- Since May 23, 2026, MR-001 and MR-003 allow the information notice to be delivered electronically, under five cumulative conditions.
- The channel depends on content: plain email if the notice reveals nothing about health, otherwise an access code or an authenticated platform.
- The MRs govern information about data processing, not the signature of consent to take part in the research.
- Multi-factor authentication is mandatory from January 1, 2027 for internet-accessible tools, and from January 1, 2028 for all.
- Ongoing research: action plan and security measures in place by May 2027 at the latest.
Since May 23, 2026, the CNIL's reference methodologies MR-001 and MR-003 (méthodologies de référence) allow the information notice (note d'information) to be delivered electronically, under five cumulative conditions and with security measures that depend on what the notice contains. They also require multi-factor authentication from January 1, 2027 for tools accessible over the internet. Your eConsent platform falls within both scopes.
Do you declare your research as compliant with MR-001 or MR-003? The CNIL, France's data protection authority, approved new versions of both methodologies in deliberations dated March 19, 2026, published in the Journal officiel (the French official gazette) on May 23, 2026 and announced by the CNIL on May 26. The texts come with a common security annex (annexe sécurité): 30 general measures and four requirements specific to electronic information notices. If your team distributes its information documents through eConsent, three questions arise: which channel the text accepts, what the platform must secure, and by when.
What changes in MR-001 and MR-003 in 2026?
The update broadens the scope of both methodologies, adds electronic delivery of information, and moves security requirements into a common annex. According to the summary table published by the CNIL in May 2026, the substantive changes cover the scope, the legal basis, data categories, recipients, information given to individuals, transfers outside the EU, and processors.
MR-001 covers research that requires the person's consent, and MR-003 covers research that does not. Three changes affect a team that uses eConsent:
- the scope now includes research on health products, clinical investigations of medical devices and performance studies included, as well as research conducted partly or entirely outside France;
- the information notice can be delivered electronically, and deferred information becomes possible when a person is enrolled in an emergency;
- security measures are set out in the security annex, approved by deliberation no. 2026-049.
Under MR-001, a data controller established in France can enroll people who do not live in France, provided the regulations of their country of residence require their consent to be obtained. A multicenter study run from France can therefore fall under MR-001 even when some participants live abroad.
Can the information notice be delivered electronically?
Yes, for research started on or after May 23, 2026, under five cumulative conditions set by deliberation no. 2026-050 adopting MR-001: the person or their representatives do not object to this delivery method, the person has the means to access the electronic medium, the information remains available throughout the research, the person can obtain the notice on paper at any time on request, and the measures in the security annex apply. MR-003 sets the same conditions.
Each condition calls for a decision in your protocol or in your tool:
- Non-objection: record the person's choice before the first sending. If they refuse the electronic format, give them the notice on paper.
- Means of access: the investigator checks that the person has a device and an email address or phone number they use, and records it.
- Availability: the notice remains accessible until the end of the research. If you send it through a download link, which the annex requires to be time-limited, decide where the person will find it afterwards, for example in their participant portal.
- Paper on request: even after accepting the electronic format, the person can ask for the notice on paper at any point in the research. Decide who hands it to them at the site.
- Security: the accepted channel depends on the content of the notice, as explained in the next section.
For all remote exchanges, the annex also requires you to verify the identity of the people you contact and to secure the electronic sending of information notices (requirement MR-SEC-23). If you enroll participants through video visits, include this identity check in your procedure.
Which channel fits the content of the information notice?
The channel depends on one question: does the notice reveal any information about the person's health? If it reveals none, a plain email is enough, sent to a personal address the person uses. If it does, the security annex requires protected access: an encrypted attachment or a link protected by a code sent through another channel, or a platform with authenticated login.
| Content of the notice | Accepted channel | Conditions set by the security annex |
|---|---|---|
| No health information | Plain email (MR-INF-02) | Personal, individual address used by the person or their representatives |
| Possible health information | Email with access code (MR-INF-03) | Neutral subject line and body; encrypted notice or link requiring a code; code sent through a separate channel (handed over in person, phone call, text message to a verified number); limited availability period on a download platform |
| Possible health information | Secure platform (MR-INF-04) | Authenticated login by the person; invitation notification with no health information |
An information notice for an oncology trial, or for a study open only to patients with diabetes, reveals their health status through its title alone. The subject line, the message body and the platform notification must then stay neutral. Review your message templates: “Your information notice for the Diabetes 2 study” already says too much.
Do the MRs govern electronic signature of consent?
No. MR-001 and MR-003 govern the processing of personal data, including the information given to participants under the GDPR. Deliberation no. 2026-050 mentions neither electronic consent nor electronic signature: obtaining consent to take part falls under the regulations specific to each type of research.
Your eConsent carries two documents that teams often confuse. The information notice on data processing falls under the MRs. The consent form to take part in the research falls under other texts, depending on the research category. Have your ethics committee and your data protection officer approve the electronic signature you choose for the consent form. Our article on electronic signatures for informed consent compares the signature levels defined by the eIDAS regulation.
What security requirements apply to your eConsent platform?
The security annex lists 30 general measures. For eConsent, four carry the most weight: multi-factor authentication to access participant data, a unique identifier for each user, activity logging, and a non-identifying code to index research data.
- Multi-factor authentication (MR-SEC-12): at least two distinct factors to access the data of the people taking part. MR-001 makes it mandatory from January 1, 2027 for services accessible over the internet, and from January 1, 2028 for all others.
- Unique identifier (MR-SEC-10): one account per user, and no account shared among the research staff of a site.
- Logging (MR-SEC-14): user activity is logged, and the logs are analyzed to detect incidents.
- Non-identifying code (MR-CNS-02, code non signifiant): the code that indexes the data contains no initials, no date of birth and no enrollment number.
The annex also prohibits the use of personal devices to access research data (MR-SEC-21) and calls for software dedicated to research, hosted on dedicated servers (MR-SEC-19). If research staff at a site open the eConsent on their personal phones, that practice falls outside the framework. The update changes retention periods only in form: our article on archiving and confidentiality in clinical trials covers them in detail.
Ongoing research: which deadlines apply?
The new MRs apply to research started on or after May 23, 2026. For research already under way on that date, the CNIL requires an action plan and the implementation of the security measures by May 2027 at the latest. Multi-factor authentication follows its own deadlines: January 1, 2027, then January 1, 2028.
| Date | What applies |
|---|---|
| May 23, 2026 | Publication in the Journal officiel; any research started from this date follows the new versions |
| January 1, 2027 | Multi-factor authentication for services accessible over the internet |
| May 2027 | End of the period given to ongoing research to apply the security measures |
| January 1, 2028 | Multi-factor authentication for all services, whether or not they are accessible over the internet |
Declarations of compliance made under the previous versions remain valid. For ongoing research, switching to remote quality control does not require CNIL authorization, according to its announcement of May 26, 2026. In your action plan, set the date on which each ongoing study switches to the electronic notice, and name the person who checks the five conditions before the first sending.
How Datacapt eConsent delivers the notice and collects consent
Datacapt eConsent sends forms by email, SMS or QR code, and participants open them on their phone, tablet or computer, with no app to install. Advanced electronic signature (AdES) under the eIDAS regulation comes with identity verification and timestamping. Multilingual content follows version control by country and by site, and the platform supports re-consent workflows.
Every user action is recorded in a timestamped audit trail, and data is hosted on an HDS-certified cloud in France (HDS is the French certification for health data hosting). Two-factor authentication can be enabled according to each organization's policy: set it up in the configuration of your studies before January 1, 2027.
Before your next submission, review three items: the message template that accompanies the information notice, the procedure that records the participant's non-objection to the electronic format, and the authentication settings of your eConsent. The first two are up to your team. You settle the third with your software vendor, and the eConsent setup guide lists the steps to follow with the ethics committee.
Frequently asked questions about MR-001 and MR-003
[[faq]]
Sources
- CNIL, Recherche en santé : la CNIL met à jour et élargit le champ des méthodologies de référence 001 et 003, May 26, 2026
- CNIL, Tableau récapitulatif des modifications réalisées sur les MR-001 et MR-003, May 2026
- CNIL, Annexe sécurité pour les méthodologies de référence (MR), April 2026 version
- CNIL, Délibération n° 2026-049 du 19 mars 2026 portant homologation de l'annexe « sécurité » pour les méthodologies de référence relatives aux traitements de données à caractère personnel mis en œuvre dans le cadre des recherches dans le domaine de la santé, Légifrance, Journal officiel, May 23, 2026
- CNIL, Délibération n° 2026-050 du 19 mars 2026 portant homologation d'une méthodologie de référence relative aux traitements de données à caractère personnel mis en œuvre dans le cadre des recherches dans le domaine de la santé nécessitant le recueil du consentement de la personne concernée en vue de la participation à la recherche (MR-001) et abrogeant la délibération n° 2018-153, Légifrance, Journal officiel, May 23, 2026
What is MR-001?
MR-001 is the CNIL's reference methodology for data processing in health research that requires the person's consent. A sponsor that complies with it files a declaration of compliance instead of an authorization request. The current version was approved on March 19, 2026 by deliberation no. 2026-050.
What is the difference between MR-001 and MR-003?
MR-001 covers research that requires the person's consent. MR-003 covers research that does not, where the person receives information and can object to the processing of their data. Both methodologies were updated on March 19, 2026 and share the same security annex.
Can a clinical study information notice be sent by email in France?
Yes, since May 23, 2026, if the person does not object, has the means to access it, keeps access to the notice throughout the research and can obtain it on paper at any time. A plain email is enough when the notice reveals nothing about the person's health. Otherwise, the security annex requires an access code sent through another channel, or a platform with authenticated login.
When does multi-factor authentication become mandatory for health research?
On January 1, 2027 for services accessible over the internet, and on January 1, 2028 for all services, under MR-001 as approved on March 19, 2026. Requirement MR-SEC-12 of the security annex calls for at least two distinct authentication factors to access the data of the people taking part in the research.
Do you need a new declaration for ongoing research?
No. Declarations of compliance made under the previous versions of the MRs remain valid. The CNIL does, however, require data controllers to define an action plan and apply the measures of the security annex by May 2027 at the latest, one year after publication.


With over 10 years of experience working in CROs, Khalil brings deep expertise in clinical trials and a clear understanding of the daily challenges faced by research professionals. His insights are grounded in real-world operations, making his perspective both practical and strategic.
Blog & News Datacapt
News, Articles, Resources et Tutorials.
