Authors: Diana Andrade, Global Pharma Privacy Advisor & Founder & Managing Director of RD Privacy| Aman Khera, Global Regulatory Science and Innovation Expert


Recently, the French Data Protection Authority (CNIL) published updated guidance to remind healthcare and pharmaceutical stakeholders of their existing obligations when processing personal data in the context of compassionate access to medicines.
In this article, we provide a comprehensive overview of the three main mechanisms in France for providing patients with access to non-authorized medicines: Early Access Authorization (AAP), Compassionate Access Authorization (AAC), and the Compassionate Prescribing Framework (CPC). We examine how each mechanism is regulated and highlight the data protection responsibilities that now define the pharmaceutical industry’s role in delivering non-authorized treatments.
Overview of Compassionate Access Mechanisms
France has established three regulatory frameworks under the oversight of the French Medicines Agency (ANSM) to facilitate patient access to unauthorized medicines outside of a clinical trial setting:
- The Early Access Authorization (Accès Précoce or AAP) allows early access to a product likely to be granted a marketing authorization within a defined timeframe. It is initiated by the pharmaceutical company, which submits a formal request to ANSM and is responsible for compliance with both regulatory and data protection requirements. The AAP pathway requires submission of a detailed Therapeutic Use Protocol (Protocole d’Utilisation Thérapeutique, or PUT) and compliance with both ANSM and CNIL obligations.
- The Compassionate Access Authorization (Accès Compassionnel or AAC) is used to authorize access to a product that is not intended to be marketed in the near term. Like AAP, the application is submitted by the company. Like the AAP it requires submission of a Therapeutic Use Protocol (Protocole d’Utilisation Thérapeutique, PUT) and involves close engagement between the sponsor and ANSM and prior data processing approval from CNIL.
- The Compassionate Prescribing Framework (Cadre de Prescription Compassionnelle or CPC) differs in that it is not initiated by the company but by ANSM, often following requests from clinicians. ANSM defines the conditions of use and publishes a PUT, allowing any physician to prescribe the product under those terms. Although companies are not involved in initiating the CPC, they become responsible for compliance once they start supplying the product and collecting follow-up data.
Independent Oversight by ANSM and CNIL
While ANSM is responsible for the regulatory evaluation and authorization of these programs, data protection supervision is the responsibility of the CNIL. Importantly, ANSM’s authorization to supply or prescribe the product does not extend to authorizing the processing of personal data. In all three mechanisms, the pharmaceutical company must separately seek authorization from the CNIL before processing any patient data.
ANSM’s authorization to supply or prescribe the product does not extend to authorizing the processing of personal data.
ANSM Procedures and Regulatory Team Obligations
In France, the regulatory pathway to compassionate access programs begins with the ANSM, but success hinges on more than just submitting forms. Whether we’re talking about Early Access Authorization (AAP) or Compassionate Access Authorization (AAC), industry regulators are at the helm of navigating this process end-to-end.
Regulatory Team Responsibilities Under AAP and AAC
For both AAP and AAC, the formal process starts with the company, which leads the development and submission of the Therapeutic Use Protocol (PUT), defining the clinical rationale, patient population, and treatment conditions. But it doesn’t stop there. Regulatory functions are responsible for:
- Coordinating internally across safety, medical, and quality to ensure the PUT is aligned with real-world use and compliant with ANSM expectations
- Leading interactions with ANSM, from submission through clarifications and finalization
- Working closely with privacy colleagues to align timelines, recognizing that ANSM approval alone is not enough, and that CNIL authorization is a separate, essential requirement
CPC: A Different Starting Point, Same Compliance Duties
Where things differ is with the Compassionate Prescribing Framework (CPC). This is not a company-initiated process. It’s ANSM-driven, often following clinician requests and ANSM publishes a PUT that sets the conditions under which the medicine can be prescribed. While companies don’t lead the charge here, it doesn’t mean regulatory teams can be passive:
- They are typically notified by ANSM (or pick up through signals from clinicians) when our product falls under a CPC
- From that point onward, they are responsible for ensuring that product supply, pharmacovigilance reporting, and data collection only occur following CNIL authorization and in full alignment with data protection requirements.
- They must act with the same diligence and structure as they would under AAC or AAP, even though they weren’t the ones who initiated the process.
In practice, this means regulatory teams are doing more than just shepherding approvals, they’re orchestrating alignment. In all three pathways, their role is to anticipate and resolve regulatory risks, translate external frameworks into internal action, and collaborate seamlessly with privacy teams to ensure nothing is lost in translation.
If companies don’t get this right and silo regulatory from privacy or misjudge timing on CNIL approvals, patient access gets delayed. And in compassionate use settings, everyday counts.
From AU-041 to the Current Frameworks: What Changed?
Before 11 November 2022, data processing under these access mechanisms was governed by a single CNIL framework: the Single Authorization AU-041. Under this regime, companies could process personal data for compassionate access by submitting a simple declaration of compliance, as long as they strictly followed the AU-041 conditions. This simplified process avoided the need for formal CNIL authorization.
However, the AU-041 framework was repealed and replaced by two new reference frameworks: one for early access (AAP) and one for compassionate access (AAC and CPC). Since then, prior authorization from the CNIL has become mandatory for any personal data processing carried out under these access schemes. Compliance with the reference framework streamlines review but does not exempt the company from seeking approval.
Prior authorization from the CNIL has become mandatory for any personal data processing carried out under these access schemes.
CNIL Authorization and the Current Landscape
While the current framework enhances transparency and legal oversight, it also introduces a critical operational constraint. Companies must wait for CNIL authorization before beginning any patient data processing. This may delay patient access to urgently needed treatments, especially if product supply is contingent on the ability to monitor and document patient outcomes. Unlike the previous AU-041 regime, companies no longer have a compliance shortcut and must navigate a potentially uncertain authorization timeline.
This transition signals not only a change in procedure, but also the CNIL’s increasing focus on pharmaceutical sector enforcement. By targeting CPCs in its latest awareness efforts, the CNIL is underscoring its expectation that pharma companies demonstrate full accountability in how they process sensitive health data. This is likely part of a broader strategic move to strengthen health data governance in France.
Regulatory and Privacy Coordination Within the Company
Pharmaceutical companies must ensure strong coordination between their regulatory, medical, and privacy teams to meet the obligations associated with early and compassionate access. Regulatory teams are responsible for aligning with the PUT and ensuring pharmacovigilance reporting and ANSM communication. The privacy team or data protection officer must oversee CNIL engagement, prepare DPIAs when necessary, and ensure that patient and physician information notices meet legal requirements.
Consequences of Missing CNIL Authorization Requirements
Failure to obtain CNIL authorization prior to processing patient data under AAP, AAC, or CPC schemes constitutes a violation of the GDPR and French Data Protection Act. This may lead to corrective orders, processing bans, and administrative fines of up to €20 million or 4% of the company’s global annual turnover. Importantly, unauthorized processing undermines the legal basis for data collection, potentially invalidating data use. The risk is particularly high under the CPC, where companies may wrongly assume ANSM’s responsibility for compliance. In reality, once a company begins supplying a product and engaging in data collection, full CNIL compliance is already expected.
Call to Action
For companies involved in AAP, AAC, or CPC programs, now is the time to reassess whether CNIL compliance is fully embedded in operational practice. This includes verifying whether appropriate authorization requests have been submitted, ensuring alignment with the relevant CNIL framework, and documenting the lawful basis for all patient data processing activities. Beyond these core compliance checks, regulatory teams must also be trained on these requirements to understand the need for close collaboration with privacy teams and ensure that CNIL obligations are effectively met.
How can we help?
Diana Andrade is a strategic data protection advisor with deep expertise in clinical research and healthcare innovation. She supports pharmaceutical and life sciences companies with privacy strategy, global compliance, and operational execution across a range of activities, from clinical trials to early access and real-world data use. Through her firm, RD Privacy, she advises on regulatory engagement, cross-border data flows, vendor oversight, and the integration of privacy into complex health data ecosystems.
Aman Khera brings extensive experience in global regulatory science and innovation. Her advisory spans regulatory strategy, clinical research, patient advocacy, product lifecycle compliance. She actively collaborates with global authorities to support market access and post-authorization initiatives, ensuring that scientific advancement aligns with both regulatory expectations and patient needs.
Contact Us:
📨 Diana Andrade – RD Privacy – [email protected] | www.rdprivacy.com
📨 Aman Khera – linkedin.com/in/aman-khera
Diana is the Founder & Managing Director at RD Privacy and a contributing columnist, specializing in privacy for the pharmaceuticals and life science sectors, particularly small biopharma companies, with extensive experience as a European qualified privacy attorney and Data Protection Officer (DPO).

