Research & clinical trials · legally led data-protection governance
Research Data & Clinical Trials, data-protection governance, legally led
Research with health data needs more than a study protocol: the HRA, the ethics committee, GDPR research law and the clean separation of identity from data must all fit together. We lead this governance on the legal side. And as a Trusted Third Party we hold the linking keys separately from the research team. One partner for research units, trial sponsors, CROs, academic centres and biobanks.
legally led (Dr. iur., CIPP/E)Trusted Third Party + DPO from one partnerDE · FR · EN
Orientation, not legal advice. Research with personal data in Switzerland and the EU sits under several interlocking regimes. We verify scope and legal bases per study.
In Switzerland the Human Research Act (HRA) governs research involving persons, their data and biological material. It generally requires authorisation by a competent ethics committee, informed consent in a defined form and clear rules on when data may be coded, anonymised or further used. The HRA and its ordinances operate alongside the revised Data Protection Act, not instead of it.
Under EU law health data falls within the special categories of Art. 9 GDPR. Processing it is in principle prohibited and permitted only through narrowly defined exceptions, such as explicit consent or scientific research. For the latter, Art. 89 GDPR provides a dedicated privilege with appropriate safeguards, in particular data minimisation and pseudonymisation. This research privilege is powerful but tied to conditions that must be cleanly documented.
Secondary use is delicate: data collected for care or an earlier study is to be used for a new research question. Here the reach of the original consent, the compatibility of the new with the old purpose and the safeguards in place decide whether the further use is permissible. We assess this question on the legal side, instead of engineering around it.
Finally, the distinction between anonymisation and pseudonymisation is central. True anonymisation takes data out of data-protection law but is technically and legally demanding and, with rich health data, often not fully achievable. Pseudonymisation separates identity from data through a key, yet the data remains personal data. Whoever controls the key controls the re-identification risk. And that is exactly where our role as a Trusted Third Party begins.
TTP and DPO from one partner, what SIDD delivers
We combine two roles that research usually buys separately: independent key custody as a Trusted Third Party and ongoing data-protection advice as an external data-protection adviser or DPO.
As a Trusted Third Party we take on pseudonymisation and the separate custody of the linking keys. The research team works with pseudonymised datasets, while the table linking pseudonym to identity sits with us, organisationally and technically separated from the research operation. Re-identification, for example for a necessary feedback to trial participants or an officially ordered procedure, only happens under clearly defined, documented rules. The re-identification risk thus drops structurally, not just on paper.
As an external data-protection adviser under the nFADP and as a DPO under Art. 37 GDPR we accompany the study across its lifecycle. We produce the data-protection impact assessment for the research project, check the legal basis and reach of consent, advise on the compatibility of a secondary use and support the correspondence with the ethics committee on the data-protection side. Where an EU or UK representative is required, we cover that role too.
Research lives on data flows between sponsor, CRO, investigator sites, academic partners and biobanks, often across borders. We design the necessary agreements: data-processing agreements, data-transfer and data-sharing agreements, joint-controllership arrangements and the safeguarding of international transfers with the appropriate guarantees. This makes the data flow in a multi-centre project contractually clean and auditable.
Why SIDD for research data, law, technology and custody in one
In research, three things together decide the risk: the legal basis, the technical separation of identity from data and an independent custody. We unite all three in one mandate, a combination that purely legal firms and purely technical providers rarely offer.
Legally led
The HRA, GDPR Art. 9 and Art. 89, the reach of a consent and the permissibility of secondary use are legal questions. We lead them with doctorate-level lawyers holding CIPP/E, backed by an in-house technical team. So the assessment stays solid and not just a technical assumption.
Trusted Third Party for the keys
We hold the linking keys separately from the research team. This makes the separation of identity from data not just a promise in the protocol but enforced organisationally and technically. Re-identification only happens under documented rules, a strong argument towards the ethics committee, participants and supervision.
DPIA & study governance
We produce the data-protection impact assessment for the research project and run the data-protection governance across the study lifecycle, from the protocol phase through ongoing processing to archiving or deletion. So the data-protection documentation fits the ethics-committee submission instead of trailing behind it.
Contracts for multi-centre projects
Sponsor, CRO, investigator sites, academic partners and biobanks need workable data flows. We design data-processing, data-sharing and transfer agreements and joint-controllership constructions and safeguard international transfers with the appropriate guarantees, contractually clean instead of improvised.
Integration with ISO 27001
Research data deserves a maintained security level. We attach the study's data-protection measures to an existing or newly built ISO 27001 ISMS. So access control, key management and evidence-keeping become part of a managed system rather than one-off measures.
Multilingual & independent
We work in German, French and English, relevant for French-speaking Switzerland, international sponsors and EU partner sites. Because we sell no in-house SOC and keep key custody independent from the research team, our assessment and our role stay neutral.
Entry: research-data governance assessment
Research-data governance assessment
Fixed fee per study or programme
Baseline for a research project or study programme: where does your project stand against the HRA, ethics requirements, GDPR research law and the expectations for pseudonymisation and data flows? With a board- and committee-ready report.
Review of legal basis, reach of consent and HRA classification of the project
Assessment of anonymisation versus pseudonymisation and the re-identification risk
Assessment of the permissibility of a planned secondary use
Draft of a data-protection impact assessment for the research project
Overview of the required data, transfer and processing agreements
Prioritised action plan and a board- and committee-ready report
Ongoing mandate: as a Trusted Third Party we hold the linking keys separately from the research team and accompany the study as external data-protection adviser or DPO across its whole lifecycle.
Pseudonymisation and separate custody of the linking keys
Documented rules and logging of every re-identification
Ongoing DPO and data-protection advice across the study lifecycle
Maintenance of the data, transfer and processing agreements with all partners
Integration with ISO 27001 / ISMS for access control and evidence-keeping
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For the data-protection impact assessment of your research project, concretely: LexCommand backs every statement on the HRA, GDPR Art. 9 and Art. 89 and on the permissibility of secondary use with the exact primary source, and lays the interlocking HRA and GDPR duties side by side, so the report stays ethics-committee-ready and auditable.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
What does Trusted Third Party mean in a research project in practice?
We act as an independent party between identity and research data. We pseudonymise the data and hold the table linking pseudonym to identity separately from the research team. The team works only with pseudonymised datasets. Re-identification happens exclusively under rules defined in advance and documented. The separation is thus enforced organisationally and technically, not just a commitment in the protocol.
Is pseudonymisation enough or must we fully anonymise?
It depends on the project. True anonymisation removes the data from data-protection law but, with rich health data, is often not fully achievable and can limit scientific usability. Pseudonymisation preserves linkability for legitimate purposes yet keeps the data as personal data. We assess per study which path is legally sound and scientifically practical, and document the re-identification risk in a traceable way.
Can we use existing care or study data for a new research question?
That is the question of secondary use and must be verified case by case. The reach of the original consent, the compatibility of the new with the previous purpose and the safeguards in place are decisive. Depending on the constellation, HRA rules on further use, a renewed or extended consent or the research privilege come into play. We assess the permissibility on the legal side and document the basis in an auditable way.
Do you handle the correspondence with the ethics committee?
We support the data-protection side of the submission and correspondence: the data-protection impact assessment, the description of processing, the pseudonymisation concept and the agreements between the parties involved. The scientific and ethical justification of the project stays with the investigators and sponsors. We make sure the data-protection parts are coherent and complete.
How do you handle international data flows between sponsor, CRO and investigator sites?
We first map the data flow and assign the roles: who is controller, who processor, where joint controllership exists. On that basis we build the appropriate agreements, data-processing, data-sharing and transfer agreements, and safeguard transfers to third countries with the suitable guarantees. The data flow of a multi-centre project is thus contractually clean and demonstrable to supervision.
Does SIDD also advise under legal confidentiality?
Where a SIDD lawyer advises in a legal capacity, your information may be covered by professional secrecy under Art. 321 of the Swiss Criminal Code, in addition to contractual confidentiality. We clarify the exact scope per mandate, precisely because research data is especially sensitive.
Ready for a research-data governance assessment?
We assess your research project, HRA classification, GDPR research law, pseudonymisation and data flows, with a board- and committee-ready report. As a Trusted Third Party we hold the keys separately from the research team on request.