Most interventional trials process health data from patients at a scale that makes a data protection impact assessment the default, not the exception. This template follows the minimum content in Article 35(7) of the GDPR and adds the trial-specific questions supervisory authorities and ethics committees ask about.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Need for a DPIA and screening result
Description of the processing
Data flow map attached
Roles: controller, processors, sub-processors
Legal basis and Article 9 condition
Necessity and proportionality
Transfers outside the EEA
Risk assessment
Measures and residual risk
DPO advice and sign-off
What to know before you start
When it is required
Article 35(1) of the GDPR requires a DPIA before processing that is likely to result in a high risk to people's rights and freedoms, particularly when new technologies are used. Article 35(3)(b) names one case outright: large-scale processing of special categories of data, which includes health and genetic data. The Article 29 Working Party guidelines on DPIAs (WP248 rev.01, endorsed by the EDPB) add nine criteria and suggest that processing meeting two or more of them will usually need a DPIA. A typical trial meets several: sensitive data, vulnerable data subjects (patients are named as an example), innovative technology such as wearables or phone-based ePRO, and often matching or combining datasets.
Each national supervisory authority also publishes an Article 35(4) list of processing that always needs a DPIA, and several cover health research. Check the list in each country where you process data. The DPIA must be done before processing starts, the controller must seek the advice of its data protection officer (Article 35(2)), and it should be reviewed when the risk changes (Article 35(11)), for example after a protocol amendment adds a wearable or a new country. If high residual risk remains after mitigation, Article 36 requires prior consultation with the supervisory authority.
One assessment can cover a set of similar processing operations with similar risks, so a sponsor running several trials on the same platform with the same data flows can reuse a core DPIA and add a study-specific annex. For the broader GDPR picture, see GDPR-compliant clinical trial software; for how the US and EU regimes differ, see HIPAA vs GDPR for clinical trial data.
The template
Sections 2, 5, 7 and 8 map to Article 35(7)(a) to (d). The prompts are trial-specific; delete what does not apply.
| Section | What to write | Trial-specific prompts |
|---|---|---|
| 1. Screening | Why a DPIA is required and who carried it out | Which Article 35(3) case or WP248 criteria apply; national list entries |
| 2. Description of processing | Purposes, data categories, data subjects, sources, recipients, retention, systems | Participants, LARs, site staff; eCRF, ePRO, eConsent, wearables, labs, imaging; a data flow diagram from site to analysis |
| 3. Roles | Controller, joint controllers, processors and sub-processors | Sponsor, sites, CRO, EDC and ePRO vendors, central lab; Article 28 contracts in place |
| 4. Legal basis | Article 6 basis and Article 9 condition per purpose | Safety and reliability purposes vs research purposes; national research law |
| 5. Necessity and proportionality | Why each data item is needed; minimisation; storage limitation | Coded IDs instead of names; dates vs ages; CTR archiving period; withdrawal handling |
| 6. Transfers | Any transfer outside the EEA and its mechanism | Hosting region, vendor support access, US sponsor access, adequacy or SCCs |
| 7. Risk assessment | Likelihood and severity of harm to participants | Re-identification, unauthorised access, breach of a phone link, over-collection from devices |
| 8. Measures and residual risk | Technical and organisational measures and the risk left after them | Access control, encryption, audit trail, training, breach procedure; accept, reduce or consult |
| 9. Advice and sign-off | DPO advice, data subjects' views where appropriate, decision and review date | Patient panel input; review trigger tied to protocol amendments |
Roles and legal bases
The sponsor normally decides the purposes and means of processing trial data and is the controller. Sites often act as separate controllers for their own medical records, and some member states treat sponsor and site as joint controllers for trial data, so check national practice. Vendors that process data on the sponsor's instructions, including the EDC provider, are processors and need an Article 28 contract that covers instructions, confidentiality, security, sub-processors, assistance with rights requests and deletion or return at the end.
EDPB Opinion 3/2019 (January 2019) splits trial processing in two. Processing for reliability and safety purposes required by the Clinical Trials Regulation, such as safety reporting and archiving, rests on Article 6(1)(c) legal obligation with Article 9(2)(i). Processing for research activities can rest on Article 6(1)(e) public interest with Article 9(2)(i) or (j), on Article 6(1)(f) legitimate interests with Article 9(2)(j), or on explicit consent, which the EDPB cautions may not be freely given in many trial settings. The EDPB published draft Guidelines 1/2026 on processing for scientific research in April 2026; check whether a final version has been adopted before you sign off.
Two trial rules shape the proportionality section. The Clinical Trials Regulation requires the trial master file to be archived for at least 25 years after the end of the trial, and it says withdrawal of consent does not affect data obtained before withdrawal. Explain both in the DPIA and in the participant information, and link them to how rights requests are handled. The EU CTR clinical trial software page covers the CTR side.
| Role | Contract | |
|---|---|---|
| Sponsor | Controller | Clinical trial agreement |
| Site | Controller or joint controller | Clinical trial agreement |
| CRO | Processor | Article 28 DPA |
| EDC / ePRO vendor | Processor | Article 28 DPA |
| Central lab | Processor | Article 28 DPA |
See role-based access, coded IDs, EU hosting and the audit trail for yourself in a free sandbox. No credit card, and you pay only when you go live.
Risk register
Starting points for section 7 and 8. Rate likelihood and severity for your own study.
Keep the subject identification log at the site; show researchers coded IDs only; avoid full dates of birth and free-text names in eCRFs.
Role-based access by study and site, with researchers and monitors limited to the data their role requires; review access when staff leave.
Field-level audit trail with user, time, old value, new value and reason; no hard deletes of clinical data.
TLS in transit and encryption at rest; two-factor sign-in and session timeouts for staff.
Enable only the device and data the protocol needs, and describe it in a wearable data consent.
Choose EU hosting where possible; map support and sponsor access; use the EU-US Data Privacy Framework for certified recipients or standard contractual clauses with a transfer assessment.
A procedure that meets the 72-hour notification window in Article 33, with vendor notification duties set in the Article 28 contract.
Your EDC vendor
Section 8 of the template depends on facts only your vendors can give you: where data is hosted, who can reach it, how it is encrypted and logged, and which sub-processors are involved. The vendor security questionnaire lists the questions; ask for the Article 28 agreement and sub-processor list at the same time.
For Capture, the answers you can put in the DPIA are these. Capture offers hosting in the EU (Frankfurt) and the USA (N. Virginia), so an EU sponsor can keep study data at rest in the EU. Data is encrypted with AES-256 at rest and TLS in transit. Role-based access control separates site coordinators, who see participant names, from researchers, who see coded IDs, enforced with row-level security in the database. The audit trail is append-only and hash-chained, clinical data is soft-deleted only, staff can use two-factor sign-in, and we review the application against the OWASP Top 10. The security page has the detail. Capture describes itself as GDPR ready, not GDPR certified: compliance depends on how the controller sets up and runs the study.
Not by name, but Article 35(3)(b) requires one for large-scale processing of health data, and most trials meet several other high-risk criteria. Many national supervisory authorities list health research in their Article 35(4) lists. In practice, sponsors treat a DPIA as the default.
The controller is responsible. For trial data that is usually the sponsor, with input from sites and processors. Sites may need their own assessment for processing they control, such as their medical records.
Article 35(7) sets the minimum: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to data subjects, and the measures planned to address those risks.
Usually not. EDPB Opinion 3/2019 says informed consent under the Clinical Trials Regulation is separate from GDPR consent and that GDPR consent may not be freely given in many trial settings. Safety and archiving purposes rest on legal obligation; research purposes on public interest, legitimate interests or, with caution, explicit consent.
Yes, if the processing operations are similar and present similar risks, as Article 35(1) allows. Many sponsors keep a core DPIA for their platform and add a short annex for each study's data, countries and vendors.
No. The DPIA belongs to the controller. Capture can answer your vendor questions about hosting, access control, encryption and the audit trail so you can complete the measures section.
Keep exploring
GDPR-compliant clinical trial software
The controls GDPR asks for, checked against Capture.
HIPAA vs GDPR for clinical trial data
How the US and EU regimes differ.
EU CTR clinical trial software
The Clinical Trials Regulation side.
Role-based access control
Who sees what in a trial database.
Vendor security questionnaire
Questions to send your EDC provider.
Wearable data sharing consent template
Consent wording for device data.
Free sandbox with every feature: EU hosting, role-based access, coded IDs and the audit trail. No credit card, and you pay only when you go live.