PRACTICE NOTES
The General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR)
The General Data Protection Regulation (Regulation (EU) 2016/679, the EU GDPR) has applied across the EEA since 25 May 2018. Organisations in the life sciences gather and/or handle volumes of personal information, including health data, relating to individuals (the ‘data subjects’), notably patients and participants in clinical trials. As such, the relevance of the EU GDPR to life sciences businesses is considerable. This Practice Note outlines elements within the EU GDPR framework that have a direct bearing on life sciences companies and their operations. It is not an exhaustive treatment of the EU GDPR and should be read alongside the following Practice Notes: Data protection principles; Processing personal data—standard of consent; and Processing personal data—obtaining, recording and managing consent. For further detail on how clinical trials interface with data protection rules, see Practice Note:
EU Law