Conducting health research in France? What the CNIL’s updated standards mean for you
The French data privacy commission (the “CNIL”) has updated two data processing standards for research involving personal health data in order to respond to major changes in the health research sector ie the increasing digitisation and decentralisation of research, social and environmental considerations at the heart of new methods, stricter testing requirements for health products prior to their launch on the market, and so on.
According to article 9(1) of the GDPR, processing of personal data concerning health is prohibited, subject to the exceptions listed in section 2. Moreover, section 4 of that article provides that Member States may maintain or introduce further conditions, including limitations, with regard in particular to the processing of data concerning health.
In that respect, France’s Data Protection Act (loi « informatique et libertés » du 6 janvier 1978, as amended) provides that processing of personal health data in the healthcare sector may only be conducted in the public interest, pursuant to articles 64 et seq. of the amended 1978 Act, and specifies that ensuring high standards of quality and safety in healthcare, medicines and medical devices constitutes such a public interest objective.
In 2018, the CNIL adopted several standards setting out procedures for the processing of personal health data – in particular “MR 001” and “MR 003” which relate to processing carried out in the context of health research involving human subjects and requiring the data subject’s consent, and to such research where no such consent is required – with a view to striking a balance between data protection and the abovementioned public interest purposes.
Under France’s Data Protection Act, processing of personal health data must comply with one of the CNIL’s standards and that compliance must be declared to the CNIL in advance by the data controller. Otherwise, the data controller is obliged to apply for permission for any data processing operation that does not comply with one of the CNIL’s standards.
Therefore, the CNIL’s data processing standards streamline and simplify the procedures for data controllers by enabling them to process data without waiting for authorisation from the CNIL, provided that they declare compliance with a data processing standards in advance.
In May this year, the CNIL updated its MR 001 and MR 003 data processing standards, along with two annexes, one relating to data security and the other to quality control (adopted by resolutions dated 19 March 2026, entering into force on 23 May 2026). Data controllers that have already filed a compliance declaration under the previous versions of MR 001 or MR 003 are not required to file a new declaration, provided their research complies with the 2026 versions going forward; however, internal documentation (processing register, DPIA) must be updated accordingly.
The MR 001 and MR 003 data processing standards have undergone significant changes since their initial publication in 2018. In particular, they have been redesigned to accommodate research involving joint controllers, as well as cases where processing takes place outside France whilst the data controller is based in France. The list of data that may be processed has also been expanded to include data concerning sexual orientation or any information relating to the individual’s quality of life.
The list of recipients who may access the data has also been updated to include natural and legal persons carrying out administrative tasks related to the research that is being conducted, as well as tasks involving information provision, participant follow-up or quality control.
With regard to research participants’ rights, MR 001 and MR 003 now contemplate situations in which information relating to the processing of their data cannot be provided immediately, particularly in emergencies, thus allowing such information to be given at a later date and also communicated electronically.
Finally, the updated data processing standards also address data processors acting on behalf of data controllers and the possibility for adherence to a supervisory authority’s code of conduct to be used as evidence of the data processor’s implementation of sufficient technical data protection safeguards.
Turning to the accompanying annexes, the quality control annex in particular covers monitoring activities, which aim to verify that the data collected is reliable and is not likely to skew the research results.
For its part, the annex on security lists around forty technical requirements that must be put in place prior to or during processing, for example, encrypting data at rest or in transit using state-of-the-art algorithms, or defining a policy for managing secret keys. The measures described in the annex on security must be implemented for research projects conducted within a data processing standard and commenced on or after 23 May 2026. For research projects already underway on that date, the CNIL has indicated that data controllers should draw up a plan to implement these measures as soon as possible and no later than one year from that date (ie May 2027).