Information Governance Statement
Effective Date: 10 September 2026 • Clear Clinical Solutions Ltd
1. Our Commitment to Data Integrity
At Clear Clinical Solutions, Information Governance (IG) is foundational to our architecture. We understand that Clinical Trials Units (CTUs), academic institutions, and biopharma sponsors entrust us with highly sensitive clinical data. Our governance frameworks are designed to ensure absolute confidentiality, integrity, availability, and continuous inspection readiness.
2. Regulatory Alignment
Clear EDC and our surrounding consultancy services are engineered to align with global clinical and data protection standards, including but not limited to:
- UK GDPR & EU GDPR: Strict adherence to data minimisation, privacy by design, and localised data sovereignty.
- ICH GCP E6 (R2/R3): Ensuring source data verification (SDV) capabilities, ALCOA+ principles, and robust investigator oversight mechanisms.
- FDA 21 CFR Part 11 / EMA Annex 11: Full support for electronic signatures, non-repudiable time-stamped audit trails, and logical security controls.
- GAMP 5 Principles: Applying a risk-based approach to compliant GxP computerised systems.
3. Data Residency and Sovereignty
To navigate complex international data transfer laws, Clear EDC utilises localised cloud infrastructure. We offer dedicated sovereign hosting instances in the UK and the EU. Trial data remains strictly within the sponsor-designated geographical boundary, ensuring compliance with local data residency mandates.
4. Platform Security Architecture
- Encryption: All data is encrypted in transit using TLS 1.2+ (targeting TLS 1.3) and encrypted at rest using AES-256 standard encryption.
- Access Controls: Granular, role-based access control (RBAC) ensures that users (Investigators, CRAs, Data Managers) only have access to the minimum data necessary for their role.
- Authentication: Support for strong password policies, Multi-Factor Authentication (MFA), and Single Sign-On (SSO) integration for institutional clients.
- Audit Trails: An immutable, system-generated audit trail records every data entry, modification, and deletion, capturing the user ID, timestamp, and reason for change.
5. Software Development Lifecycle (SDLC) & Validation
Clear EDC is developed under a strict Quality Management System (QMS). All software releases are subject to rigorous automated and manual testing. We provide our enterprise and early-adopter clients with pre-packaged Validation Documentation Packs (including Functional Specifications and UAT templates) to streamline your internal vendor qualification and GxP validation processes.
6. Incident Management and Disaster Recovery
We maintain a comprehensive Business Continuity and Disaster Recovery (BCDR) plan. In the highly unlikely event of a data breach or availability disruption, Clear Clinical Solutions operates under strict Service Level Agreements (SLAs) for rapid incident response, regulatory notification, and sponsor communication as required by GDPR and clinical reporting guidelines.
7. Contact Information Governance
To request our full SOC 2 / ISO 27001 posture documentation (under NDA) or to speak with our Quality Assurance team, please contact our early access team:
Request access to the early adopter programme