The CNIL (Commission Nationale de l’Informatique et des Libertés) is the French data protection authority. CNIL has issued various “Reference Methodologies” (Méthodologies de Référence or MRs) which are guidelines/frameworks for compliance with data protection regulations in specific areas e.g., MR-001 (interventional research) and MR-003 (non-interventional research) which cover research involving direct interactions with people (RIPH), or MR-004 for research involving secondary use of existing personal healthcare data i.e., research not involving direct interaction with people (RNIPH).
By declaring conformity to the applicable reference methodology to the CNIL, research sponsors do not need to seek individual authorisation for each research project that involves non-anonymous data, making this an efficient and effective form of self-regulation.
Key features of MR-004 conformity include:
- Data Minimisation: Only collect the data that is strictly necessary for the research or healthcare activity.
- Purpose Limitation: Use the data only for the specified, explicit, and legitimate purposes for which it was collected.
- Consent: Access to and use (re-use) of existing patient health data is subject to informing the affected patients (patient information).
- Security: Guidelines for data storage, encryption, and access control, in line with GDPR requirements.
- Data Subject Rights: Details about how to facilitate data subjects’ rights like access, rectification, deletion, and data portability.
- Data Retention: Sets time limits on how long the data can be stored and provides guidance on secure deletion practices.
- Accountability and Governance: Stresses the importance of record-keeping, conducting impact assessments, and potentially appointing a Data Protection Officer (DPO).
- Data Sharing: Provides guidelines for sharing data with third parties, including cross-border data transfers.
- Legal Compliance: Ensures that the data processing activities are compliant with other relevant laws and ethical considerations.
By adhering to MR-004 or similar CNIL Reference Methodologies (as applicable), healthcare organizations and researchers can use real-world data while fulfilling their legal obligations and ethical responsibilities for data protection (GDPR). Note that these guidelines are subject to change, so it’s crucial to consult the most current version and seek legal advice for complex scenarios.
Share this story...
Lithuania – Leaping into Digital Health Future with RWE and RWD Innovations
RWE 201 - Lithuania – Leaping into Digital Health Future with RWE and RWD Innovations EU Partnership Agreement: https://ec.europa.eu/commission/presscorner/detail/en/ip_22_2547Lithuania is actively implementing Real-World Evidence (RWE) and Real-World Data (RWD) [...]
RWE Guest Post – Does Real-World Evidence Play a Role in G-BA’s Benefit Assessments in Germany?
RWE 201 - RWE Guest Post - Does real-world evidence play a role in G-BA's benefit assessments in Germany? Guest: Anja PownellGerman Market Access – Simplified: https://germanmarketaccesssimplified.com/IntroductionThe German [...]
RWE Guest Post – Germany – From Concept to Evaluation: The Journey of RWE requests by the G-BA
RWE 201 - RWE Guest Post – Germany - From Concept to Evaluation: The Journey of RWE requests by the G-BA Guest: Anja PownellGerman Market Access – Simplified: [...]
Spain – Championing the Ethical and Responsible Use of Real World Data
RWE 201 - Spain – Championing the Ethical and Responsible Use of Real World Data Farmindustria Code of Conduct: https://codigoprotecciondatos.farmaindustria.org/sites/medicamentosinnovadores/docs/PRODF484450.pdfIn 2022, the Spanish Data Protection Agency (AEPD) gave its [...]
EU – RWD/RWE is Embedded into the New EU Medicines Regulations
RWE 201 - EU – RWD/RWE is Embedded into the New EU Medicines Regulations Coming Soon…New EU Medicines Regulations: https://health.ec.europa.eu/medicinal-products/pharmaceutical-strategy-europe/reform-eu-pharmaceutical-legislation_enIn 2023, the European Commission undertook an ambitious overhaul of [...]
EU – EU’s Action Plan for Real-World Data (RWD) & RWE
RWE 201 - EU – EU's Action Plan for Real-World Data (RWD) & RWE The European Union has embarked on an ambitious journey to weave Real World Evidence (RWE) [...]







