Customer Lifecycle

Contracting & Compliance Validation

πŸ“„ 27 of 33 πŸ“… January 2, 2026 🏷️ v1.1.0

Contracting & Compliance Validation

Category: Customer Lifecycle | Audience: undefined | Page: 27 of 33

Table of Contents

- Vet Subcontractors

- Manage Breach Notification Timelines

- Create a Data Retention Policy

- Delete Data at End of Contract

- Support DSARs

- Request and Review Audit Reports


Contracting & Compliance Validation

Welcome to the onboarding guide for Contracting & Compliance Validation at Elixia Health. This document will help you understand the essential compliance and contractual information needed to ensure smooth operations and adherence to regulations.

Key Concepts

  • Sub-processors: Third-party services used by Elixia Health to support clinical trials.
  • Subcontractor Vetting: Process of assessing and approving subcontractors to ensure they meet necessary qualifications.
  • Breach Notification: Automated system to manage GDPR compliance for data breaches.
  • Data Retention Policy: Guidelines for how long data is retained in the system.
  • Data Deletion: Process for securely deleting data at the end of a contract.
  • DSARs (Data Subject Access Requests): Requests from data subjects to access or modify their personal data under GDPR.
  • Customer Audits: Process for reviewing audit reports and conducting inspections to ensure compliance.

What You Can Do

  • Vet and approve subcontractors
  • Manage breach notification timelines
  • Create and manage data retention policies
  • Delete data securely at the end of contracts
  • Support DSARs
  • Request and review audit reports

How To

Vet Subcontractors

  1. Prepare and Send the Vetting Questionnaire to the subcontractor:

- The questionnaire should cover the following areas:

- Organization Information: Company name, registration details, location, years in operation

- Data Protection Compliance: GDPR, HIPAA, or other applicable regulation compliance certifications

- Security Practices: Information security policies, data encryption methods, access controls, and incident response procedures

- References and Experience: Previous clients in healthcare/clinical trial industry, case studies

- Audit and Certification Status: ISO 27001, SOC 2 Type II, or other relevant certifications

- Data Processing: How they will process, store, and protect PHI/PII

- Subcontractor Relationships: Whether they use further sub-processors and their vetting processes

- Financial Stability: Proof of financial viability and insurance coverage

- Allow 2-4 weeks for the subcontractor to complete and return the questionnaire

  1. Review the Questionnaire with subject matter experts:

- Assemble a review team including:

- Compliance Officer: Reviews regulatory and compliance requirements

- Security Officer: Evaluates security practices and certifications

- Operations Lead: Assesses operational capability and reliability

- Evaluate responses against your organization's vetting criteria and risk tolerance

- Identify any gaps or concerns that require clarification

- Request additional documentation (certifications, audit reports, contracts) as needed

- Rate each subcontractor based on your vetting matrix (e.g., Low/Medium/High Risk)

  1. Obtain Approval from the Business Owner:

- Prepare a vetting report summarizing:

- Subcontractor profile and background

- Risk assessment and compliance gaps

- Recommendations and concerns

- Approval or conditional approval recommendation

- Present the report to the appropriate business owner (Project Manager, Director, or C-level executive)

- Obtain documented approval (email or system-based approval) before engaging the subcontractor

- If conditional approval, clearly define conditions that must be met

- Document the approval and maintain records for audit purposes

  1. Execute Data Processing Agreement (DPA):

- Once approved, execute a Data Processing Agreement outlining:

- Scope of data processing activities

- Data protection obligations and responsibilities

- Audit and inspection rights

- Data breach notification requirements

- Data deletion or return procedures at contract termination

- Maintain all vetting and approval documentation in a centralized register

Manage Breach Notification Timelines

  1. Create a SharePoint Site for GDPR breach management:

- Navigate to your SharePoint tenant and create a new site titled "GDPR Breach Management"

- Select "Team Site" as the site template

- Configure permissions to restrict access to authorized personnel (see step 4)

- Add a description and governance policy for the site

- Enable versioning and auditing on all lists within the site

  1. Set up Lists for breach tracking and notification:

- Create the Breach Incident Register list with the following columns:

- Breach ID (unique identifier)

- Date of Breach Discovery

- Date Breach Occurred

- Description of Breach

- Category (e.g., Unauthorized Access, Data Loss, Malware)

- Number of Data Subjects Affected

- Type of Personal Data Involved

- Risk Level (Low/Medium/High)

- Internal Owner

- Status (Identified, Under Investigation, Remediated, Closed)

- Create the Timeline Tracker list with columns:

- Breach ID (linked to Incident Register)

- Event Type (Discovery, Initial Assessment, Notification Sent, Follow-up, etc.)

- Planned Date

- Actual Date

- Description

- Owner

- Notes

- Create the Notification Templates list with columns:

- Template Name

- Recipient Type (Data Subject, Supervisory Authority, Media)

- Template Content

- Language

- Last Updated

- Version Number

  1. Create Notification Templates with specific fields:

- Data Subject Notification Template:

- Description of the breach (without sensitive details)

- Date of breach and discovery

- Type of data affected

- Likely consequences

- Measures taken or proposed to mitigate harm

- Contact information for more information

- Data Protection Officer details

- Supervisory Authority Notification Template (for serious breaches):

- Breach description and facts

- Likely adverse effects on data subjects

- Measures taken or proposed to address and mitigate harm

- Contact information for questions

- Data Protection Officer or authorized representative details

- Media/Public Communication (if applicable):

- Formal statement about the incident

- Measures taken to protect data subjects

- Company's commitment to data protection

- Contact information for inquiries

  1. Restrict Site Access to authorized personnel:

- Define access levels: Viewers, Editors, Owners

- Add specific users or security groups to the site

- Owners: Compliance Officer, Data Protection Officer (full control)

- Editors: Incident Response Team, Legal Team (can create/edit items)

- Viewers: Management/Executive stakeholders (read-only access)

- Remove inherited permissions and apply site-specific permissions

- Enable multi-factor authentication (MFA) requirement for site access

- Regularly audit access logs to ensure only authorized personnel access breach information

  1. Configure the Breach Incident List to track critical information:

- Set up automated workflows/Power Automate flows:

- When a breach is logged, send notification to Data Protection Officer

- Automatically calculate timeline milestones (72-hour notification deadline, etc.)

- Create timeline tracker items automatically when incident status changes

- Add views for different stakeholders:

- "High Risk Breaches" view (filtered by risk level)

- "Pending Notification" view (filtered by status)

- "Timeline Overview" view (showing all timeline events)

- Enable alerts for critical updates (e.g., when status is updated to "Remediated")

- Set up monthly reports summarizing breach metrics:

- Total breaches identified

- Average time to notification

- Categories of breaches

- Data subjects affected

Create a Data Retention Policy

  1. Log in to MCT or MTJ.
  2. Navigate to the DataRetentionPolicy table.
  3. Click on "Create New" to create a new retention policy.
  4. Fill in the required fields.
  5. Save the new retention policy.

Delete Data at End of Contract

  1. Notify the customer of the data deletion process.
  2. Provide options for securely deleting or returning data, including backups.
  3. Ensure all Contracted Processors delete or return the data as applicable.

Support DSARs

  1. Use the GDPR Data Subject Rights Request Form (MTJ Patient) for submissions.
  2. Track all DSRs using the Data Subject Request (DSR) Tracking (MCT).
  3. Receive automated notifications for new DSRs.
  4. Follow the standardized workflow for handling DSRs.
  5. Use escalation criteria for complex requests.
  6. Maintain audit trails for all DSR-related actions.

Request and Review Audit Reports

  1. Request an audit report or related documentation through the MCT platform.
  2. Review the report or documentation to ensure compliance with Applicable Data Protection Laws.
  3. Request further assistance and documentation if needed.
  4. Conduct remote inspections or audits with the Service Provider’s cooperation.
πŸ’‘ Tip: Regularly review and update your data retention policies to align with changing regulations and business needs.

Tips & Best Practices

  • Keep subcontractor vetting documents organized and easily accessible.
  • Regularly test your breach notification system to ensure it functions correctly.
  • Communicate clearly with customers about data deletion processes.
  • Train your team on handling DSARs efficiently and within deadlines.
  • Schedule regular audits to maintain compliance and identify areas for improvement.

Next Steps

  • Familiarize yourself with the subcontractor vetting process.
  • Set up your breach notification system in SharePoint.
  • Create and implement data retention policies.
  • Understand the data deletion process at contract end.
  • Learn how to support and manage DSARs.
  • Request and review audit reports to ensure compliance.

← Previous: Evaluation & Due Diligence

πŸ“š Documentation Home

Next: Onboarding & Integration β†’


Generated from MCT Knowledge Base β€’ v1.1.0 β€’ January 2, 2026