Data Privacy & Tech

#2026-051Updated CNIL Reference Methodology for Health Research Without Participant Consent

🇫🇷France··Other·Medium Impact·View source ↗

AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.

🇬🇧 English

This measure updates France’s CNIL reference framework for certain health research projects that process personal data without needing the person’s consent to participate. Research sponsors and data controllers can use a simplified compliance declaration if their data processing meets the updated MR-003 requirements, instead of applying for a separate CNIL authorization. The update reflects changes in health research practice, especially digital tools, cybersecurity risks, and modern IT security standards. Organizations running covered studies will need to check their procedures against the new MR-003, including the security and quality-control annexes. The previous 2018 version is repealed, and most of the new framework applies from publication, with a delayed start for the multifactor authentication requirement.

AI-generated summary. May contain errors. Refer to official sources for legal decisions.

Key Changes

  • Replaces the 2018 MR-003 reference methodology for health research data processing without participant consent
  • Allows covered health research data processing to proceed through a CNIL compliance declaration when all MR-003 conditions are met
  • Adds updated security and quality-control expectations, including a delayed multifactor authentication requirement

Obligations

What this law requires

high

Before relying on the MR-003 simplified compliance declaration, the data controller for covered health research must ensure the personal data processing complies with all MR-003 requirements, including the security annex and the quality-control annex.

health research data controllershealth research sponsors
From publication, except requirements with delayed application such as multifactor authentication
operational
high

If a health research processing activity does not meet all requirements of the applicable CNIL reference methodology, the controller must submit an authorization request to the CNIL instead of filing a declaration of conformity.

health research data controllers
licensing
medium

Organizations conducting covered health research without obtaining participant consent for research participation must align their data-processing procedures with the updated MR-003 framework rather than the repealed 2018 MR-003 methodology.

health research sponsorshealth research data controllers
From entry into application of the updated MR-003
operational
high

Covered health research processing must implement the updated MR-003 security measures, reflecting current cybersecurity risks and IT security standards, including the delayed multifactor authentication requirement where applicable.

health research data controllershealth research sponsors
Multifactor authentication applies after the delayed start specified by the measure
operational

Affected Parties

Health research sponsorsClinical research organizations+3 more…

Tags

health data,CNIL,GDPR…