All resources

Eunomia perspective · 2026-09-29 · GDPR & Data Compliance in Pharma, HCP Engagement & Transparency Reporting

Managing Healthcare Professionals’ Personal Data under GDPR: CRM, FMV and Engagement Records

Published by Eunomia Pharma Services · Updated

How should pharma companies manage HCP personal data under GDPR?

Define the purpose of each engagement step, document a lawful basis, collect only the data each decision needs, keep a single accurate HCP record, tell HCPs how their data is used, and put processor contracts, transfer safeguards and retention periods in place.

Practical steps

  1. Map each engagement step to a purpose, lawful basis and data set.
  2. Keep a single HCP master record with a named owner.
  3. Limit FMV and selection data to documented criteria.
  4. Put processor contracts and transfer safeguards in place.
  5. Set retention by purpose and assess new analytics or AI for a DPIA.

The practical steps above are Eunomia’s operational guidance. See the source notes below for the scope of the external references.

Pharmaceutical compliance runs on data about healthcare professionals (HCPs). A single advisory board can generate a CRM record, a needs assessment, a selection rationale, a contract, a fair market value (FMV) tiering decision, a payment and a disclosure entry. Each holds personal data, and each is subject to the GDPR (Regulation (EU) 2016/679) or, in the UK, the UK GDPR and the Data Protection Act 2018.

This article looks at how the core data protection principles apply to HCP engagement records, and the practical controls that help compliance and data protection teams work from the same record.

Start with purpose

Article 5(1)(b) of the GDPR requires personal data to be collected for specified, explicit and legitimate purposes and not further processed in a way that is incompatible with them. In an HCP engagement, the purposes are usually distinct: managing the relationship, assessing and contracting the service, calculating and paying the fee, meeting disclosure obligations, and keeping evidence for audit.

Writing those purposes down, and mapping which data each one needs, is the foundation for everything else. It also makes the record of processing activities that Article 30 requires much easier to maintain.

Choose and document the lawful basis

Article 6(1) sets out the lawful bases. For HCP engagement records, companies commonly assess legitimate interests (Article 6(1)(f)), which applies unless the individual’s interests or fundamental rights and freedoms override the interests pursued. The UK Information Commissioner’s Office (ICO) describes a three-part test (purpose, necessity and balancing) and recommends documenting it in a legitimate interests assessment. The European Data Protection Board’s Guidelines 1/2024, adopted for public consultation in October 2024, set out the same three cumulative conditions.

Disclosure of transfers of value may rely on a different basis from the rest of the engagement. EFPIA’s training material states that named disclosure of HCPs requires either individual consent or legitimate interest, with a documented process. Our article on GDPR and transparency reporting covers that step in detail.

Collect only what the decision needs

Data minimisation (Article 5(1)(c)) means data must be adequate, relevant and limited to what is necessary. This matters most in FMV and selection.

An FMV methodology typically tiers HCPs using objective criteria, such as role, experience or specialist expertise, to set a compensation level. Our FMV case study describes objective tiering and rate cards for six stakeholder categories across five markets. The criteria should be the data you hold for tiering: enough to justify the decision, and no more. A free-text CV field that accumulates unrelated personal detail is a common source of over-collection.

The same applies to selection. Record why an HCP was selected against the legitimate need for the service, rather than general notes about the individual.

Keep records accurate and connected

The accuracy principle (Article 5(1)(d)) requires data to be accurate and, where necessary, kept up to date. In practice, HCP data sits in several places: CRM, events platforms, contract management, finance and disclosure tools. Duplicates and mismatches cause problems for both compliance and data protection: the wrong tier applied to a fee, a payment missed from disclosure, or a consent status that differs between systems.

A single HCP master record, with defined ownership and a controlled change process, supports both. HCPs also have the right to access their data (Article 15) and to have inaccurate data corrected (Article 16). In the UK, the ICO’s guidance on the Data (Use and Access) Act 2025 notes that organisations only have to make reasonable and proportionate searches when responding to access requests. That is easier to show when the data sits in known systems with clear owners.

Tell HCPs what you do with their data

Article 13 requires the controller to provide specified information when data is collected from the individual, and Article 14 covers data obtained from other sources, such as a third-party database or an agency. The practical points are the first contact and the contract: the privacy information should explain the purposes, the lawful basis, recipients, retention and the HCP’s rights, including the right to object to processing based on legitimate interests (Article 21).

Agencies, platforms and shared services

Much HCP engagement work is delivered with third parties: meeting agencies, CRM and events platforms, and shared-service teams. Where they process personal data on your behalf, Article 28 requires a binding contract that governs the processing. Where data moves outside the UK or EEA, for example to a global business services centre, the transfer rules in Chapter V apply. Under Article 46, in the absence of an adequacy decision, transfers need appropriate safeguards, with enforceable rights and effective legal remedies available to individuals.

Retention and new technology

Storage limitation (Article 5(1)(e)) means data should not be kept in identifiable form for longer than necessary. For HCP engagement records, set retention periods by purpose. Records that support disclosure, for example, need to meet the EFPIA Code’s minimum record-keeping period of five years, unless national law requires otherwise.

New processing, such as analytics on engagement data or AI-assisted review, may need a data protection impact assessment. Article 35 requires one before processing that is likely to result in a high risk to individuals’ rights and freedoms.

Practical controls

  • Map each HCP engagement step to a purpose, a lawful basis and the data it needs.
  • Keep a single HCP master record with a named owner.
  • Limit FMV and selection data to the documented criteria.
  • Build privacy information into first contact and contracts.
  • Put processor contracts and transfer safeguards in place for agencies and shared services.
  • Set retention periods by purpose, and review new analytics or AI uses for a DPIA.

This article is general information, not legal advice. Confirm the position for your organisation and each market with qualified data protection and legal advisers.

Sources and scope

External sources accessed 29 September 2026. Check the applicable country rules and current source text for a specific engagement.

Put this into practice