Use of Personal Data Implications Outside Clinical Trial Protocol Within GDPR - Florence (2024)

Skip to content

StudyOrganizer – Your Complimentary Study Management Assistant

Set-Up for Free Now

  • All Resources
  • Blog
  • Guides
  • Reports
  • Product Information
  • Case Studies
  • Webinars
  • Videos
  • Podcasts
    • ESSENTIAL INFORMATION

    • Florence Compliance
    • FDA Guidance
    • Shared Responsibility Model
    • CFR Part 11
    • ICH GCP R2
    • GDPR Guidance
    • HIPAA Guidance
    • Digital Research Certification
    • Change Management Certification
  • Company
      • Contact
      • Partners
      • News
      • Careers
      • Leadership
  • Login
  • Request Demo

  • Use of Personal Data Implications Outside Clinical Trial Protocol Within GDPRBlake Adams2024-02-16T17:05:25-05:00

    What is the meaning of Article 28(2) of the CTR and what are the implications for the use of personal data outside the protocol of the clinical trial (secondary use) within the scope of the GDPR?

    The CTR explicitly refers to the situation where consent may be sought from the clinical trial subject for the use of personal data concerning that subject outside that clinical trial protocol for future scientific purposes (Article 28(2) of the CTR).

    Secondary use of data which is anonymised does not fall within the scope of the GDPR. By contrast, in case of processing of personal (including pseudonymised) data outside of the CT protocol the following must be considered:

    If a sponsor/investigator would like to use the personal data gathered for any other purposes than the one defined by the clinical trial protocol (e.g. medical data collected to conduct a clinical trial on breast cancer used to run a study aiming to identify new biomarkers, but which was not foreseen in the clinical trial protocol), it would require a valid legal ground under Article 6 of the GDPR (16) (see question 3 for the legal basis). The chosen legal basis may or may not differ from the legal basis of the primary use.

    Due account must be taken of Article 5(1)(b) of the GDPR which provides for a presumption of compatibility of purposes, subject to the conditions set for in Article 89(1) GDPR, when further processing is carried out for purposes of scientific research. In any event, even when the presumption of compatibility is found to apply , the scientific research making use of the data outside the protocol of the clinical trial must be conducted in compliance with the relevant legal basis and all other relevant applicable provisions of data protection law as stated under Article 28(2) CTR. Therefore, the controller is not exempt from the other obligations under data protection law, for example with regard to fairness, lawfulness, necessity and proportionality, as well as data quality.

    Where consent (Article 6(1) (a) of the GDPR) is sought to be used as a legal basis for the processing of personal data for secondary use, the following considerations should be taken into account:

    The GDPR requires that personal data is collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Further processing for scientific research purposes shall, in accordance with Article 89(1), not be considered incompatible with the initial purposes (Article 5(1) (b)).

    • Pursuant to Article 4(11) of the GDPR, consent of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her (17.)
    • Pursuant to Article 7(3) of the GDPR, an individual has the right to withdraw his/her consent at any time during the conduct of the clinical trial. Data subjects should be given this information prior to giving consent to participate in the clinical trial.
    • As regards consent for processing personal data for the purpose of scientific research, it is further clarified in Recital 33 of the GDPR: “It is often not possible to fully identify the purpose of personal data processing for scientific research purposes at the time of data collection. Therefore, data subjects should be allowed to give their consent to certain areas of scientific research when in keeping with recognised ethical standards for scientific research. Data subjects should have the opportunity to give their consent only to certain areas of research or parts of research projects to the extent allowed by the intended purpose.”
    • Recital 33 brings some flexibility to the degree of specification of consent and allows that the purpose may be described at a more general level. Yet it must be interpreted in a strict manner and requires a high degree of scrutiny. It should be noted that the obligations with regard to the requirement of specific consent still apply, despite the flexibility of recital 33. This means that, in principle, scientific research projects can only include personal data on the basis of consent if they have a well-described purpose.
    • Therefore, the sponsor may either seek consent of the subject for a secondary use already in the beginning of the clinical trial (the first use). Here it is important to note that this form of consent must strictly be distinguished from the informed consent in the context of the CTR. The sponsor must ask separately for consent of data processing within a secondary use (using different consent sheets) and has to indicate the specific research purposes of this use.
    • On the other hand if the aim of using the data for further research outside the protocol of the CT arises after the clinical trial has been completed, the sponsor must go back to the data subjects for specific consent.
    • In any case the sponsor/investigator must inform the subject according to Article 13 of the GDPR (e.g. on the legal basis and the right to withdraw consent) (see Q&A5).

    Download all questions and answers in the Florence Beginner’s Guide to GDPR for Clinical Trials.

    The information presented in our library is for informational purposes only, they are not for implementation in operations. Please consult official GDPR guidance documents for operational use.

    This information was sourced from the European Commission Directorate-General For Health And Food Safety: Question and Answers on the interplay between the Clinical Trials Regulation and the General Data Protection Regulation.

    Return to Florence Library of GDPR and Clinical Trial Resources

    Download the Beginner’s Guide to Global Data Protection Regulation (GDPR) for Clinical Trials

    Download Now

    Use of Personal Data Implications Outside Clinical Trial Protocol Within GDPR - Florence (13)

    Learn more about the #1 eISF platform on the market

    Learn More

    Industries

    Company

    Products

    Legal

    Get in Touch

    Contact Us

    Schedule a Demo

    info@florencehc.com

    Global Offices

    USA (HQ)
    600 Peachtree St. NE, Suite 920
    Atlanta, GA 30308

    Serbia
    Bulevar Kralja Aleksandra 84
    11000 Belgrade, Serbia

    Use of Personal Data Implications Outside Clinical Trial Protocol Within GDPR - Florence (14)

    © 2023. Florence Healthcare.

    Page load link
    Go to Top
    Use of Personal Data Implications Outside Clinical Trial Protocol Within GDPR - Florence (2024)

    FAQs

    Use of Personal Data Implications Outside Clinical Trial Protocol Within GDPR - Florence? ›

    In any event, even when the presumption of compatibility is found to apply , the scientific research making use of the data outside the protocol of the clinical trial must be conducted in compliance with the relevant legal basis and all other relevant applicable provisions of data protection law as stated under Article ...

    Does GDPR apply to clinical trial data? ›

    For clinical trials, the GDPR provides that subjects have the right to object to the processing of their personal data on grounds relating to their particular situation, unless the processing is necessary for performing a task carried out in the public interest or another limitation set forth in member state ...

    What is Article 28 3 of the CTR? ›

    Article 28(3) of the CTR states that withdrawal of the informed consent to participate in a clinical trial shall not affect any activities already carried out and the use of data obtained on the basis of the informed consent before that withdrawal. . 15 Recital 31 CTR.

    When must a clinical investigator in the US comply with GDPR requirements? ›

    The only time a U.S. company would need to follow GDPR is when conducting a trial in the European Union (EU), as it involves staff and/or patients who are in the EU (meaning any identified or identifiable natural persons, regardless of whether they are citizens or residents of the EU).

    Does GDPR apply to research data? ›

    The GDPR does not prevent research data from being archived and shared for research use by others, as long as the data protection principles are met. An example is where researchers collect data directly from participants, you should discuss their intention to reuse in further research and to deposit in an archive.

    Does GDPR apply to personal data? ›

    The term 'personal data' is the entryway to the application of the General Data Protection Regulation (GDPR). Only if a processing of data concerns personal data, the General Data Protection Regulation applies.

    What data is not covered by GDPR? ›

    The GDPR does not apply if: the data subject is dead. the data subject is a legal person. the processing is done by a person acting for purposes which are outside his trade, business, or profession.

    What is Article 74 of the CTR? ›

    Legal representative requirements under CTR

    According to Article 74 of the CTR, if a sponsor of a Clinical Trial is not based in the EU, then they are required to appoint a representative within the EU to act as a Legal Representative.

    What is Article 30 of the General Data Protection Regulation? ›

    Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility.

    Under what circ*mstances must a CTR be filed? ›

    Federal law requires financial institutions to report currency (cash or coin) transactions over $10,000 conducted by, or on behalf of, one person, as well as multiple currency transactions that aggregate to be over $10,000 in a single day. These transactions are reported on Currency Transaction Reports (CTRs).

    Does GDPR apply in the USA? ›

    Does the GDPR Apply to the US? The short answer is yes; the GDPR applies to the U.S. in several ways. You can find a description of the GDPR's extraterritorial scope in Article 3 of the text. U.S. companies fall under the jurisdiction of the GDPR as either data controllers or data processors.

    What are the requirements for PII under GDPR? ›

    According to GDPR requirements, companies must employ data and privacy protections for Personally Identifiable Information (PII) related to any EU citizen they engage with, including employees, customers, and third-party vendors.

    What is the equivalent of GDPR compliance in the US? ›

    The CCPA (California Consumer Privacy Act) is the US equivalent of GDPR. This comprehensive data privacy act gives Californian residents greater transparency and control over how businesses collect and use their personal information. What are the main principles of GDPR? How is CCPA different from GDPR?

    What data is prohibited by GDPR? ›

    Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex ...

    What personal data is GDPR compliant? ›

    Any information that can provide insight into the physical, physiological, genetic, psychological, economic, cultural or social identity falls under the term personal data. Examples include telephone numbers, IP addresses or the appearance of a person.

    What should be done with personal data that is out of date in GDPR? ›

    What should we do with personal data that we no longer need? You can either erase (delete) it, or anonymise it. You need to remember that there is a significant difference between permanently deleting personal data, and taking it offline.

    Which data subjects does GDPR apply to? ›

    The term 'data subject' refers to any living individual whose personal data is collected, held or processed by an organisation. Personal data is any data that can be used to identify an individual, such as a name, home address or credit card number.

    Is research exempt from GDPR? ›

    Data subjects should have the opportunity to give their consent only to certain areas of research or parts of research projects to the extent allowed by the intended purpose.” The GDPR provides for aresearch exemption in Article 89 GDPR, inter alia for scientific and research purposes.

    Is clinical trial data confidential? ›

    Clinical trial information is protected by the regulations of Good Clinical Practice and any local data privacy laws and regulations that apply. This ensures strict control over who can access the information. Information is kept confidential as far as possible.

    Top Articles
    Latest Posts
    Article information

    Author: Kelle Weber

    Last Updated:

    Views: 6745

    Rating: 4.2 / 5 (53 voted)

    Reviews: 84% of readers found this page helpful

    Author information

    Name: Kelle Weber

    Birthday: 2000-08-05

    Address: 6796 Juan Square, Markfort, MN 58988

    Phone: +8215934114615

    Job: Hospitality Director

    Hobby: tabletop games, Foreign language learning, Leather crafting, Horseback riding, Swimming, Knapping, Handball

    Introduction: My name is Kelle Weber, I am a magnificent, enchanting, fair, joyous, light, determined, joyous person who loves writing and wants to share my knowledge and understanding with you.