Eunomia perspective · 2026-09-29 · GDPR & Data Compliance in Pharma, HCP Engagement & Transparency Reporting
GDPR and Transparency Reporting: Disclosing HCP Transfers of Value
Published by Eunomia Pharma Services · Updated
How does GDPR apply to disclosing HCP transfers of value?
Naming an HCP in a transfers-of-value disclosure is processing of personal data, so it needs a lawful basis under Article 6 of the GDPR. EFPIA’s training material identifies individual consent or legitimate interest, with a documented process. HCO information is not personal data, according to the ABPI.
Practical steps
- Decide and document the lawful basis for naming HCPs.
- Complete a legitimate interests assessment if relying on Article 6(1)(f).
- Build privacy information into HCP contracts.
- Track consent, withdrawal and objection status in one place.
- Reconcile payments from all sources before preparing the file.
The practical steps above are Eunomia’s operational guidance. See the source notes below for the scope of the external references.
Every year, pharmaceutical companies publish the transfers of value they have made to healthcare professionals (HCPs) and healthcare organisations (HCOs). Where the recipient is an individual HCP, that disclosure is also a publication of personal data: a name, a practice address and an amount. That puts transparency reporting under two sets of rules at once: the industry disclosure code and data protection law.
This article explains where the two meet, what the EFPIA and ABPI say about the legal basis for naming HCPs, and the practical controls that help a disclosure stand up to both.
Why disclosure is a data protection question
The EFPIA Code requires annual disclosure of transfers of value to HCPs and HCOs, and EFPIA’s member associations transpose that requirement into national codes. In the UK, disclosures are published on Disclosure UK, the ABPI’s database.
The GDPR (Regulation (EU) 2016/679) and, in the UK, the UK GDPR and the Data Protection Act 2018 govern how personal data is processed. Article 5(1) sets the core principles: personal data must be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; limited to what is necessary; accurate and kept up to date; kept no longer than necessary; and processed securely. Article 5(2) makes the controller responsible for being able to demonstrate compliance with those principles.
Information about HCOs is treated differently. The ABPI’s December 2025 factsheet on Disclosure UK states that information about HCOs is not considered personal data, so a lawful basis is not required for it. The data protection questions therefore centre on individual HCPs.
Consent or legitimate interests?
Article 6(1) of the GDPR lists the lawful bases for processing. Two are relevant to most HCP disclosures: consent (Article 6(1)(a)) and legitimate interests (Article 6(1)(f)).
EFPIA’s training material on the disclosure of transfers of value states that, as per the GDPR, named disclosure of HCPs requires a legal basis, either individual consent or legitimate interest, and that companies must have a documented process. It adds that where a company uses legitimate interest, the HCP must be informed before the company engages with them.
In the UK, the ABPI’s factsheet notes that a majority of companies rely on consent to publish an HCP’s name and practice address on Disclosure UK. The ABPI champions the use of legitimate interests and, since 2021, has provided guidance to disclosing companies on it.
The choice has operational consequences:
- Consent. Under Article 7(3), an HCP can withdraw consent at any time, and withdrawing must be as easy as giving it. Where consent is refused or withdrawn, the EFPIA material explains that the transfer is disclosed in aggregate rather than by name. Consent status must therefore be tracked per HCP and carried through to the disclosure file.
- Legitimate interests. The ABPI factsheet notes that, while formal consent is no longer requested, the company must be clear about its intentions and must allow individuals to exercise their right to object. Under Article 21, an HCP can object on grounds relating to their particular situation, and the company must stop unless it demonstrates compelling legitimate grounds.
Some countries have statutory transparency regimes rather than code-only disclosure. France is one example: disclosures under the Loi Bertrand are published on the public Transparence Santé database. Where a disclosure obligation comes from national law, assess the lawful basis in that context with local advice.
Documenting a legitimate interests assessment
If you rely on legitimate interests, document the reasoning. The UK Information Commissioner’s Office (ICO) describes a three-part test and recommends documenting the outcome in a legitimate interests assessment (LIA):
- The purpose test: identify the legitimate interest.
- The necessity test: show that the processing is necessary for that purpose.
- The balancing test: consider the individual’s interests, rights and freedoms.
The European Data Protection Board’s Guidelines 1/2024 on Article 6(1)(f), adopted for public consultation in October 2024, describe the same three cumulative conditions. An LIA for disclosure should be specific to the data published, the audience and the safeguards, rather than a generic template.
Telling HCPs what will be published
Whichever basis you use, Articles 13 and 14 of the GDPR require the controller to give individuals information about the processing, including when the data is collected from them. For transparency reporting, the practical moment is at contracting: the agreement or accompanying notice should explain what will be disclosed, where, on what basis, and how the HCP can exercise their rights.
HCPs can also ask for access to their data (Article 15) and for inaccurate data to be corrected (Article 16). A process that routes these requests to a named owner, with a record of the outcome, avoids last-minute changes to the file.
Keeping the data accurate
Accuracy is both a disclosure requirement and a data protection principle. Common sources of error include duplicate HCP records across systems, payments made through agencies and not captured centrally, and consent status that is not carried from the CRM to the disclosure file. The EFPIA material also states that a pharma company must not allow “cherry picking” of which transfers of value are disclosed.
Useful controls include:
- a single HCP master record, with one source of truth for consent or objection status;
- reconciliation of agency and affiliate payments to the general ledger before the file is prepared;
- a methodology note that explains how each category of transfer is identified and valued;
- a documented review and sign-off, with evidence retained.
Processors, retention and transfers
Disclosure data often passes through agencies, event organisers and technology providers. Where they process personal data on your behalf, Article 28 requires a binding contract setting out the processing. Record the activity in your record of processing activities (Article 30), and set retention periods that satisfy both the disclosure code and the storage limitation principle. The EFPIA Code requires disclosures to remain public for at least three years and records to be kept for at least five years, unless national law requires otherwise.
If disclosure data is prepared or hosted outside the UK or EEA, for example by a global shared-service centre, the international transfer rules in Chapter V of the GDPR apply.
A short checklist
- Decide and document the lawful basis for naming HCPs, by country where needed.
- If relying on legitimate interests, complete and retain an LIA.
- Build the privacy information into HCP contracts and engagement workflows.
- Track consent, withdrawal and objection status in one place.
- Route access and correction requests to a named owner.
- Reconcile payments from all sources before preparing the file.
- Put processor contracts, records of processing and retention rules in place.
This article is general information, not legal advice. Confirm the position for your organisation and each market with qualified data protection and legal advisers.
Sources and scope
- Regulation (EU) 2016/679 (GDPR)
Articles 5, 6, 7(3), 13–16, 21, 28, 30 and Chapter V.
- EFPIA: Disclosure of Transfers of Value (Code training module)
States that named HCP disclosure needs a legal basis, consent or legitimate interest, with a documented process.
- ABPI: Disclosure UK – What is Legitimate Interests? (December 2025)
Notes that most companies rely on consent for Disclosure UK, that the ABPI champions legitimate interests, and that HCO information is not personal data.
- ICO: How do we apply legitimate interests in practice?
The ICO’s three-part test (purpose, necessity, balancing) and its recommendation to document a legitimate interests assessment.
- EDPB Guidelines 1/2024 on Article 6(1)(f) GDPR
Version 1.0, adopted for public consultation on 8 October 2024; sets out three cumulative conditions for legitimate interests.
- EFPIA: The EFPIA Code of Practice
Annual disclosure of transfers of value and record-keeping requirements.
External sources accessed 29 September 2026. Check the applicable country rules and current source text for a specific engagement.
