EMA Compliance

EMA Guideline on Computerized Systems and Electronic Data in Clinical Trials

Assessed and qualified by an independent computer system validation service provider (Zifo).

1. cubeCDMS

image-20250131-001349.png

2. cubeTMF

image-20250131-001447.png



GDPR Chapter 5

Chapter 5 of the GDPR (General Data Protection Regulation) governs the transfer of personal data to third countries or international organisations.

1. CRScube Data Centers

CRScube’s cloud data centers are strategically deployed to support global operations while strictly adhering to GDPR.

  • Frankfurt, Germany & Dublin, Ireland : Located within the EU and fully governed by standard GDPR laws.

  • Seoul, South Korea & Tokyo, Japan: Fully compliant and backed by official EU Adequacy Decisions.

  • Oregon, United States: Fully compliant via AWS’s certification with the EU-US Data Privacy Framework (DPF), maintaining lawful data transfers between the EU and US.

image-20240118-062612.png

Region

Solution

Main Center

DR Center






Global

cubeCDMS



AWS Tokyo



AWS Oregon

cubeIWRS

cubePRO

cubeDDC

cubeCTMS


AWS Frankfurt


AWS Ireland

cubeTMF

cubeSAFETY

cubeRBQM


AWS Seoul


AWS Oregon

cubeCONSENT

cubeLMS

Region

Solution

Main Center

DR Center





EU

cubeCDMS





AWS Frankfurt





AWS Ireland

cubeIWRS

cubePRO

cubeDDC

cubeCTMS

cubeTMF

cubeSAFETY

cubeRBQM


2. Adequacy Decisions

What are adequacy decisions?

The European Commission has the power to determine, on the basis of article 45 of Regulation (EU) 2016/679 whether a country outside the EU offers an adequate level of data protection.

The effect of such an Adequacy Decision is that personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that third country without any further safeguard being necessary. In others words, transfers to the country in question will be assimilated to intra-EU transmissions of data.

(Source: European Commission)

CRScube’s data centers in Tokyo and Seoul strictly adhere to local privacy regulations — Japan’s APPI (Act on the Protection of Personal Information) and South Korea’s PIPA (Personal Information Protection Act) — while maintaining full alignment with the GDPR.

Backed by official EU Adequacy Decisions for both South Korea and Japan, data transfers from the EU, including operational access by our South Korea team for customer support and system analytics, are legally recognized as equivalent to intra-EU transfers under GDPR Article 45, requiring no additional safeguards.


Japan


image-20240118-062947.png

Read the full document: EU Adequacy Decision for Japan.pdf

Republic of Korea


image-20240118-063025.png

Read the full document: EU Adequacy Decision for Republic of Korea.pdf


3. EU-US Data Privacy Framework

What is the EU-US Data Privacy Framework?

The EU-US Data Privacy Framework (DPF) is a specialized adequacy decision adopted by the European Commission (under Article 45 of the GDPR) to enable safe and lawful personal data transfers from the EU/EEA to participating organizations in the United States.

CRScube utilizes Amazon Web Services (AWS) infrastructure to deliver secure, scalable cloud hosting for our clients.

Since AWS maintains active certification under the EU-US Data Privacy Framework, transfers of personal data from the EU to our US server are legally assimilated to intra-EU transfers. This allows data to flow safely and seamlessly to our cloud environment without requiring complex legal workarounds or additional safeguards.