GDPR sets rules for how you collect, secure and limit access to personal data. It is not a badge a vendor can sell you. Capture hosts EU studies in Frankfurt, encrypts data at rest and in transit, and segregates identifiers by role, so you can check the specific controls GDPR asks for instead of taking a claim on faith.
Free sandbox · No credit card · 21 CFR Part 11 aligned
EU (Frankfurt)
Default for EU-sponsored studies
US (N. Virginia)
Default for US-sponsored studies
2
hosting regions: EU (Frankfurt) and US (N. Virginia)
AES-256
encryption at rest, TLS/SSL in transit
3
access roles, with PII segregated from coded data
Row-level
security enforced at the database layer
The regulation
GDPR gives participants rights over their own data and asks you to justify why you collect it, secure it, and limit who can see it. No agency certifies software as GDPR compliant. What you can check is whether a system gives you the specific controls GDPR asks for: a lawful, secure place to store the data and limits on who can view it.
Study owner
Builds and configures the study
Principal investigator
Oversees the site, signs off the casebook
Sub-investigator
Enters and signs clinical data
Study coordinator
Screens subjects, enters visit data
Monitor (CRA)
Verifies data, raises queries
Data manager
Reviews, freezes and locks data
Participant
Completes their own questionnaires
The checklist
Walk any vendor, Capture included, through this list.
Pick your data region, Frankfurt or N. Virginia, when you set up the study.
AES-256 at rest, TLS/SSL on every connection.
Site coordinators see names for their site, researchers see only a coded ID.
Enforced at the database layer, not just hidden in the interface.
Your data, your export, not locked to one vendor’s format.
CSV or Excel export, filtered to a single participant.
Access control
A GDPR review usually asks who can see a participant’s name alongside their clinical data. Capture answers with roles: site coordinators see participant names for their own site, researchers see the same records under a coded ID, and row-level security enforces that split at the database layer, not just in what the screen shows.
Site coordinator
Jane Peterson
DOB: 04-Mar-1978
Subject 01-004
Sees direct identifiersResearcher
Subject 01-004
DOB: withheld
Coded ID only
Sees coded ID onlySame record, two roles. Row-level security enforces the split.
The difference
Before you switch
EU/US hosting, encryption and role-based access are part of every plan, including the free sandbox.
GDPR is shared: Capture provides the controls, you still document your own basis for processing.
You pick a hosting region during study setup. No separate infrastructure to provision.
Bring an existing study in the same way, whichever system you are switching from.
Email support, typically under 24 hours, plus documentation for your own assessment on Enterprise.
Free sandbox with every feature. No credit card, no sales call.
Capture provides the specific controls GDPR asks for: EU hosting in Frankfurt, AES-256 encryption at rest, TLS/SSL in transit, and role-based access that separates personal data from coded clinical data. GDPR compliance also depends on how you configure and use the system, so pair this with your own data protection assessment.
You choose at study setup: the EU region is in Frankfurt, and a US region is available in N. Virginia.
Site coordinators see participant names for their own site. Researchers see the same records under a coded ID only. Row-level security enforces that split, not just the interface.
Yes. CSV and Excel exports can be filtered to one participant, one site, or a date range.
Yes. Hosting region and access roles are set up the same way whichever system you are switching from. See our REDCap migration guide for a step-by-step example.
Yes. The free sandbox includes full hosting, encryption and role-based access with sample data, no credit card required.
Keep exploring
HIPAA-compliant clinical trial software
The same safeguards, framed for US protected health information.
EU CTR & CTIS guide
What changed for EU-wide trial submissions and where Capture fits.
21 CFR Part 11 compliance checklist
The audit trail and e-signature side of the compliance picture.
Audit trail software
How field-level logging works on every change.
eConsent software
Where signed consent and PII controls meet.
Migrate from REDCap
Bring an existing study in without losing your GDPR setup.
Free sandbox with every feature. No credit card, no sales call.