Framework

GDPR

Lawful basis, DPIAs, processors and cross-border transfer for personal and health data. A DHT programme can cross a border before anyone has written down which basis carries it, and the vendor cloud is often where that is discovered.

12 documents reference GDPR
Article

A Lean Approach to Digital Risk, Quality, and Compliance Management for Small to Medium Life Sciences Companies

How can small to medium-sized life sciences companies effectively manage compliance without large budgets? What strategies can SMEs employ to navigate…

Read the article →
Article

AI Software Assurance Framework for FDA-regulated applications

How does the AI Software Assurance Framework ensure compliance in FDA-regulated applications? What are the key components of an effective AI Software…

Read the article →
Article

Are Consumer Devices (e.g. Fitbits, …) Compliant for Endpoint Data Collection?

Can consumer wearables like Fitbits generate regulatory-grade clinical trial data? What risks arise when sponsors use consumer devices for endpoint…

Read the article →
Article

BYOD/eCOA in 2026: Timestamp Drift, Part 11/GDPR, and Audit Trails No One Wants to Own

What is “timestamp drift,” and how can a few minutes of clock deviation invalidate your eCOA endpoint data? Who actually owns the audit trail when…

Read the article →
Article

Device Fit and Classification: When “Commercial” Becomes “Clinical” (Part 3/8)

Have you validated every DHT used in your trial for analytical, clinical, and usability accuracy? Are you certain of each device’s risk class in all…

Read the article →
Article

Endpoints and Algorithms: How Firmware Can Break Your Study (Part 4/8)

Can a single firmware update, algorithm change or data-sync failure invalidate months of trial data? How did the FDA’s DHT guidances change who answers for endpoint traceability and version control?

Read the article →
Article

Roles Redefined: Manufacturer, Importer, System Producer — Which Are You? (Part 6/8)

Are you certain your organisation’s role under MDR or FDA law is correctly defined? Have you appointed authorised importers or representatives for DHT…

Read the article →
Article

The Global Compliance Map: Deploying DHTs Across Borders (Part 7/8)

Are your DHTs classified and registered in every country where they’re used? Have you appointed local importers and authorised representatives? Do your…

Read the article →
Article

The Importance of Cybersecurity in Medical Device Manufacturing: Safeguarding Patient Data and Ensuring Regulatory Compliance

How can robust cybersecurity measures safeguard patient data in medical device manufacturing? Are your medical devices protected from cyberattacks that could…

Read the article →
Article

The May 2026 EUDAMED Deadline: What It Means for Digital Health Technologies in Clinical Trials

The first EUDAMED modules became mandatory on 28 May 2026 — is the wearable sensor in your trial registered, and did it need to be? What happens to your EU clinical trial if the device manufacturer…

Read the article →
Article

The Shockwave: What the FDA’s DHT Framework Really Means (Part 1/8)

Are your current DHTs validated for analytical, clinical, and usability accuracy? Who in your organisation owns responsibility for device version control?…

Read the article →
Article

“It’s Just a Phone”

Did you know a consumer smartphone can trigger four separate regulatory frameworks the moment it touches a clinical endpoint? Why do so many sponsors fail…

Read the article →

A document appears here because it names GDPR in its own text. Nothing is inferred: this is what we have actually written about it.

Discuss your programme Or take the 10-minute scorecard →