In This Article
- Executive Summary
- The Professional Data Exemption That Does Not Exist
- Where the Rules Actually Stand in August 2026
- Lawful Basis: The Assessment Almost Nobody Performed
- Consent and Preference Management as an Operating System
- Purchased and Inferred Data: Saying Where It Came From
- When Privacy Rights and Disclosure Duties Collide
- The Representative in the Field: What Belongs in a Note
- A 90-Day Path to a Defensible Position
- Conclusion
- For Further Reading
- References & Sources
Executive Summary
A pharmaceutical field force runs on data about named individuals. Contact details, affiliations, prescribing and dispensing behavior, engagement history, channel preferences, call notes, and consent flags all attach to a specific doctor, pharmacist, or nurse practitioner. Most of that data was purchased, licensed, scraped, or inferred rather than given. And most privacy programs in life sciences were built around patient data, which means the largest, most actively used personal dataset in the commercial organization has often received the least attention.
The core point is simple and widely misunderstood. A healthcare professional is a natural person. Under the GDPR, information about that person in a professional capacity is personal data with no professional-context carve-out, and European regulators have now enforced that view against companies whose entire product was professional contact data. US state privacy laws are different, and the difference matters: nearly all of them exclude people acting in a commercial context from the definition of consumer, while California does not. A global commercial data model that assumes one answer will be wrong somewhere.
This article establishes what is actually in force as of August 2026 across the EU, the UK, and the United States. It then works through the four questions that decide whether an HCP engagement program is defensible: what lawful basis supports it and what a legitimate interests assessment has to weigh, how an opt-out propagates across CRM, email, events, and agencies inside a workable timeframe, what transparency obligations attach to purchased and inferred data including prescribing data, and what a sales representative should and should not type into a call note.
The Professional Data Exemption That Does Not Exist
Ask a commercial operations leader whether HCP data is regulated personal data and you will often get a qualified yes followed by an unqualified assumption: yes in principle, but this is business contact information, so the strict rules do not really apply. That assumption is the single most consequential misunderstanding in pharmaceutical commercial data management, and it is wrong in Europe.
The GDPR defines personal data as any information relating to an identified or identifiable natural person.1 There is no qualifier for context. The only relevant exclusion sits in Recital 14, which states that the Regulation does not cover the processing of personal data concerning legal persons. A hospital is a legal person. A group practice is a legal person. Dr. Alvarez, who works at that hospital, is a natural person, and her work email address, her specialty, her institutional affiliation, her attendance at your advisory board, and the model output that scores her as a high-potential target are all information relating to her.
The scope of personal data is deliberately wide
European courts have consistently read the concept broadly. In Nowak, the Court of Justice held that the definition reflects a deliberate intent to assign wide scope to the concept, covering not only objective information but also subjective information in the form of opinions and assessments, provided it relates to the person.3 The case concerned an examination script and an examiner’s handwritten comments. Both were personal data.
Translate that into a commercial system. A segmentation tier is an assessment. A propensity score is an assessment. A free-text note reading “resistant to switching, dismissive of the new data” is an opinion about a named person. Every one of those is personal data about the HCP, and every one of them is in scope for an access request.
Regulators have now enforced this directly
Two enforcement actions have removed any remaining ambiguity. In December 2024, the French supervisory authority fined KASPR 240,000 euros. KASPR sold a browser extension that harvested professional contact details from a social network and assembled a database of roughly 160 million business contacts. The authority found that the company collected details of users who had restricted visibility of those details, and that it failed to provide transparent information to the people concerned. It was ordered to stop the collection and delete what it had gathered.78 The data at issue was entirely professional. That did not help.
The second is older but more instructive because it went all the way through the courts. The Polish authority fined a business information company for failing to give an Article 14 privacy notice to roughly six million people whose data it had taken from public business registers. The company had posted a notice on its website and argued that individually contacting everyone was a disproportionate effort. The authority disagreed, and after several years of appeals the Polish Supreme Administrative Court upheld the decision, confirming the information duty applied to people actively conducting economic activity.9 Publicly available professional data, taken from an official register, still triggered an active notification duty.
The practical test. If your commercial data platform can produce a row for a named individual, that row is personal data in the EEA and the UK regardless of whether every field on it describes professional activity. The question is never whether the GDPR applies. The question is which lawful basis supports each purpose, and whether you can evidence it.
Where the United States diverges
The US position is genuinely different, and the difference runs the opposite way from what most people expect. State comprehensive privacy laws generally define a consumer as a resident of the state acting only in an individual or household context, and then expressly exclude a natural person acting in a commercial or employment context. Virginia’s statute is the model that most later states copied almost word for word.16 Under that definition, a physician receiving a sales call at her practice is generally not a consumer for that interaction, and professional data generated in that commercial context usually sits outside the statute.
California is the exception, and it is the one state where the exception is expensive. The CCPA originally carried temporary exemptions for employee data and for business-to-business data. Both expired on January 1, 2023 and were not renewed.17 Since then, a California-resident prescriber’s professional contact details, engagement history, and inferred profile have been personal information under the CCPA, carrying access, deletion, correction, and opt-out rights. The commonly cited HIPAA exemption does not rescue this: prescribing data describes the prescriber’s professional conduct, not the prescriber’s own health, so it is not that person’s protected health information.
| Question | EU / EEA and UK | Most US states | California |
|---|---|---|---|
| Is HCP professional data in scope? | Yes. No professional-context exclusion exists. | Generally no. Commercial-context exclusion applies. | Yes. B2B exemption expired January 1, 2023. |
| Notice required for purchased data? | Yes, actively, under Article 14. | Not under the comprehensive statutes. | Yes, at or before collection. |
| Right to object to marketing? | Yes, absolute for direct marketing. | Opt-out of sale and targeted advertising, where in scope. | Opt-out of sale and sharing, and limits on sensitive data use. |
| Access to call notes and scores? | Yes, including opinions and inferences. | Generally out of scope. | Yes, including inferences. |
| Practical planning assumption | Design to this standard. | Do not assume the exclusion covers affiliated systems. | Treat as equivalent to EU scope. |
The strategic conclusion is uncomfortable but clear. A multinational cannot run two commercial data models, one careful and one casual, on the same platform and the same field force. The EU standard is the one that has to be designed for, and the US commercial-context exclusion should be treated as a narrowing of obligations in specific states rather than as a general permission.
Where the Rules Actually Stand in August 2026
Three things changed in the eighteen months to August 2026, and each one touches HCP engagement directly.
Europe: transparency is the 2026 enforcement priority
The European Data Protection Board selected transparency and the right to information as the topic of its 2026 Coordinated Enforcement Framework action, and launched it on March 19, 2026 with 25 supervisory authorities taking part. The action assesses compliance with Articles 12, 13, and 14, which govern how information about processing is given to people, what must be told to those whose data was collected directly, and what must be told to those whose data was obtained from somewhere else.56 Participating authorities are contacting controllers across sectors through formal investigations and fact-finding exercises during 2026, with findings aggregated in the second half of the year.
Article 14 is the provision that governs purchased and licensed HCP data. A coordinated European action aimed squarely at Article 14, in the same year, is about as clear a signal as regulators give.
United Kingdom: a changed statute, commenced in February 2026
The Data (Use and Access) Act 2025 received Royal Assent in June 2025, and the substantive data protection provisions were commenced on February 5, 2026.1011 The Act introduces a list of recognized legitimate interests that can be relied on without a balancing test. Direct marketing is not one of them. The Act does confirm that direct marketing may constitute a legitimate interest under the ordinary route, which means the balancing assessment still has to be done and documented.
Separately, the UK electronic marketing rules remain in place and remain widely misread by commercial teams. Under PECR the opt-in requirement for marketing by electronic mail does not apply to corporate subscribers, so unsolicited email to a limited company, a limited liability partnership, or a public body is permitted. Sole traders and most other partnerships are treated as individual subscribers and are not covered by that relaxation.12 Many prescribing HCPs in the UK practice through structures that fall on the individual-subscriber side. And even where the electronic mail relaxation applies, the UK GDPR still governs the underlying processing of the named individual’s data, so a lawful basis and a privacy notice are still required.
United States: more states, and a live data broker deadline
Twenty comprehensive state privacy laws were in effect at the start of 2026, with Indiana, Kentucky, and Rhode Island taking effect on January 1.14 Legislative activity through the first half of 2026 brought the total on the books to 24 states, though not all are yet effective.1528 Connecticut’s amendments took effect on July 1, 2026, lowering the applicability threshold from 100,000 to 35,000 consumers, removing the threshold entirely for any business that processes sensitive data or sells data, and tightening data minimization to require that collection be proportionate as well as reasonably necessary.29
The development with the sharpest edge for commercial data supply chains is California’s Delete Act. The Delete Request and Opt-Out Platform opened to California residents on January 1, 2026 and lets a resident submit one deletion request that reaches every registered data broker. From August 1, 2026, registered brokers must begin processing those requests, checking the platform at least once every 45 days and completing deletions within 45 days, with penalties of 200 dollars per request per day for failure.181920
Why the Delete Act matters to a pharma commercial team even though you are not a data broker. Several vendors that supply HCP contact, affiliation, and reference data to the industry meet the definition of a data broker in California and are registered. Once a California-resident prescriber uses the platform, the vendor must delete. If your CRM was populated from that vendor and your contract has no downstream deletion clause, you now hold a record the source has been ordered to erase, and you may have no automated way to learn about it. That is a supply chain question, not a marketing question, and it should be raised with vendor management before renewal.
Lawful Basis: The Assessment Almost Nobody Performed
Most HCP engagement in Europe does not run on consent. It runs on legitimate interests, and in most cases that is the correct choice. Consent under the GDPR must be freely given, specific, informed, unambiguous, and withdrawable at any time with no detriment. Trying to obtain valid consent for every field visit, every conference follow-up, and every medical information exchange with tens of thousands of professionals produces a system that is both unworkable and fragile, because a withdrawal collapses the basis for processing that may still be necessary.
The problem is not the choice of legitimate interests. The problem is that Article 6(1)(f) is conditional. It applies only where processing is necessary for a legitimate interest and where that interest is not overridden by the interests or fundamental rights of the person. That balancing exercise is a documented assessment, and in a great many commercial organizations it has never actually been carried out for the field force. There is a line in a privacy notice saying legitimate interests, and nothing behind it.
What the law now says about commercial interests
Two developments in October 2024 clarified the position. The Court of Justice ruled in KNLTB that a legitimate interest need not be laid down in law and that a purely commercial interest is not categorically excluded, pointing to Recital 47 of the GDPR, which states that processing for direct marketing purposes may be regarded as carried out for a legitimate interest.2 That is genuinely helpful for the industry.
In the same month the European Data Protection Board issued draft Guidelines 1/2024, still in their public consultation version, which set out the three-step test in detail and are explicit that direct marketing does not automatically constitute a legitimate interest and that Article 6(1)(f) cannot be relied on for all kinds of direct marketing activity.427 The Board treats an interest as legitimate only where it is lawful, clearly and precisely articulated, and real and present rather than speculative. Taken together: the door is open, and the standard of evidence for walking through it went up.
The three steps, applied to a field force
Identify the interest, precisely and per purpose
Not “commercial activity.” Something specific and defensible for each distinct processing purpose: informing prescribers about an approved indication within the terms of the marketing authorization, maintaining a record of interactions required by promotional codes and adverse event reporting duties, planning territory coverage so that clinicians who treat a rare condition are reachable. Different purposes may reach different answers, and bundling them into one assessment is what makes the assessment unusable later.
Test necessity, not convenience
Necessity asks whether a less intrusive route would achieve the same purpose. If territory planning works on aggregated regional volume, then person-level prescribing data is not necessary for that purpose. If a channel preference can be gathered directly from the HCP at first contact, buying an inferred preference score is harder to justify. This step is where most assessments are weakest, because commercial teams describe what the current platform does rather than what the purpose requires.
Balance, with the HCP’s reasonable expectations at the center
Weigh the nature of the data, the source, the scale, the sensitivity of any inference, the effect on the person, and whether they would reasonably expect this processing given the relationship and the point of collection. A prescriber expects a company whose product she prescribes to know she prescribes it. She does not necessarily expect a purchased behavioral score, a predicted switching propensity, or a social media influence ranking. Safeguards you actually apply, such as retention limits, access restriction, and a working objection route, belong in this step and can shift the outcome.
The right that outranks the assessment
Whatever the balancing produces, Article 21(2) gives every person an unconditional right to object to processing for direct marketing purposes, and once they object the data may no longer be processed for that purpose.1 There is no balancing, no override, and no legitimate interest that survives it. A well-documented legitimate interests assessment does not buy you the right to keep contacting someone who has said stop. It buys you the right to contact everyone who has not.
A common failure worth naming. Organizations that switched to consent to look conservative often made their position worse. If consent was gathered through a pre-ticked box, a bundled sign-up at a congress booth, or a form where declining meant losing access to medical information, it is unlikely to be valid. An invalid consent is not a weaker basis, it is no basis. Reassessing whether legitimate interests was the correct answer all along, and documenting it properly, is frequently the stronger remediation.
Consent and Preference Management as an Operating System
An HCP does not opt out of your company. She opts out of the email channel while remaining willing to see a representative. Or she asks to be removed from congress invitations but wants safety communications. Or she says stop to everything. In a modern commercial operation these signals arrive through at least six routes: a representative in the field, an unsubscribe link, a call center, a web preference center, a congress registration desk, and a third-party agency running a program on your behalf.
The signal has to reach every system that could produce an outreach. This is where most programs fail, and the failure is architectural rather than behavioral. Nobody in the organization decided to keep emailing a professional who asked to stop. The opt-out landed in the marketing automation platform and never reached the CRM, or it reached the CRM and never reached the agency running the speaker program, or it reached both and the next monthly file load from the data vendor reinstated the record with a blank preference field.
The four surfaces an opt-out has to cross
CRM and field planning
The representative’s call plan, the territory target list, and the suggested-next-action engine all have to respect the flag. If suppression happens only at send time in the email platform, the rep still sees the HCP on a target list and still visits. That is processing for a marketing purpose after an objection.
Marketing automation and paid media
Email, SMS, and any audience list pushed to an advertising platform. Uploaded audiences are the hardest to reverse because the identifier has already left your control. Suppression has to include a documented removal path from every audience previously uploaded, not just an exclusion on the next upload.
Events, congresses, and medical education
Invitation lists, registration systems, and speaker and advisory board pipelines are often run in separate tools, sometimes by an affiliate rather than the global team. These are the systems most likely to hold a stale copy of a contact list exported months earlier.
Agencies, contract sales teams, and vendors
Any processor acting on your instructions is your responsibility. The contract has to require them to receive and apply suppression within a stated period and to confirm it, and you have to actually send them the file. Article 19 also requires you to tell every recipient of the data about a deletion or restriction, unless doing so proves impossible or involves disproportionate effort.
The clock is shorter than most teams assume
There is no single global deadline, which is exactly why the fastest applicable one should be adopted as the internal standard.
| Regime | Trigger | Deadline |
|---|---|---|
| GDPR Article 12(3) | Any rights request, including an objection to marketing | Without undue delay and at the latest within one month, extendable by two further months for complex requests |
| GDPR Article 21(2) | Objection to direct marketing | Processing for that purpose must stop; no balancing applies |
| Most US state privacy laws | Consumer rights request, where in scope | 45 days, typically extendable once |
| California Delete Act (DROP) | Deletion request reaching a registered data broker | Check the platform at least every 45 days; process within 45 days, from August 1, 2026 |
| FCC rules under the TCPA | Revocation of consent for calls and texts | 10 business days to honor; the broader revoke-all provision has been extended to January 31, 2027 |
Regulators have kept moving on the US telephone side. The FCC rules requiring companies to honor a revocation within ten business days and to accept common opt-out keywords are in force, while the separate provision that would treat one revocation as blocking all future unrelated calls and texts from the same company has been delayed again, now to January 31, 2027.2526 The delay is narrow, and the safer design assumption is that a single stop request will eventually be read broadly.
What good looks like. One consent and preference service holds the authoritative record for each HCP, keyed to a stable identifier that survives vendor refreshes. Every capture point writes to it rather than to a local table. Every outbound system reads from it before every send or plan, rather than caching a copy. Every change is timestamped with its source, its channel scope, and the person or system that recorded it. Target latency from capture to full propagation is measured, reported, and treated as a service level, not an aspiration. A single query can answer, for any named HCP on any past date, what the state of their preferences was and which systems knew.
Purchased and Inferred Data: Saying Where It Came From
Almost none of the data in an HCP master record came from the HCP. It came from licensed reference files, professional registries, publication and trial databases, claims-derived prescribing panels, congress attendance lists, and models built on top of all of it. Under the GDPR, that changes which transparency obligation applies. Article 13 covers data collected from the person. Article 14 covers data obtained from anywhere else, and it is materially more demanding.
What Article 14 actually requires
Where data was not obtained from the person, the controller must tell them the identity and contact details of the controller, the purposes and lawful basis, the categories of personal data concerned, the recipients, retention periods, their rights including the right to object, and the source of the data including whether it came from publicly accessible sources.1 The information must be given within a reasonable period and at the latest within one month, or at the time of first communication with the person if that is sooner.
The disproportionate effort exemption exists, and it is read narrowly. The Polish case discussed earlier is the reference point: a company holding data on roughly six million entrepreneurs taken from public registers argued the effort of contacting them was disproportionate, posted a notice on its website instead. The first-instance court partially annulled the decision for people who had ceased trading, but the core holding was upheld on final appeal.9 A privacy notice sitting on a corporate website that the HCP has never visited is not compliance with Article 14. It is the exact fact pattern that produced the fine.
For a field force this has an operationally convenient answer. Because the obligation crystallizes at first communication, the first email, the first letter, and the first face-to-face interaction are all natural delivery points. A short, plain notice covering purpose, source, and the right to object, delivered at first contact and repeated in every email footer, discharges most of the duty. The reason organizations fail this test is not that it is hard. It is that the obligation was never assigned to anyone in commercial operations.
Prescribing data specifically
Prescriber-identifiable data has a longer and more contested history than most commercial data. In the United States it is protected commercial speech. Vermont banned the sale and use of prescriber-identifiable data for pharmaceutical marketing without prescriber consent, and in 2011 the Supreme Court struck the law down in Sorrell v. IMS Health, holding that the statute imposed content-based and speaker-based burdens on protected expression and was not narrowly tailored.21 The practical result is that US constraints on prescriber data are mostly contractual and voluntary rather than statutory.
The main voluntary mechanism remains the American Medical Association’s Physician Data Restriction Program, which has operated since 2006 and lets a physician block pharmaceutical sales representatives and first-line sales managers from accessing individual prescribing data, while leaving access open to other employees of the company.22 Any US commercial program that uses prescriber-level data should be able to demonstrate that restriction flags flow through to field-facing views, and should be able to show when that check last ran.
In Europe the analysis is completely different. Prescribing behavior attributed to a named prescriber is that person’s personal data, obtained indirectly, used for a commercial purpose. Article 14 applies, Article 15 gives the prescriber a right to obtain a copy along with any available information as to the source, and Article 21(2) lets them object to its use for marketing. Whether that person-level attribution is necessary for the stated purpose is exactly the question step two of the balancing assessment is supposed to answer, and in some markets the honest answer for some purposes is no.
The access request you cannot answer
Here is the scenario that exposes an unprepared program. A prescriber writes and asks what you hold about her and where it came from. Your CRM shows a decile ranking, a specialty, an affiliation, three inferred channel preferences, and a behavioral segment. None of the fields carry a source attribute. Some came from a licensed reference file, some from a panel-derived estimate, some from a model your analytics team built two years ago on inputs nobody documented.
You now have one month to tell her the source, and you cannot, because provenance was never captured as a field. Then she asks for deletion, and you discover that the record will be recreated at the next vendor refresh because deletion was implemented in the CRM rather than as a suppression rule applied to every inbound load.
Four things to require of every HCP data vendor at the next renewal.
- Provenance at field level. Every delivered attribute carries a source identifier and a collection or derivation date, not just a file-level statement in the contract.
- A source lawful basis statement. Written confirmation of the lawful basis on which the vendor collected and licenses the data, and evidence of how the vendor met its own Article 14 duty.
- Bidirectional suppression. A defined mechanism for you to send suppressions upstream and for the vendor to notify you of deletions and restrictions applied at their end, with a stated turnaround. The California DROP obligations from August 1, 2026 make this urgent for any registered broker.
- Assistance with rights requests. A contractual commitment, with a service level shorter than your one-month deadline, to answer source and provenance questions arising from an access request.
When Privacy Rights and Disclosure Duties Collide
Life sciences is unusual because the same named professional data that privacy law restricts, transparency law sometimes compels you to publish. Handled badly, the two obligations look contradictory. Handled properly, they are simply governed by different lawful bases and should be separated in the record.
In the United States, the Open Payments program requires applicable manufacturers to report payments and other transfers of value to covered recipients, which the reporting regulations then make publicly available.23 That is a legal obligation. Consent is irrelevant to it, and a physician’s objection does not stop it.
In Europe the position is different and messier. The EFPIA disclosure framework requires member companies to document and disclose transfers of value to HCPs and healthcare organizations, covering sponsorship to attend meetings, speaker fees, consultancy, and advisory board work.24 Because no equivalent EU-wide legal obligation compels named publication, companies have generally relied on individual consent or legitimate interests, and where consent is used the HCP can decline or withdraw, in which case the amounts are reported in aggregate along with the number of professionals who did not consent.
Why this creates confusion inside the commercial organization
The failure mode is treating the HCP’s various consents and objections as one switch. A professional who withdraws consent for named publication of transfers of value has not objected to receiving medical information. A professional who objects to promotional email has not withdrawn from a contracted advisory role, and the contract, the payment, and the reporting all continue under different bases. Conflating them produces two opposite errors: suppressing a person from a disclosure you are obliged to make, or continuing to market to someone who asked you to stop because the disclosure record showed an active relationship.
The design rule. Record the lawful basis alongside every consent or objection, scoped to a specific purpose and channel, rather than holding a single global permission flag on the HCP record. A defensible record answers four questions for any date: what did this person agree to, what did they refuse, under what basis are we processing for each purpose, and which obligation overrides their preference. This is the same discipline applied to patient consent in clinical programs, and the commercial organization is generally a decade behind on it.
The Representative in the Field: What Belongs in a Note
Every free-text field in a commercial system is a privacy exposure that no policy document controls. A representative finishes a call and types what happened. That note is personal data about the HCP, it is subject to an access request, and under Nowak it is in scope whether it records fact or opinion.3
Most field representatives have never been told this. They have been trained on adverse event reporting, on promotional code compliance, and on off-label boundaries. They have rarely been told that the person they wrote about can ask to read it, and that the company will have roughly a month to produce it.
The three problems in a typical note
Opinion recorded as characterization. “Difficult, seems more interested in the competitor’s dinner invitations than the data” is an assessment of a named professional. It is disclosable. It reads very differently in a printed access response than it did in a rushed field entry.
Third-party personal data. “His practice partner is leaving in the spring and he is worried about covering the list” contains personal data about someone else who never interacted with your company. Access request handling then has to weigh the requester’s right against that third party’s rights, using a documented balancing process, which slows every response and creates risk in both directions.13
Health information that should never be there. “Mentioned he has been off with his back and is cutting his clinic days” is information about the health of an identified natural person. In the EEA and the UK that is a special category of personal data under Article 9, requiring a separate condition for processing that a commercial CRM almost certainly does not have. A single sentence can move a record into a category the system was never designed or validated to hold.
| Write this | Not this | Why |
|---|---|---|
| Discussed the Phase 3 efficacy data; asked for the full publication. | Skeptical type, always wants to argue about the data. | The first records what happened. The second is a disclosable character assessment. |
| Requested no further email; preference updated. | Got annoyed about the emails again, will probably calm down. | The first is an actionable, auditable preference. The second is commentary and does not update anything. |
| Prefers morning appointments; next visit scheduled for October. | Only free in the mornings because of a family situation at home. | The first is a business preference. The second is personal information about the HCP and possibly about family members. |
| Raised a question about dosing in renal impairment; referred to Medical Information. | Says his patient had a bad reaction, sounded serious. | A suspected adverse event goes through the pharmacovigilance process, not a free-text CRM field where it will be missed. |
The guidance a field force actually needs
Long policies do not change behavior in a car between calls. A short standard, reinforced in the tool itself, does.
- Write what happened, not what you concluded about the person. Record actions, questions asked, materials provided, commitments made, and preferences stated.
- Assume the HCP will read it. This one line does more work than a training module. If you would not be comfortable with the note being read back to the person, rewrite it.
- Never record health information about the HCP or anyone else. Not the HCP’s own health, not a patient’s, not a colleague’s.
- Route regulated content to the regulated channel. Suspected adverse events, product quality complaints, and off-label questions have defined processes. A CRM note is not one of them.
- Record preferences as structured data, not prose. “Asked me to stop emailing” in a text box changes nothing. The preference field is what suppresses the next send.
- Keep third parties out. If a colleague or patient must be referenced for the interaction to make sense, describe the role rather than the person.
Two enforcement mechanisms make this stick. Put a one-line reminder in the note entry screen, where it is read at the moment of writing. And sample notes in the same quality review that already checks promotional compliance, because a field force learns what is actually reviewed. Where AI assistants now draft call summaries from voice input, the same standard applies to the output, and someone has to own the review step before the summary is saved.
A 90-Day Path to a Defensible Position
None of this requires a platform replacement. It requires knowing what you hold, why you are allowed to hold it, and being able to prove that a stop request stops things.
Days 1 to 30: inventory the HCP data estate and its sources
List every system that holds data about named professionals, including the ones commercial operations does not own: event platforms, agency-run programs, contract sales organizations, medical information systems, and affiliate spreadsheets. For each, record the categories held, the origin, whether provenance is captured at field level, and which markets it covers. The output is a single register, and the most useful thing it produces is the list of fields whose source nobody can identify.
Days 15 to 45: write the legitimate interests assessments that are missing
One per distinct purpose, following the EDPB three-step structure. Field engagement, digital promotion, targeting and segmentation, and event invitation are different purposes and may reach different conclusions. Document what you rejected as unnecessary, because a rejected option is the strongest evidence that the necessity test was applied honestly.
Days 30 to 60: run an end-to-end opt-out test
Take a small set of test records. Submit an objection through each capture route: field, email footer, web, call center, event desk, agency. Measure how long each one takes to reach every downstream system, including the agency and any uploaded advertising audience. Then run a vendor refresh and confirm the suppression survived it. The elapsed time you measure is your real compliance position, and it is usually the number that gets the funding conversation started.
Days 45 to 75: fix transparency at first contact
Draft one short HCP-facing notice covering purposes, sources, retention, and the right to object. Deliver it at first contact in every channel and make it reachable from every email. Assign an owner in commercial operations, not only in legal, because the obligation is triggered by commercial activity.
Days 60 to 90: rehearse an access request and brief the field
Pick a real HCP record and assemble the full response as if it had been requested: every field, every note, every score, every source. Time it and note what you could not answer. In parallel, deliver the note-writing standard to the field force in a fifteen-minute briefing with the four-column table above, and add the reminder line to the CRM entry screen.
At the end of ninety days the organization can answer the questions a regulator or an HCP would actually ask: what do you hold, where did it come from, why are you allowed to hold it, what happens when someone says stop, and how long does that take. Very few commercial organizations can answer all five today.
General information, not legal advice. Sakara Digital is a digital consulting firm, not a law firm. This article describes data governance practice and the systems questions behind it. Privacy obligations for healthcare professional data vary by market and by fact pattern, and any engagement program should be reviewed with qualified counsel in each jurisdiction where it operates.
Conclusion
The reason HCP data privacy has been neglected is not that anyone decided it did not matter. It is that privacy programs in life sciences were built by people whose reference point was the patient, and the commercial organization sat outside their line of sight. Meanwhile the commercial organization built a data estate of considerable sophistication about named professionals, sourced largely from third parties, governed largely by a sentence in a privacy notice. Those two facts have coexisted comfortably for years. The 2026 European enforcement focus on Articles 12, 13, and 14, a data broker deletion regime taking effect in California this month, and a US state privacy map that now diverges sharply between California and everywhere else are what make continuing to leave them alone the more difficult option.
The work is not exotic. Know what you hold and where each field came from. Write the assessment that justifies each purpose, and be honest in the necessity step. Make one system the authority on preferences and make everything else read from it. Tell the professional at first contact, not on a website they will never visit. And give the person in the field a short, memorable rule about what belongs in a note. None of that is a technology program. It is data governance applied to a domain that has not had much of it.
Sakara Digital works with pharma and biotech organizations building this kind of governance into commercial data platforms rather than bolting it on after an inquiry arrives. If you are looking at your HCP data estate and want an independent perspective on where the real exposure sits and what to fix first, we are happy to have that conversation.
For Further Reading
For Further Reading
- Omnichannel Orchestration for Pharma Commercial: Building Unified Customer Engagement Platforms
- Consent Management for Patient AI Interactions: Framework and Templates
- Master Data Management for Life Sciences: Creating a Single Source of Truth Across Global Operations
- Patient Data Privacy in Clinical Research: Navigating GDPR and FDA Expectations
- Digital Transformation Roadmap for Pharma Commercial Operations
References & Sources
- European Union. “Regulation (EU) 2016/679 (General Data Protection Regulation), consolidated text.” EUR-Lex. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- Court of Justice of the European Union. “Judgment in Case C-621/22, Koninklijke Nederlandse Lawn Tennisbond v Autoriteit Persoonsgegevens.” 4 October 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62022CJ0621
- Court of Justice of the European Union. “Judgment in Case C-434/16, Peter Nowak v Data Protection Commissioner.” 20 December 2017. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62016CJ0434
- European Data Protection Board. “Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR.” October 2024. https://www.edpb.europa.eu/system/files/2024-10/edpb_guidelines_202401_legitimateinterest_en.pdf
- European Data Protection Board. “CEF 2026: EDPB launches coordinated enforcement action on transparency and information obligations under the GDPR.” 19 March 2026. https://www.edpb.europa.eu/news/news/2026/cef-2026-edpb-launches-coordinated-enforcement-action-transparency-and-information_en
- European Data Protection Board. “Coordinated Enforcement Framework: EDPB selects topic for 2026.” October 2025. https://www.edpb.europa.eu/news/news/2025/coordinated-enforcement-framework-edpb-selects-topic-2026_en
- Commission Nationale de l’Informatique et des Libertés. “Data scraping: KASPR fined 240,000 euros.” 2024. https://www.cnil.fr/en/data-scraping-kaspr-fined-eu240000
- European Data Protection Board. “Data scraping: French Supervisory Authority fined KASPR 240,000 euros.” 2025. https://www.edpb.europa.eu/news/news/2025/data-scraping-french-supervisory-authority-fined-kaspr-eu240-000_en
- Urząd Ochrony Danych Osobowych (Polish Data Protection Authority). “The Supreme Administrative Court upheld the decision of the Personal Data Protection Office.” https://uodo.gov.pl/en/553/1572
- Information Commissioner’s Office. “The Data Use and Access Act 2025 (DUAA): what does it mean for organizations?” ico.org.uk guidance on the Data (Use and Access) Act 2025
- DLA Piper. “UK: Commencement of the data protection provisions in the Data (Use and Access) Act.” Privacy Matters, February 2026. https://privacymatters.dlapiper.com/2026/02/uk-commencement-of-the-data-protection-provisions-in-the-data-use-and-access-act/
- Information Commissioner’s Office. “Business to business marketing.” Direct marketing and PECR guidance. ico.org.uk guidance on business to business marketing
- Information Commissioner’s Office. “A guide to subject access.” ico.org.uk guide to subject access requests
- MultiState. “20 State Privacy Laws in Effect in 2026: Key Dates and Changes.” February 2026. https://www.multistate.us/insider/2026/2/4/all-of-the-comprehensive-privacy-laws-that-take-effect-in-2026
- Byte Back. “U.S. State Privacy Law Landscape Expands to 24 States: What the Latest Legislative Wave Means for Businesses.” June 2026. https://www.bytebacklaw.com/2026/06/u-s-state-privacy-law-landscape-expands-to-24-states-what-the-latest-legislative-wave-means-for-businesses/
- Commonwealth of Virginia. “Code of Virginia, Title 59.1, Chapter 53: Consumer Data Protection Act.” https://law.lis.virginia.gov/vacodefull/title59.1/chapter53/
- Morgan Lewis. “California Consumer Privacy Act: Employee and B2B Exemptions Expire January 1, 2023.” October 2022. https://www.morganlewis.com/pubs/2022/10/california-consumer-privacy-act-employee-and-b2b-exemptions-expire-january-1-2023
- California Privacy Protection Agency. “DROP for data brokers.” https://privacy.ca.gov/drop-for-data-brokers/
- California Privacy Protection Agency. “California Approves Delete Act Regulations.” 13 November 2025. https://cppa.ca.gov/announcements/2025/20251113.html
- Alston & Bird. “DROP Is Coming Due: What California’s Delete Act Means for Data Brokers in August.” 2026. https://www.alstonprivacy.com/drop-is-coming-due-what-californias-delete-act-means-for-data-brokers-in-august/
- Supreme Court of the United States. “Sorrell v. IMS Health Inc., 564 U.S. 552 (2011), syllabus.” Cornell Legal Information Institute. https://www.law.cornell.edu/supct/html/10-779.ZS.html
- American Medical Association. “AMA Physician Data Restriction Program.” https://www.ama-assn.org/about/ama-physician-professional-data/ama-physician-data-restriction-program
- U.S. Government. “42 CFR Part 403, Subpart I: Transparency Reports and Reporting of Physician Ownership or Investment Interests (Open Payments).” eCFR. https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-403/subpart-I
- European Federation of Pharmaceutical Industries and Associations. “Module 6: Disclosure of Transfers of Value.” EFPIA Code of Practice. https://www.efpia.eu/media/uoxnhpww/module-6_disclosure-of-transfers-of-value.pdf
- Troutman Pepper Locke. “FCC Further Extends Effective Date for TCPA Revoke-All Rule.” Consumer Financial Services Law Monitor, January 2026. https://www.consumerfinancialserviceslawmonitor.com/2026/01/fcc-further-extends-effective-date-for-tcpa-revoke-all-rule/
- Federal Communications Commission. “Order, DA 25-312: Consumer and Governmental Affairs Bureau, TCPA consent revocation rules.” https://docs.fcc.gov/public/attachments/DA-25-312A1.pdf
- Timelex. “The three-step test in practice: EDPB guidelines on legitimate interest.” https://www.timelex.eu/en/blog/three-step-test-practice-edpb-guidelines-legitimate-interest-0
- International Association of Privacy Professionals. “US State Privacy Legislation Tracker.” https://iapp.org/resources/article/us-state-privacy-legislation-tracker/
- Snell & Wilmer. “Connecticut Data Privacy Act: 2026 Amendments.” https://www.swlaw.com/publication/connecticut-data-privacy-act-2026-amendments/








Your perspective matters—join the conversation.