DPDP compliance for clinical research organisations and CROs
Clinical trials and research studies collect highly sensitive health and genetic data. Here is how the DPDP Act applies alongside ICMR and Schedule Y regulations.
Is clinical trial data personal data under the DPDP Act?
Yes. Clinical trial data linked to an identifiable participant — through subject ID, name, or unique participant codes that could be reverse-engineered — is personal data. Genetic data, biological sample data, and adverse event reports tied to an individual participant are sensitive personal data. Even pseudonymised trial data (where the name is replaced with a participant ID) remains personal data if re-identification is reasonably possible, which it typically is in clinical settings.
How does trial consent interact with DPDP consent?
Clinical trial informed consent under the Drugs and Cosmetics Act and ICMR's National Ethical Guidelines covers the medical and experimental aspects of participation. DPDP consent adds a parallel data protection layer: participants must be informed specifically about data processing — who will access their health data, which countries it will be transferred to (for multinational trials), how long it will be retained, and what rights they have. Build a combined consent document that satisfies both the clinical ethics and DPDP requirements.
How do cross-border data transfers work for multinational clinical trials?
Multinational clinical trials routinely transfer participant data to sponsor countries (often the US or EU) for analysis. Under DPDP, cross-border transfers must go to countries on the government's approved list (once published). Until then, build your data architecture to be adaptable — use federated analysis methods where possible to minimise raw data exports, and ensure your trial protocol's data management plan addresses DPDP transfer compliance. Include DPDP transfer obligations in the Clinical Study Agreement with the international sponsor.
What data rights do trial participants have under DPDP?
Trial participants have the right to access the personal data held about them, correct inaccurate data, and withdraw consent. However, once a participant withdraws from a trial, the ability to delete already-collected data may be limited — collected biological data has typically already been processed, and regulatory requirements (CDSCO, ICH GCP) may require retention of trial records for specified periods. Inform participants at consent that withdrawal stops future data collection but cannot reverse past processing, and document this clearly.
How should CROs handle data sharing with sponsors?
When a CRO processes trial data on behalf of a sponsor, the sponsor is the Data Fiduciary and the CRO is the Data Processor. The Clinical Research Agreement must function as a DPA: specifying what data is processed, prohibiting the CRO from using it for its own research or business development, requiring the CRO to implement GCP-compliant data security, and mandating breach notification. Sub-CROs and central laboratories are sub-processors — require the primary CRO to flow down data protection obligations to them.
What security standards apply to clinical research data under DPDP?
Clinical trial data requires the highest security standards: encryption at rest and in transit, role-based access controls, audit logs of every data access, secure transmission protocols for data exchange with sponsors, and validated systems for electronic data capture. The DPDP Act's requirement for 'appropriate technical and organisational measures' maps closely to ICH E6 GCP requirements — document the overlap in your Quality Management System so compliance resources are not duplicated.
Frequently asked questions
Can a research institution use a completed trial's data for a new research project?
Using completed trial data for a new research study is a secondary processing purpose not covered by the original trial consent. The research exemption under DPDP (once defined in Rules) may permit certain secondary research uses on appropriately anonymised or de-identified data. Until the research exemption is clarified, the safest approach is either to re-consent participants for the new study, use genuinely anonymised data, or obtain ethical committee approval for a waiver of consent in accordance with ICMR guidelines.
Does DPDP apply to biobanks storing biological samples?
Biobanks storing biological samples linked to participant identifiers are processing personal (and sensitive) data. DPDP applies to the associated data records even if the physical sample itself is not 'data'. If the biobank processes linked genomic or clinical data, the full suite of DPDP obligations applies: consent for storage and future use, participant access rights, security safeguards, and transfer restrictions. Build a tiered consent model for biobank samples covering original study use, de-identified research, and future commercial research separately.
Are CROs required to appoint a Data Protection Officer under DPDP?
Standard CROs are not automatically required to appoint a DPO unless designated as Significant Data Fiduciaries. However, CROs handling sensitive health and genetic data at scale — particularly those running large multinational trials — should consider appointing a privacy function (internal or external) as a matter of good governance and to manage the heightened compliance complexity of cross-border research data transfers.
Assess your CRO DPDP compliance
Niti Bharat's DPDP Readiness Assessment covers clinical research organisations — trial consent design, cross-border transfer architecture, sponsor DPAs, and participant rights workflows.
Start CRO DPDP Assessment