Compliance · Data protectionUpdated September 28, 2026

HIPAA vs GDPR for clinical trial data

US and EU privacy rules overlap in goals but differ in scope, legal bases and what counts as anonymous. For trials that run on both sides of the Atlantic, the differences change how consent, data and contracts are set up.

  • Scope and legal bases
  • De-identified vs pseudonymised
  • Breach timelines compared

Free sandbox · No credit card · 21 CFR Part 11 aligned

HIPAA vs GDPR at a glance
HIPAAGDPR
Applies toCovered entities and associatesAnyone processing EU data
Health dataPHISpecial category
Coded data still regulated
Breach notice to regulatorUp to 60 days72 hours
Vendor contractBAADPA

Key differences

  • Scope: HIPAA applies to covered entities (most healthcare providers, health plans, clearinghouses) and their business associates. GDPR applies to anyone processing personal data of people in the EU, including sponsors, CROs and vendors.
  • Legal basis: HIPAA uses authorisation (or waivers) for research uses of protected health information. GDPR needs a legal basis under Article 6 plus a condition under Article 9 for health data; consent is only one option.
  • Identifiability: HIPAA-de-identified data (Safe Harbor or Expert Determination) is outside HIPAA. Under GDPR, pseudonymised (coded) data is still personal data; only truly anonymised data falls outside.
  • Breaches: GDPR requires notifying the supervisory authority within 72 hours of awareness of a reportable breach; HIPAA requires notice without unreasonable delay and no later than 60 days for breaches of unsecured PHI.
  • Contracts: HIPAA uses business associate agreements; GDPR uses data processing agreements, and international transfers need an appropriate mechanism.

Side by side

HIPAA and GDPR compared for clinical research

TopicHIPAA (US)GDPR (EU/EEA)
Who must complyCovered entities and their business associatesControllers and processors of personal data of people in the EU
Health data statusProtected health information (PHI)Special category data (Article 9)
Research legal basisIndividual authorisation, or IRB/privacy board waiverArticle 6 basis (e.g. public interest, legitimate interest, consent) plus an Article 9 condition
Coded study dataCan be de-identified if it meets Safe Harbor or Expert DeterminationPseudonymised data remains personal data
Minimum necessary / minimisationMinimum necessary standardData minimisation principle
Participant rightsAccess and accounting of disclosuresAccess, rectification, erasure, restriction, portability, objection (with research exemptions)
Breach notificationWithout unreasonable delay, within 60 daysSupervisory authority within 72 hours; individuals if high risk
Vendor agreementsBusiness associate agreementData processing agreement
International transfersNo specific transfer regimeAdequacy, standard contractual clauses or other mechanisms

A summary for orientation, not legal advice. Research exemptions and national laws vary; involve your privacy counsel.

In practice

What changes when a trial spans both

A US sponsor running EU sites is subject to GDPR for the EU participants' data, even if the sponsor never sees a name. Because coded data is still personal data under GDPR, the sponsor needs a legal basis, a record of processing, data processing agreements with vendors, a data protection impact assessment for most trials, and a transfer mechanism for data leaving the EU. Consent forms must explain all of this in plain language.

In the other direction, EU sponsors with US sites deal with HIPAA through the sites: the covered entity is usually the hospital, and research disclosures of PHI rely on the participant's HIPAA authorisation. The sponsor rarely becomes a business associate simply by receiving research data.

Design choices that help with both

Keep identifiers at the site and show the sponsor coded IDs; collect only what the protocol needs (year of birth instead of full date, for example); choose the hosting region deliberately; and document access, changes and exports. Capture separates participant identities (visible to site coordinators) from coded research data (visible to sponsor roles), enforces it at the database layer, hosts in the EU or US as chosen, and logs every export.

Site coordinator

Jane Peterson

DOB: 04-Mar-1978

Subject 01-004

Sees direct identifiers

Researcher

Subject 01-004

DOB: withheld

Coded ID only

Sees coded ID only

Same record, two roles. Row-level security enforces the split.

Hosting

Choose the region per study

EU (Frankfurt) or US (N. Virginia), chosen at study setup, with AES-256 encryption at rest and TLS in transit. Exports are logged with user, time, filters and row count, and blinded exports stay blinded.

  • Hosting region per study.
  • PII segregation between site and sponsor roles.
  • Append-only export log.
GDPR compliant clinical trial software
Data residency
EU

EU (Frankfurt)

Default for EU-sponsored studies

US

US (N. Virginia)

Default for US-sponsored studies

AES-256 at rest TLS/SSL in transit Chosen at study setup

See what each role can see

Compare the coordinator and sponsor views in the free sandbox.

See the controls in a sandbox

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Does a trial need a data protection officer?

GDPR requires one when core activities involve large-scale processing of health data, which covers many sponsors and research institutions. Check with your privacy team.

Does HIPAA apply to a European site?

HIPAA applies to US covered entities and their business associates. A European hospital is generally not covered by HIPAA, but its data is covered by GDPR.

Does GDPR apply to US sponsors?

Yes, for personal data of participants in the EU, including coded data the sponsor receives.

Is pseudonymised data personal data?

Under GDPR, yes. Only anonymised data that cannot reasonably be re-identified falls outside GDPR.

What is the breach notification deadline?

GDPR: 72 hours to the supervisory authority after becoming aware of a reportable breach. HIPAA: without unreasonable delay and within 60 days for breaches of unsecured PHI.

Is consent the only GDPR basis for research?

No. Research is often based on public interest or legitimate interest, with a separate Article 9 condition. Clinical trial consent under medicines law is a different requirement from GDPR consent.

Is this legal advice?

No. It is an orientation summary. Involve privacy counsel for your study.

Privacy by design, on both sides of the Atlantic

EU or US hosting, coded research data. Free sandbox.

See the controls in a sandbox