Data Privacy in Clinical Trials: GDPR Meets DSG
Multi-jurisdictional clinical research faces an increasingly complex web of data protection requirements. How do GDPR and the Swiss DSG intersect, and where do they diverge?
Health data is the most heavily regulated category of personal data on both sides of the Atlantic, and for a US company with European operations the GDPR and the Swiss DSG are only the start. The European Health Data Space compels secondary-use access from 2029, the EU Data Act overrides much of what a standard cloud contract says about access and switching, transatlantic transfers rest on a Data Privacy Framework whose premises a US Supreme Court ruling has unsettled, and the Digital Omnibus would rewrite the GDPR's own definitions without yet being law. The analyses below cover trial data under two regimes, cloud contracts across jurisdictions, Swiss professional secrecy against US e-discovery, and the reforms that decide what a compliance program can plan for and what it cannot.
9 insights ยท latest July 2026
Multi-jurisdictional clinical research faces an increasingly complex web of data protection requirements. How do GDPR and the Swiss DSG intersect, and where do they diverge?
One HFG informed-consent form does not discharge the DSG duties attaching to the same sensitive health data. For US sponsors, the unresolved legal-basis question surfaces in protocol design and site contracts, not during the trial.
The European Health Data Space compels holders to make health data available through public access bodies, from 2029 for general records and 2031 for genomic and clinical-trial data; a US biotech's EU subsidiary may itself be a holder.
The EU-US Data Privacy Framework rests on the independence of three American institutions, and the 2026 Supreme Court ruling on at-will removal of Federal Trade Commission members unsettles that premise for companies that retired their standard contractual clauses.
The Digital Omnibus would make the GDPR's personal-data definition relative to the holder, put AI training on an express legitimate-interest footing, and route cookie consent into a new Art. 88a GDPR. None of it is yet law.
The EU Digital Omnibus moves at two speeds: an adopted AI Act track defers high-risk deadlines to December 2027 and August 2028, while the GDPR, ePrivacy and Data Act rewrite remains an unagreed proposal.
When your data resides in multiple jurisdictions simultaneously, which law governs? Cloud service agreements often create legal uncertainties that surface only during disputes.
The EU Data Act has applied since 12 September 2025 to any provider serving Union customers, wherever established, and its switching, access and unfair-terms rules override much of what standard US cloud and connected-product contracts still say.
Swiss professional secrecy meets US e-discovery: criminal exposure for compliance, sanctions for refusal. Strategies for life sciences companies.
Counsel on this topic: Health-data & research-data law.
Good questions deserve specific answers.
Get in Touch