Skip to content
Start.cat

Guide · Health and research

What a clinical study app needs

An app that collects data from study participants is not just any app: it handles health data, needs the go-ahead from an ethics committee and has to pass Apple's and Google's review. This guide sums up what needs to be sorted out, and in what order, based on what we have learned building apps for clinical studies with the Hospital del Mar Research Institute and the Hôpital Robert-Debré.

Updated: October 2026

This is a practical guide, not legal advice. Decisions on the legal basis and data protection are made by the research team, its ethics committee and the centre's data protection officer.

Health data needs special care

The GDPR treats health data as a special category of personal data: it can only be processed in the cases the regulation allows, such as scientific research with appropriate safeguards or the participant's explicit consent. Which legal basis applies is decided by the research team with its ethics committee and data protection officer (DPO).

For whoever builds the app, that turns into design decisions:

  • Collect only what the protocol asks for. If the study doesn't need the participant's name, the app doesn't ask for it. Every extra field is a risk and one more thing to justify to the committee.
  • Pseudonymise from the start. Participants sign in with a code from the team, and the link between codes and people is kept by the centre, not the app. Exports for analysis carry the code, with no identifying data.
  • Protect the data wherever it lives: encrypted in transit and at rest, with backups and a log of who accesses it.
  • Decide what happens when the study ends: how long the data is kept, how it is handed over to the team and when it is deleted.

Where the data lives

What works best for us is keeping the environments separate:

  • Development and staging, on our servers in Barcelona. That is where we build and test each version with the project team, without depending on the centre’s systems.
  • Production, on the centre's infrastructure. We install the app and its server on the hospital's or institute's own systems, usually on its Kubernetes. Participant data never leaves the centre and is covered by the security measures the centre already applies to health data. For a Spanish public hospital, that includes the National Security Framework (ENS), worth asking about or checking in the tender.

If the centre has nowhere to host the app, production can run on servers contracted for the project, always within the EU. That adds one more provider to the data processing agreement and to the committee documentation.

Who's who: controller and processor

The hospital or research institute is the data controller: it decides why and how the data is processed. Whoever develops and maintains the app, if they can access that data, acts as a data processor, and both sign a data processing agreement that sets out what the processor may do with it and which security measures apply.

It should be signed before the first real data comes in, and reviewed by the centre's DPO. With a private centre it is usually signed together with the project contract; with a public hospital, it often comes formalised with the award of the tender.

The impact assessment

When health data is processed, the centre will usually need to carry out a data protection impact assessment (DPIA) before starting. The centre does it, with its DPO, but it needs technical information only the app builder has: what data is collected, where it is stored, who accesses it and how it is protected. That information should be in writing from the proposal onwards.

The ethics committee

No study with people starts without a favourable opinion from a research ethics committee. The committee doesn't only assess the protocol: it also wants to know how data is collected and what participants see. It usually asks for:

  • A description of the app and the data it collects.
  • The participant information sheet and consent text, as the participant will see them.
  • How the data is protected and pseudonymised, and who has access to it.
  • Screenshots or a prototype of the key screens.

The committee's calendar tends to set the project's: if the app has to be ready on the day the study is approved, this documentation has to be prepared alongside development, not at the end. We prepare the technical part for the research team to submit.

Is the app a medical device?

An app that collects questionnaires for a study usually is not. But if it calculates doses, helps with diagnosis or recommends a treatment, it may be a medical device and fall under the European rules that govern them, which changes the project completely. It is worth clarifying at the start, with the team and, if needed, a regulatory expert, because it affects scope, timeline and budget.

Publishing on the app stores

Apple and Google review health apps more closely:

  • They require a public privacy policy explaining what data is collected and why, and a way to delete the account and the data.
  • For apps that run research with people, they may ask for evidence of participants' consent and ethics committee approval.
  • Google Play also requires a specific declaration for health apps.

A closed study doesn't stop the app from being public. Anyone can download Cohorte ARCA, but only people who receive the code their doctor texts them when enrolling them in the study can sign in. Installing it is like installing any app, and the team controls access.

Getting people to respond

The best legal design is useless if participants stop answering. What helps most, in our experience:

  • Short questionnaires with one question per screen, or in a chat format, as in ARCA.
  • Reminders at the right moment, configurable by the team.
  • Working offline: participants answer whenever they like and the app sends the answers when coverage returns.
  • Thinking about who answers: children with their families, older people, patients at a difficult time. Readable type, plain language and each participant's own language.

Before you start

Checklist

Before the first real data comes in:

  • The data the app collects is in the protocol, and nothing more.
  • Participants sign in with a code and exports come out pseudonymised.
  • It's decided where the data lives, and it is encrypted, backed up and access-logged.
  • The data processing agreement is signed and the centre's DPO has reviewed it.
  • The centre has done the impact assessment, if it needs one.
  • The ethics committee has given a favourable opinion, with the app and the consent described.
  • It's clear whether or not the app is a medical device.
  • The privacy policy is published and participants can withdraw consent and delete their data.
  • It's decided what happens to the data when the study ends.

FAQ

What people ask us most

Who is responsible for the data, the hospital or the app builder?

The hospital or research institute is the data controller. Whoever develops and maintains the app acts as a processor and signs a data processing agreement with the centre that sets out what it may do with the data.

Can the data stay in the hospital?

Yes, and that is what we usually do: the production version is installed on the centre's infrastructure, so participant data never leaves its systems. Development and testing run on our servers in Barcelona.

If the data is pseudonymised, does the GDPR no longer apply?

It still applies: pseudonymised data is still personal data. Pseudonymisation reduces the risk, but does not replace the other obligations.

How long does the ethics committee take?

It depends on the committee and its meeting calendar. What we can control is having the app's technical documentation ready in time for the session the team is aiming for.

Can the app be on the App Store if the study is closed?

Yes. The app can be freely downloadable and still be for participants only: in Cohorte ARCA, signing in requires the code the doctor texts to participants when enrolling them in the study.

What happens to the data when the study ends?

Whatever the protocol says: usually the final export is handed over to the team and the data is deleted from the server within the agreed period.

Planning a study with an app?

Tell us about the protocol and we'll tell you what it needs, what it costs and how long it takes. We've done it for Cohorte ARCA and Your Decision.

Contact

Got a project in mind? Tell us about it and we'll get back to you within 24 hours.

  1. You write to usTell us the idea, even if it's just a sketch.
  2. We talk for 30 minutesA call to understand what you need.
  3. A clear proposalScope, timeline and budget, no small print.
hello@start.cat
Project type
Estimated budget

By submitting this form you accept our Privacy Policy.