Category - data protection

medicaldeviceslegal

The EU Court’s Schrems II judgement – urgent revisiting of international personal data transfer mechanisms required

Wasn’t the MDR about More Data Required, and the same for the IVDR? Aren’t more and more devices running software that processes patient and user data? Isn’t the medical devices industry a very international business? Indeed – so the ability for companies working with the MDR and IVDR to transfer personal data internationally for all […]

medicaldeviceslegal

The MDCG cybersecurity guidance – a helpful rush job

It has been some time since the MDCG guidance on cybersecurity for medical devices was released (MDCG 2019-16 December 2019), so everybody has probably had the opportunity to get used to the document by now. While the document is by no means ideal or even flawless (congratulations MDCG on a glaring spelling mistake in the […]

medicaldeviceslegal

€ 500 per data subject – a quantification of why GDPR matters

Clients often ask me why they should invest in General Data Protection Regulation (GDPR) compliance so much. For medical devices and medicines regulatory compliance, they get it to an extent. Non-compliant devices carry risk of enforcement, which can lead to them being taken off the market. Devices off the market = collapse of cash flow […]

medicaldeviceslegal

Happy New Medical Devices Year!

Happy New Year everybody – may your transition to the MDR and IVDR be unproblematic and timely. May your management be convinced that making and selling medical devices is actually core business of the company and dedicate sufficient resources to your transition project. Halfway point of MDR transition 2018 is the year in which we will […]

medicaldeviceslegal

Festive alert! Change is on its way.

Change is on its way – medical devices law will not be the same again as of next year. Panic soccer The authorities are not your friend anymore. Notified bodies are engaging in massive ‘panic soccer’ (Dutch expression) dropping companies like they’re hot. If you have not implemented the new clinical evaluation MEDDEV fully by […]

medicaldeviceslegal

Privacy by design and data portability

I’ve often warned medical devices companies that they need to start looking at privacy by design obligations under the General Data Protection Regulation, the GDPR. Engineers at a company where I gave an in-company presentation earlier this year were seriously unhappy that privacy by design obligations can affect both hard and software and that the […]

medicaldeviceslegal

Medical devices M&A – data protection

Lately I have been doing a lot of work in medical devices M&A projects, some very big, some quite small and some in between. Everybody seems to be merging with everybody else these days as the bigger companies divest branches to reposition and smaller companies put themselves up for sale. These projects are invariably highly […]