Biotech Act: a reading through the lens of the Joint Opinion 3/2026

0

The European Biotech Act is one of the most ambitious recent attempts to reorganize the EU regulatory framework for biotechnology and biomanufacturing. Its data-protection architecture is also one of the most consequential, and still relatively under-examined, parts of the proposal. This post analyses that architecture through the lens of EDPB/EDPS Joint Opinion 3/2026 and asks whether the proposed harmonization delivers genuine simplification, or only the appearance of it.

  1. The Proposal at a glance

On 16 December 2025, the Commission published the Proposal for a European Biotech Act, a Regulation aimed at strengthening the Union’s biotechnology and biomanufacturing sectors, including through regulatory simplification and a reduction of administrative burdens. The Proposal amends a wide range of EU instruments, including the Clinical Trials Regulation (hereinafter CTR), the Veterinary Medicines Regulation, the General Food Law Regulation, the Regulation on Advanced Therapy Medicinal Products, the STEP Regulation and the SoHO Regulation. It also introduces new mechanisms for strategic biotechnology projects, innovation-oriented testing environments, data quality initiatives, AI-enabled biotechnology and biodefence.

For data-protection law, the most significant intervention is the proposed rewriting of Article 93 of the Clinical Trials Regulation. The objective is to provide a harmonized Union-level framework for the processing of personal data by sponsors and investigators in clinical trials, thereby reducing the fragmentation that has traditionally affected multi-country studies.

The Proposal also contains other innovation-driven mechanisms with data-protection implications: biotechnology testing environments, biotechnology data quality accelerators, clinical-trial regulatory sandboxes, sandboxes for novel health biotechnology products, electronic informed consent, and provisions on AI-enabled biotechnology projects. Each of these raises a distinct question: does simplification merely reduce formal fragmentation, or does it also make GDPR compliance clearer in practice?

On 10 March 2026, the EDPB and the EDPS adopted Joint Opinion 3/2026. The Opinion broadly supports the objective of harmonizing the data-protection framework applicable to clinical trials, but warns that simplification must not result in a lower level of protection for sensitive health and genetic data. The Opinion therefore provides a useful map for assessing the Proposal’s real impact.

  1. A harmonized legal basis for clinical trials

Under the current framework, the legal basis for processing personal data in clinical trials has been one of the most complex aspects of the interaction between the GDPR and the Clinical Trials Regulation. The difficulty does not stem from the CTR alone, but from the need to distinguish between different categories of processing operations. The EDPB had already clarified in its 2019 Opinion on the interplay between the CTR and the GDPR that the informed consent required under the Clinical Trials Regulation is not necessarily the same as consent under Article 6(1)(a) GDPR. The former is primarily an ethical and regulatory requirement for participation in a clinical trial; the latter is one possible legal basis for data processing. Conflating the two has been one of the recurring sources of uncertainty in clinical research.

The pre-existing framework was also not reducible to a simple choice between consent, public interest and legal obligation. For processing operations linked to reliability and safety purposes, Article 6(1)(c) GDPR could already be relevant. For processing operations more directly related to research activities, different bases could come into play depending on the circumstances, including explicit consent, a task carried out in the public interest, or legitimate interests, together with the relevant Article 9 GDPR conditions for special categories of data.

The proposed new Article 93 CTR seeks to reduce that complexity. For the primary processing operations covered by proposed Article 93(1) and (2) CTR, the Proposal frames the processing of personal data by sponsors and investigators as processing necessary to comply with a legal obligation under Article 6(1)(c) GDPR. For health and genetic data, the Proposal relies on Article 9(2)(i) and Article 9(2)(j) GDPR, respectively concerning public interest in the area of public health and scientific research purposes, subject to suitable and specific safeguards. This should be regarded as a meaningful harmonization move as it potentially narrows the space for divergent national interpretations and reduces one of the persistent sources of friction in cross-border clinical trials. However, the harmonization attempt does not certainly remove the GDPR from the picture, relocating the key compliance questions to the level of necessity, purpose specification, allocation of controllership, safeguards, retention and further processing.

  1. The EDPB/EDPS recommendations

Joint Opinion 3/2026 supports the direction of travel, but it also makes clear that the new architecture will only work if the legal basis is accompanied by sufficiently precise safeguards. The recommendations can be grouped into three main clusters: controllership and accountability; data minimization, retention and further processing; and innovation mechanisms.

3.1 Controllership and accountability

The Proposal designates sponsors and investigators as controllers under the GDPR, but does not fully clarify whether, in specific circumstances, they act as independent controllers or as joint controllers. This distinction matters because Article 26 GDPR requires joint controllers to transparently determine their respective responsibilities. The EDPB and the EDPS therefore recommend clarifying the allocation of roles. Where sponsors and investigators jointly determine the purposes and means of processing, they should be treated as joint controllers. The same logic should apply to co-sponsors where they jointly determine purposes and means.

The Opinion also raises a more structural issue: whether controllership should lie with the individual investigator or with the institution hosting the trial site. Reallocating controllership to the clinical trial site or host institution may better reflect the organizational reality of clinical trial governance. If this approach were adopted, it would have important practical consequences for clinical trial agreements, GDPR role-allocation clauses and related data governance documentation. That consequence is not itself stated as a rule in the Opinion but follows logically from the recommended clarification of roles.

3.2. Data minimization, retention and protocol specificity

The supervisors also recommend strengthening the language of necessity in the new Article 93 CTR. In particular, the provision should make clear that personal data may be processed only where necessary for the purposes identified. Under the GDPR, a harmonized legal basis does not dispense with the principles of data minimization and purpose limitation. The trial protocol and related documentation should therefore specify the categories of data processed, the categories of data subjects, the relevant purposes, the recipients, the storage periods and the safeguards applied.

The Opinion also recommends making pseudonymization the default where direct identification is not strictly required. This is especially important in clinical trials, where the data may include health data, genetic data and other highly sensitive information.

On retention, the Opinion usefully clarifies a recurrent ambiguity. The 25-year minimum retention period under Article 58 CTR concerns the clinical trial master file: the structured set of essential documents that allows the conduct of the trial and the quality of the data to be verified. It should not be read as a general authorization to retain all personal data processed in the course of a clinical trial for 25 years. The Proposal should therefore make the scope of that retention period explicit.

3.2.1. Further processing and secondary research

One of the most delicate aspects of the proposed Article 93 CTR concerns further processing. The Proposal would allow the same controller, such as a sponsor or investigator, to further process trial data for other clinical trials or for scientific research aimed at protecting public health, improving the standard of care or fostering innovation. The EDPB and the EDPS do not reject such further processing. They do, however, recommend that the provision be made more precise. In particular, the legal basis for further processing should be expressly framed as Article 6(1)(e) GDPR, namely processing necessary for the performance of a task carried out in the public interest. The purposes should also be more narrowly specified. Broad references to innovation, public health or improvement of care may be valuable policy objectives, but they are not always sufficiently precise for the purposes of Article 5(1)(b) GDPR.

The Opinion further calls for specific safeguards, including pseudonymization, governance mechanisms, confidentiality obligations and clear limits on access. This is one of the points where the simplification narrative becomes more complex. The Proposal simplifies the map of legal bases, but it also requires more precise ex ante governance of reuse.

A related issue concerns withdrawal of informed consent under the CTR. Withdrawal of consent to participate in a trial does not automatically invalidate processing operations already lawfully carried out on another GDPR basis, such as Article 6(1)(c). However, the Proposal should clarify which processing may continue after withdrawal and which must cease, particularly where vulnerable populations are involved.

3.3. Innovation mechanisms

The Proposal also introduces a series of innovation-oriented mechanisms which cannot be treated as a single category as they actually raise different GDPR issues: biotechnology testing environments are addressed separately from biotechnology data quality accelerators. Clinical-trial regulatory sandboxes are introduced through amendments to the Clinical Trials Regulation, while sandboxes for novel health biotechnology products are dealt with elsewhere in the Biotech Act.

Across these mechanisms, although with different legal consequences depending on the instrument concerned, the EDPB and the EDPS insist on one central point: the GDPR remains fully applicable whenever personal data are processed. If personal data are processed in a sandbox, testing environment or data quality accelerator, the relevant legal basis under Article 6 GDPR and, where special categories of data are involved, the applicable Article 9(2) condition must be clearly identified. The supervisors also recommend specifying the categories of data, the categories of participants, the roles of the actors involved and the applicable safeguards.

The same logic applies to electronic informed consent. The Proposal opens the door to electronic means for the informed consent process, including electronic signatures and identification tools compliant with the eIDAS framework or equivalent standards and electronic informed consent may rely on eIDAS-compliant tools, while any use of the European Digital Identity Wallet must remain voluntary. Non-electronic routes should remain available for participants who cannot or do not wish to use digital identity tools.

  1. AI-enabled biotechnology and the AI Act

The Proposal also engages with AI-enabled biotechnology. This is another area where simplification depends on regulatory coordination rather than replacement of existing rules. The EDPB and the EDPS stress that obligations under the Biotech Act should complement, not displace, obligations under the AI Act. This is particularly important in clinical trials. Article 2(8) of the AI Act excludes from its scope certain research, testing and development activities before an AI system is placed on the market or put into service. Where that exclusion applies, the GDPR may remain the main operative layer for the processing of personal data during the research phase.

At the same time, once AI systems move towards market placement or deployment, the AI Act may become relevant. In the medical context, the more accurate high-risk pathway is not a generic reference to Annex III point 5, which concerns access to and enjoyment of essential private and public services. For medical-device AI, the key route is typically Article 6(1) AI Act, where the AI system is a product, or a safety component of a product, covered by sectoral Union harmonization legislation requiring third-party conformity assessment. The Proposal should therefore be read as adding a biotechnology-specific layer to the existing AI and data-protection framework, not as creating a self-standing regime that absorbs it.

  1. The systemic coherence challenge: GDPR, EHDS and Digital Omnibus

The data-protection questions raised by the Biotech Act do not arise in isolation. The Proposal sits at the intersection of the GDPR, the AI Act and the European Health Data Space Regulation (hereinafter EHDS).

The clearest intersection is with the EHDS, which creates a regime for the secondary use of electronic health data by third-party data users through Health Data Access Bodies and data permits. The Biotech Act’s proposed Article 93(6) CTR addresses a different scenario: further processing by the same controller, such as a sponsor or investigator, of data already collected in the clinical trial context. The two regimes are therefore not redundant. One concerns internal further use by the original controller; the other concerns access by third-party users through the EHDS governance structure. But the same clinical trial dataset may fall within both logics. If Article 93(6) CTR remains too broadly drafted, sponsors, investigators, data users and regulators may face overlapping but not fully aligned frameworks for the same data.

The Digital Omnibus Proposal adds a further variable. Its proposed harmonized definition of “scientific research” could help reduce lexical fragmentation across EU data legislation. But such a definition will only simplify compliance if it is coordinated with the CTR, the EHDS and the GDPR’s safeguards for special categories of data.

In this respect, the Biotech Act exposes a broader problem of EU digital and health regulation: legal certainty is not achieved only by adding a common legal basis. It also requires that adjacent instruments use compatible concepts, safeguards and governance structures.

  1. Simplification, or the appearance of it?

The Biotech Act’s harmonization of the legal basis for clinical trial processing is a real step forward aiming to reduce uncertainty for sponsors and investigators, particularly in multi-country trials. In that sense, the Proposal delivers genuine simplification yet the Joint Opinion shows that many of the decisive questions remain open: who is the controller, or joint controller, in complex trial structures; how precisely must the protocol define data processing operations; how far may further processing go; what safeguards are required for reuse; which Article 9 GDPR condition applies in sandboxes and data quality environments; and how the Biotech Act should interact with the AI Act and the EHDS?

The Proposal therefore simplifies the map of legal bases, but it does not eliminate the underlying compliance work. In some respects, it may even make that work more demanding, because sponsors will need to document necessity, role allocation, retention, pseudonymization and further-use safeguards with greater precision.

However, it must be acknowledged that this is not necessarily a weakness. In clinical research, simplification should not mean deregulation. It should mean a clearer allocation of legal responsibilities, a more predictable legal basis and stronger ex ante safeguards. The EDPB and EDPS recommendations point precisely in that direction.

There is also a trust dimension. Clinical trials depend on the willingness of participants to allow highly sensitive data to be used in contexts that may extend beyond immediate care. A framework perceived as procedurally weak may undermine participant trust and, ultimately, the efficiency and competitiveness the Biotech Act seeks to promote. The Biotech Act offers real simplification at the level of formal legal basis. But unless the supervisors’ recommendations are translated into operative text that simplification risks remaining incomplete.

  1. Conclusion

The Biotech Act is best understood as a targeted simplification of the GDPR interface for clinical trials, not as a general reduction of data-protection obligations. Its central promise is to replace fragmented national approaches with a more coherent Union-level legal basis for processing personal data in clinical trials. Legal certainty will depend on the precision of the final text. The real question that is raised by this legal tool is whether it simplifies in the right place. If harmonization is limited to the legal basis, while the most sensitive choices are deferred to implementing acts or left to controller-level documentation, the result may be simplification on paper and complexity in practice.

Share this article!

About Author

Sergio Sulmicelli

Università di Trento

Leave A Reply