DPO requirements beyond Article 37 GDPR: national extensions and clinical research frameworks

DPO requirements beyond Article 37 GDPR: national extensions and clinical research frameworks

The obligation to appoint a Data Protection Officer is often approached as a closed question under Article 37 GDPR. For organisations involved in clinical trials, that approach is incomplete.

While Article 37 provides the baseline test, it is not exhaustive. Member States may introduce additional circumstances in which a DPO must be appointed, and in certain cases sector-specific frameworks impose equivalent requirements as part of a compliance regime.

The distinction between these two types of rules is important. National laws operate as binding extensions of GDPR. By contrast, clinical research frameworks do not amend GDPR, but may make DPO designation a condition of relying on a particular regulatory pathway.

The position across key jurisdictions is summarised below.

Jurisdiction Nature of rule Trigger Practical relevance for clinical trials
Germany National statutory extension >20 persons prodcessing data, or processing required a DPIA Frequently triggered in clinical trial environments
Spain National statutory extension Defined categories of entities, including certain healthcare record-holders Relevant where sponsor or controller is a healthcare provider
Belgium National statutory extension Processing for or with a federal public authority and high-risk processing Relevant for public or hybrid research structures
Luxembourg National research safeguard regime Research/statistical processing requires additional safeguards, including DPO (unless justified otherwise) Creates strong expectation of DPS in research in contexts
Romania National statutory safeguard Processing of national indentification numbers under legitimate interest Typically operational rather than core trial data
Czech Republic Expanded public authority concept Bodies established by law performing public-interest tasks Relevant for academic and public-sector trials
France Clinical research framework (MR-001) Use of MR-001 methodology for health research DPO required as a condition of using the framework

In other jurisdictions, including the UK, Ireland, the Netherlands, Italy and the Nordic countries, no additional statutory triggers have been identified. In those cases, the analysis remains anchored in Article 37 GDPR.

The French position is structurally different from the national law extensions described above. The framework issued by the CNIL for health research (MR-001) provides a recognised compliance route for interventional studies, including clinical trials. It operates as a form of pre-approved compliance framework: where a sponsor confirms full adherence to its requirements, the study may proceed without prior authorisation; if not, specific approval must be sought from the CNIL.

MR-001 imposes a detailed set of conditions governing the processing of clinical trial data, including strict limitations on purpose, requirements for pseudonymisation, defined access controls, and mandatory data protection impact assessments. Within that framework, the designation of a Data Protection Officer by the controller is expressly required. This obligation arises from the terms of the framework itself rather than from Article 37 GDPR, and should therefore be treated as a condition of relying on that framework.

The most operationally significant national extension remains Germany. The combination of a relatively low headcount threshold and an independent trigger linked to DPIA requirements means that DPO designation is frequently mandatory for organisations engaged in clinical research, irrespective of whether Article 37 alone would clearly apply.

Spain and Belgium introduce more situational triggers, generally linked to the nature of the controller or the involvement of public authorities. Spain has adopted a sectoral Code of Conduct for clinical trials and pharmacovigilance approved by the AEPD. Unlike the French MR-001 framework, this operates as a voluntary compliance tool and does not itself impose a requirement to appoint a Data Protection Officer.

Luxembourg adopts a different model, requiring a package of safeguards for research processing, with DPO appointment forming part of that framework unless there is a documented basis for not implementing it.

Romania and the Czech Republic operate more narrowly, but remain relevant depending on how trial structures are organised.

In practice, DPO analysis in a clinical trial context should not be limited to Article 37. A structured assessment should consider whether the processing is carried out under a clinical research framework that imposes governance conditions, whether national law introduces additional triggers in the relevant jurisdiction, and whether the Article 37 thresholds are met in any event.

For many sponsors and CROs, particularly where health data processing is central to their operations, the conclusion will be that a DPO is required regardless of which route is applied. The additional layers described above are most relevant in cases where the Article 37 position is uncertain or marginal.