Data Protection

This page summarizes RTI Health Solutions, LLC (RTI-HS) compliance with the European Union (EU) General Data Protection Regulation ([GDPR] EU Regulation 2016/679). RTI-HS is a wholly owned subsidiary of RTI International.

RTI-HS business practices respect the confidentiality and privacy of personal data collected or acquired during the conduct of our clients’ research projects and our business operations, and we comply with applicable data protection laws, including the GDPR, in all activities. Our standard operating procedures outline the requirements necessary to identify and protect personal data throughout its life cycle from initial acquisition to destruction and to operationalize the rights of data subjects under GPDR.

The RTI-HS Legal and Regulatory Affairs (LRA), Office of Quality (OQ) and RTI's Global Privacy Officer work together to facilitate compliance with the laws and regulations governing the collection, processing, and use of personal data. RTI-HS works together with the RTI Information Technology and Security Team to ensure the security and protection of personal data processed by RTI-HS.

RTI-HS GDPR Compliance Framework

RTI-HS implemented the necessary processes and procedures to comply with the GDPR prior to its effective date in May 2018. These processes and procedures, regularly evaluated and updated, form the foundation for our continued compliance with the GDPR and other applicable global data protection regulations.

The RTI-HS GDPR compliance framework described here demonstrates how we have implemented the requirements for data protection. Our compliance framework is built upon 6 key elements that together ensure privacy by design and default, accompanied by ongoing oversight and continuous improvement:

  • Governance and accountability
  • Compliant data processing
  • Data protection security and controls
  • Risk management
  • Data breach management
  • Records management

The key aspects of each element of the GDPR compliance framework are described further below.

ELEMENT: Governance and Accountability
GDPR Articles 5, 6, 9, 24, 25, 28, and 37 to 39

RTI-HS has proactively addressed data protection compliance through policies, procedures, staff training, vendor management, and dedicated staff. Our procedures include training all staff on proper identification and handling of EU personal data, data subject rights, confidentiality, data archive and destruction, and data breach notification.

Staff Dedicated to Data Protection
RTI-HS LRA includes staff who provide strategic leadership for data protection compliance across the organization, informing and advising RTI-HS management and staff on compliance obligations and supporting day-to-day operational issues for data protection while also serving as the first point of contact for data protection authorities and individuals whose data are processed.

RTI-HS LRA also liaises with the RTI organization-wide Global Privacy Officer. 

NOTE: RTI-HS is not required to designate a Data Protection Officer because its core activities do not involve regular and systematic monitoring of data subjects on a large scale or processing on a large scale of special categories of data.

RTI-HS Employees
RTI-HS employees share responsibility for data protection compliance. All RTI-HS employees undergo background checks prior to employment as well as ongoing debarment screening and sign an employment contract that includes the requirement for employees to protect the confidentiality and privacy of all information provided or obtained for business purposes. All RTI-HS employees complete training on information security and handling of personal data at first hire and periodically thereafter according to standard operating procedures.

Vendors and Research Partners
Vendors and research partners supporting data processing are evaluated for their ability to process data in compliance with applicable data protection regulations before approval to process personal data on behalf of RTI-HS. Designated experienced staff in RTI-HS LRA review the responses and determine whether the vendor or research partner is approved for processing personal data. This evaluation is in addition to the qualification by RTI-HS OQ conducted for all vendors and research partners providing substantive research services to RTI-HS.

In addition to these assessments, RTI-HS vendor agreements require compliance with applicable data protection regulations and include data processing agreements applicable for any processing of data subject to GDPR.

Data Controller Registration
RTI-HS is registered as a data controller in the United Kingdom (UK) and Spain and operates office locations in each country.

Data Subjects
RTI-HS has an established research privacy policy outlining the methods by which data subjects may exercise their rights per GDPR Articles 12 to 23. An RTI-HS email address is available for data subject questions, concerns, and complaints and is monitored regularly by designated staff in RTI-HS LRA. Procedures are in place to enable data subjects to exercise their rights to exert control over the data about them, including rights existing after their data have been provided to RTI-HS.

Website Privacy and Cookie Policies
Visitors to this website are encouraged to read the website privacy policy regarding how RTI-HS collects and uses personal data based on website visits. The website privacy policy provides information to website users, including how individuals may exercise their rights. This website also contains a cookie policy to inform users regarding the types of cookies present, data tracked by the cookies, and purposes for which these data are used. The cookie policy clearly explains how users can manage preferences for cookies, including how to withdraw consent.

ELEMENT: Compliant Data Processing
GDPR Articles 5, 6, 9, 12 to 21, 28, and 30

RTI-HS data processing activities incorporate the fundamental principles of GDPR data protection:

  • Data are processed fairly, lawfully and transparently (“fair and lawful processing”).
  • Data are processed for limited purposes and in an appropriate way (“purpose limitation”).
  • Only the relevant and minimum necessary data are processed (“data minimization”).
  • Steps are taken to assure the accuracy of data.
  • Data are not kept longer than necessary for the purpose (“storage limitation”).
  • Data are processed with due respect of the data subject rights of access, rectification, deletion, portability of information, and the limitation or opposition to processing (“data subject rights”).
  • Data are processed using appropriate technological and organizational security measures.
  • Data are transferred outside the EU only with adequate protections in place.

Types of RTI-HS Personal Information
RTI-HS uses several types of personal information in conducting our business. Primarily these include:

  • Public business information from clients and vendors: This is information routinely made available in the public domain by those persons as part of their business operations e.g., the contact information in emails or included on a company website.
  • Confidential business information from clients and vendors: This includes financial and legal information (e.g., tax identifiers) and information submitted by a vendor working with us in support of our proposals and contracts with clients or our business operations. This confidential information is maintained on secure business operations databases or secure project servers.
  • Project information: This is information provided to us by clients or third parties or information that we collect while conducting research projects. Health data, a special category of personal data per GDRP Article 9, may be processed with data subject consent and/or ethics committee or institutional review board approval. When conducting research projects, we always seek to limit such data to the minimum necessary to fulfill the research purpose (e.g. receiving data with the least amount of personal identifiers possible).

Legal Basis for Processing
RTI-HS processes all data in a lawful manner. Our legal basis for processing personal data of EU origin typically relies on 1 or more of the following:

  • Data subject consent (Article 6.1.a), especially for our research projects where consent is obtained for processing of any personal data, including any data transfer outside the EU.
  • Processing is necessary for the performance of a contract to which the data subject is a party, (Article 6.1.b).
  • Processing is necessary for compliance with a legal obligation to which the controller is subject, (Article 6.1.c).
  • Processing is in the legitimate interests of RTI-HS (Article 6.1.f), as when we process personal data consistent with our business operations (e.g. database of vendors with contact information and credentials).

Records of Data Processing
RTI-HS has implemented an organization-wide records registry to identify and document our records of data processing for research projects. The records registry entries are completed by the project leader or another project team member with an understanding of the data to be used in the project. The project leader or delegate must update a project-specific records registry entry if the data collection or use plans change during the project. Prior to April 2023, information was entered into the data registry, which remains available to staff for projects started before that date.

Designated staff in RTI-HS LRA review the records registry entries. The database housing the records registry is programmed to send automatic reminders in advance of and on the scheduled dates for data destruction to ensure that data are retained only for as long as necessary.

Data Transfers Outside the EU or United Kingdom (UK)
Prior to collecting or obtaining personal data of EU or UK origin, RTI-HS procedures require the project leader to confirm that the data will reside at all times within the EU or UK and be accessible only to RTI-HS staff or approved vendors based in the EU or UK, or to create a plan for the collection, transfer, and processing of data that accounts for the transfer of the data outside the EU or UK in accordance with governing data protection laws.

RTI-HS relies on 1 of 2 authorizations to transfer the data to RTI-HS offices and personnel in the United States:

  • Standard contractual clauses per GDPR Article 46: Staff in RTI-HS LRA implement a properly executed set of “model contract” (standard contractual clauses) between RTI-HS and the exporting data controller entity.
  • Explicit data subject consent per GDPR Article 49: Data subject consent may be obtained verbally with confirmation documented in a contemporaneous written record or, if web based, through click-through consent. RTI-HS requires separate explicit consents from the data subject for both the processing of the data subject’s personal data and the transfer of the data subject’s personal data to the US.

ELEMENT: Data Protection Security and Controls
GDPR Articles 5.1(f), 24, 25, 28, 30, and 32

RTI-HS has implemented robust measures to protect the confidentiality and security of all data, not just personal data as required by GDPR. Physical, logical, and procedural controls are in place to protect data from loss, misuse, unauthorized access or disclosure, alteration, or destruction. These include physical and network security including firewalls, access and password controls, data segregation, encryption, patch management and antivirus controls, on-site and remote backups with defined destruction process, and disaster recovery and business continuity plans.

Confidential Business Information
Confidential business information from clients and vendors is maintained in our secure business operations databases or in secure project servers. All staff are trained on confidentiality and sign employment contracts with provisions requiring protection of confidential information.

Research Project Data
Project data are stored on dedicated secure network servers within Europe or in approved cloud vendor platforms. Access to each project-specific share within the secure network is controlled through a documented process with access and permission levels requested by the project leader on a need-to-know basis and then implemented by the RTI Information Technology and Security Team system administrators.

RTI Information Technology and Security
The RTI Information Technology and Security Team supports the RTI-HS information systems and network. Policies and procedures are based upon the security framework of the US National Institute of Standards and Technology Special Publication 800-53 Rev. 5. The RTI Information Technology and Security Team has also obtained an International Organization for Standards (ISO) 27001:2022 certificate for its operations of the RTI-HS information systems and network. The certificate is issued by an ISO/International Electro-technical Commission 27001:2022 certified provider whose information security management system has received third-party accreditation from the ISO and the International Electro-technical Commission. The technical and organizational security measures are extensive and commensurate with industry standards.

ELEMENT: Risk Management
GDPR Articles 25 and 35

RTI-HS has taken steps to limit its risks associated with the processing of personal data. We do not engage in regular “large-scale” data processing. We work most frequently with pseudonymized, anonymized, or aggregated data in our studies.

Data Protection Impact Assessment (DPIA)
As a data controller, in general, RTI-HS does not engage in “high risk” types of data processing that require completion of a DPIA as defined under GDPR or the UK Data Protection Act. RTI-HS acts as a data processor for client’s research projects. RTI-HS will assist the client, who serves as the data controller, in the completion of any requested project-specific DPIA.

Vendor Management
RTI-HS OQ performs vendor risk assessments and qualifications to ensure that RTI-HS works with vendors capable of delivering services in accordance with the standards applicable to their work. As part of the OQ vendor qualification process, the designated staff in RTI-HS LRA partner with OQA to identify and assess relevant vendors for compliance with GDPR. Vendors who may provide or process personal data during the conduct of RTI-HS research must complete an in-depth privacy questionnaire. Designated staff in RTI-HS LRA review the completed questionnaire and supporting documentation provided by the vendor to determine whether the vendor is approved for processing personal data.

RTI-HS standard vendor agreements and purchase orders include requirements for vendors to comply with all applicable data protection laws, specifically referencing the GDPR, and to execute a data processing agreement when processing data subject to GDPR.

ELEMENT: Data Breach Management
GDPR Articles 5.1(f), 33, and 34

RTI-HS has implemented comprehensive procedures, best practices, and technological controls to prevent or limit the risks associated with unintended data exposure. Internal procedures provide an incident response framework for when, where, and how to report potential and actual data breaches.

Data Breach Notification Procedures
All RTI-HS employees are trained to immediately notify RTI-HS LRA of incidents where personal data may have been improperly transferred, disclosed, or processed by RTI-HS staff, vendors, or clients. Upon notification, RTI-HS LRA will then promptly coordinate further actions with the RTI Global Privacy Officer per the established RTI organizational Data Incident Response and Breach Notification Plan.

ELEMENT: Records Management
GDPR Article 5.1(e)

RTI-HS has implemented processes and procedures to retain records in a secure and confidential manner only for the minimum time required by applicable law, regulation, contract, or mission-critical business needs.

Storage Limitation
RTI-HS adheres to the “storage limitation” requirement of GDPR Article 5.1(e) by keeping personal data only for as long as required for the purpose for which the data were collected, or as required by law or regulation.

RTI-HS procedures require all personal data held in electronic form to be segregated and stored only in restricted access folders and files. Access to personal data is restricted to persons who have a need to know based on their organizational or project role.

Electronic personal data of EU origin that is not approved for export must reside in project-specific controlled-access folders created on UK- or EU-based servers.

Record Retention Schedules
RTI-HS has a record retention schedule based on typical record types created during our normal course of business. The record retention schedules are periodically reviewed to align with applicable laws and provide default retention periods when applicable laws, research informed consent forms, or contract provisions do not dictate the retention period.

Destruction
When personal data are no longer needed and there is no contractual or regulatory requirement to retain the data for a longer period, RTI-HS requires that the data be permanently erased or destroyed, and the destruction documented per written process. If personal data are no longer needed but there is a contractual or regulatory requirement to retain the data, the data must be placed in a read-only archive with access restricted to the project leader and the RTI Information Technology and Security Team.

Owner and Data Controller

RTI Health Solutions
3040 E. Cornwallis Road
Research Triangle Park, NC 27713 USA

Data Protection contact email: dataprotection@rtihs.org

To learn more about how this website collects and processes personal data, please read our website privacy policy and cookie policy.

Revision 3, Effective Date: August 25, 2026