This section explains standards, regulations, and frameworks that shape
clinical research data. Clinical Research Data Management Guide does not
create standards — we explain established ones and point to their
authoritative sources.
Clinical Research Data Management Guide provides educational information
and is not legal, regulatory, compliance, or security advice. Whether and
how any standard applies depends on your study and organization's
specific circumstances.
21 CFR Part 11
FDA regulations for electronic records and electronic signatures in FDA-regulated research — the reason audit trails, e-signatures, and validation dominate EDC conversations.
Who should care: Anyone running or supporting FDA-regulated studies; anyone evaluating EDC or eClinical vendors.
What you need to know
Part 11 applies when electronic records or signatures are used to satisfy FDA requirements — most drug and device trials under an IND or IDE, but not most non-regulated academic research.
It requires computer-generated, time-stamped audit trails, controlled system access, and electronic signatures that are legally bound to their records.
Compliance belongs to the regulated organization, not the vendor. "Part 11 compliant software" is a capability claim; your validation, SOPs, and training complete the picture.
FDA's scope-and-application guidance narrows enforcement to records required by predicate rules — which is why understanding what your protocol and regulations require comes first.
The international Good Clinical Practice guideline — the quality standard for designing, conducting, recording, and reporting trials involving human participants.
Who should care: Everyone working on interventional clinical trials; data managers implementing data integrity and oversight expectations.
What you need to know
GCP is the shared quality framework regulators in the U.S., EU, Japan, and beyond expect for clinical trials — protecting participants and ensuring data credibility.
The E6(R3) revision emphasizes quality by design, risk-proportionate approaches, and fitness of data — moving away from checking everything toward managing what matters.
For data management, GCP expectations show up as data integrity (ALCOA+ principles), documented system validation, access control, and traceable corrections.
GCP is a guideline adopted into regulation differently by each authority — how it binds you depends on where and under what authorization your study runs.
U.S. federal privacy and security rules for protected health information — which reach clinical research when data comes from or through covered entities.
Who should care: Researchers recruiting through hospitals and clinics; anyone evaluating vendors that may store identifiable health data.
What you need to know
HIPAA binds "covered entities" — providers, plans, and clearinghouses — and their business associates. Research teams inside a hospital or academic medical center are usually working with PHI under it.
Research use of PHI generally requires participant authorization, an IRB or privacy-board waiver, or de-identification under the Safe Harbor or Expert Determination standards.
A vendor holding identifiable participant data for a covered entity is a business associate and must sign a business associate agreement (BAA). No BAA, no deal.
Even when HIPAA does not apply, other rules — the Common Rule, state law, GDPR for EU participants, sponsor contracts — may. "HIPAA doesn't apply" starts a privacy analysis; it doesn't end one.
The European Union's General Data Protection Regulation — comprehensive rules for processing personal data, with specific provisions for scientific research and health data.
Who should care: Studies enrolling participants in the EU/EEA or transferring EU participant data elsewhere; sponsors and vendors serving international trials.
What you need to know
GDPR applies to personal data of people in the EU/EEA regardless of where the sponsor or database sits — a U.S. sponsor running EU sites is in scope.
Health and genetic data are "special categories" needing an explicit legal basis; research consent under GDPR is a separate question from informed consent to participate.
Key-coded (pseudonymized) trial data is still personal data under GDPR — only truly anonymous data escapes it, a higher bar than HIPAA de-identification.
Cross-border transfers out of the EU need a lawful mechanism (adequacy, standard contractual clauses, and supporting safeguards) — worth confirming with any vendor hosting EU data.
The U.S. federal policy for the protection of human subjects (45 CFR 46) — IRB review, informed consent, and continuing oversight for federally supported research.
Who should care: Federally funded investigators and their institutions; anyone designing consent and data-protection plans.
What you need to know
The Common Rule governs research on human subjects conducted or supported by most U.S. federal agencies — and most institutions apply it to all their human research.
It requires IRB review, informed consent with specific required elements, and provisions to protect participant privacy and maintain data confidentiality.
The 2018 revision added consent provisions for future research use of identifiable data and biospecimens — directly shaping how research data can be reused and shared.
FDA-regulated research follows FDA's parallel human-subject rules (21 CFR 50 and 56); many studies must satisfy both regimes at once.
The data standards suite for clinical research — CDASH for collection, SDTM for tabulation, ADaM for analysis, and ODM for interchange — required for FDA and PMDA submissions.
Who should care: Sponsors preparing regulatory submissions; data managers who want collection that maps cleanly to submission datasets.
What you need to know
FDA and Japan's PMDA require study data in CDISC formats (SDTM and ADaM) for most new drug and biologic submissions — this is not optional for those pathways.
CDASH standardizes what you collect and how fields are named on CRFs; starting there makes the downstream mapping to SDTM far cheaper than retrofitting.
ODM is the machine-readable interchange format for study metadata and data — the plumbing behind study build portability and some system integrations.
Even outside regulated submissions, CDISC alignment makes data more reusable and shareable — and several funders and repositories now encourage it.
NIH's policy requiring a Data Management and Sharing Plan — and budgetable data-management costs — for all NIH-funded research generating scientific data.
Who should care: NIH-funded investigators and their institutions; anyone planning repositories, formats, and sharing timelines.
What you need to know
Since January 2023, NIH applications generating scientific data must include a Data Management and Sharing (DMS) Plan — and compliance is a term of award.
Plans cover data types, standards, timelines, repositories, and access considerations; sharing is expected no later than publication or the end of the award.
Reasonable data-management and sharing costs are allowable in the budget — a rare case where doing data management well is explicitly fundable.
Participant protections still govern: consent language, de-identification, and controlled-access arrangements determine what can actually be shared.
Findable, Accessible, Interoperable, Reusable — guiding principles for making research data usable by people and machines beyond the team that created it.
Who should care: Investigators planning data sharing; repositories and platforms positioning data for reuse.
What you need to know
FAIR is a set of principles, not a standard or a certification — there is no FAIR badge to buy, only practices that make data more reusable.
In practice FAIR means persistent identifiers, rich machine-readable metadata, standard vocabularies (like CDISC), and clear licenses and access conditions.
"Accessible" does not mean "open": FAIR explicitly accommodates controlled access, which is how identifiable or sensitive clinical data is shared responsibly.
Funders increasingly reference FAIR — NIH's sharing policy and many EU programs among them — so it is becoming review language, not just aspiration.
An auditing framework in which an independent auditor examines a service organization's controls for security, availability, and related criteria.
Who should care: Buyers assessing a vendor's security posture; a SOC 2 report is evidence, not a government certification.
What you need to know
A SOC 2 is an independent auditor's report on a vendor's controls — evidence of security practices, not a government certification or a pass/fail license.
Type I examines control design at a single point in time; Type II tests whether controls actually operated over a period of months. Ask for Type II.
Security is the only required criterion — availability, confidentiality, processing integrity, and privacy are optional add-ons, so ask which were covered.
Ask to read the actual report (vendors usually share it under NDA). The exceptions and auditor notes tell you more than the badge on the website.
The Web Content Accessibility Guidelines — the widely referenced standard for making web software usable by people with disabilities.
Who should care: Anyone whose staff or participants use web software; relevant to ePRO, eConsent, and participant portals.
What you need to know
The global reference standard for accessible web software, with three conformance levels — Level AA is the common target in policy and procurement.
Covers the things that determine whether staff and participants with disabilities can actually use a system: keyboard operation, screen-reader compatibility, contrast, focus visibility, forms, and error handling.
Often legally relevant: U.S. federal procurement (Section 508) maps to WCAG, many institutional contracts require it, and ADA claims frequently reference it.
When evaluating vendors, ask for an accessibility conformance report (ACR/VPAT) — and remember your participants, not just your staff, use the ePRO apps and portals the vendor provides.
What FDA's electronic records and electronic signatures rule actually requires, when it applies to clinical research and when it doesn't, why no product is simply 'Part 11 compliant' on its own — and the questions to ask a vendor.