On May 26, 2026, the French data protection authority (“CNIL”) published updated versions of its Reference Methodology 001 (“MR-001”, available here in French) and Reference Methodology 003 (“MR-003”, available here in French), two key frameworks governing the processing of personal data in the context of health research.

Under the French Data Protection Act, unless one of the limited exceptions applies, organizations processing health data must either comply with an applicable CNIL standard or obtain prior authorization from the CNIL. MR‑001 and MR‑003 (hereafter referred to as “the MRs”) are widely relied upon by research stakeholders to streamline compliance:

  • MR‑001 applies to research requiring patients’ consent for participation (e.g., most clinical trials);
  • MR‑003 covers certain non‑interventional research not based on consent.

The updated versions introduce a number of clarifications and targeted changes, with implications for governance, transparency, and the design of data flows in clinical research. This blog post provides an overview of some of the most significant changes.

I. Additional Guidance From The CNIL and Common Annexes

The CNIL has published annotated versions of MR‑001 and MR‑003, alongside compliance checklists (see here for MR-001 and here for MR-003). It also announced forthcoming practical guidance for each MR. These materials are expected to play a key role in interpreting certain provisions that remain high‑level in the operative text.

In addition, both MRs now include common annexes on security and quality control, reflecting a more standardized approach to technical and organizational requirements.

II. Key Updates Under The Revised MRs

Research Site Not Defined As Processor. Unlike their previous versions, the updated MRs no longer defines the “research site” as a processor. This update may indicate that the CNIL would at least be open to research sites being considered controllers, which would better align with the position taken by many authorities in other EU Member States and in the draft Biotech Act (see our blog post here).

Joint Controllership. The MRs now expressly acknowledge the possibility of joint controllership. They emphasize that joint controllers should allocate their respective obligations in accordance with Art. 26 GDPR and clarify that each joint controller must submit a compliance declaration to the CNIL prior to the study.

Territorial Scope. The revised MRs clarify their territorial scope, confirming that they apply where:

  • the controller is established in France or
  • all or some of the data subjects reside in France, regardless of where the controller is established.

Limited Facilitation of Decentralized Trials. One of the stated objectives of the MR updates was to address and facilitate the conduct of decentralized studies. Interestingly, the term “research site” now covers not only health institutions but also the patient’s home. At the same time, the MRs seem to prevent professionals involved in the research from carrying out their activities (including follow-up activities) in the patient’s home. This would not necessarily prevent such professionals from relying on connected platforms or apps to follow-up with patients remotely. However, the fact that the revised MRs still do not cover the processing of technical data necessary for decentralized studies (e.g., IT logs) remains a concern. The CNIL’s annotated guidance references sending a message to “activate an IT account to use a web application” as an example of permissible ancillary follow-up activity suggesting a degree of flexibility at the margins.

Data Recipients. The section relating to data recipients has been substantially rewritten under both MRs, further aligning the requirements for sharing study data with the GDPR (in particular, Article 28 GDPR). However, the updated provisions do not directly address practical challenges associated with sharing data with IT providers, leaving some uncertainty for decentralized studies.

Clarified Transparency Obligations. The CNIL has strengthened requirements relating to the information provided to participants, including:

  • explicit recognition of electronic delivery of privacy information;
  • increased expectations regarding transparency around processors’ access to “administrative data” (e.g., participant’s name, contact details, banking information, full date of birth, information relating to social security, medical insurance or reimbursement). In particular, controllers are expected to specify the purpose of processor access, and the categories of data shared with the processor.

This will likely require more granular disclosures in informed consent forms and supporting documentation.

Data Subject Rights: Limits on Article 11 GDPR. The revised MRs specifically prevent controllers from relying on Article 11 GDPR to restrict the exercise of data subject rights where data subjects provide additional information allowing for their reidentification (in which case Article 11 GDPR does not apply in any case). They also require controllers to “set up a mechanism” to guarantee that information provided by the data subject seeking to exercise their rights could be matched with personal data collected in the context of the study.

International Transfers. The updated MRs largely align the transfer requirements with Chapter V of the GDPR, with slight specificities. For instance, they specifically require that participants be informed inter alia of the countries of destination. In practice, this may require controllers to provide a comprehensive list of recipient jurisdictions, which could prove operationally complex, if at all possible, especially as the recipients may change during and after the trial.

III. Entry Into Force and Transitional Measures

The updated MRs entered into force the day following their publication in the Official Journal, on May 24, 2026. As a result, any study implemented after this date should already comply with the relevant, updated MR. However, the CNIL clarifies that:

  • Ongoing processing operations compliant with the previous versions of the MRs may continue under those frameworks;
  • Controllers that have already filed compliance declarations under the previous MRs are not required to submit new declarations, provided that future studies comply with the updated MRs.
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Kristof Van Quathem Kristof Van Quathem

Kristof Van Quathem advises clients on information technology matters and policy, with a focus on data protection, cybercrime and various EU data-related initiatives, such as the Data Act, the AI Act and EHDS.

Kristof has been specializing in this area for over twenty…

Kristof Van Quathem advises clients on information technology matters and policy, with a focus on data protection, cybercrime and various EU data-related initiatives, such as the Data Act, the AI Act and EHDS.

Kristof has been specializing in this area for over twenty years and developed particular experience in the life science and information technology sectors. He counsels clients on government affairs strategies concerning EU lawmaking and their compliance with applicable regulatory frameworks, and has represented clients in non-contentious and contentious matters before data protection authorities, national courts and the Court of the Justice of the EU.

Kristof is admitted to practice in Belgium.

Photo of Alix Bertrand Alix Bertrand

Alix advises clients on EU data protection and technology law, with a particular focus on French privacy and data protection requirements. She regularly assists clients in relation to international data transfers, direct marketing rules as well as IT and data protection contracts. Alix…

Alix advises clients on EU data protection and technology law, with a particular focus on French privacy and data protection requirements. She regularly assists clients in relation to international data transfers, direct marketing rules as well as IT and data protection contracts. Alix is a member of the Paris and Brussels Bars.