What the GDPR means for US Sponsors of Clinical Trials in the EU and in the UK

Why you most likely have to appoint an EU and/or UK data protection representative in order to avoid sanctions under the GDPR

Does the GDPR apply to your clinical trials in the EU and/or in the UK?

  • Are you a US-based sponsor with no establishment in the EU and/or the UK? 
  • Do you conduct clinical trials in the EU and/or in the UK?

If you answered yes to both of these questions, then you most likely fall under the scope of the GDPR and have to appoint an EU-based and/or a UK-based representative for GDPR purposes.

GDPR + AI Act + DSA: What It Means For Non-EU Companies

With the EU AI Act switching on in phases (and enforcement accelerating), many non-EU teams discover a familiar problem: one product can trigger three EU regulatory frameworks at once — and the “forgotten obligation” is often the local representative...

The Data Protection Representative in the EU, UK, and Switzerland: Common Ground and Key Differences

Even when your product, team, and servers sit outside Europe, a data protection representative can be the “forgotten obligation” for companies doing business in the EU, UK, or Switzerland without a local presence. It is a key obligation that helps...

What Is A RoPA? Record Of Processing Activities Under Article 30 GDPR (Including Non-EU Companies)

Article 30 GDPR explained for EU and non-EU organisationsA record of processing activities (often shortened to RoPA) is not a “nice to have”. It is a core GDPR accountability requirement under Article 30 GDPR....

Data protection day

EDPO attended the Data Protection Day organised by the EDPS and the Council of Europe. Here are the key takeaways that stood out for us. The 2026 edition, themed “Reset or refine?”, explored how Europe can...

Digital Clearhouse 2.0

EDPO attended the EDPS Digital Clearinghouse 2.0 Conference in Brussels. Here are the key takeaways that stood out for us. The EU’s Digital Rulebook continues to expand rapidly with the DSA, DMA, Data Act, AI...

ISO 27001 added value

ISO 27001: Security You Can Rely On At EDPO, we provide representative services under Article 27 of the GDPR and other digital regulations. To support this role, and to ensure the highest standards of security...

AI Act: Are you ready?

The AI Act is here. Are you truly compliant? The new European Regulation on artificial intelligence, the AI Act, is redefining how AI may be developed, deployed, and governed across the EU. If your company...

IAPP Data Protection Congress – Brussels

Two days at the IAPP Data Protection Congress 2025 in Brussels. Here are the key takeaways that stood out for us. Over the past forty-eight hours, Brussels gathered thousands of privacy, tech and policy...

IAPP PSR 2025 SAN DIEGO

Two Days at IAPP PSR 2025: Trust, AI, and the Future of Privacy Back from IAPP hashtag#PSR25 in San Diego. Two days packed with sharp minds, hard questions, and a clear sense that our field is evolving faster...

Brussels Privacy Symptomium

EDPO had the pleasure of attending the Brussels Privacy Symposium 2025, organized by the Future of Privacy Forum and Brussels Privacy Hub, a day filled with insightful discussions on the evolving relationship...

Download our White Paper on The GDPR and US Sponsors of Clinical Trials in the EU & the UK

How can EDPO help you?

As your GDPR data protection Representative, EDPO will provide you with the following services (which are all included in our annual fees):

  • The handling of an unlimited number of requests from individuals (data subjects) and from data protection authorities in the EU and/or the UK
  • Assistance with the handling of an unlimited number of data breach notifications to the data protection authorities in the EU and/or the UK
  • The storage of a copy of your Record of processing activities on a platform that has the highest security levels in Europe (ISO27001)
  • Translation of requests and replies (from the initial language into English, and from English back to the initial language)
  • The right to use EDPO’s contact details and logo on your website and on other company material
  • The granting of the EDPO Compliance Certificate
  • Alerts regarding relevant GDPR-related news and developments

Get your Compliance Certificate

  • Lets customers know that your company is accountable and that your compliance with Article 27 of the GDPR is verifiable
  • Creates trust and provides security
  • Informs your business partners that your company complies with the EU’s data protection standards and allows for greater business opportunities
  • Provides your company with a competitive advantage
  • Reduces risks of heavy sanctions that can reach up to EU 20 million or 4% of global turnover, whichever is highest
  • Guarantees authenticity by use of the Smart Certificate™ technology

EDPO helps your US business grow while

protecting EU and UK customers