For many Life Sciences organizations, the end of a clinical trial is often perceived as the end of operational complexity. In reality, it marks the beginning of one of the longest and most underestimated risk periods: the archiving phase.
In Europe, clinical trial data must typically be retained for at least 25 years. During this time, it continues to generate regulatory exposure, operational dependencies, and strategic risks, especially for companies operating globally.
For executives driving international growth, understanding how data protection obligations evolve after trial closure and across jurisdictions is critical.
🗄️ Archiving is not the end of processing, but a new risk phase
Once a clinical trial concludes, the Trial Master File (TMF) shall be archived, as shall all associated data, wherever it is stored, whether in the main trial database or across other systems. This transition is often treated as an administrative step, but it introduces a new set of long-term risks and responsibilities.
Archived clinical trial data must remain accessible, reliable, and secure for decades. This involves not only storage, but also continuous activities such as system maintenance, data migration, backup management, and controlled access for regulatory inspections or scientific reuse. In a global organization, these activities are rarely confined to a single jurisdiction. Data may be hosted in one country, accessed from another, and managed by vendors in multiple regions.
From a legal standpoint, none of this is passive. Storage itself a processing activity. As long as data remains identifiable, even in pseudonymized form, it remains subject to data protection laws.
This follows from one of the core principles of data protection laws: storage limitation. In the GDPR, Article 5(1)(e) requires that personal data be retained only for as long as necessary for the relevant processing purpose. Where longer retention is justified for archiving, research, or statistical purposes, the GDPR further requires the implementation of appropriate safeguards to protect the data.
⚙️ Core processing activities during the archiving phase
Even when a trial is “inactive”, many processing operations continue. Some examples are provided in the table below.
Each of these constitutes processing within the meaning of GDPR, even if access is infrequent. A key misconception is to consider archived data as “inactive”. In reality, storage is itself an active form of processing.
⚠️ What can go wrong: the real risks of long-term data storage
Regulatory enforcement across sectors consistently shows that failures in data storage, not just data use, lead to significant penalties.
- Retention periods identified but not enforced.
In July 2020, the CNIL imposed a €1.75 million fine on an insurance company[1] for retaining personal data of millions of individuals for periods exceeding legal limits, in some cases over 30 years. While the company had a framework in place to set out retention periods, this framework was not actually implemented within the information systems for all processing activities.
A key issue was the absence of a clear distinction between active systems and archived data, with historical records remaining accessible under conditions equivalent to active processing. The company failed to implement appropriate archiving safeguards, such as restricted access or purpose limitation for long-term retention. This case illustrates that a dataset can be considered properly archived only if:
- retention rules are effectively implemented in systems, not merely documented in a policy;
data is clearly transitioned out of active environments (via dedicated archive database or strict access restrictions). In other words, archived data must be segregated from active
- data or subject to equivalent access constraints, and no longer available under normal operational conditions.;
- access is limited to specifically authorized users with a legitimate need; and
- retention is strictly linked to defined purposes, not precautionary storage.
In addition, proper archiving requires enforced retention limits, with deletion or anonymization once legal timelines expire; ongoing lifecycle management and periodic review; and technical controls ensuring restricted access and governance over time. Organizations must be able to demonstrate control regardless of system complexity, and ensure that archiving applies consistently across datasets, including large volumes and sensitive data.
- Archiving system without data removal option
This approach is consistent with enforcement practice. In particular, the case of Deutsche Wohnen SE[1], fined in 2019 approximately €14.5 million for operating an archiving system without deletion capabilities and for storing data without verifying whether its retention was lawful or necessary, illustrating German regulatory expectations around lawful retention, archiving governance, and lifecycle management.
- Governance of inherited systems
In 2020, the UK Information Commissioner’s Office imposed a fine of £18.4 million on Marriott[2] stemmed from a breach originating in legacy Starwood systems that had been effectively archived within the organization following acquisition. These systems, containing historical guest data, were not adequately audited, secured, or integrated into Marriott’s security governance framework.
This meant that personal data remained stored in systems that were not consistently monitored, patched, or reviewed for security and necessity, allowing attackers to maintain undetected access for several years. The case illustrates that archived or inherited legacy systems remain fully within the controller’s responsibility and must be actively governed. It also points to the need of a careful data protection focused due diligence during acquisitions.
- Need for data migration procedure.
In the healthcare sector, Dedalus Biologie case[3] in 2021, provides a direct parallel to clinical trial archiving. A fine of 1.5 million euros was imposed due to the lack of specific procedure for data migration, resulting in the failure to properly secure data during a system migration (including the lack of encryption of personal data stored on the affected server, no automated deletion of data following migration to the new software, and the use of shared user accounts across multiple
employees in the server’s restricted area) exposed sensitive medical information, demonstrating how transitional moments, such as vendor changes or infrastructure upgrades, likely to occur over 25-year archiving period, create heightened risk. Indeed, risk increases with time if governance does not keep pace. Over a 25-year archiving period, static compliance quickly becomes obsolete.
- Lack of defined retention periods and safeguards over datasets.
In the case involving Cegedim Santé[1], the French data protection authority (CNIL) imposed an €800,000 fine in 2024 for unlawful processing of large-scale health data used for statistical and analytical purposes. The authority found that the company had maintained and reused extensive patient datasets over prolonged periods as part of a health data warehouse without defined or effectively enforced deletion or limitation period, enabling the reconstruction of detailed patient care pathways over time. Datasets were retained in a structured and reusable form without sufficient limitation of their duration or secondary use. Further, the CNIL criticized the absence of adequate safeguards to ensure strict control over how long such sensitive health data was kept and reused, reinforcing that long-term storage of health datasets must be tightly governed and continuously justified under the principles of necessity and data minimization.
🌍 From compliance to strategy: what global life science organizations must do differently
For C-level leaders, the challenge is no longer just achieving compliance at the outset but ensuring that archiving remains compliant over time—across decades and jurisdictions. This requires a shift from a one-shot end of the trail compliance mindset to a long-term archiving governance and strategy.
First, organizations must ensure that retention periods are identified and in line with the storage limitation principle; and that archived data is not fragmented across multiple systems or vendors. Fragmentation leads to loss of visibility and control, particularly in global environments where different regions may adopt different solutions.
Second, vendor management becomes a strategic priority. Archiving providers, cloud platforms, and CROs must be assessed not only for their technical capabilities but also for their ability to meet multi-jurisdictional regulatory requirements. Outsourcing storage does not outsource accountability.
Third, storage-related policies and procedures (including archiving and retention, data migration, secondary use, and deletion) must not only be defined but also effectively implemented within the
organization’s systems. Robust lifecycle management of data reduces the risks associated with long-term storage of archived information.
Fourth, risk assessments such as DPIAs must be treated as living documents. Over a 25-year period, technologies, threats, and regulatory expectations evolve. Static assessments quickly become irrelevant.
Fifth, access to archived data must be tightly controlled, including a specific governance for the secondary use of data, and continuously reviewed. In global organizations, access rights often expand over time due to organizational changes, increasing the risk of unauthorized or unnecessary access.
Sixth, organizations must maintain the ability to respond to incidents and requests at any point during the archiving period. Data breaches can still occur, and data subject rights may still be exercised. This requires sustained operational readiness, not just initial compliance.
Finally, governance structures, including the role of the DPO, must extend into the archiving phase. Oversight cannot end when the trial does.
The business case: why this matters for global expansion
For life science companies expanding internationally, clinical trial data is a critical asset but also a long-term liability.
Failing to manage archiving properly can lead to:
- regulatory fines across multiple jurisdictions,
- delays in regulatory submissions or inspections,
- reputational damage affecting partnerships and market access,
- loss of acquisition opportunities,
- data breach and malicious activity,
- operational disruption due to data loss or inaccessibility.
Conversely, organizations that treat data archiving as a strategic function gain a competitive advantage. They are better positioned to:
- support global regulatory interactions,
- enable secondary use of data for innovation,
- ensure and proactively support data quality assurance and validation over time,
- demonstrate trustworthiness to investors, partners and authorities
Conclusion
Clinical trial data does not go of privacy compliance limits once a study ends. It enters a prolonged phase of regulatory exposure that spans decades and jurisdictions.
Ultimately, compliance in this context is not about storing data, it is about ensuring its protection, accessibility, and integrity over time, wherever in the world it resides.
Authors: Anastassia Negrouk & Michelle Ayora