Is it a good idea to appoint your contract research organization as your data protection representative or data protection officer?

There is sometimes confusion between the role of the Data Protection Representative, the Data Protection Officer and the Legal Representative of the Sponsor in the Union. It may be worth recalling that these are three different functions, even if they may all be encountered in the context of clinical studies.

The designation of a Data Protection Representative is an obligation that comes from the General Data Protection Regulation,[1]  while the designation of a Legal Representative of the Sponsor in the Union is an obligation imposed by the Clinical Trial Regulation.[2] The Data Protection Officer is also a GDPR function, but it has a different purpose: the DPO does not represent the sponsor in the Union but advises and monitors the organisation’s data protection compliance.[3]

Non-EU-based controllers or processors can be subject to the GDPR. Depending on their situation, some of them may have to designate a Data Protection Representative (“DPR”)[4] in the Union and some may also have to appoint a Data Protection Officer (“DPO”). Failure to comply with these obligations, where applicable, may constitute a breach of the GDPR.

Within the context of clinical trials, Sponsors occasionally consider designating their Contract Research Organization (“CRO”) as DPR or DPO. At first sight, this may seem convenient, as the CRO already knows the study, the sites, the vendors and the operational set-up. However, convenience alone is not a valid criterion for such a designation. These GDPR roles require independence, availability, appropriate expertise and, above all, the absence of conflicts of interest.

The purpose of this article is therefore to explain the difference between the DPR and the DPO, and why appointing the operational CRO to one of these roles may not be advisable.

⚖️ Data Protection Representative and Data Protection Officer: two different roles, two different safeguards

Before deciding whether a CRO can serve as DPR or DPO, it is important to understand the difference between these two roles under the GDPR. Although both may involve exchanges with supervisory authorities and data subjects, they serve different purposes.

The Data Protection Representative is mainly an external-facing function. It is a natural or legal person established in the Union, appointed by certain non-EU controllers or processors that are subject to the GDPR but do not have an establishment in the Union. The DPR acts as a local point of contact for supervisory authorities and data subjects.[5]

The Data Protection Officer, by contrast, is an independent compliance function. The DPO is not appointed to represent a non-EU controller or processor in the Union, but to advise the organisation, monitor GDPR compliance and cooperate with supervisory authorities.

🎯 When is the role relevant?

A DPR must be appointed where a non-EU controller or processor is subject to the GDPR because it offers goods or services to individuals in the Union or monitors their behaviour, as far as that behaviour takes place in the Union, unless an exemption applies.

In the context of clinical studies, this may be relevant for a non-EU Sponsor that has no establishment in the Union but is nevertheless subject to the GDPR because of the way the study is conducted or because of the individuals concerned.

The appointment of a DPO follows a different logic. A DPO must be appointed in certain cases, including where the core activities of the controller or processor consist of processing operations which require regular and systematic monitoring of individuals on a large scale, or where the core activities consist of large-scale processing of special categories of data,[6] such as health data. [7] In other cases, an organisation may also voluntarily appoint a DPO.

The DPO may be a staff member of the controller or processor, or may perform the role on the basis of a service contract. (e.g., external DPO).

📌 What is the purpose of these roles?

The DPR is designated to represent a non-EU controller or processor in the Union with regard to its obligations under the GDPR. Its role is to ensure that supervisory authorities and data subjects have a contact point in the Union.

The DPO is appointed for another purpose. The DPO informs, advises and monitors the organisation’s data protection compliance. The DPO does not replace the controller or processor and does not become responsible for their GDPR obligations. Instead, the DPO acts as an independent data protection function within or for the organisation.

📋 What are their main tasks?

The DPR must be formally designated by the controller or processor, through a written mandate allowing the representative to act on behalf of the controller or processor with regard to its GDPR obligations.[8] In practice, this means that the agreement should clearly describe the respective obligations of the representative and of the controller or processor. An oral appointment is therefore not sufficient.

The DPR acts as a point of contact in the Union for data subjects and supervisory authorities. It does not replace the controller or processor and is not itself responsible for handling data subjects’ requests, but it must facilitate communication with the controller or processor it represents. The same applies in relation to supervisory authorities: where a matter concerns the GDPR obligations of the non-EU controller or processor, the authority may contact the DPR to facilitate informational or procedural exchanges.

Additionally, the DPR also has a role in relation to the record of processing activities. The non-EU controller or processor must make the necessary accurate and up-to-date information available to the representative, so that the record can be maintained and made available where required.

The DPO’s tasks include informing and advising the organisation and its employees on data protection compliance, monitoring compliance with the GDPR and internal data protection policies, providing advice where requested in relation to data protection impact assessments, cooperating with supervisory authorities, and acting as a contact point for supervisory authorities.[9]

The DPO must be involved, properly and in a timely manner, in matters relating to personal data protection. In practice, this means that the DPO may be consulted on study set-up, data flows, vendor management, data protection notices, DPIAs, data breach assessments, data subject requests or exchanges with supervisory authorities.

Data subjects may also contact the DPO with regard to any issue relating to the processing of their personal data or the exercise of their rights. The DPO is therefore often a visible and accessible contact point for individuals, even though the DPO does not replace the controller or processor in their GDPR responsibilities.

🚩 Why can the appointment of the CRO be problematic?

Although the DPR and the DPO are different roles, they both raise conflict-of-interest concerns where the proposed appointee is also the operational CRO for the same Sponsor or the same study.

For the DPR, the concern is linked to its authority-facing role and to the information it may receive. As point of contact for supervisory authorities, the DPR may have access to internal compliance documents of the controller or processor it represents. These may include records of processing activities, training materials, gap analyses, board memoranda, data transfer clauses, contracts with subcontractors, assessments of service providers or other documents relating to the internal implementation of the GDPR.

Such information is confidential and may go beyond what the CRO would normally need to receive for the performance of its operational study services. It is therefore not recommended to mix the role of DPR with operational clinical trial responsibilities performed by the same CRO.

The issue is not only practical. Recital 80 of the GDPR also clarifies that the DPR may be subject to enforcement proceedings in the event of non-compliance by the controller or processor. The purpose of the representative mechanism is to ensure that supervisory authorities have an effective point of action in the Union in relation to non-EU controllers or processors.

This creates a possible conflict of obligations and interests where the representative is also a processor or operational service provider involved in the same processing activities. For this reason, the European Data Protection Board does not consider the function of representative in the Union to be compatible with the role of data processor for the same controller.[10]

For the DPO, the concern is different but equally important. It is linked to independence.

The DPO must be able to perform their tasks independently. This means that the organisation may not give instructions to the DPO regarding the performance of their DPO duties. The DPO must not be told how to deal with a matter, what the result of their advice should be, how to investigate a complaint, whether a supervisory authority should be consulted, or which interpretation of data protection law should be adopted.

The DPO must also not be dismissed or penalised for performing their tasks. In addition, the organisation must ensure that any other tasks or duties performed by the DPO do not result in a conflict of interests.

This independence requirement is key when assessing whether a CRO can act as DPO for a Sponsor. In many clinical studies, the CRO is involved in operational study management, monitoring, site coordination, vendor oversight, data handling, safety support, clinical systems management or other processing activities performed on behalf of the Sponsor.

If the same CRO is appointed as DPO, it may be required to independently assess, monitor or advise on processing activities that it helped design, implement or operate. In practice, this may create a self-review situation. For example, the DPO may need to advise the Sponsor on whether the CRO’s access rights, security measures, subcontracting structure, retention practices or incident management process are compliant. If the CRO is also acting as DPO, it would effectively be asked to review and potentially criticise its own services.

This is difficult to reconcile with the DPO’s requirement to act independently and without a conflict of interests. The DPO must remain free to provide independent advice, including where that advice may be commercially inconvenient for the organisation or for another service provider involved in the study.

🤝 Choosing the right service provider

Various entities can act as Data Protection Representative or Data Protection Officer, but it is important to choose the right service provider for the right role.

The DPR should not be treated as a simple administrative contact point in the Union. The DPR must have appropriate knowledge of the GDPR, including the rights of data subjects and the powers of supervisory authorities. Where the mandate requires the representative to support other compliance-related actions, knowledge of Member State data protection laws may also be necessary.

Availability is also essential. Data subjects and supervisory authorities must be able to establish contact easily with the non-EU controller or processor through the representative.

For the DPO, expertise is equally important, but independence is the central point. The organisation should ensure that the DPO can provide advice freely, without being influenced by operational responsibilities, commercial interests or the need to defend the work of another team involved in the study.

For this reason, appointing a specialised and independent service provider may be more appropriate than appointing an operational CRO that is already involved in the same study or processing activities.

🔍 Let’s illustrate this with an example

Imagine that a supervisory authority questions the security measures implemented by one of the Sponsor’s processors in the context of a clinical study. The authority may request information, ask for documents or require corrective actions.

If the CRO acts as DPR while also being involved as an operational processor, this may create a difficult situation. The DPR may have to facilitate exchanges with the authority on matters that concern the CRO’s own operational activities or those of another service provider. It may also have access to confidential compliance assessments, contracts or internal documents that are not necessary for its CRO services.

A similar issue may arise for the DPO function. If a data breach occurs in a clinical trial system operated or managed by the CRO, the DPO may need to advise the Sponsor on breach qualification, notification to the supervisory authority, communication to data subjects, remediation measures and potential weaknesses in the CRO’s safeguards. A CRO acting as DPO would face a clear tension between its duty to provide independent advice and its interest in limiting criticism of its own operational role.

This does not mean that a CRO can never provide data protection support. CROs often play an important role in the practical implementation of data protection requirements in clinical studies. However, where the CRO is also operationally involved in the same study or processing activities, appointing it as DPR or DPO should be approached with great caution.

✅ In conclusion

The DPR and the DPO are both important GDPR functions, but they serve different purposes.

The DPR represents certain non-EU controllers or processors in the Union and acts as a point of contact for supervisory authorities and data subjects. The DPO advises and monitors the organisation’s GDPR compliance, cooperates with supervisory authorities and acts independently in the performance of their statutory tasks.

Because of these responsibilities, both functions require appropriate expertise, availability and a clear absence of conflicts of interest. In the clinical research context, a CRO may already play an important operational role in the study and may act as a processor or service provider for the Sponsor.

Appointing the same CRO as DPR may create conflicts in relation to authority-facing representation, access to internal compliance documents and enforcement-related exposure. Appointing the same CRO as DPO may create conflicts in relation to independence, self-review and the ability to challenge the CRO’s own operational practices.

For these reasons, we advise against appointing an operational CRO, or another data processor involved in the study, as Data Protection Representative or Data Protection Officer for the same Sponsor or the same processing activities, unless a robust and documented conflict assessment demonstrates that the function can be performed independently and without competing interests.

 

[1] Article 27 of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/ 46/EC (GDPR).

[2] Article 74 of the Regulation (EU) No 536/2014 of the European Parliament and of the Council of 16 April 2014 on clinical trials on medicinal products for human use, and repealing Directive 2001/20/EC.

[3] Article 37 of the GDPR.

[4] This obligation does not apply to processing which is occasional, does not include, on a large scale, processing of sensitive data or data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of natural persons.

[5] Article 4 (17) of the GDPR.

[6] Article 37(1) of the GDPR.

[7] Article 9(1) of the GDPR.

[8] As clarified by Recital 80 of the GDPR.

[9] Article 39 of the GDPR.

[10] European Data Protection Board, Guidelines 3/2018 on the territorial scope of the GDPR (Article 3), adopted on 16 November 2018, page 21.

 

Authors: Margherita Orcalli & Michelle Ayora

Prev post
Next post
Powered by MyData-TRUST

Want to subscribe to our newsletter ?

Name(Required)
Privacy(Required)