Opinion

Patient Data Across Boundaries

Which privacy rules govern a multi-country trial’s data depends on where each participant enrolled, what they agreed to, and who holds each copy. A set of example fields, some on each participant record and some on each copy, can help a clinical data platform apply EU, US, Singaporean, and Brazilian rules as data moves.
Patient Data Across Boundaries — hero image

A trial that enrols patients in the EU, the US, Singapore, and Brazil holds its data under four data protection regimes. They don’t all apply to every record. Which rules govern a participant’s data depends on where that participant enrolled, what they agreed to, and who holds the copy in question. The trial’s documents capture most of this: the protocol, the consent forms, the data transfer agreements. The data itself usually carries the site, the country, and the consent date, but rarely the legal basis, the permitted purposes, or the optional consents a participant did or didn’t give.

Those missing values decide what the platform may do next. This post sets out some example fields a multi-jurisdiction trial platform can carry, what values each can take, and where the four regimes differ. There’s a reference table at the end.

Who holds the obligation

Start with who the rules bind, because it isn’t the same in every country. HIPAA binds covered entities, such as the hospitals and clinics running US sites, and their business associates. A sponsor usually isn’t either. HIPAA governs what the site may disclose to the sponsor, and the authorisation a US participant signs has to warn that information disclosed under it may no longer be protected by the Privacy Rule (HHS, n.d.a, §164.508(c)(2)(iii)). From there, HIPAA no longer applies, and what binds the sponsor is the informed consent it obtained under FDA rules, its contracts with sites, and any applicable state privacy laws. In the EU, Singapore, and Brazil, data protection law applies to the sponsor’s own processing as well as the site’s. In Brazil, the 2024 law on research with human beings now governs the protection of participants’ personal data, with the LGPD applying where it is silent (Presidência da República, 2024, Art. 61).

So it helps to record, for each copy of the data, who holds it and in what role.

Example fields

Some of these belong on each participant record and some on each copy of the data. They’re examples, not a complete schema.

holder_role

On each copy: the organisation that holds it, the country it’s established in, and its role, such as site, sponsor, CRO, or partner. Most of the fields below can only be read correctly alongside this one.

jurisdiction

The country where the participant enrolled. It decides which regime governs collection, but it doesn’t settle every later use. GDPR also applies to processing in the context of a holder established in the EU, wherever the processing happens (European Parliament and Council, 2016, Art. 3(1)), so this field has to be read together with holder_role. It also has to stay attached when data from several countries is pooled, since a pooled dataset that has lost its country column is hard to check against any of the rules that follow.

The basis on which the data is processed, which is often more than one, and differs by purpose.

In the EU, the informed consent a trial requires is an ethical safeguard, and the European Data Protection Board says it must not be confused with consent as a legal basis under GDPR. Processing for safety reporting and record-keeping rests on legal obligation. Processing for the research itself can rest on explicit consent, a task in the public interest, or the sponsor’s legitimate interests, combined with a condition in Article 9, and the Board says consent will not be the appropriate basis in most cases (EDPB, 2019). Member states may also add conditions for health and genetic data (European Parliament and Council, 2016, Art. 9(4)). In the US, a site discloses to the sponsor under a written authorisation that describes each purpose, or under a waiver approved by an institutional review board, and can disclose to an FDA-regulated sponsor for safety purposes such as adverse event reporting (HHS, n.d.a, §164.508; HHS, n.d.c, §164.512(b) and (i)).

Singapore’s PDPA requires consent unless a listed exception applies (AGC, n.d., s.13), and other written law prevails where it is inconsistent with the PDPA (AGC, n.d., s.4(6)(b)), so trial-specific rules can take precedence. Its research exception for using personal data requires, among other things, that the results won’t be used to make any decision that affects the individual (AGC, n.d., Second Schedule, Part 2, Division 3), which suits later research better than the trial itself. In Brazil, the LGPD, which fills the gaps in the research law, allows sensitive data to be processed with specific, highlighted consent, or without consent where needed for a legal or regulatory obligation. Its research route is limited to Brazilian public bodies and non-profits established in Brazil whose mission includes research, which leaves most commercial sponsors relying on consent or legal obligation (Presidência da República, 2018, Arts. 5 and 11).

Record the basis per purpose at enrolment, from the consent version the participant signed, so that each later use can be checked against it.

The optional consents, separate from the main trial consent. The EU Clinical Trials Regulation lets a sponsor ask participants to agree to use of their data outside the protocol, exclusively for scientific purposes, and says that consent can be withdrawn at any time, without prejudice to data protection law (European Parliament and Council, 2014, Art. 28(2)). Other countries use similar optional consents for future research, sample storage, or sharing with partners. Each one is a yes, a no, or not asked, and it can change. A model-training project, a partner extract, or a pooled analysis should only draw on participants whose consent scope covers it, and the use still needs its own legal_basis entry, because the Board treats this optional consent as an ethical safeguard rather than a GDPR legal basis (EDPB, 2019). Consent and lineage models like these are a regular part of the clinical data platforms our Data & AI practice works on.

transfer_route

How the data may leave the country, and under what safeguard. All four regimes regulate how data leaves; none of them requires it to stay. GDPR allows transfers to countries the European Commission has found adequate, with appropriate safeguards, or in limited cases under a derogation (European Parliament and Council, 2016, Chapter V). LGPD allows transfers to adequate countries or with safeguards such as standard contractual clauses (Presidência da República, 2018, Art. 33). PDPA makes the transferring organisation ensure the data gets protection comparable to the Act’s (AGC, n.d., s.26). HIPAA’s Privacy Rule has no data-location rule. Separately, a US Justice Department rule bars US persons from some transactions, and restricts others, that give countries of concern access to bulk US sensitive personal data. The thresholds include personal health data on more than 10,000 US persons and genomic data on more than 100, and transactions involving bulk genomic and other ‘omic data or biospecimens are prohibited (DOJ, n.d., §§202.205 and 202.303). There’s an exemption for transactions ordinarily incident to and part of FDA-regulated clinical investigations (DOJ, n.d., §202.511), but reuse outside the trial may fall outside it.

Each transfer, including a CRO statistician working from another country, needs a recorded route. The platform should be able to show, for any dataset, which participants’ data left which country and on what basis. Our Sovereignty Versus Efficiency post looked at residency as an architecture question across regulated industries, and participant data adds a further question about which uses each participant agreed to.

identifiability

Whether a given copy counts as personal data, which depends on the law and on who holds it. Under GDPR, pseudonymised data that could be attributed to a person using additional information is personal data (European Parliament and Council, 2016, Recital 26). The EU Court of Justice has since held, under the equivalent rules for EU institutions, that pseudonymised data isn’t personal data in all cases and for every person, since pseudonymisation may prevent people other than the controller from identifying anyone (CJEU, 2025, para. 86). Singapore’s PDPA counts data as personal if a person can be identified from it together with other information the organisation has or is likely to have access to (AGC, n.d., s.2). HIPAA treats data as de-identified when an expert determines the risk of re-identification is very small, or when a listed set of identifiers is removed and the covered entity has no actual knowledge that what’s left could identify someone (HHS, n.d.b, §164.514(b)). That list includes all elements of dates except the year, so a coded trial dataset with visit dates isn’t de-identified under the second method. LGPD treats anonymised data as outside the law unless the anonymisation can be reversed with reasonable effort (Presidência da República, 2018, Art. 12).

So the same coded dataset can be personal data under one regime and not under another, and the answer can change when it’s copied to a new holder. Set this field per copy, and record which participants’ data trained or validated each model, so a later question about reuse can be answered.

withdrawal_state

What still applies after a participant leaves. Every regime gives participants a way out, and they differ on what happens next. In the EU, the Board’s view is that withdrawing consent stops the research based on that consent, and that where no other basis applies the data should be deleted, while processing for legal obligations such as safety reporting continues (EDPB, 2019), and the Clinical Trials Regulation keeps data obtained before withdrawal, without prejudice to GDPR (European Parliament and Council, 2014, Art. 28(3)). In the US, FDA policy is that data already collected about participants who leave a study is kept as part of the study data (FDA, 2008), and a site’s HIPAA authorisation can be revoked in writing except where the site has already acted on it (HHS, n.d.a, §164.508(b)(5)). PDPA requires the organisation to stop using the data unless the law requires or authorises the use without consent (AGC, n.d., s.16(4)). LGPD keeps processing done before revocation valid while no deletion is requested (Presidência da República, 2018, Art. 8 §5).

The field can record which uses must stop, which may continue, and whether deletion applies, so the platform can find every copy affected: analysis datasets, partner extracts, and the training data behind models. Keeping the evidence of those checks current as consents and regulations change is what Praxis, Sakura’s compliance solution, is built for.

The four regimes side by side

A simplified reference. Each cell has exceptions, and the sources above give the detail. In the EU, member states may add conditions for health and genetic data. In Brazil, the 2024 research law applies first, with the LGPD filling gaps.

QuestionEUUSSingaporeBrazil
BasisLegal obligation for safety and records; explicit consent, public interest, or legitimate interests for research (EDPB)Site: authorisation or IRB waiver (HIPAA); sponsor: consent, FDA rules, and contractsConsent, or listed exceptions with conditions (PDPA)Research law first; under LGPD, specific consent or legal or regulatory obligation
TransferAdequacy, safeguards, or limited derogations (GDPR)No HIPAA location rule; DOJ bulk data rule, with a trial exemptionTransferring organisation ensures comparable protection (PDPA)Adequacy or safeguards (LGPD)
Identifiers removedDepends on who holds it (GDPR; CJEU)De-identified by expert determination or by removing listed identifiers (HIPAA)Personal if identifiable with information the holder has or can access (PDPA)Not personal data unless reasonably reversible (LGPD)
WithdrawalConsent-based research stops, with deletion if no other basis; legal obligations continueAccrued data kept (FDA); site authorisation revocableStop using unless the law permits (PDPA)Earlier processing valid unless deletion requested (LGPD)

Example fields like these help keep each participant’s data current and checked before a transfer or a new use. Clear-cut cases can be handled by the platform, and the rest can go to someone who can decide.

That closes the Pharma and Healthcare series. Part 1 covered custody of trial data and Part 2 the provenance of research data, and this post has looked at permission, meaning which uses each participant’s data allows in each country. For the jurisdiction-by-jurisdiction mapping behind those fields, talk to our GRC service.


Not legal advice. This article offers general commentary on the EU General Data Protection Regulation, the EU Clinical Trials Regulation, the US HIPAA Privacy Rule, FDA guidance, the US Justice Department’s rule on access to sensitive personal data, Singapore’s Personal Data Protection Act, and Brazil’s research and data protection laws for a pharma and healthcare engineering audience. It is not legal advice and is not a substitute for advice from qualified counsel or qualified regulatory affairs professionals. Specific obligations depend on the nature of your clinical programme, the jurisdictions in which you operate, your sponsor and CRO agreements, and the regulators to which you are subject. Readers must obtain independent legal and regulatory advice on how these laws apply to their specific products and clinical operations.

References

Attorney-General’s Chambers (AGC), n.d. Personal Data Protection Act 2012. Singapore Statutes Online. Available at: https://sso.agc.gov.sg/Act/PDPA2012?WholeDoc=1 [Accessed 6 October 2026].

Court of Justice of the European Union (CJEU), 2025. European Data Protection Supervisor v Single Resolution Board, Case C-413/23 P. Judgment of 4 September 2025, ECLI:EU:C:2025:645. Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0413 [Accessed 6 October 2026].

European Data Protection Board (EDPB), 2019. Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection Regulation (GDPR). Adopted 23 January 2019. Available at: https://www.edpb.europa.eu/documents/legislative-opinion/opinion-32019-concerning-the-questions-and-answers-on-the-interplay_en [Accessed 6 October 2026].

European Parliament and Council, 2014. Regulation (EU) No 536/2014 of the European Parliament and of the Council of 16 April 2014 on clinical trials on medicinal products for human use. Official Journal of the European Union, L 158, 27 May. Available at: https://eur-lex.europa.eu/eli/reg/2014/536/oj [Accessed 6 October 2026].

European Parliament and Council, 2016. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Official Journal of the European Union, L 119, 4 May, pp. 1-88. Available at: https://eur-lex.europa.eu/eli/reg/2016/679/oj [Accessed 6 October 2026].

Presidência da República, 2018. Lei nº 13.709, de 14 de agosto de 2018: Lei Geral de Proteção de Dados Pessoais (LGPD). Brasília. Available at: https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm [Accessed 6 October 2026].

Presidência da República, 2024. Lei nº 14.874, de 28 de maio de 2024: dispõe sobre a pesquisa com seres humanos e institui o Sistema Nacional de Ética em Pesquisa com Seres Humanos. Brasília. Available at: https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2024/lei/L14874.htm [Accessed 6 October 2026].

US Department of Health and Human Services (HHS), n.d.a. 45 CFR 164.508: Uses and disclosures for which an authorization is required. Electronic Code of Federal Regulations. Available at: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.508 [Accessed 6 October 2026].

US Department of Health and Human Services (HHS), n.d.b. 45 CFR 164.514: Other requirements relating to uses and disclosures of protected health information. Electronic Code of Federal Regulations. Available at: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514 [Accessed 6 October 2026].

US Department of Health and Human Services (HHS), n.d.c. 45 CFR 164.512: Uses and disclosures for which an authorization or opportunity to agree or object is not required. Electronic Code of Federal Regulations. Available at: https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.512 [Accessed 6 October 2026].

US Department of Justice (DOJ), n.d. 28 CFR Part 202: Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons. Electronic Code of Federal Regulations. Available at: https://www.ecfr.gov/current/title-28/chapter-I/part-202 [Accessed 6 October 2026].

US Food and Drug Administration (FDA), 2008. Guidance for Sponsors, Clinical Investigators, and IRBs: Data Retention When Subjects Withdraw from FDA-Regulated Clinical Trials. October 2008. Available at: https://www.fda.gov/regulatory-information/search-fda-guidance-documents/data-retention-when-subjects-withdraw-fda-regulated-clinical-trials [Accessed 6 October 2026].