Template · GDPRUpdated October 8, 2026

A GDPR DPIA template for clinical trials, section by section

Most interventional trials process health data from patients at a scale that makes a data protection impact assessment the default, not the exception. This template follows the minimum content in Article 35(7) of the GDPR and adds the trial-specific questions supervisory authorities and ethics committees ask about.

  • Article 35(7) structure
  • EDPB Opinion 3/2019 legal bases
  • Not legal advice

Free sandbox · No credit card · 21 CFR Part 11 aligned

DPIA · demo study DEMO-201
DEMO-201_DPIA_v0.3.docx4/9 complete
  1. 1

    Need for a DPIA and screening result

    Complete
  2. 2

    Description of the processing

    Data flow map attached

    Complete
  3. 3

    Roles: controller, processors, sub-processors

    Complete
  4. 4

    Legal basis and Article 9 condition

    Complete
  5. 5

    Necessity and proportionality

    Draft
  6. 6

    Transfers outside the EEA

    Draft
  7. 7

    Risk assessment

    To do
  8. 8

    Measures and residual risk

    To do
  9. 9

    DPO advice and sign-off

    To do
Demo outline. Article 35 requires the DPIA before processing starts.

What to know before you start

  • Assume you need one. Article 35(3)(b) requires a DPIA for large-scale processing of health data, and most trials also meet other high-risk criteria such as vulnerable data subjects (patients) and new technology.
  • The controller writes it. In most trials that is the sponsor. Processors such as the EDC vendor, CRO and central lab supply information but do not own the assessment.
  • Article 35(7) sets the minimum. A description of the processing, a necessity and proportionality assessment, a risk assessment, and the measures that address the risks.
  • Trial consent is not GDPR consent. EDPB Opinion 3/2019 says informed consent under the Clinical Trials Regulation does not mean consent is your GDPR legal basis.
  • This is a working template, not legal advice. Ask your data protection officer and local counsel, and check your national authority's DPIA list.

When it is required

Why a clinical trial almost always triggers Article 35

Article 35(1) of the GDPR requires a DPIA before processing that is likely to result in a high risk to people's rights and freedoms, particularly when new technologies are used. Article 35(3)(b) names one case outright: large-scale processing of special categories of data, which includes health and genetic data. The Article 29 Working Party guidelines on DPIAs (WP248 rev.01, endorsed by the EDPB) add nine criteria and suggest that processing meeting two or more of them will usually need a DPIA. A typical trial meets several: sensitive data, vulnerable data subjects (patients are named as an example), innovative technology such as wearables or phone-based ePRO, and often matching or combining datasets.

Each national supervisory authority also publishes an Article 35(4) list of processing that always needs a DPIA, and several cover health research. Check the list in each country where you process data. The DPIA must be done before processing starts, the controller must seek the advice of its data protection officer (Article 35(2)), and it should be reviewed when the risk changes (Article 35(11)), for example after a protocol amendment adds a wearable or a new country. If high residual risk remains after mitigation, Article 36 requires prior consultation with the supervisory authority.

One assessment can cover a set of similar processing operations with similar risks, so a sponsor running several trials on the same platform with the same data flows can reuse a core DPIA and add a study-specific annex. For the broader GDPR picture, see GDPR-compliant clinical trial software; for how the US and EU regimes differ, see HIPAA vs GDPR for clinical trial data.

The template

DPIA template for a clinical trial

Sections 2, 5, 7 and 8 map to Article 35(7)(a) to (d). The prompts are trial-specific; delete what does not apply.

SectionWhat to writeTrial-specific prompts
1. ScreeningWhy a DPIA is required and who carried it outWhich Article 35(3) case or WP248 criteria apply; national list entries
2. Description of processingPurposes, data categories, data subjects, sources, recipients, retention, systemsParticipants, LARs, site staff; eCRF, ePRO, eConsent, wearables, labs, imaging; a data flow diagram from site to analysis
3. RolesController, joint controllers, processors and sub-processorsSponsor, sites, CRO, EDC and ePRO vendors, central lab; Article 28 contracts in place
4. Legal basisArticle 6 basis and Article 9 condition per purposeSafety and reliability purposes vs research purposes; national research law
5. Necessity and proportionalityWhy each data item is needed; minimisation; storage limitationCoded IDs instead of names; dates vs ages; CTR archiving period; withdrawal handling
6. TransfersAny transfer outside the EEA and its mechanismHosting region, vendor support access, US sponsor access, adequacy or SCCs
7. Risk assessmentLikelihood and severity of harm to participantsRe-identification, unauthorised access, breach of a phone link, over-collection from devices
8. Measures and residual riskTechnical and organisational measures and the risk left after themAccess control, encryption, audit trail, training, breach procedure; accept, reduce or consult
9. Advice and sign-offDPO advice, data subjects' views where appropriate, decision and review datePatient panel input; review trigger tied to protocol amendments

Roles and legal bases

Who is the controller, and which legal basis applies

The sponsor normally decides the purposes and means of processing trial data and is the controller. Sites often act as separate controllers for their own medical records, and some member states treat sponsor and site as joint controllers for trial data, so check national practice. Vendors that process data on the sponsor's instructions, including the EDC provider, are processors and need an Article 28 contract that covers instructions, confidentiality, security, sub-processors, assistance with rights requests and deletion or return at the end.

EDPB Opinion 3/2019 (January 2019) splits trial processing in two. Processing for reliability and safety purposes required by the Clinical Trials Regulation, such as safety reporting and archiving, rests on Article 6(1)(c) legal obligation with Article 9(2)(i). Processing for research activities can rest on Article 6(1)(e) public interest with Article 9(2)(i) or (j), on Article 6(1)(f) legitimate interests with Article 9(2)(j), or on explicit consent, which the EDPB cautions may not be freely given in many trial settings. The EDPB published draft Guidelines 1/2026 on processing for scientific research in April 2026; check whether a final version has been adopted before you sign off.

Two trial rules shape the proportionality section. The Clinical Trials Regulation requires the trial master file to be archived for at least 25 years after the end of the trial, and it says withdrawal of consent does not affect data obtained before withdrawal. Explain both in the DPIA and in the participant information, and link them to how rights requests are handled. The EU CTR clinical trial software page covers the CTR side.

Typical GDPR roles in a sponsor-led trial
RoleContract
SponsorControllerClinical trial agreement
SiteController or joint controllerClinical trial agreement
CROProcessorArticle 28 DPA
EDC / ePRO vendorProcessorArticle 28 DPA
Central labProcessorArticle 28 DPA
Typical pattern only. National law and the actual facts decide each role.

Check the controls before you write the measures section

See role-based access, coded IDs, EU hosting and the audit trail for yourself in a free sandbox. No credit card, and you pay only when you go live.

Start free in the sandbox

Risk register

Common trial risks and the measures that address them

Starting points for section 7 and 8. Rate likelihood and severity for your own study.

Re-identification from coded data

Keep the subject identification log at the site; show researchers coded IDs only; avoid full dates of birth and free-text names in eCRFs.

Staff seeing more than they need

Role-based access by study and site, with researchers and monitors limited to the data their role requires; review access when staff leave.

Unauthorised changes or silent deletion

Field-level audit trail with user, time, old value, new value and reason; no hard deletes of clinical data.

Interception of data in transit or theft at rest

TLS in transit and encryption at rest; two-factor sign-in and session timeouts for staff.

Over-collection from wearables

Enable only the device and data the protocol needs, and describe it in a wearable data consent.

Transfers outside the EEA

Choose EU hosting where possible; map support and sponsor access; use the EU-US Data Privacy Framework for certified recipients or standard contractual clauses with a transfer assessment.

Breach response

A procedure that meets the 72-hour notification window in Article 33, with vendor notification duties set in the Article 28 contract.

Your EDC vendor

What to ask your data capture provider for the DPIA

Section 8 of the template depends on facts only your vendors can give you: where data is hosted, who can reach it, how it is encrypted and logged, and which sub-processors are involved. The vendor security questionnaire lists the questions; ask for the Article 28 agreement and sub-processor list at the same time.

For Capture, the answers you can put in the DPIA are these. Capture offers hosting in the EU (Frankfurt) and the USA (N. Virginia), so an EU sponsor can keep study data at rest in the EU. Data is encrypted with AES-256 at rest and TLS in transit. Role-based access control separates site coordinators, who see participant names, from researchers, who see coded IDs, enforced with row-level security in the database. The audit trail is append-only and hash-chained, clinical data is soft-deleted only, staff can use two-factor sign-in, and we review the application against the OWASP Top 10. The security page has the detail. Capture describes itself as GDPR ready, not GDPR certified: compliance depends on how the controller sets up and runs the study.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Is a DPIA mandatory for every clinical trial?

Not by name, but Article 35(3)(b) requires one for large-scale processing of health data, and most trials meet several other high-risk criteria. Many national supervisory authorities list health research in their Article 35(4) lists. In practice, sponsors treat a DPIA as the default.

Who is responsible for the DPIA: the sponsor or the site?

The controller is responsible. For trial data that is usually the sponsor, with input from sites and processors. Sites may need their own assessment for processing they control, such as their medical records.

What must a DPIA contain?

Article 35(7) sets the minimum: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to data subjects, and the measures planned to address those risks.

Can we rely on the participant's informed consent as our GDPR legal basis?

Usually not. EDPB Opinion 3/2019 says informed consent under the Clinical Trials Regulation is separate from GDPR consent and that GDPR consent may not be freely given in many trial settings. Safety and archiving purposes rest on legal obligation; research purposes on public interest, legitimate interests or, with caution, explicit consent.

Can one DPIA cover several trials?

Yes, if the processing operations are similar and present similar risks, as Article 35(1) allows. Many sponsors keep a core DPIA for their platform and add a short annex for each study's data, countries and vendors.

Does Capture provide a DPIA for my study?

No. The DPIA belongs to the controller. Capture can answer your vendor questions about hosting, access control, encryption and the audit trail so you can complete the measures section.

Fill in your measures section with controls you have tested

Free sandbox with every feature: EU hosting, role-based access, coded IDs and the audit trail. No credit card, and you pay only when you go live.

Start free in the sandbox