Data Privacy & Tech

#2026-050CNIL reference methodology for consent-based health research data processing

🇫🇷France··Other·Medium Impact·View source ↗

AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.

🇬🇧 English

This measure updates France’s CNIL reference methodology MR-001 for personal data processing in health research where participants give consent. It lets eligible research controllers use a simplified compliance declaration instead of seeking individual authorization, but only if their data processing fully follows the updated MR-001 requirements. The update reflects changes in clinical research practices, including heavier use of digital tools and stronger cybersecurity expectations. Health research sponsors, hospitals, research institutions, and vendors will need to check their consent-based research data systems against the new security and quality-control annexes. A multifactor authentication requirement is phased in from 1 January 2027 for relevant digital research tools and systems.

AI-generated summary. May contain errors. Refer to official sources for legal decisions.

Key Changes

  • Replaces the 2018 MR-001 methodology with an updated reference framework for consent-based health research data processing
  • Keeps the simplified CNIL compliance declaration route for research that fully meets the MR-001 requirements
  • Adds updated security and quality-control expectations, including phased multifactor authentication for relevant digital research systems

Obligations

What this law requires

high

Controllers carrying out consent-based health research within the scope of MR-001 may use the simplified CNIL declaration of conformity only if the personal data processing complies with all MR-001 requirements, including the security annex and quality-control annex.

health research data controllersresearch sponsors
reporting
high

Controllers whose consent-based health research processing does not meet all applicable MR-001 requirements must seek an individual CNIL authorization instead of relying on a declaration of conformity.

health research data controllersresearch sponsors
licensing
high

Controllers relying on MR-001 must implement the measures required by the MR-001 security annex for personal data processing systems used in consent-based health research.

health research data controllersresearch sponsorshospitalsresearch institutions
operational
medium

Controllers relying on MR-001 must implement the measures required by the MR-001 quality-control annex for consent-based health research data processing.

health research data controllersresearch sponsorshospitalsresearch institutions
operational
high

Relevant digital research tools and systems used for MR-001 health research must apply multifactor authentication from 1 January 2027.

health research data controllersresearch sponsorshospitalsresearch institutionsresearch technology vendors
From 1 January 2027
operational

Affected Parties

Health research sponsors and controllersHospitals and clinical research institutions+2 more…

Tags

health research,personal data,CNIL…