Regulatory Strategy

Regulatory
Strategy

France's largest private portfolio of CNIL-authorised health data warehouses. CESREES files, MR-004, MR-006, MR-008 reference methodologies and GDPR governance. First application for a European health data warehouse filed with the CNIL, forerunner of the EHDS.

8
CNIL-authorised EDS
35+
Authorised CNIL projects
100%
Requests accepted
1st
European EDS authorised by CNIL

Complete mastery of the regulatory framework

We support every stage of your health data project, from protocol design through to obtaining CNIL authorisation and ongoing operational compliance.

CESREES & CNIL files

Drafting and submission of authorisation request files to CESREES and the CNIL. Managing exchanges, responding to supplementary requests, through to obtaining authorisation. 100% authorisation rate across more than 35 files submitted.

Reference methodologies

Expertise in the three reference methodologies applicable to healthcare industry projects: MR-004 (research on EDS), MR-006 (PMSI access for industry) and MR-008 (SNDS access for industry). Selection and application of the appropriate methodology for each project.

GDPR governance & DPIA

Implementation of data governance: processing register, Data Protection Impact Assessments (DPIA) following the CNIL methodology, privacy by design policy and data minimisation.

Full project compliance

Complete management of regulatory compliance for each project: from feasibility analysis through to obtaining CNIL authorisation. Continuous monitoring, regulatory watch and compliance oversight throughout the project lifecycle.

Reference Methodologies

The three CNIL regulatory frameworks governing health data research. Clinityx masters each of them and guides you towards the methodology best suited to your project.

MR-004

Research not involving the human person

Framework applicable to health data processing for research, study or evaluation purposes in the health field, conducted using data collected in the course of care or existing treatments.
Scope

Studies on health data warehouses (EDS), registries, observational cohorts and medico-administrative databases outside the SNDS main database — including SNDS-linked systems under certain conditions. This is the framework for studies conducted on our CNIL-authorised EDS (6 of the 8 warehouses).

Key conditions

Data collected in the course of care or prior research, public interest of the study, individual information of data subjects (Articles 13 and 14 of the GDPR), declaration of compliance with MR-004, DPIA, registration of each project in the Health Data Hub's public registry — without CNIL review or referral to CESREES.
Where only collective information of data subjects is possible, the study falls under the authorisation route — CESREES opinion followed by CNIL authorisation — a process we manage in full.

Specialised EDSRegistriesCohortsCompliance setup: a few weeksTypical project timeline: 3 to 6 months
MR-006

PMSI data access for healthcare industry

Framework dedicated to PMSI (Programme de Médicalisation des Systèmes d'Information) data processing carried out on behalf of organisations producing or marketing health products (pharmaceutical laboratories, medical device manufacturers).
Scope

Studies on national PMSI hospital data made available by ATIH via a secure platform. 10 years (9 + current year). No linkage with other personal data.

Key conditions

Mandatory use of a research bureau having made a compliance commitment to the CNIL. Access via the secure service provider designated by ATIH (CASD) or approved secure enclave. Independent audit every 3 years. Registration of each study in a public registry.

PMSI / ATIHPharma industrySecure enclaveSimple commitment
MR-008

SNDS main database access for industry

Framework enabling research, studies or evaluations of public interest to be carried out on the SNDS main database (DCIR, PMSI, CepiDC) made available by CNAM, subject to an expressly favourable opinion from CESREES. Analyses are carried out exclusively by an accredited research laboratory or research bureau, within an approved controlled environment — precisely Clinityx's positioning.
Scope

Pharmaco-epidemiological studies on the comprehensive SNDS (65M+ beneficiaries), real-world studies, centre targeting and feasibility studies. Data comes exclusively from CNAM. Our Magellan studies are conducted under the authorisation regime specific to the Magellan warehouse (CNIL deliberation No. 2022-009, amended by No. 2025-070 of 24 July 2025), in accordance with requirements aligned with MR-008.

Key conditions

Expressly favourable opinion from CESREES mandatory. Compliance commitment with CNIL. Access via secure enclave. Triennial practice report to CNIL and CESREES. Only aggregated statistics may be extracted.

SNDS / CNAMPharma industryCESREES required8 to 12 months

From feasibility to CNIL authorisation

A proven 7-step process. 35+ files submitted, 100% authorisations obtained.

1

Regulatory feasibility

Project analysis to determine the applicable reference methodology (MR-004, MR-006 or MR-008), the legal basis for processing and the required authorisations. Verification of data availability and technical feasibility.

1 to 2 weeks
2

Scientific protocol

Drafting of the protocol in accordance with the HAS methodological guide on real-world studies. Definition of objectives, inclusion criteria, statistical analysis plan and data protection measures.

3 to 6 weeks
3

CESREES file

Preparation of the file for the Scientific and Ethical Committee for Research, Studies and Evaluations in the Health field. CESREES assesses the scientific and ethical relevance of the protocol before transmission to the CNIL.

4 to 8 weeks (opinion) - Non-MR projects
4

CNIL authorisation

Submission of the complete file to the CNIL with the CESREES opinion, DPIA, compliance commitment and security measures. Managing exchanges and responding to supplementary requests.

2 to 3 months (decision) - Non-MR projects
5

Technical compliance

Deployment of compliant infrastructure: certified HDS hosting, secure analysis enclave, access control, query traceability, encryption and data pseudonymisation.

In parallel
6

Extraction & analysis

Data extraction in the secure environment, quality verification, execution of the statistical analysis plan set out in the protocol. No individual data leaves the secure enclave.

Project-dependent
7

Delivery & transparency

Before delivery of the aggregated results, a re-identification risk analysis is carried out by the study team and submitted for the DPO's opinion, who reviews the methodology and conclusions — ensuring no output allows direct or indirect identification.

2 to 4 weeks

Authorised EDS & SNDS access

Clinityx holds France's largest private portfolio of CNIL-authorised health data warehouses, and masters SNDS access procedures.

Health Data Warehouses

8 CNIL-authorised EDS — research projects under MR-004

Each EDS is the subject of a CNIL authorisation, then each research project conducted on an EDS is covered by MR-004. This model allows simplified, multi-project access to specialised clinical data.

  • Prior CNIL authorisation of the warehouse
  • Internal governance: scientific committee, ethics committee
  • Each study validated by the warehouse's scientific and ethics committee, then implemented under MR-004
  • 4 partner EDS natively linked to SNDS: CardioHub, UroCCR-Chain, Colibri-Pneumo, DataMesh
  • Certified HDS hosting, secure analysis enclave
  • Transparency via the Semaphore portal

Immediate SNDS-linked data access for the 4 already-linked EDS — no additional processing delay.

PMSI & SNDS access for industry

MR-006 (PMSI / ATIH) & MR-008 (SNDS / CNAM) — 65M+ beneficiaries

Two distinct frameworks for healthcare industry players: MR-006 for access to PMSI hospital data via ATIH, and MR-008 for access to the SNDS main database (DCIR, PMSI, CepiDC) via CNAM. This is the framework for our Magellan studies.

  • MR-006: PMSI access via ATIH secure platform (CASD)
  • MR-008: full SNDS access, favourable CESREES opinion required
  • Research bureau with CNIL compliance commitment
  • Approved secure enclave, only aggregated statistics extracted
  • Independent audit every 3 years, triennial report to CESREES
  • EDS-SNDS linkage possible for 4 of our warehouses

Clinityx has experience with more than 35 CNIL files submitted with a 100% success rate across all applications.

First application for a European EDS filed with the CNIL

Clinityx submitted the first authorisation application for a European health data warehouse to the CNIL, forerunner of the European Health Data Space (EHDS). This pioneering approach anticipates the future European regulatory framework for secondary health data.

The EHDS, whose regulation was adopted by the European Parliament, plans to create a common health data space across the EU. France, via the CNIL and the Health Data Hub, plays a structuring role in defining access and governance standards. Clinityx is already positioning itself as a player in this transformation by adapting its reference frameworks to European requirements.

1st
European EDS application filed with the CNIL
27
EU Member States covered by the EHDS
EHDS
European Health Data Space — regulation adopted
2026
Progressive implementation of the regulation

GDPR, DPIA & operational compliance

A structured compliance approach that integrates data protection from the very first stages of project design.

Impact Assessment (DPIA)

Systematic completion of a DPIA following the CNIL methodology for every health data research project. The DPIA is mandatory under MR-004, MR-006 and MR-008.

  • Detailed description of the processing and its purposes
  • Assessment of necessity and proportionality
  • Mapping of risks to individuals' rights
  • Mitigation measures and action plan

Privacy by Design

Integration of data protection from the design stage of each project and each infrastructure. Data minimisation, pseudonymisation, granular access control.

  • Data pseudonymisation at source
  • Minimisation: only necessary variables
  • Encryption in transit and at rest
  • Role-based access control (RBAC)

End-to-end regulatory management

Full management of compliance for each research project. From drafting the initial file to post-authorisation monitoring, we handle end-to-end compliance for every project we manage.

  • Drafting and submission of CESREES and CNIL files
  • Maintenance of the processing register per project
  • Post-authorisation monitoring and compliance commitments
  • Ongoing regulatory watch (CNIL, EHDS, HAS)

Security & traceability

Technical and organisational security measures compliant with CNIL and HDS reference framework requirements. Complete traceability of every access and every data operation.

  • Certified HDS hosting (Health Data)
  • Logging of all accesses and queries
  • Periodic security audits
  • Data breach management plan

eBIOS-RM & self-certification

Our security approach is based on ANSSI's eBIOS Risk Manager method, with annual renewal of self-certification and continuous monitoring of the risk treatment plan.

eBIOS-RM risk analysis

Application of the eBIOS Risk Manager method (ANSSI) to identify and assess risks to our information systems processing health data. Mapping of strategic and operational scenarios.

  • Identification of business assets and supporting assets
  • Analysis of risk sources and targeted objectives
  • Strategic and operational scenarios
  • Residual risk treatment plan

Annual self-certification

Security accreditation following ANSSI's eBIOS Risk Manager approach, renewed annually; data-processing environments accredited to the SNDS and Health Data Warehouse security frameworks.

  • Annual renewal of the certification decision
  • Risk treatment plan monitoring
  • Independent third-party security audit (annual)
  • Continuous update of security measures

Semaphore Portal

Transparency is a cornerstone of our regulatory approach. All our authorisations and studies are publicly accessible.

View our authorisations & studies

Semaphore is our transparency portal. It lists all CNIL authorisations obtained for our warehouses, approved research projects, information notices for data subjects, and published results. It meets the transparency requirements set by the reference methodologies.

Access Semaphore

Secure your project

Secure your project with our regulatory team. We manage the entire CNIL and GDPR compliance process.