Companies involved in the development of medicinal products and therapeutic treatments process patients’ health data, yet they often cannot rely on the same legal basis for processing as healthcare providers. Many therefore choose patient consent as apparently the safest route. Supervisory authorities, including those in the Czech Republic, have warned, however, that such consent may not be regarded as freely given due to structural imbalance between the parties. In this article, we examine some situations in which this issue should be carefully considered.
The processing of patients' health data is an everyday reality in clinical research. Healthcare providers and physicians acting as investigators may, during providing general healthcare, including that within clinical research, rely on the exception to the prohibition on processing special categories of personal data under Article 9(2)(h) GDPR. This exception permits the processing of health data for the purposes of providing healthcare or medical treatment. This exception, however, is reserved exclusively for healthcare professionals. Pharmaceutical companies acting as sponsors of clinical trials, do not fall within this category, even though in many cases this would be appropriate. This is where a practical problem arises: if these companies cannot rely on the healthcare-related exception, what legal basis can they use instead? For many years, the answer in practice was straightforward: patient consent. Today, that answer will no longer suffice, or at least not without further thought.
Why patient consent does not always solve the problem in practice
Under the GDPR, consent must meet strict requirements: it must be freely given, informed, specific and explicit (Article 9(2)(a) in conjunction with Article 4(11) and Article 7 GDPR). The requirement that consent be freely given is particularly important, and problematic, in the context of clinical research. In its Opinion 3/2019 on the interplay between the Clinical Trials Regulation (No. 536/2014) and the GDPR, the European Data Protection Board (EDPB) points out that consent cannot serve as a valid legal basis where there is a clear imbalance of power between the participant and the controller. Examples include situations where the participant is not in good health condition, belongs to an economically or socially disadvantaged group, or is in a position of institutional or hierarchical dependence. In other words, a patient who depends on treatment provided, for example, by a sole manufacturer, or who is referred to a particular course of treatment by his/her attending physician, is unlikely to be in a position to give truly free consent. The EDPB therefore concludes that, in most cases, consent will not be an appropriate legal basis for primary research activities, namely processing directly connected with the conduct of a clinical study. In our experience, the Czech Office for Personal Data Protection (the “Czech DPA”) shares the EDPB’s position outlined above. While consent cannot be ruled out as a legal basis in the healthcare sector, particularly for the secondary use of health data for scientific purposes that were not part of the original clinical study protocol, where consent remains one of the available options, controllers are required to comply strictly with all conditions attached to this legal basis, in particular the requirement that consent be freely given.
What legal basis should be considered instead?
The EDPB distinguishes between two main categories of processing:
- Processing for safety and reliability purposes – for example, reporting safety events to regulatory authorities or archiving documentation in accordance with the Clinical Trials Regulation. Such processing is based on a legal obligation (Article 6(1)(c) GDPR), while the processing of sensitive health data relies on Article 9(2)(i) GDPR (public interest in the area of public health, including ensuring the quality and safety of medicinal products).
- Research-related processing and treatment quality assurance, on the other hand, covers activities such as conducting the clinical study itself, collecting data on a medicinal product’s effects, and analysing study results. In this context, three alternative legal bases may be considered:
- The controller’s legitimate interest (Article 6(1)(f) GDPR in conjunction with Article 9(2)(i) and (j)) is typically relevant for commercial controllers that do not conduct research as a statutory public task. This legal basis requires a three-step proportionality assessment, commonly referred to as a balancing test.
- A task carried out in the public interest (Article 6(1)(e) GDPR) – applicable only in rather marginal cases, where the conduct of a clinical trial is directly entrusted to the given organisation by law as a public task. Where the controller is the sponsor of the clinical trial and is not itself the contracting/public entity, this legal basis is not available.
- Explicit consent (Article 6(1)(a) in conjunction with Article 9(2)(a) GDPR) may be relied upon for primary processing only where the controller can demonstrate, in the specific circumstances, that consent is genuinely freely given and satisfies all statutory requirements. Typically, this may be the case in situations involving surgical procedures that are not necessary for the patient’s life or health. In the secondary use of data, the position of consent is also stronger.
Clinical trials as a practical example
Clinical trials of medicinal products provide a textbook example of an environment in which, in our view, consent as a legal basis is particularly problematic. The patient is suffering from a condition for which no effective treatment exists, or for which available authorised medicinal products provide only limited therapeutic benefit. As part of the clinical trial, the patient is offered access to a potentially effective medicinal product. At the same time, the research team represents the interests of the sponsor as the data controller. In such an inherently asymmetric relationship, it is difficult to argue that consent is truly “freely given” within the meaning of the GDPR.
Importantly, the relevant SÚKL KLH-22 Guideline correctly distinguishes between informed consent as an ethical and regulatory requirement under the Clinical Trials Regulation, on the one hand, and consent as a legal basis for processing personal data on the other. These are two separate documents serving two different purposes and confusing them remains one of the most common mistakes in practice. Informed consent within the meaning of the SÚKL Guideline is not, in practice, a consent under GDPR, even though the two concepts are frequently conflated in practice. At present, there is a growing trend away from consent-based models in the private sector. Compared with the past, template information sheets and forms for subjects now more frequently identify legitimate interests (Article 6(1)(f) GDPR) and compliance with a legal obligation (Article 6(1)(c) GDPR) as the legal bases for primary processing, with reference to Article 9(2)(i) and (j) GDPR for the processing of sensitive health data.
Where consent is still most commonly encountered in the clinical trials context is in relation to the secondary use of data. Here, we take the view that, if properly structured, the use of consent can be justified.
Practical implications and risks of taking the incorrect approach
A controller that relies on patient consent as the legal basis for primary processing in a clinical trial, without carefully assessing whether that consent is genuinely freely given and therefore valid, exposes itself to several significant risks:
- Regulatory risk: During an inspection, the Czech DPA may conclude that the consent does not meet the requirement of being freely given and is therefore invalid. In such a case, the processing would be regarded as lacking a valid legal basis, with all the consequences that follow. These may include the inability to use the collected data for the intended purposes, an obligation to erase the data, and potentially the imposition of penalties.
- Risk of consent being withdrawn: Where consent is used as the legal basis, the data subject has the right to withdraw that consent at any time (Article 7(3) GDPR). If consent is withdrawn in relation to research activities, the controller may be required to cease the relevant research processing and refrain from any further use of the data. This can undermine the integrity of the clinical study, at least in part, particularly in clinical studies involving a smaller number of patients.
- Risk of incorrectly structured documentation: Confusing informed consent (an ethical document) with a document addressing personal data protection (legal bases for processing) can lead to personal data protection processes being structured incorrectly. This may result, for example, in inappropriate contractual arrangements or in the failure to carry out a Legitimate Interests Assessment (LIA) or a Data Protection Impact Assessment (DPIA) where required. On the other hand, legitimate interest is not a “free pass” either. Controllers must conduct a balancing test, document the same, and be able to produce it upon request to the Czech DPA.
Conclusion: time to reconsider existing approach
The approach relating to the processing of personal data, just as the field of practice as a whole, continues to evolve. An increasing number of controllers are moving away from relying on patient consent as the legal basis for primary processing carried out in the course of their research activities, replacing it instead with a combination of a legitimate interest and/or compliance with a legal obligation, together with the relevant exceptions under Article 9 GDPR. For the secondary use of data, by contrast, consent may continue to constitute an appropriate legal basis where it is structured correctly. Supervisory authorities – both the EDPB and the Czech DPA – have endorsed this shift in approach. If your company still relies on patient consent as the default legal basis for the primary processing of health data, it is now may be the time to reconsider that approach. The HAVEL & PARTNERS Data Protection team can help you assess your current arrangements and implement an appropriate legal framework for the processing of health data.







.jpg.webp?hash=c79c1a2b2a7046cd8f93f5079cf07b0bd9e67b72)