Framework overlap

Does GDPR cover ICH E6(R3)?

You hold GDPR and have been told to do ICH E6(R3). Here is how much overlaps, control by control.

56% of ICH E6(R3) you already have

GDPR already covers about 56% of ICH E6(R3), leaving 4 of 9 controls as genuinely new work.

Already covered 0 Likely covered 5 New work 4

No control in GDPR maps directly to one in ICH E6(R3). Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in GDPR reaches these. This is the list to scope.

ICH-E6-DataMgmt-ExternalData-EHRs-RealWorldData-Coord-FDA-EMA
ICH E6 Data Management + External Data + EHR + Real-World Data + Coordination FDA + EMA + PMDA + ICH Family
ICH-E6-IRB-IEC-EthicsCommittee-InformedConsent-Vulnerable
ICH E6 Section 3 - Institutional Review Board (IRB) + Independent Ethics Committee (IEC) + Informed Consent + Vulnerable Populations
ICH-E6-Investigator-Qualifications-Resources-Communication-SafetyReporting
ICH E6 Section 4 - Investigator + Qualifications + Resources + Communication + Safety Reporting + Source Document Verification
ICH-E6-Protocol-IB-CSR-ClinicalStudyReport-Authoring
ICH E6 Section 6 + 7 - Protocol + Investigator Brochure (IB) + Clinical Study Report (CSR) + Reporting
Show the 5 you already have
ICH-E6-Annex1-ElectronicSystems-CSV-eSig-Audit-ALCOA-DataIntegrity
ICH E6(R3) Annex 1 - Computer Systems + Computer System Validation (CSV) + Electronic Signature + Audit Trail + ALCOA+ Data Integrity
ICH-E6-Annex2-DecentralisedClinicalTrials-DCT-eConsent-Remote-Wearables
ICH E6(R3) Annex 2 - Decentralised Clinical Trial (DCT) Elements + eConsent + Remote Monitoring + Wearables + Real-World Evidence
ICH-E6-EssentialDocs-TMF-eTMF-ArchiveRetention-ICH-Section8
ICH E6 Section 8 - Essential Documents + Trial Master File (TMF) + eTMF + Archive + Retention
ICH-E6-Scope-Principles-R3-2025-Risk-Based-DecentralisedClinical
ICH E6 Good Clinical Practice - Scope + 13 Principles + R3 January 2025 + Risk-Based + Decentralised + Modernisation
ICH-E6-Sponsor-QualityRiskMgmt-Monitoring-CRO-Vendor
ICH E6 Section 5 - Sponsor + Quality Management System + Risk-Based Monitoring + CRO + Vendor Oversight

How this is calculated

Already covered means a mapping runs from a control in GDPR to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition