assess not only the vendor's stated security architecture but also the specific deployment configuration used for that trial. At a minimum, it should cover: (1) a description of the processing, systems and the vendor's role; (2) the necessity and proportionality of processing relative to scientific objectives; (3) risks to participants including logging gaps and configuration errors; (4) measures to address those risks, including contractual controls, audit-trail requirements and incident response timelines; and (5) evidence that the vendor agrees to participate in any supervisory authority consultation under Article 36 GDPR if residual risk remains high. Configuration changes during the trial must trigger a fresh DPIA review.
A logging gap directly prevents a sponsor from detecting a personal data breach, which in turn makes it impossible to meet the 72-hour notification deadline required under Article 33 GDPR. If a vendor's system produces no record of unauthorised access, the controller may never become aware of the breach at all. This means the sponsor cannot determine whether trial data was accessed or altered, cannot assess the risk to data subjects as required by Article 33(3) GDPR, and cannot notify affected participants under Article 34 GDPR where a high risk to their rights and freedoms exists. This risk is especially severe in oncology or rare disease trials, where re-identification from small datasets is feasible and unauthorised disclosure of diagnosis or treatment data can have serious consequences for participants' insurance, employment and wellbeing.
Under Article 28 GDPR, a sponsor acting as data controller may only appoint processors who provide sufficient guarantees to implement appropriate technical and organisational measures ensuring GDPR compliance and the protection of data subjects' rights. In practice, this means every technology vendor handling participant data — including EDC platforms, ePRO tools, randomisation systems and eTMF solutions — must be bound by a written Data Processing Agreement (DPA) before any processing begins. The DPA must specify the subject matter, duration, nature and purpose of processing, the categories of personal data involved, and the obligations of both parties. It must also require the processor to maintain records of processing activities, support the controller's security obligations under Article 32, and notify the controller without undue delay upon becoming aware of a personal data breach.
Find out how iliomad can help your company.
Only visible in production
We'll get back to you as soon as possible.

Clinical studies and disability data governance: what life sciences sponsors must track
Learn how proposed cuts to US federal health surveys affect clinical studies, real-world evidence and cross-border data benchmarking for life sciences sponsors.

iliomad Weekly Digest: AI in Clinical Research, EU Health Data Rules, Cybersecurity and Regulatory Enforcement
This week: ARPA-H SURPASS trials programme, EHDS metadata rules, EDPB fine methodology, Citrix zero-days, Labcorp settlement and AI health-data governance.

GDPR Article 89 research: lawful basis and safeguards for clinical trials
Understand how GDPR Article 89 enables lawful processing of personal data in clinical research, what safeguards apply, and how sponsors can comply across the EU.


