Skip to main content

Life Sciences & Healthcare · Counsel brief · 10 min · Updated 8 Aug 2026

Real-World Evidence Projects in China

Real-world evidence projects in China require a privacy-by-design analysis: original collection basis, sensitive-data consent, de-identification standard, and cross-border transfer mechanisms.

Key takeaways
  1. Life Sciences & Healthcare Blog · Legal cluster
  2. Global pharmaceutical and medical-device companies fund real-world studies in China for regulatory submissions, health-economic evaluations, and post-market safety.
  3. That assumption collapses at the privacy gate.
Cite this article
Article
Real-World Evidence Projects in China: Privacy and Secondary-Use Traps for Global RWE Teams
Author
Ying Chen
Last updated
8 Aug 2026
Publisher
China Legal Portal

Ying Chen. “Real-World Evidence Projects in China: Privacy and Secondary-Use Traps for Global RWE Teams.” China Legal Portal, updated 8 Aug 2026. https://chinalegalportal.com/lawyer-blog/life-sciences-healthcare-blog/2399-ls-blog-rwe-privacy-secondary-use

Life Sciences & Healthcare Blog · Legal cluster

Real-world evidence (RWE) decks assume "the data already exists, so research is free." In China, the Personal Information Protection Law (PIPL) and — where genetic material or health datasets are involved — the human genetic resources (HGR) rules treat secondary use as a design problem, not a footnote. This article explains the threshold questions that global RWE teams routinely skip: whether the original collection was lawful for this secondary purpose, whether the dataset is still personal information after processing, what cross-border restrictions apply, and why the RWE project must be structured as privacy-by-design from the first data request.

Why this matters: RWE is the fastest-growing, least-filed area of healthcare data work

Global pharmaceutical and medical-device companies fund real-world studies in China for regulatory submissions, health-economic evaluations, and post-market safety. The appeal is that the data "already exists" — hospital records, claims databases, registries, wearable outputs — so the research appears cheaper and faster than a new clinical trial. That assumption collapses at the privacy gate. The data may exist, but its lawful basis for the original purpose does not automatically extend to a new research purpose, and Chinese regulators have made clear that secondary use of health data is a regulated activity with its own consent, security, and cross-border rules.

The practical stakes are high: a Chinese RWE project built on patient data collected under a treatment consent form, repurposed without separate consent or de-identification, creates exposure for the hospital, the data provider, the CRO, and the sponsor. Regulatory warnings have already been issued against healthcare AI and data platforms for illicit secondary harvesting of health data, and the trend is toward stricter enforcement. This article gives the gate questions that turn an RWE project from a privacy afterthought into a compliant design.

Diagram in text
  • PIPL + health data rules — “data already exists” is not a free research licence. Real-world evidence is processing of personal information — often sensitive health PI.
  • MUST PROVE
  • Lawful basis for secondary use
  • PIPL purpose limitation; separate consent where

Personal Information Protection Law of the People's Republic of China (2021)

PIPL governs the processing of personal information, and health information is sensitive personal information under Article 28, subject to the stricter rules of Articles 13, 23, 29, and 30. Article 13 lists the lawful bases for processing; Article 23 imposes obligations for transferring personal information to other processors; Article 29 requires separate consent for processing sensitive personal information. For an RWE project, the analysis begins with the original collection: under what lawful basis was the health data first collected, and does that basis extend to the research use? If the original collection was for treatment or for Trial X, the RWE secondary use is a new purpose that requires its own analysis.

Personal Information Protection Law of the People's Republic of China, Article 29: The processing of sensitive personal information shall be based on a specific purpose and sufficient necessity, and the consent of the individual shall be obtained separately... Where laws and administrative regulations provide that written consent shall be obtained for the processing of sensitive personal information, such provisions shall prevail.

Data Security Law of the People's Republic of China (2021)

The Data Security Law establishes the classification and grading system for data, including health-related data, and requires data processors to establish security management systems. For RWE datasets, the law matters in two ways: it imposes general data-security duties, and it restricts the cross-border transfer of important data. Whether a given RWE dataset rises to "important data" depends on its scope and sensitivity, but the analysis must be conducted, not assumed away.

NMPA RWE evaluation guidance

The National Medical Products Administration has issued guidance on real-world data and real-world evidence, recognising RWE's value for regulatory purposes while requiring that the data be reliable, relevant, and lawfully obtained. The NMPA's regulatory acceptance of RWE does not override the privacy law; it adds a data-quality layer on top. An RWE submission based on data collected unlawfully is not merely a privacy problem — it undermines the regulatory submission itself.

Since PIPL took effect, the Cyberspace Administration of China (CAC) and sector regulators have examined secondary use of health data in the healthcare-AI and data-platform context. The published warnings and penalty cases share a common pattern: platforms that collected health data under one stated purpose, then repurposed it for model training or research — or shared it with third parties — without the separate consent and security measures that PIPL requires. The enforcement message for RWE teams is that "we already have the data" is not a defence; the original collection's lawful basis, purpose, and consent scope are the starting point of every secondary-use analysis.

The cross-border dimension is the most frequently underestimated. RWE datasets are routinely shared with global analytical teams, cloud providers, or partner CROs outside China. That sharing triggers PIPL's cross-border-transfer provisions — a security assessment by the CAC for important data or large volumes, standard contract clauses, or certification — and, where genetic or related data is involved, the HGR framework's separate approval or filing requirements. An RWE project that moves de-identified-but-reidentifiable data offshore without the correct mechanism has built its own enforcement file.

The HGR layer applies when the dataset contains human genetic resources — gene sequences, genotypes, or related information derived from Chinese subjects. The HGR regulations require approval or filing for international cooperation and cross-border provision, and penalties for unapproved transfers have been issued. For RWE projects involving biomarker or genomic data, the HGR analysis runs in parallel with the privacy analysis, and both must be completed before the data moves.

The threshold for the CAC security assessment matters to RWE teams because it sets the point at which a cross-border data transfer becomes an approval exercise rather than a filing exercise. Under the cross-border data transfer rules, a security assessment is required for transfers of important data, for transfers by operators processing personal information of a defined scale, and for transfers of defined volumes of personal information or sensitive personal information. The thresholds are calculated per operator, which means the sponsor, the CRO, and the hospital may each be a separate data processor with separate obligations. An RWE project that transfers data from a hospital that crosses the threshold, through a CRO that does not, and to a sponsor that does, must map the obligations per entity — not assume one mechanism covers the chain.

Operational vulnerabilities and transactional pitfalls

  • The "it's for research" assumption: the data provider's consent form covers treatment or a prior trial, and the RWE team assumes research is a permissible extension. PIPL does not presume; it requires a purpose-based analysis with separate consent where sensitive data is involved.
  • The de-identification illusion: the dataset is "anonymised" in the marketing sense — hashed, coded, or aggregated — but the processing does not meet PIPL's definition of anonymisation, and the dataset is still personal information. The legal status determines whether PIPL applies at all.
  • The untracked cloud copy: the global analytics team copies the dataset to a foreign cloud for tooling, and no one records it as a cross-border transfer. The transfer mechanism is missing, and the mirror copy is the evidence.
  • Undocumented data provenance: the RWE deck cannot show, for each dataset, the original collection basis, the consent scope, the ethics approval, and the chain of custody. A dataset without provenance is a liability without a label.
  • The vendor assumption: the CRO or data provider certifies compliance in a clause, but the sponsor never verifies the actual consent forms, approvals, or security measures. The contractual comfort does not survive an inspection.

In my clinical-research and health-data practice, the RWE engagement usually starts with a data request that looks innocent — a sponsor wants hospital records, claims data or wearable outputs for a real-world study, and the data provider says the data already exists, so the research is free. The first question I ask is not about the research protocol; it is about the original collection basis. The treatment consent form that the hospital obtained does not automatically authorise secondary research use, and under the PIPL the health data is sensitive personal information requiring separate consent for a materially different purpose. The de-identification claim is the second gate: a dataset that is hashed, coded or aggregated while the provider retains the key or the mapping is pseudonymised, not anonymised, and the research team that treats the two as the same has built the finding that the regulator will issue. The HGR layer is the third: where the data includes genetic material or related information, the human genetic resources rules apply to the collection and any cross-border transfer, and a global RWE team that routes data through a foreign cloud without the HGR analysis has created an exposure for the hospital, the CRO and the sponsor at once. The RWE project is a privacy-by-design exercise from the first data request; the map of the original collection basis is the first document, and everything else follows from it.

Diagram in text
  • Inventory source data
  • Which patients, fields, sites, vendors
  • hold RWE inputs
  • Build consent map
  • What original consent / notice

Strategic compliance roadmap and action plan

Structure every China RWE project as privacy-by-design, with the analysis completed before the first data request:

  1. Map the original collection basis: for each dataset, document the original lawful basis, the consent form, the ethics approval, and the stated purpose. The RWE secondary use is lawful only if it fits within the original basis or obtains new consent — and the map shows which.
  2. Classify the dataset: determine whether the processed dataset is personal information under PIPL (including whether any anonymisation meets the legal standard), whether it is sensitive health data, and whether it constitutes important data under the Data Security Law or human genetic resources under the HGR rules. The classification drives every downstream requirement.
  3. Design the de-identification standard: apply technical controls that satisfy PIPL's anonymisation definition — irreversible, no reasonable re-identification — or, if the research genuinely needs identifiable data, build the separate-consent and security package for sensitive data processing.
  4. Plan the cross-border mechanism: identify every offshore recipient — analytical team, cloud provider, partner CRO — and select the correct transfer mechanism (CAC security assessment, standard contract clauses, or certification), with the HGR approval or filing added where genetic data is involved. No dataset moves without the mechanism.
  5. Contract the compliance chain: the data-provider, CRO, and vendor agreements require the provider to warrant the original collection basis, consent scope, and approvals, and give the sponsor audit rights to verify them. The contract converts the provider's compliance into the sponsor's evidence.

When the project is designed, document the whole file — the collection map, the classification, the de-identification standard, the transfer mechanisms, and the contract chain — and review it before the first dataset is accessed. The file is the proof that the research was designed lawfully, not retro-fitted.

The NMPA's RWE guidance and the privacy rules should be read together in the study protocol itself, not in separate silos. A protocol that describes the data sources, the lawful basis for each, the de-identification standard, and the transfer mechanisms gives the ethics committee, the regulator, and the sponsor's own reviewers one document to test. In our experience advising global sponsors on China RWE projects, the studies that clear review fastest are the ones that treat the privacy and data-security sections as core protocol content with named responsible persons, rather than as an appendix drafted by counsel after the science is locked. Building the gate questions into the protocol at design stage converts compliance from a late-stage inspection risk into a design feature the reviewers can verify.

What not to do

Do not assume that existing data means free data. Do not let a de-identification claim written by marketing replace the legal anonymisation analysis. Do not copy the dataset to a foreign cloud for convenience and call it internal. Do not rely on a vendor's clause when the consent forms and approvals are the real evidence. RWE in China is a design problem — build the privacy and HGR gates into the design, and the research runs; skip the gates, and the research becomes the investigation.

Read next: HGR compliance · Clinical data · Privacy

Cluster: Life sciences legal hub · Life sciences blog

READER DISCUSSION

Discussion

Share experience or questions about this topic. This is a public discussion — not legal advice. Do not post confidential case details.

Have a question after reading? Leave it here, or Ask a Lawyer for a free initial consultation.

Comments are moderated. China Legal Portal is a directory and information resource; no attorney–client relationship is formed by posting here.

End of brief

Ying Chen, Life Sciences & Healthcare lawyer

Author

Ying Chen

Hangzhou T&C Law Firm · Life Sciences & Healthcare

Hangzhou T&C Law Firm · Verified listing. This insight is educational and does not create an attorney–client relationship.

View lawyer profile

Life Sciences & Healthcare

Need a next step?

Take a focused intake, or browse listed life sciences & healthcare practitioners.

Request a consultation Find listed counsel

In the library

Go deeper on this topic

Educational information only — not legal advice. Laws change; consult qualified counsel for your situation. No attorney–client relationship is formed by using this site.

Disclaimer Editorial policy AI content policy