#2026-050CNIL reference methodology for consent-based health research data processing
AI-generated summary for informational purposes only. Not legal advice. See the original source for the authoritative text.
This measure updates France’s CNIL reference methodology MR-001 for personal data processing in health research where participants give consent. It lets eligible research controllers use a simplified compliance declaration instead of seeking individual authorization, but only if their data processing fully follows the updated MR-001 requirements. The update reflects changes in clinical research practices, including heavier use of digital tools and stronger cybersecurity expectations. Health research sponsors, hospitals, research institutions, and vendors will need to check their consent-based research data systems against the new security and quality-control annexes. A multifactor authentication requirement is phased in from 1 January 2027 for relevant digital research tools and systems.
AI-generated summary. May contain errors. Refer to official sources for legal decisions.
Key Changes
- Replaces the 2018 MR-001 methodology with an updated reference framework for consent-based health research data processing
- Keeps the simplified CNIL compliance declaration route for research that fully meets the MR-001 requirements
- Adds updated security and quality-control expectations, including phased multifactor authentication for relevant digital research systems
Obligations
What this law requires
Controllers carrying out consent-based health research within the scope of MR-001 may use the simplified CNIL declaration of conformity only if the personal data processing complies with all MR-001 requirements, including the security annex and quality-control annex.
Controllers whose consent-based health research processing does not meet all applicable MR-001 requirements must seek an individual CNIL authorization instead of relying on a declaration of conformity.
Controllers relying on MR-001 must implement the measures required by the MR-001 security annex for personal data processing systems used in consent-based health research.
Controllers relying on MR-001 must implement the measures required by the MR-001 quality-control annex for consent-based health research data processing.
Relevant digital research tools and systems used for MR-001 health research must apply multifactor authentication from 1 January 2027.