Making sense of GDPR in human trials
GDPR has been in force since May 2018, replacing the EU's 1995 Data Protection Directive. For researchers collecting personal health data, including diagnoses, blood results, and genetic information, understanding what it requires is not optional. The regulation is long and, in places, deliberately principle-based rather than prescriptive, which makes it easy for research teams to either over-interpret it into paralysis or under-interpret it into a compliance gap. The goal here is a working understanding, not a substitute for legal advice on a specific study.
Where GDPR applies
GDPR covers the European Economic Area: all 27 EU member states, plus Liechtenstein, Iceland, and Norway. The UK operates under UK GDPR post-Brexit, which is substantially equivalent. The key threshold is whether you are processing data belonging to EEA residents while they are in the EEA. Non-EEA citizens' data, or data collected about EEA citizens when they are outside the EEA, falls outside the regulation's scope.
What data it covers
Any information that can be linked to an identifiable individual is personal data. Names, identification numbers, location data, email addresses, and phone numbers all qualify. Research settings frequently involve categories that attract additional protections:
- Racial or ethnic origin
- Physical or mental health data
- Genetic and biometric data
- Sexual orientation
- Political opinions, religious beliefs, or trade union membership
For most human trials, health data will be the primary special category in play, and its status as a special category means the bar for lawful processing is higher than for ordinary personal data. A general legal basis for processing is not enough on its own; you generally also need a specific condition under Article 9 that applies to health data directly, such as explicit consent or a defined research exemption available under national law.
Anonymisation and pseudonymisation
Good clinical practice already calls for anonymising data where feasible. Truly anonymised data falls outside GDPR's scope. Pseudonymisation (replacing names with codes or initials) reduces risk but does not remove GDPR obligations entirely, since the key to re-identification still exists somewhere, whether that's a separate lookup table, a study coordinator's memory, or a combination of other variables in the dataset that narrows identity down regardless of whether a name is present.
Controllers and processors
The organisation or sponsor that decides what data to collect and why is the data controller. Any party that handles, stores, or processes data on the controller's behalf is a data processor. In practice, this means your CRO, your eCRF vendor, and any third-party systems that touch participant data may all qualify as processors and must be covered by appropriate agreements. It's worth auditing this list explicitly rather than assuming it's obvious: a wearable device manufacturer, a translation service handling consent forms, and a cloud hosting provider can all quietly become processors without anyone formally documenting the relationship.
Penalties for non-compliance
Fines under GDPR are tiered, and it's worth understanding both tiers rather than just the headline number. Article 83(4) sets a lower tier for less severe, more procedural violations: up to 10 million euros or 2% of global annual turnover, whichever is higher. Article 83(5) sets the higher tier for more serious breaches, including violations of core data protection principles and data subject rights: up to 20 million euros or 4% of global annual turnover, whichever is higher.
| Tier | Applies to | Maximum fine |
|---|---|---|
| Article 83(4) | Procedural violations (e.g. inadequate records, missing impact assessments) | €10 million or 2% of global turnover, whichever is higher |
| Article 83(5) | Substantive violations of core principles or data subject rights | €20 million or 4% of global turnover, whichever is higher |
Beyond financial penalties, the reputational consequences of a breach in a research context are significant, particularly when sensitive health data is involved. A fine is recoverable in a way that participant trust, once damaged, often isn't.
What this means in practice
Document what personal data you collect, why you need it, how it is stored, and how long you will retain it. Ensure that data processing agreements are in place with any third parties who will handle participant data. Appoint a Data Protection Officer if required, and ensure that participants are clearly informed of their rights. For studies involving EEA participants, treating GDPR compliance as a design requirement rather than an afterthought is the approach most likely to avoid problems, and it tends to be considerably cheaper than retrofitting compliance onto a study that's already running.