Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Research Sites Are Just Processors, Right?Data Privacy
5 min readFor Compliance Officers

Research Sites Are Just Processors, Right?

If you're managing health research under CNIL's Reference Methodologies, you've likely operated on assumptions about data roles, transfer requirements, and transparency obligations that no longer apply. The updated MR-001 and MR-003, effective May 24, 2026, have dismantled several myths that shaped how French health research projects allocated GDPR responsibilities.

These myths persist due to previous framework ambiguities and the convenience of copying past compliance declarations. However, CNIL's revisions require a closer examination of who controls what, and how your research sites, sponsors, and IT vendors fit into the GDPR's accountability structure.

Myth 1: Research Sites Are Always Processors

Reality: The updated methodologies removed the definition of research sites as processors. This change indicates CNIL's openness to classifying research sites as controllers, aligning France with other EU Member States.

If your research site makes decisions about participant data usage, retention, or secondary analyses, it's likely a controller under Article 4(7) of the General Data Protection Regulation. The sponsor initiating the study doesn't automatically make the site a processor.

Practical implication: Your data processing agreements may be incorrect. If a site is a controller, you need a joint controller arrangement under Article 26 GDPR, not a processor agreement under Article 28. This requires transparent allocation of obligations, a public summary of responsibilities, and separate compliance declarations to CNIL for each joint controller before the study begins.

Myth 2: You Can Avoid Naming a GDPR Legal Basis

Reality: The updated methodologies require identifying both an Article 6 legal basis and an Article 9(2) derogation for processing health data. This is now mandatory.

CNIL's guidance suggests legitimate interests (Article 6(1)(f)) for private sponsors and the scientific research derogation (Article 9(2)(j)) for sensitive data. You must document your assessment. If relying on legitimate interests, conduct a balancing test showing why your research purposes outweigh participants' privacy expectations, and why consent or another basis won't work.

Don't assume the MR compliance declaration substitutes for this analysis. The methodologies streamline authorization but don't exempt you from the GDPR's foundational requirements. Your records of processing activities should explicitly name the bases you're relying on and why they're appropriate for each processing operation.

Myth 3: Decentralized Trials Are Now Fully Supported

Reality: The updated methodologies expand the definition of "research site" to include patients' homes but don't solve the operational challenges of decentralized studies. Professionals involved in research still can't carry out activities, including follow-up, in patients' homes under the methodologies.

You can use connected platforms or apps for remote follow-up, and CNIL's guidance mentions activating an IT account for a web application as permissible ancillary activity. However, the methodologies don't cover the processing of technical data necessary for decentralized studies, such as IT logs or geolocation data.

If your decentralized trial relies on this technical data, you're outside the methodologies' safe harbor. You'll need to seek individual CNIL authorization or find another compliance path. This gap is significant because decentralized trials generate exactly the kind of granular technical data that the methodologies were supposed to facilitate.

Myth 4: Transparency Obligations Haven't Changed Much

Reality: The updated methodologies impose stricter disclosure requirements, particularly around processors' access to administrative data. You must specify the purpose of processor access and the categories of data shared, not just list processors generically.

Administrative data includes participants' names, contact details, banking information, full dates of birth, and social security or insurance information. If your CRO or IT vendor accesses this data for trial management, randomization, or payment processing, you must explain why in your informed consent forms and privacy notices.

The methodologies also recognize electronic delivery of privacy information. For international transfers, you must inform participants of the destination countries. If your study involves cloud infrastructure across multiple jurisdictions or a global CRO with regional subprocessors, providing a comprehensive list of recipient countries is complex. If recipients change during or after the trial, you may need to update disclosures mid-study.

Myth 5: Article 11 GDPR Lets You Ignore Rights Requests for Pseudonymized Data

Reality: The updated methodologies prevent you from relying on Article 11 GDPR to restrict data subject rights when participants provide additional information that allows reidentification. Article 11 only applies when you genuinely cannot identify the data subject. If a participant gives you their trial ID, date of birth, or site location, and you can match that to study records, Article 11 doesn't shield you.

The methodologies require you to "set up a mechanism" to ensure that information provided by a data subject can be matched with personal data collected in the study. This means you need a documented process for handling Data Subject Access Requests, rectification requests, and erasure requests even when data is pseudonymized.

Consider a participant who contacts you two years post-trial asking what data you still hold. If your pseudonymization key is archived and accessible, you need to retrieve it, match the request to the participant's records, and respond within one month. If you've destroyed the key and truly cannot reidentify the data, document that fact and explain it to the participant.

What to Do Instead

Start by auditing your current studies against the updated methodologies. For each active study that relied on the previous versions, confirm whether you can continue under the transitional measures or need to file new compliance declarations. CNIL allows ongoing processing to continue under the old frameworks, but any new study must comply with the updated methodologies.

Next, revisit your controller-processor classifications. If you've been treating research sites as processors by default, assess whether that's still defensible. Look at who decides retention periods, who determines secondary use, and who responds to data subject requests. If the site makes those calls, draft a joint controller arrangement and allocate obligations transparently.

Update your informed consent templates to address the new transparency requirements. Specify which processors access administrative data and why. List destination countries for international transfers, or at least the categories of countries if exact lists aren't feasible. And build a mechanism for matching data subject requests to pseudonymized records, whether that's a secure key management process or a documented procedure for handling requests when reidentification isn't possible.

Finally, if you're planning decentralized trials, recognize that the methodologies' coverage is limited. You may need individual CNIL authorization for technical data processing, or you may need to structure the trial so that technical data is processed by a separate controller under a different legal basis. Either way, don't assume the methodologies give you blanket coverage just because they mention patients' homes.

Promotional banner for the Penetration Report Template Kit

You Might Also Like