Research in health and new reference methodologies MR-001 and MR-003 of the CNIL: what changes for professionals and what recommendations ?

By four deliberations dated March 19, 20261, the French National Commission on Informatics and Liberty (CNIL) has updated its “reference methodologies” MR-001 and MR-003, which govern data processing carried out in the context of health research. Beyond a mere editorial update, the reform adapts these frameworks to new digital practices, broadens their scope, and raises the level of requirements, particularly in terms of security.

Published in the Official Journal on May 23, 2026, the new methodologies came into effect upon their publication. For reference, MR-001 pertains to research requiring the collection of the individual’s consent, while MR-003 addresses research that does not require the collection of consent. 

This article summarizes the major developments, the implementation timeline, and the practical consequences for the entities involved.

I. The reference methodologies and their new exhibits

Reference methodologies allow the data controller to declare the compliance of a research project when it adheres to the entirety of the applicable methodology: in this context, a simple declaration of compliance is sufficient. In the absence of this, as soon as any one of these provisions is not respected, a request for authorization from the CNIL will be mandatory.

The main structural innovation lies in the introduction of two common annexes to the two methodologies2, one relates to security, the other to quality control. These annexes are not mere recommendations: compliance with them is a condition for conformity. Indeed, research is only compliant with its methodology if it also adheres to these two documents.

II. A clarified scope

1. Research conducted abroad

The methodology now expressly admits research conducted abroad: research carried out by a data controller established in France concerning individuals not residing in France may benefit from this, provided that the applicable sectoral regulation in their country of residence does not require the collection of consent for MR-003 (or, conversely, requires it for MR-001). For the rest, the methodology remains applicable according to the connection criteria of the “Informatique et Libertés” law: establishment of the data controller in France or residence in France of all or part of the individuals concerned.

2. Joint liability between data controllers

The deliberations also incorporate joint liability among multiple data controllers3. In accordance with Article 26 of the GDPR, they must transparently define their respective obligations.

3. An opening to health products specific to MR-001

The MR-001 now explicitly covers clinical investigations of medical devices and performance studies of diagnostic medical devices in vitro (MD-IVD) requiring the collection of consent4. Unlike the MR-001, the MR-003 does not target clinical investigations of medical devices or performance studies of MD-IVD. 

The exclusions from the scope are specified: required consent, high residual risk, matching with databases governed by a legislative or regulatory act and the central SNDS, processing of the NIR.

III. Expanded data, compartmentalized access

The list of data that can be mobilized under the MR is expanding: sexual orientation, geographical origin and place of residence, household income by brackets, as well as the search for vital status by consulting the INSEE death register. This broadening calls for heightened vigilance regarding the principles of necessity and minimization: each category of data processed must remain justified in light of the purpose of the research, in accordance with the provisions of the GDPR.

In return, access to the data is more rigorously regulated5. The logic of a restrictive list of recipients is abandoned in favor of access determined by the tasks assigned (monitoring, administrative tasks, information, quality control). General principles apply to all recipients: authorization, access limited to only the data necessary for the task, professional secrecy, and security. Above all, the same actor cannot, in principle, access both administrative data and research data simultaneously, and any accumulation of tasks requires measures for physical, organizational, and compartmental separation. For many organizations, this necessitates a reassessment of the authorization schemes between clinical teams, support functions, and service providers.

IV. A modernized information for individuals

The new methodologies establish the possibility of providing information in a dematerialized manner, aligning the law with already widespread practices6. Deferred information to the legal representatives of the data subject is provided for when the patient is not in a condition to receive the information. An exception governs the information of both holders of parental authority when the second cannot be consulted within a timeframe compatible with the research. Furthermore, new GDPR mentions are added.

This relaxation of the modalities does not reduce the level of proof expected: the data controller must remain able to demonstrate effective, intelligible, and secure information.

V. Security, subcontracting, and transfers: an elevated level of requirement

Taking into account aspects related to data security constitutes the most demanding aspect of the reform. The dedicated annex consolidates previously scattered measures and adds new ones, including the use of a non-significant code for participant identification and multi-factor authentication. The current context explains this tightening: indeed, the CNIL recorded 547 notifications of health data breaches in 2024, compared to 16 in 20187.

The regulation of subcontracting is also strengthened: auditing of each subcontractor, recognition of codes of conduct as a tool for demonstrating the guarantees provided by subcontractors, and an obligation for the direct subcontractor to keep updated information regarding subsequent subcontractors. In terms of transfers outside the European Union, the transfer of administrative data is permitted under certain conditions, in compliance with Chapter V of the GDPR.

VI. Implementation timeline and practical consequences

1. The implementation timeline

The new methodologies do not only concern future research8. On the contrary, it is necessary to distinguish several situations.

  • Investigations initiated as of May 23, 2026. They must comply with the new methodologies and their annexes (§ 91).
  • Ongoing investigations reported under the 2018 version. They may continue in compliance with the provisions of the 2018 version (§ 90). Transitioning to the 2026 version is not required in this regard.
  • Prior compliance declaration from 2018. The data controller is not required to re-declare its compliance, provided that the research initiated after the entry into force complies with the new methodology (§ 91).
  • Substantial modification of a research conducted following an authorization. When research previously authorized by the CNIL undergoes a substantial modification and becomes compliant with the new methodology, no new authorization request is required (§ 92).
DeadlineObligation
May 23, 2026Entry into force. Research initiated from this date complies with the new methodologies and their annexes.
January 1, 2027Authentication Multi-factor Required for web access.
May 2027Deadline for the security action plan for ongoing research.
January 1, 2028Authentication Multi-factor Required for other accesses.

2. The practical consequences for organizations

Promoters, healthcare institutions, service providers, and research industries have a vested interest in promptly initiating a review of their systems. The main areas of focus are as follows :

  • Qualify each search In light of MR-001 or MR-003, by verifying the eligibility of research conducted abroad and, for MR-001, those concerning medical devices.
  • Prioritize security : Deploy multi-factor authentication within deadlines, implement non-significant code, encryption, access management, and logging, and establish an action plan for ongoing investigations.
  • Review the authorizations and the compartmentalization accesses between missions, in order to identify and correct the previously less visible areas of overlap.
  • Update the information of individuals : notices, GDPR mentions, dematerialized information, and applicable exemptions.
  • Securing subcontracting : Auditing subcontractors, supervising subsequent subcontractors, and considering adherence to a code of conduct.
  • Secure transfers outside the EU of administrative data through appropriate safeguards.
  • Update the documentation : processing register, impact assessment, and compliance checklist. 

VII. Compliance

Compliance in terms of security is the most demanding aspect, due to the timeline for multi-factor authentication and the action plan imposed for ongoing investigations.

Compliance with a methodology now implies adherence to its two annexes. These requirements must be integrated from the design phase of the research, as early as possible.

The firm Aumans Attorneys, specialized in health data law, assists research stakeholders in ensuring their processing complies with MR-001 and MR-003: qualification of research, review of access and subcontracting, documentation, and anticipation of security deadlines.


  1. Deliberations No. 2026-049 (Security Annex), No. 2026-050 (MR-001, repealing Deliberation No. 2018-153), No. 2026-051 (MR-003, repealing Deliberation No. 2018-154), and No. 2026-052 (Quality Control Annex), all dated 19 March 2026 and published in the Journal officiel on 23 May 2026. ↩︎
  2. “Security” Annex: Deliberation No. 2026-049; “Quality Control” Annex: Deliberation No. 2026-052. ↩︎
  3. Reference Frameworks, Part II, Section 2 (joint controllership within the meaning of Article 26 of the GDPR). ↩︎
  4. Under the applicable sector-specific legislation, MR-001 refers to Regulations (EU) 2017/745 (Medical Devices Regulation – MDR) and 2017/746 (In Vitro Diagnostic Medical Devices Regulation – IVDR), whereas MR-003 does not. ↩︎
  5. Reference Frameworks, Part VII, Sections 28 to 41 (general principles applicable to all recipients in Section 30; prohibition of simultaneous access in Section 31; combination of roles in Sections 36 to 41). ↩︎
  6. Reference Frameworks, Part VIII, Sections 45 to 54. ↩︎
  7. “Security” Annex (Deliberation No. 2026-049). Statistics published by the CNIL. ↩︎
  8. Reference Frameworks, Part XVII, Sections 89 to 92. ↩︎

AUMANS AVOCATS (formerly FOUSSAT AVOCATS & DEROULEZ AVOCATS)
AARPI
Paris +33 (0)1 85 08 54 76 / Lyon +33 (0)4 28 29 14 92 /
Marseille 
+33 (0)4 84 25 67 89 / Bruxelles +32 (0)2 318 18 36

Contact us

Categories

Share

Related Articles