CNIL & GDPR

Compliance
CNIL & GDPR

Privacy by design at every step. Data Protection Officer support, processing register, impact assessments and end-to-end regulatory oversight for your health data research projects.

100%
Requests accepted
35+
CNIL-authorized projects
8
CNIL-authorized EDS
13
Therapeutic areas

Simplified CNIL compliance

We handle all aspects of CNIL and GDPR compliance for your health data research projects.

Data Protection Officer support

Our Data Protection Officer and regulatory team oversee every project: preparing GDPR deliverables (register, DPIA, information notices), coordinating with your organization's DPO, and following through until study closure.

Processing register

Documentation compliant with Article 30 of the GDPR, kept up to date project by project and aligned with the requirements of reference methodologies.

DPIA (Impact Assessments)

Systematic impact assessment for health data projects (Art. 35 GDPR), following the CNIL methodology.

CESREES & CNIL files

Preparation, submission and follow-up with authorities. Management of exchanges with CNIL and data protection committees.

CNIL reference frameworks

MR-004

Studies on existing data: studies on data already collected (EDS, registries, cohorts). Compliance declaration, no CNIL review required. This is the framework for our authorized EDS.

MR-006

Access to PMSI (ATIH): studies conducted by health industry players on national PMSI hospital data, via an approved research firm. Depth: 9 years plus the current year.

MR-008

Access to the SNDS (CNAM): studies on the SNDS main database, subject to a favorable CESREES opinion. Analyses conducted in an approved secure environment, aggregated results.

Institutional authorizations

For projects outside reference methodologies — collective information to data subjects, complex data linkages, Magellan studies: CESREES opinion followed by CNIL authorization.

Our approach

We determine the framework applicable to your project — MR-004, MR-006, MR-008, or the authorization regime — and handle all formalities in full, from protocol to decision. To date, our expertise has resulted in a 100% acceptance rate for authorization requests.

Proven expertise

35+ projects carried out in compliance, with a 100% authorization acceptance rate to date. Proven track record with CNIL and CESREES procedures.

Controlled timelines

Complete files that minimize requests for additional information and secure timelines, with documented follow-up through to the decision.

Semaphore, our transparency portal

In accordance with Article 14 of the GDPR and the requirements of reference methodologies, Semaphore publicly lists: the CNIL authorizations for our health data warehouses, approved studies and their listing in the Health Data Hub's public directory, information notices for data subjects, and published results. Public access, no authentication required: transparency is a commitment, not a service.

Secure compliance for your next project

Contact our regulatory team to determine the applicable path for your project and secure its compliance.