#2026-049CNIL Approves Security Annex for Health Research Data Processing Methods
AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.
This measure approves a common security annex for CNIL reference methods used in health research involving personal data. It gives research sponsors and data controllers a shared baseline for protecting sensitive health data, including governance, privacy-by-design, risk assessment, data minimisation and pseudonymisation. Health research organisations should treat the annex as the current security benchmark when using CNIL reference methodologies that refer to it. They may also need additional project-specific measures depending on the research design, systems used and risks to participants.
AI-generated summary. May contain errors. Refer to official sources for legal decisions.
Key Changes
- Approves a shared CNIL security annex for health research data processing under reference methodologies
- Sets baseline security expectations such as governance, privacy-by-design, risk assessment, minimisation and pseudonymisation
- Allows reference methodologies to add specific security measures on top of the common annex
Obligations
What this law requires
For health research processing carried out under CNIL reference methodologies that expressly refer to the security annex, apply the security requirements in that annex to the processing.
Identify the competent data protection and IT security actors for the research project, including the data protection officer and the information systems security officer.
Ensure that the health research project complies with the organisation’s general data protection policy.
Integrate data protection and security measures from the design phase of the health research project.
Involve competent data protection and IT security actors in the design of research protocols.