US and EU privacy rules overlap in goals but differ in scope, legal bases and what counts as anonymous. For trials that run on both sides of the Atlantic, the differences change how consent, data and contracts are set up.
Free sandbox · No credit card · 21 CFR Part 11 aligned
| HIPAA | GDPR | |
|---|---|---|
| Applies to | Covered entities and associates | Anyone processing EU data |
| Health data | PHI | Special category |
| Coded data still regulated | ||
| Breach notice to regulator | Up to 60 days | 72 hours |
| Vendor contract | BAA | DPA |
Key differences
Side by side
| Topic | HIPAA (US) | GDPR (EU/EEA) |
|---|---|---|
| Who must comply | Covered entities and their business associates | Controllers and processors of personal data of people in the EU |
| Health data status | Protected health information (PHI) | Special category data (Article 9) |
| Research legal basis | Individual authorisation, or IRB/privacy board waiver | Article 6 basis (e.g. public interest, legitimate interest, consent) plus an Article 9 condition |
| Coded study data | Can be de-identified if it meets Safe Harbor or Expert Determination | Pseudonymised data remains personal data |
| Minimum necessary / minimisation | Minimum necessary standard | Data minimisation principle |
| Participant rights | Access and accounting of disclosures | Access, rectification, erasure, restriction, portability, objection (with research exemptions) |
| Breach notification | Without unreasonable delay, within 60 days | Supervisory authority within 72 hours; individuals if high risk |
| Vendor agreements | Business associate agreement | Data processing agreement |
| International transfers | No specific transfer regime | Adequacy, standard contractual clauses or other mechanisms |
A summary for orientation, not legal advice. Research exemptions and national laws vary; involve your privacy counsel.
In practice
A US sponsor running EU sites is subject to GDPR for the EU participants' data, even if the sponsor never sees a name. Because coded data is still personal data under GDPR, the sponsor needs a legal basis, a record of processing, data processing agreements with vendors, a data protection impact assessment for most trials, and a transfer mechanism for data leaving the EU. Consent forms must explain all of this in plain language.
In the other direction, EU sponsors with US sites deal with HIPAA through the sites: the covered entity is usually the hospital, and research disclosures of PHI rely on the participant's HIPAA authorisation. The sponsor rarely becomes a business associate simply by receiving research data.
Keep identifiers at the site and show the sponsor coded IDs; collect only what the protocol needs (year of birth instead of full date, for example); choose the hosting region deliberately; and document access, changes and exports. Capture separates participant identities (visible to site coordinators) from coded research data (visible to sponsor roles), enforces it at the database layer, hosts in the EU or US as chosen, and logs every export.
Site coordinator
Jane Peterson
DOB: 04-Mar-1978
Subject 01-004
Sees direct identifiersResearcher
Subject 01-004
DOB: withheld
Coded ID only
Sees coded ID onlySame record, two roles. Row-level security enforces the split.
Hosting
EU (Frankfurt) or US (N. Virginia), chosen at study setup, with AES-256 encryption at rest and TLS in transit. Exports are logged with user, time, filters and row count, and blinded exports stay blinded.
EU (Frankfurt)
Default for EU-sponsored studies
US (N. Virginia)
Default for US-sponsored studies
Compare the coordinator and sponsor views in the free sandbox.
GDPR requires one when core activities involve large-scale processing of health data, which covers many sponsors and research institutions. Check with your privacy team.
HIPAA applies to US covered entities and their business associates. A European hospital is generally not covered by HIPAA, but its data is covered by GDPR.
Yes, for personal data of participants in the EU, including coded data the sponsor receives.
Under GDPR, yes. Only anonymised data that cannot reasonably be re-identified falls outside GDPR.
GDPR: 72 hours to the supervisory authority after becoming aware of a reportable breach. HIPAA: without unreasonable delay and within 60 days for breaches of unsecured PHI.
No. Research is often based on public interest or legitimate interest, with a separate Article 9 condition. Clinical trial consent under medicines law is a different requirement from GDPR consent.
No. It is an orientation summary. Involve privacy counsel for your study.
Keep exploring
GDPR compliant trial software
EU data protection in depth.
HIPAA compliant trial software
US health data protection.
Vendor security questionnaire
Vendor due diligence.
Demographics eCRF template
Data minimisation in practice.
Clinical trial software UK
UK GDPR.
Clinical trial software Ireland
GDPR plus national rules.
EU or US hosting, coded research data. Free sandbox.