CONFIDENTIAL YET ACCOUNTABLE? PROTECTING COMMERCIAL DATA WHILE KEEPING EU HTA TRANSPARENT

Author(s)

Mondher Toumi, MSc, PhD, MD1, Farah Moalla, BioE2, Imen Reguei, PharmD2, Laurent Boyer, MD3, Lylia Chachoua, PharmD4.
1Aix-Marseille University, Marseille, France, 2Clever-Access, Tunis, Tunisia, 3Health Services Research and Quality of Life Center, Aix-Marseille University, Marseille, France, 4Clever-Access, Paris, France.
OBJECTIVES: Joint Clinical Assessment must protect commercially confidential data and remain transparent enough to be trusted — two duties that pull in opposite directions. This study examined how the framework manages that tension across the dossier, the published report, and national use.
METHODS: A legal and policy analysis used Regulation (EU) 2021/2282 (the confidentiality and IT-platform provisions, including Article 30), Commission Implementing Regulation (EU) 2024/1381 (confidentiality undertakings and redaction), the duty of due consideration under Article 13, and the General Data Protection Regulation as it applies to patient-level data.
RESULTS: The framework relies on full disclosure to the assessment team under confidentiality undertakings, redaction of commercially confidential information from the public report, and exclusion of such information from the public platform. Two frictions emerge. First, transparency about how national bodies considered a JCA report can collide with the duty to protect confidential information, leaving the documentation of due consideration under-specified. Second, the flow of confidential information into national institutions — and the subsequent national assessment by officials who saw the unredacted dossier — rests largely on individual undertakings rather than an explicit institutional confidentiality framework. Where dossiers contain patient-level data, data-protection obligations add a further layer. The net effect is uncertainty about who may see what, and how transparency is demonstrated without breaching confidentiality.
CONCLUSIONS: Trust requires both discretion and openness. A clear institutional confidentiality framework — specifying access, logging, and how due consideration is shown without disclosing protected data — would let the system be confidential and accountable at once.

Conference/Value in Health Info

2026-11, ISPOR Europe 2026, Vienna, Austria

Value in Health, Volume 29, Issue 12S

Code

RWD115

Topic

Real World Data & Information Systems

Topic Subcategory

Data Protection, Integrity, & Quality Assurance

Disease

No Additional Disease & Conditions/Specialized Treatment Areas

Your browser is out-of-date

ISPOR recommends that you update your browser for more security, speed and the best experience on ispor.org. Update my browser now

×