Updated CNIL reference methodologies: towards simpler data processing in research

CNIL updated reference methodologies governing the processing of personal data in research with human participants.

Last updated on 17 August 2026

In brief

  • The French Data Protection Authority (CNIL) published updated versions of the MR-001 and MR-003 reference methodologies (MRs) in May 2026, which govern the processing of personal data in the context of research involving human participants.
  • These new versions provide an updated framework to support current practices in the health research sector: studies conducted abroad, digital information, remote quality control, access to identifying data, etc.

Why update the reference methodologies?

Certain types of health data processing are subject to prior formalities with the CNIL. Depending on the circumstances, this may involve a declaration or an application for authorisation.

The reference methodologies (MRs) apply to studies requiring access to personal health data. There are eight reference methodologies: the first three MRs (MR-001, MR-002 and MR-003) concern research involving human participants (RIPH). The CNIL has also developed specific methodologies for research not involving human participants (MR-004) and studies using certain medico-administrative databases (MR-005 to MR-008).

The CNIL decided to improve its reference frameworks to simplify procedures for health research organisations. It therefore launched a public consultation in May 2024 with the various stakeholders involved in health research. ANRS MIE and Inserm jointly undertook substantive work to identify recurring data protection issues in their research projects.

The contribution of ANRS MIE and Inserm

Inserm’s Data Protection Office (DPO) collected feedback from the Institute’s researchers to report on the most frequent difficulties they encountered when reviewing the various files submitted to the CNIL.

For its part, ANRS MIE’s DPO representatives consulted the agency’s project managers as well as the Methodology and Management Centres (MMCs), which are involved in coordinating and promoting clinical studies. The difficulties reported included those relating to the categories of data collected and the application of sector-specific regulations for research conducted abroad, the secondary reuse of data, and the impossibility of assigning a new identification code when data and samples are reused. As ANRS MIE is highly involved in projects conducted abroad, it particularly emphasised the time required to obtain CNIL authorisation. The updated MRs should now make it easier for such projects to begin.

It should be noted that Inserm’s Clinical Research Division, France Cohortes, IRD and Inserm’s other research departments also took part in the public consultation. The updated MR-001 and MR-003 were published in the Official Journal on 23 May 2026 and entered into force on 24 May 2026.

Who is concerned by the updated MR-001 and MR-003?

All public or private organisations conducting health research involving participants living in France, including sponsors located abroad, whether they are established in the European Economic Area (EEA).

The new framework also ensures consistent application of European rules, even when research participants are abroad and the organisation responsible for the research is established in the EEA.

What are the main changes?

New arrangements for collecting certain data

Under the updated MRs, it is no longer necessary to obtain CNIL authorisation to collect data relating to the sexual orientation and gender of research participants. However, the relevance of collecting these sensitive data in light of the data minimisation principle must still be stated in the data protection impact assessment (DPIA).

Extension of the scope of the MRs

Research conducted in low- and middle-income countries (LMICs) may comply with MR-001 and MR-003 provided that local regulations are respected and subject to verification of the other requirements as part of the data protection impact assessment (DPIA) by the data controller/sponsor.

This point is important for ANRS MIE. Previously, research conducted in an LMIC necessarily had to be subject to CNIL authorisation. The process is now simpler.

Broader access to directly identifying data

New categories of professionals (nurses, psychologists, health coordinators, etc.) may, in the context of research and subject to certain conditions, access directly identifying health data.

These changes will facilitate the inclusion of health-related human and social sciences components in ANRS MIE projects, as well as the collection of samples at home as part of a clinical trial.

Remote quality control

The updated MRs now allow, subject to certain conditions, remote quality controls to be carried out, a revolution for decentralised research, such as telemedicine clinical trials, for example. This measure responds to the increasing digitalisation of studies, particularly since the COVID-19 pandemic.

Strengthening data security

The 2026 MR-001 and MR-003 include an annex on security (MR-SEC), requiring enhanced measures to protect health data, which are classified as sensitive data within the meaning of the General Data Protection Regulation (GDPR).

The main technical requirements concern data encryption, logging, access management (principle of least privilege and strong authentication), secure backups and penetration testing.

In practice, how can the compliance of a research project be checked?

If ANRS MIE is the sponsor of a research project, the project manager responsible for the study at ANRS MIE should be contacted so that the appropriate procedures can be followed. The DPIA remains mandatory under Article 35 of the GDPR. It should be recalled that, until compliance with an MR has been confirmed or CNIL authorisation has been obtained, participant enrolment or data collection cannot begin.

The CNIL has created tools to help check in advance whether research projects comply with the reference frameworks:

 

These checklists do not replace the review and assessment process carried out by ANRS MIE’s DPO contacts or, where necessary, validation by the Inserm DPO unit.

What is the implementation timetable?

All the measures described in this annex must be implemented for research initiated from 23 May 2026 onwards where the data controller wishes to operate under a declaration of compliance. For research already under way on that date, data controllers are invited to define an action plan aimed at implementing these measures as soon as possible and no later than within one year (May 2027).

What benefits are expected for ANRS MIE?

A projection was carried out based on projects sponsored by Inserm ANRS MIE between 2021 and 2025 to assess the benefits of the updated reference methodologies.

With the updated MRs, the estimate shows that the number of applications for CNIL authorisation is expected to decrease by 30%. A sharp increase in compliance with MR-001 and MR-003 was also observed.