Under the French Data Protection Act, unless one of the limited exceptions applies, organizations processing health data must either comply with an applicable CNIL standard or obtain prior authorization from the CNIL. MR‑001 and MR‑003 (hereafter referred to as “the MRs”) are widely relied upon by research stakeholders to streamline compliance:
- MR‑001 applies to research requiring patients’ consent for participation (e.g., most clinical trials);
- MR‑003 covers certain non‑interventional research not based on consent.
The updated versions introduce a number of clarifications and targeted changes, with implications for governance, transparency, and the design of data flows in clinical research. This blog post provides an overview of some of the most significant changes.
I. Additional Guidance From The CNIL and Common Annexes
The CNIL has published annotated versions of MR‑001 and MR‑003, alongside compliance checklists (see here for MR-001 and here for MR-003). It also announced forthcoming practical guidance for each MR. These materials are expected to play a key role in interpreting certain provisions that remain high‑level in the operative text.
In addition, both MRs now include common annexes on security and quality control, reflecting a more standardized approach to technical and organizational requirements.
II. Key Updates Under The Revised MRs
Research Site Not Defined As Processor. Unlike their previous versions, the updated MRs no longer defines the “research site” as a processor. This update may indicate that the CNIL would at least be open to research sites being considered controllers, which would better align with the position taken by many authorities in other EU Member States and in the draft Biotech Act (see our blog post here).
Joint Controllership. The MRs now expressly acknowledge the possibility of joint controllership. They emphasize that joint controllers should allocate their respective obligations in accordance with Art. 26 GDPR and clarify that each joint controller must submit a compliance declaration to the CNIL prior to the study.
Territorial Scope. The revised MRs clarify their territorial scope, confirming that they apply where:
- the controller is established in France or
- all or some of the data subjects reside in France, regardless of where the controller is established.
Express Requirement to Identify GDPR Legal Bases. The updated MRs explicitly require controllers to rely on (i) a legal basis under Article 6 GDPR and (ii) a derogation under Article 9 GDPR for sensitive data (e.g., health data). While the official text of the MRs does not specify which bases should be used, the CNIL considers in its annotated versions of the MRs that:
- the most appropriate legal basis for a private sponsor would be legitimate interests (Article 6(f) GDPR), and
- the most appropriate derogation for sensitive data is scientific research (Article 9(2(j) GDPR).
Limited Facilitation of Decentralized Trials. One of the stated objectives of the MR updates was to address and facilitate the conduct of decentralized studies. Interestingly, the term “research site” now covers not only health institutions but also the patient’s home. At the same time, the MRs seem to prevent professionals involved in the research from carrying out their activities (including follow-up activities) in the patient’s home. This would not necessarily prevent such professionals from relying on connected platforms or apps to follow-up with patients remotely. However, the fact that the revised MRs still do not cover the processing of technical data necessary for decentralized studies (e.g., IT logs) remains a concern. The CNIL’s annotated guidance references sending a message to “activate an IT account to use a web application” as an example of permissible ancillary follow-up activity suggesting a degree of flexibility at the margins.
Data Recipients. The section relating to data recipients has been substantially rewritten under both MRs, further aligning the requirements for sharing study data with the GDPR (in particular, Article 28 GDPR). However, the updated provisions do not directly address practical challenges associated with sharing data with IT providers, leaving some uncertainty for decentralized studies.
Clarified Transparency Obligations. The CNIL has strengthened requirements relating to the information provided to participants, including:
- explicit recognition of electronic delivery of privacy information;
- increased expectations regarding transparency around processors’ access to “administrative data” (e.g., participant’s name, contact details, banking information, full date of birth, information relating to social security, medical insurance or reimbursement). In particular, controllers are expected to specify the purpose of processor access, and the categories of data shared with the processor.
This will likely require more granular disclosures in informed consent forms and supporting documentation.
Data Subject Rights: Limits on Article 11 GDPR. The revised MRs specifically prevent controllers from relying on Article 11 GDPR to restrict the exercise of data subject rights where data subjects provide additional information allowing for their reidentification (in which case Article 11 GDPR does not apply in any case). They also require controllers to “set up a mechanism” to guarantee that information provided by the data subject seeking to exercise their rights could be matched with personal data collected in the context of the study.
International Transfers. The updated MRs largely align the transfer requirements with Chapter V of the GDPR, with slight specificities. For instance, they specifically require that participants be informed inter alia of the countries of destination. In practice, this may require controllers to provide a comprehensive list of recipient jurisdictions, which could prove operationally complex, if at all possible, especially as the recipients may change during and after the trial.
III. Entry Into Force and Transitional Measures
The updated MRs entered into force the day following their publication in the Official Journal, on May 24, 2026. As a result, any study implemented after this date should already comply with the relevant, updated MR. However, the CNIL clarifies that:
- Ongoing processing operations compliant with the previous versions of the MRs may continue under those frameworks;
- Controllers that have already filed compliance declarations under the previous MRs are not required to submit new declarations, provided that future studies comply with the updated MRs.