France's largest private portfolio of CNIL-authorised health data warehouses. CESREES files, MR-004, MR-006, MR-008 reference methodologies and GDPR governance. First application for a European health data warehouse filed with the CNIL, forerunner of the EHDS.
We support every stage of your health data project, from protocol design through to obtaining CNIL authorisation and ongoing operational compliance.
Drafting and submission of authorisation request files to CESREES and the CNIL. Managing exchanges, responding to supplementary requests, through to obtaining authorisation. 100% authorisation rate across more than 35 files submitted.
Expertise in the three reference methodologies applicable to healthcare industry projects: MR-004 (research on EDS), MR-006 (PMSI access for industry) and MR-008 (SNDS access for industry). Selection and application of the appropriate methodology for each project.
Implementation of data governance: processing register, Data Protection Impact Assessments (DPIA) following the CNIL methodology, privacy by design policy and data minimisation.
Complete management of regulatory compliance for each project: from feasibility analysis through to obtaining CNIL authorisation. Continuous monitoring, regulatory watch and compliance oversight throughout the project lifecycle.
The three CNIL regulatory frameworks governing health data research. Clinityx masters each of them and guides you towards the methodology best suited to your project.
Studies on health data warehouses (EDS), registries, observational cohorts and medico-administrative databases outside the SNDS main database — including SNDS-linked systems under certain conditions. This is the framework for studies conducted on our CNIL-authorised EDS (6 of the 8 warehouses).
Data collected in the course of care or prior research, public interest of the study, individual information of data subjects (Articles 13 and 14 of the GDPR), declaration of compliance with MR-004, DPIA, registration of each project in the Health Data Hub's public registry — without CNIL review or referral to CESREES.
Where only collective information of data subjects is possible, the study falls under the authorisation route — CESREES opinion followed by CNIL authorisation — a process we manage in full.
Studies on national PMSI hospital data made available by ATIH via a secure platform. 10 years (9 + current year). No linkage with other personal data.
Mandatory use of a research bureau having made a compliance commitment to the CNIL. Access via the secure service provider designated by ATIH (CASD) or approved secure enclave. Independent audit every 3 years. Registration of each study in a public registry.
Pharmaco-epidemiological studies on the comprehensive SNDS (65M+ beneficiaries), real-world studies, centre targeting and feasibility studies. Data comes exclusively from CNAM. Our Magellan studies are conducted under the authorisation regime specific to the Magellan warehouse (CNIL deliberation No. 2022-009, amended by No. 2025-070 of 24 July 2025), in accordance with requirements aligned with MR-008.
Expressly favourable opinion from CESREES mandatory. Compliance commitment with CNIL. Access via secure enclave. Triennial practice report to CNIL and CESREES. Only aggregated statistics may be extracted.
A proven 7-step process. 35+ files submitted, 100% authorisations obtained.
Project analysis to determine the applicable reference methodology (MR-004, MR-006 or MR-008), the legal basis for processing and the required authorisations. Verification of data availability and technical feasibility.
Drafting of the protocol in accordance with the HAS methodological guide on real-world studies. Definition of objectives, inclusion criteria, statistical analysis plan and data protection measures.
Preparation of the file for the Scientific and Ethical Committee for Research, Studies and Evaluations in the Health field. CESREES assesses the scientific and ethical relevance of the protocol before transmission to the CNIL.
Submission of the complete file to the CNIL with the CESREES opinion, DPIA, compliance commitment and security measures. Managing exchanges and responding to supplementary requests.
Deployment of compliant infrastructure: certified HDS hosting, secure analysis enclave, access control, query traceability, encryption and data pseudonymisation.
Data extraction in the secure environment, quality verification, execution of the statistical analysis plan set out in the protocol. No individual data leaves the secure enclave.
Before delivery of the aggregated results, a re-identification risk analysis is carried out by the study team and submitted for the DPO's opinion, who reviews the methodology and conclusions — ensuring no output allows direct or indirect identification.
Clinityx holds France's largest private portfolio of CNIL-authorised health data warehouses, and masters SNDS access procedures.
Each EDS is the subject of a CNIL authorisation, then each research project conducted on an EDS is covered by MR-004. This model allows simplified, multi-project access to specialised clinical data.
Immediate SNDS-linked data access for the 4 already-linked EDS — no additional processing delay.
Two distinct frameworks for healthcare industry players: MR-006 for access to PMSI hospital data via ATIH, and MR-008 for access to the SNDS main database (DCIR, PMSI, CepiDC) via CNAM. This is the framework for our Magellan studies.
Clinityx has experience with more than 35 CNIL files submitted with a 100% success rate across all applications.
A structured compliance approach that integrates data protection from the very first stages of project design.
Systematic completion of a DPIA following the CNIL methodology for every health data research project. The DPIA is mandatory under MR-004, MR-006 and MR-008.
Integration of data protection from the design stage of each project and each infrastructure. Data minimisation, pseudonymisation, granular access control.
Full management of compliance for each research project. From drafting the initial file to post-authorisation monitoring, we handle end-to-end compliance for every project we manage.
Technical and organisational security measures compliant with CNIL and HDS reference framework requirements. Complete traceability of every access and every data operation.
Our security approach is based on ANSSI's eBIOS Risk Manager method, with annual renewal of self-certification and continuous monitoring of the risk treatment plan.
Application of the eBIOS Risk Manager method (ANSSI) to identify and assess risks to our information systems processing health data. Mapping of strategic and operational scenarios.
Security accreditation following ANSSI's eBIOS Risk Manager approach, renewed annually; data-processing environments accredited to the SNDS and Health Data Warehouse security frameworks.
Transparency is a cornerstone of our regulatory approach. All our authorisations and studies are publicly accessible.
Semaphore is our transparency portal. It lists all CNIL authorisations obtained for our warehouses, approved research projects, information notices for data subjects, and published results. It meets the transparency requirements set by the reference methodologies.
Access SemaphoreSecure your project with our regulatory team. We manage the entire CNIL and GDPR compliance process.