AMLEGALS — Strategic Lawyering

Clinical Trial and Research Data Under DPDPA

Clinical Trial and Research Data Under DPDPA

The protocol ends. The purpose ends with it.

The scene

The trial closed in 2021. The participant list survived in the medical affairs team's drive. In 2024 the brand team used it to invite ‘patients like you’ to a launch webinar. Every invitation was a new purpose, and not one had a consent behind it.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Trial participants are our patients now.

They consented to a protocol, not to a relationship.

Ring-fence trial data from commercial systems.

The CRO handles the data.

The sponsor that decides the purpose is the fiduciary; the CRO processes for it.

Contract, audit and close out with every CRO.

Close-out as a data event

At trial close-out, decide what the law requires to be retained, for how long, and where. Everything else should be erased or returned, with a certificate.

Monday morning

01 Search commercial systems for any trial participant data.

02 Map every CRO and site that still holds copies.

03 Add data close-out to the trial close-out checklist.

Questions, answered plainly

Can pharma companies reuse clinical trial data for marketing? +

Using trial participants' personal data for marketing is a new purpose. It would generally require fresh, specific consent under DPDPA.

Is a CRO a Data Processor under DPDPA? +

Where a CRO processes participant data on the sponsor's instructions, it generally acts as a Data Processor, and the sponsor as Data Fiduciary remains responsible.

Sector · Healthcare & Pharma The Act has no 'sensitive' category. Your patients do. Read →

Healthcare & Pharma · Deep dive Treatment is not a blank cheque. Read →

Healthcare & Pharma · Deep dive The report on WhatsApp is still your report. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).