EMA Guideline on Computerized Systems and Electronic Data in Clinical Trials
Assessed and qualified by an independent computer system validation service provider (Zifo).
1. cubeCDMS
2. cubeTMF
GDPR Chapter 5
Chapter 5 of the GDPR (General Data Protection Regulation) governs the transfer of personal data to third countries or international organisations.
1. CRScube Data Centers
CRScube’s cloud data centers are strategically deployed to support global operations while strictly adhering to GDPR.
-
Frankfurt, Germany & Dublin, Ireland : Located within the EU and fully governed by standard GDPR laws.
-
Seoul, South Korea & Tokyo, Japan: Fully compliant and backed by official EU Adequacy Decisions.
-
Oregon, United States: Fully compliant via AWS’s certification with the EU-US Data Privacy Framework (DPF), maintaining lawful data transfers between the EU and US.
|
Region |
Solution |
Main Center |
DR Center |
|---|---|---|---|
|
Global |
cubeCDMS |
AWS Tokyo |
AWS Oregon |
|
cubeIWRS |
|||
|
cubePRO |
|||
|
cubeDDC |
|||
|
cubeCTMS |
AWS Frankfurt |
AWS Ireland |
|
|
cubeTMF |
|||
|
cubeSAFETY |
|||
|
cubeRBQM |
AWS Seoul |
AWS Oregon |
|
|
cubeCONSENT |
|||
|
cubeLMS |
|
Region |
Solution |
Main Center |
DR Center |
|---|---|---|---|
|
EU |
cubeCDMS |
AWS Frankfurt |
AWS Ireland |
|
cubeIWRS |
|||
|
cubePRO |
|||
|
cubeDDC |
|||
|
cubeCTMS |
|||
|
cubeTMF |
|||
|
cubeSAFETY |
|||
|
cubeRBQM |
2. Adequacy Decisions
What are adequacy decisions?
The European Commission has the power to determine, on the basis of article 45 of Regulation (EU) 2016/679 whether a country outside the EU offers an adequate level of data protection.
The effect of such an Adequacy Decision is that personal data can flow from the EU (and Norway, Liechtenstein and Iceland) to that third country without any further safeguard being necessary. In others words, transfers to the country in question will be assimilated to intra-EU transmissions of data.
(Source: European Commission)
CRScube’s data centers in Tokyo and Seoul strictly adhere to local privacy regulations — Japan’s APPI (Act on the Protection of Personal Information) and South Korea’s PIPA (Personal Information Protection Act) — while maintaining full alignment with the GDPR.
Backed by official EU Adequacy Decisions for both South Korea and Japan, data transfers from the EU, including operational access by our South Korea team for customer support and system analytics, are legally recognized as equivalent to intra-EU transfers under GDPR Article 45, requiring no additional safeguards.
3. EU-US Data Privacy Framework
What is the EU-US Data Privacy Framework?
The EU-US Data Privacy Framework (DPF) is a specialized adequacy decision adopted by the European Commission (under Article 45 of the GDPR) to enable safe and lawful personal data transfers from the EU/EEA to participating organizations in the United States.
CRScube utilizes Amazon Web Services (AWS) infrastructure to deliver secure, scalable cloud hosting for our clients.
Since AWS maintains active certification under the EU-US Data Privacy Framework, transfers of personal data from the EU to our US server are legally assimilated to intra-EU transfers. This allows data to flow safely and seamlessly to our cloud environment without requiring complex legal workarounds or additional safeguards.
-
Link to the Data Privacy Framework: https://www.dataprivacyframework.gov/list
-
Link to AWS’s guide on ‘The EU-U.S. Data Privacy Framework’: https://aws.amazon.com/compliance/eu-us-data-privacy-framework/