What distinguishes our lawyers is the ability to see the whole regulatory picture. We have assisted multiple clients, ranging from CROs to pharma start-ups to medical device manufacturers, in setting up GDPR compliance processes and agreements that allow for seamless interaction with other legal frameworks such as MDR and IVDR.
Data Protection, (Cyber)security and AI
Data is the backbone of the life sciences sector, driving innovation during the R&D phase, scientific research, patient care, and regulatory compliance. Data collection and processing however is subject to a wide array of legislation which directly impact the commercial viability and regulatory compliance of your product or service. But with the GDPR, the European Health Data Space Act (EHDS Act), the Data Act, the Network and Information Security Directive (NIS II Directive), and the AI Act, the regulatory landscape for (personal) data and AI is increasingly complex, particularly where these laws interact with product legislation such as the Medical Device Regulation (MDR) and In Vitro Diagnostics Regulation (IVDR). The interaction between these frameworks demands an integrated compliance approach.
Our expertise
We speak both the language of regulators and the language of product teams. Our practice sits at the intersection of product legislation such as the AI Act, the MDR, the IVDR, the Clinical Trials Regulation, and horizontal data and cybersecurity frameworks, including the GDPR, the Data Act, the Data Governance Act, the EHDS Act, the NIS II Directive, and the Cyber Resilience Act. That combination allows us to see the full picture and provide you with one coherent compliance strategy.
How we can help
We advise on lawful data collection, processing, and international transfers under the GDPR, whether in the context of clinical research, post-market surveillance, or real-world evidence generation. When the EHDS Act or the Data Act requires you to share or provide access to data, we help you understand what the consequences are for your company and advise you on structuring compliance in a way that protects your business interests. For AI-driven medical devices and drug development tools, we assess risk classifications under the AI Act and align your compliance approach with both data protection and product safety requirements. We advise on cybersecurity strategies under the NIS II Directive and the Cyber Resilience Act, focussing on practical integration thereof in your existing processes and systems. And when things go wrong in the form of a data subject complaint, a personal data breach or an enforcement action by a data protection or competent authority or cybersecurity regulator, we are the team you call.
Our data protection, (cyber)security and AI specialists
Recent
See which lawyer fits your needs
Expert legal counsel matched to your needs