MR-003: The Complete Guide to Understanding and Applying This CNIL (National Commission for Information Technology and Civil Liberties) Reference Methodology
MR-003 is the reference methodology approved by the CNIL (National Commission for Information Technology and Civil Liberties) Decision No. 2018-154 of May 3, 2018. It provides a framework for health research conducted without obtaining consent. In return, a commitment to compliance is required. Do you want to launch a clinical study without obtaining written consent? MR-003 is likely the framework you need. However, it imposes strict rules. This guide explains how to apply it correctly.
Contents
1. What is MR-003? Definition and role within the CNIL (National Commission for Information Technology and Civil Liberties) framework
MR-003 occupies a specific place within the CNIL (National Commission for Information Technology and Civil Liberties) ecosystem. It complements other methodologies and falls within the framework of GDPR. To fully understand its role, it should be compared to MR-001, which covers research involving the collection of consent. MR-003 addresses the other side of the spectrum. Consent is not required.
Dipeeo assists research organizations in achieving compliance through an outsourced DPO specialised medical research.
1.1. The CNIL (National Commission for Information Technology and Civil Liberties) Reference Methodologies CNIL (National Commission for Information Technology and Civil Liberties) What Are They Used For?
Reference methodologies are frameworks pre-approved by the National Commission for Information Technology and Civil Liberties. They outline in advance the conditions for compliant data processing. The data controller signs a compliance agreement. The data controller then carries out the research without obtaining individual consent.
The requirements are strict: every condition set by the CNIL (National Commission for Information Technology and Civil Liberties) be met. The documentation must demonstrate compliance. As soon as a project falls outside these parameters, a standard authorization request becomes necessary again.
1.2. MR-003 in a nutshell: health research without explicit consent
MR-003 governs the processing of health data in the public interest, carried out as part of research involving human subjects. It applies to research for which patient consent is not required, provided that:
He has been informed.
That he did not object to her participation.
Please note: Even when consent is not required, the patient must be informed. The patient receives a detailed notice regarding the use of their data and may object at any time. If the patient objects, the data controller must comply with this decision.
1.3. How MR-003 Differs from Other Methodologies (MR-001, MR-002, MR-004)
Noninterventional Studies of In Vitro Diagnostic Medical Devices
Individual Information
No. 2016-264, dated July 21, 2016
MR-003
Research Involving Human Subjects Without Informed Consent
Not required; right to object
No. 2018-154, dated May 3, 2018
MR-004
Research Not Involving Human Subjects, Studies, and Evaluations
Not Required, Information and Objection
No. 2018-155, dated May 3, 2018
If your study involves the reuse of data that has already been collected, you will fall under MR-004 rather than MR-003.
2. Is your organization eligible for MR-003?
2.1. The 4 types of research covered by MR-003 according to the CNIL (National Commission for Information Technology and Civil Liberties)
The methodology does not apply to all health research. The CNIL (National Commission for Information Technology and Civil Liberties) ts CNIL (National Commission for Information Technology and Civil Liberties) use to four specific categories:
noninterventional research as provided for in Article L. 1121-1(3) of the Public Health Code;
interventional research involving minimal risk and minimal burden, following review by the Institutional Review Board;
cluster clinical trials of drugs;
certain research projects requiring an examination of genetic characteristics, in accordance with Article L. 1131-1-1 of the CSP.
In any case, the obligation to provide information and the right to object remain in effect.
2.2. The principle of no consent: what the Jardé Act and the GDPR
Two legal provisions allow researchers to proceed without written consent in certain health research studies.
The first is the Jardé Act (Law No. 2012-300 of March 5, 2012). It classifies research involving human subjects into three categories—RIPH 1, 2, and 3—based on the level of risk to the patient.
RIPH 1 encompasses traditional interventional research.
RIPH 2 covers those with minimal risks and constraints.
RIPH 3 focuses on non-interventional research.
For RIPH 2 and 3, written consent is not required: clear information and the right to object are sufficient. This is precisely the scope of MR-003.
The second piece of legislation is the GDPR. It permits the processing of health data for research purposes in the public interest (Article 9(2)(j)). In practical terms, this means that the “legal basis” for the processing is not the patient’s consent, but the public interest objective pursued by the research.
2.3. The cumulative requirements that must be met
Several conditions must be met, without exception:
a demonstrable public interest;
a research protocol that has been scientifically validated prior to implementation;
the appointment of a Data Protection Officer (DPO);
a compliance commitment filed with the CNIL (National Commission for Information Technology and Civil Liberties).
Dipeeo Tip: The CNIL (National Commission for Information Technology and Civil Liberties) conduct an audit at any time and require proof that each condition has been met. Document everything from the very start of the protocol.
3. What types of data can be processed under MR-003?
3.1. Permitted Health Data: List and Sensitivity Rules
The list of permitted data is exhaustive. It is set forth in Resolution No. 2018-154. The following, among others, are permitted:
the data strictly necessary to conduct the research;
the patient's age and family situation;
lifestyle habits;
the relevant information from the medical record.
Any data not included in this list is excluded. Furthermore, the presentation of the results must never allow for the direct or indirect identification of the individuals participating in the research.
3.2. The relevant administrative and identification data
To identify patients, MR-003 requires a serial number or an alphanumeric code. The following are excluded:
the patient's first and last name;
the registration number in the National Registry of Natural Persons (NIR).
The CNIL (National Commission for Information Technology and Civil Liberties) using only initials, followed by a registration number. The mapping table that links the code to the actual identity must be stored securely. Only professionals speaker research speaker the research site may access it.
3.3. Data retention periods Data retention by the CNIL (National Commission for Information Technology and Civil Liberties)
, the CNIL (National Commission for Information Technology and Civil Liberties) guideline CNIL (National Commission for Information Technology and Civil Liberties) personal Data retention periods, sets out specific rules:
Patient data: 2 years in the active database following the most recent publication, followed by archiving for up to 20 years;
Data on professionals speaker the study: 15 years after the end of the last study.
These time periods must be recorded in your log and be verifiable.
4. What obligations does your organization have under MR-003?
4.1. Notification of Data Subjects: Form, Content, and Proof
Individual notices are mandatory. They must include all the information required by Article 13 of GDPR
the identity of the data controller;
the purposes and legal basis of the processing;
the recipients of the data;
the Data retention period Data retention
the rights that the Data subject may exercise Data subject
the DPO's contact information.
For low-risk interventional research, collective informed consent is permitted. This requires prior approval from the human subjects protection committee, in accordance with Article L. 1122-1-4 of the Public Health Code. Proof that the information was provided must be retained.
4.2. The Right to Object: How to Organize and Track It
In the absence of consent, the right to object becomes the cornerstone of the system. It must be effective. This requires:
a documented procedure that is easily accessible to the patient;
a clearly identified point of contact;
an internally defined response time;
traceability of the objections raised.
If a patient objects, their data must be removed from the processing, unless otherwise provided by law.
4.3. Security Measures Specific to Health Data
Health data is considered sensitive under Article 9 of GDPR. MR-003 therefore imposes stricter rules:
Only professionals speaker the speaker research can access the cross-reference table.
4.4. What Your Data Processing Record Must Include
For a study conducted under MR-003, the registry must include the following:
The Purpose the research;
the legal basis for the processing;
the categories of people affected;
the categories of data collected;
the recipients of the data;
Data retention periods Data retention
any transfers outside the European Union;
the security measures that have been put in place.
It also documents the compliance agreement signed with the CNIL (National Commission for Information Technology and Civil Liberties) the data protection impact assessment (DPIA) that was conducted.
5. How to Interpret the CNIL (National Commission for Information Technology and Civil Liberties) Documents CNIL (National Commission for Information Technology and Civil Liberties) MR-003
5.1. The Concept of “Public Interest Research”: Where Does Interpretation End?
The public interest is a central—and often misunderstood—concept. It is not limited to public institutions. Research conducted by a private entity may serve the public interest, provided that it pursues objectives that benefit public health, the quality of care, or the evaluation of practices. The CNIL (National Commission for Information Technology and Civil Liberties) each case individually, based on the research protocol and the Purpose .
5.2. The distinction between MR-003 and a CNIL (National Commission for Information Technology and Civil Liberties) authorization
As soon as a condition is not met, you fall outside the scope of MR-003. The CNIL (National Commission for Information Technology and Civil Liberties) then CNIL (National Commission for Information Technology and Civil Liberties) a standard authorization request. This is the case when individual-level data cannot be used and an opinion from the CPP is required. It also applies to studies involving identifiable genetic data or health data repositories.
5.3. The 3 Common Mistakes Made by Research Organizations
Confusing a commitment with authorization: The simplified declaration is not a blank check; it is a commitment that can be verified.
Collecting too much data: MR-003 requires data collection to be minimized. Data not included in the list is prohibited.
Failing to ensure the traceability of the right to object: this is precisely what the CNIL (National Commission for Information Technology and Civil Liberties) in CNIL (National Commission for Information Technology and Civil Liberties) .
6. How Dipeeo Supports Research Organizations Working on MR-003
6.1. From Eligibility to Documentation: Our Method in Practice
Dipeeo serves as an outsourced DPO outsourced university hospitals, clinical research organizations, and healthcare companies. Our process always begins with an MR-003 eligibility audit to verify that your project falls within the scope of the methodology. Once this foundation is established, we take over responsibility for the key deliverables:
drafting the “personal data” section of the research protocol;
the patient information sheet;
the data protection impact assessment (DPIA) required by Article 35 of GDPR
the compliance declaration to be filed with the CNIL (National Commission for Information Technology and Civil Liberties).
6.2. An outsourced DPOspecialised and medical research
Specifically, our legal experts and former attorneys begin with an audit questionnaire designed specifically for medical research. Based on your responses, we develop a customized action plan that aligns with the requirements of the CNIL (National Commission for Information Technology and Civil Liberties), the Public Health Code, and the GDPR.
7. Key Takeaways
The MR-003 is a simplification tool approved by the CNIL (National Commission for Information Technology and Civil Liberties) health-related research that does not require consent. In exchange, it requires individual notification, a traceable right to object, a personal data protection plan (AIPD), an up-to-date registry, and strict compliance with Resolution 2018-154.
Are you launching a study and want to verify your eligibility for MR-003? The Dipeeo teams will support you from the audit through to the compliance commitment. Talk to an outsourced DPO expert → Dipeeo
8. Frequently Asked Questions
Does MR-003 apply to retrospective studies based on medical records?
Not always. A purely retrospective study based on data that has already been collected generally falls under MR-004. MR-003 applies to research involving human subjects, even in the absence of any intervention.
Is it necessary to report your data processing to the CNIL (National Commission for Information Technology and Civil Liberties) you use the MR-003?
Yes. The data controller submits a simplified declaration of compliance. No attachments are required, but the documentation must remain available in the event of an audit.
What happens if a patient objects after the study has begun?
The data must be removed from processing, unless otherwise required by law. The objection must be recorded in the register.
Is the MR-003 compatible with data transfers outside the EU?
Yes, under strict conditions. Only anonymous or indirectly identifiable data may be transferred outside the European Union, subject to the safeguards set forth in Chapter V of GDPR.
What penalties can one face for noncompliance with MR-003?
Up to 20 million euros or 4% of global annual revenue, whichever is greater.