Data Residency and Cross-Border Transfer in Decentralised Trials
Where clinical data physically travels — and why the device, the connectivity layer and the controller question, not just the cloud, decide it.
Residency is decided in two layers — where data is stored and where it travels — and the second is the one nobody assesses.
The device holds a copy before sync; the eSIM or data plan decides the route. Transit through a third country needs no Chapter V mechanism, but it engages security of transit, localization statutes and — where a third-country party can access the data — a real transfer. Map both layers before enrollment.
Only a transfer needs a Chapter V mechanism, and more than a signature
Third-country routing is transit — until a controller or processor there can access it.
Article 32: encryption the carrier cannot defeat. Then check localization statutes.
An adequacy decision, or a framework such as the EU–US DPF, needs no further measures.
Absent adequacy: SCCs, a transfer impact assessment and supplementary measures.
Article 49 routes such as explicit consent are narrow — not for routine trial transfers.
Four distinctions that collapse in most residency assessments
Storage location says nothing about the route, the legal basis for special-category data, the mechanism a third-country recipient needs, or who is controller.
Needs an Article 6 basis plus an Article 9(2) condition and, at scale, a DPIA under Article 35(3)(b). Part 11 and EMA/INS/GCP/112288/2023 compliance is a separate perimeter.
The sponsor is usually controller, but sites and some vendors may be controllers or joint controllers. Consent to take part and the lawful basis for processing are two different things.
On-device copies sit in the participant's jurisdiction; sync routing decides whether a border is crossed; an IMEI, MAC or eSIM linked to a participant makes the device a personal-data asset.
Six duties, one per party in the transfer map
- 1Sponsor: own the RIA entry and the DPIA; decide lawful basis, transfer mechanism and roles; sign off the transfer map.
- 2eCOA / ePRO vendor: document the storage and sync design, encrypt at rest, and supply it to the DPIA.
- 3Connectivity provider: disclose routing, egress regions and payload access; pin or restrict third-country backhaul.
- 4Logistics vendor: treat identifier-to-participant linkage as personal data; secure and reconcile it at decommissioning.
- 5CRO: disclose sub-processors and their locations so they enter the transfer map (QPP-12).
- 6Data-protection function: run TIAs and records of processing; feed the Trigger Register and reconcile globally.
GDPR Art. 6, 9, 32, 35(3)(b), 49, Chapter V · UK GDPR, IDTA, DUA Act 2025 · HIPAA · 28 CFR Part 202 · PIPL · 152-FZ · PDPL · DPDP Act · EU CTR Art. 28(3), 32 · 21 CFR Part 11 · EMA/INS/GCP/112288/2023 · EU AI Act · EHDS
© qointa 2026 – Public – Uncontrolled when printed · Not legal advice; this summary does not classify any device.
sales@qointa.com · qointa.com
More from the library
Digital Health Technologies in Clinical Trials — A Regulatory Position-Paper Series
One device, several perimeters: a framework for assessing the regulatory impact of the technologies a trial relies on.
Read more →Who Is the Manufacturer? Economic-Operator Roles in DHT Supply Chains
How provisioning, importing, kitting and modifying a device assign manufacturer, importer and distributor duties — often by operation of law.
Read more →You Can Delegate the Work, Not the Accountability: Vendor Qualification and Oversight under ICH E6(R3)
The sponsor’s duty to qualify and oversee its DHT vendors — distinct from who holds the economic-operator role.
Read more →Talk to a specialist
Bring one device and one protocol — a wearable, a sensor, an app, anything. We will tell you which regulatory perimeters it opens and what it takes to close them.
Book a 15-minute call