Skip to content

Data Protection, (Cyber)security and AI

Data is the backbone of the life sciences sector, driving innovation during the R&D phase, scientific research, patient care, and regulatory compliance. Data collection and processing however is subject to a wide array of legislation which directly impact the commercial viability and regulatory compliance of your product or service. But with the GDPR, the European Health Data Space Act (EHDS Act), the Data Act, the Network and Information Security Directive (NIS II Directive), and the AI Act, the regulatory landscape for (personal) data and AI is increasingly complex, particularly where these laws interact with product legislation such as the Medical Device Regulation (MDR) and In Vitro Diagnostics Regulation (IVDR). The interaction between these frameworks demands an integrated compliance approach.

Our expertise

We speak both the language of regulators and the language of product teams. Our practice sits at the intersection of product legislation such as the AI Act, the MDR, the IVDR, the Clinical Trials Regulation, and horizontal data and cybersecurity frameworks, including the GDPR, the Data Act, the Data Governance Act, the EHDS Act, the NIS II Directive, and the Cyber Resilience Act. That combination allows us to see the full picture and provide you with one coherent compliance strategy.

How we can help

We advise on lawful data collection, processing, and international transfers under the GDPR, whether in the context of clinical research, post-market surveillance, or real-world evidence generation. When the EHDS Act or the Data Act requires you to share or provide access to data, we help you understand what the consequences are for your company and advise you on structuring compliance in a way that protects your business interests. For AI-driven medical devices and drug development tools, we assess risk classifications under the AI Act and align your compliance approach with both data protection and product safety requirements. We advise on cybersecurity strategies under the NIS II Directive and the Cyber Resilience Act, focussing on practical integration thereof in your existing processes and systems. And when things go wrong in the form of a data subject complaint, a personal data breach or an enforcement action by a data protection or competent authority or cybersecurity regulator, we are the team you call.

Recent

Healthcare Medical Devices Pharmaceuticals Data Protection, (Cyber)security and AI Testimonial

What distinguishes our lawyers is the ability to see the whole regulatory picture. We have assisted multiple clients, ranging from CROs to pharma start-ups to medical device manufacturers, in setting up GDPR compliance processes and agreements that allow for seamless interaction with other legal frameworks such as MDR and IVDR.

Digital Health Medical Devices Data Protection, (Cyber)security and AI Testimonial

We have assisted a medical device manufacturer in ensuring that their SAAS-application complies with the Data Act and the GDPR.

Medical Devices Data Protection, (Cyber)security and AI Testimonial

We have advised a medical device manufacturer on collaborations with academic institutions on data collection for training of AI systems, including the necessary data protection contracts.

Data Protection, (Cyber)security and AI Testimonial

We have created the data protection strategy for a long-term registry study.

Medical Devices Data Protection, (Cyber)security and AI Testimonial

We have trained the entire regulatory team of a medical device company on understanding GDPR compliance in a clinical research setting.

Data Protection, (Cyber)security and AI Testimonial

For a client conducting a multinational clinical investigation, we have drafted informed consent notices that allow for long term use of clinical research data beyond the confines of the study.

Healthcare Data Protection, (Cyber)security and AI Testimonial

We have assisted a client in setting up a multinational data strategy, including advice on anonymisation of personal data and interaction product regulations and the upcoming high-risk regime under the European Health Data Space Act (EHDS Act) to help them continue innovating without endangering company confidential developments.

Data Protection, (Cyber)security and AI Testimonial

We set up procedures for multiple clients continues transfers of personal data beyond the EU, including to countries without an adequate data protection regime, for various purposes.

Medical Devices Data Protection, (Cyber)security and AI Testimonial

On behalf of a medical device company, we reported a personal data breach to the supervisory authority and have advised on internal communication.

Medical Devices Data Protection, (Cyber)security and AI Due Diligence Regulatory Compliance and Enforcement Testimonial

We have conducted regulatory due diligence on behalf of a private equity firm in connection with the acquisition of a medical device manufacturer, covering MDR compliance (including notified body certificates and post-market surveillance obligations), as well as data protection aspects.

See which lawyer fits your needs

Expert legal counsel matched to your needs

Get started