The trial closed in 2021. The participant list survived in the medical affairs team's drive. In 2024 the brand team used it to invite ‘patients like you’ to a launch webinar. Every invitation was a new purpose, and not one had a consent behind it.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Trial participants are our patients now.
They consented to a protocol, not to a relationship.
Ring-fence trial data from commercial systems.
The CRO handles the data.
The sponsor that decides the purpose is the fiduciary; the CRO processes for it.
Contract, audit and close out with every CRO.
Close-out as a data event
At trial close-out, decide what the law requires to be retained, for how long, and where. Everything else should be erased or returned, with a certificate.
Monday morning
01 Search commercial systems for any trial participant data.
02 Map every CRO and site that still holds copies.
03 Add data close-out to the trial close-out checklist.
Questions, answered plainly
Can pharma companies reuse clinical trial data for marketing? +
Using trial participants' personal data for marketing is a new purpose. It would generally require fresh, specific consent under DPDPA.
Is a CRO a Data Processor under DPDPA? +
Where a CRO processes participant data on the sponsor's instructions, it generally acts as a Data Processor, and the sponsor as Data Fiduciary remains responsible.
Sector · Healthcare & Pharma The Act has no 'sensitive' category. Your patients do. Read →
Healthcare & Pharma · Deep dive Treatment is not a blank cheque. Read →
Healthcare & Pharma · Deep dive The report on WhatsApp is still your report. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).