What's Actually Public vs. Confidential in a Clinical Trial Protocol?

Ask most people in clinical research whether a trial protocol is confidential, and the answer comes fast: "Of course it is." Ask a regulator, and the answer is more precise: parts of it are, and increasingly, large parts are not.

Yin-yang style diagram illustrating that a clinical trial protocol is part public and part confidential, with "Public" curving around the green half and "Confidential" curving around the navy half, each containing a small dot of the opposite color

This distinction matters for far more than curiosity. It shapes how project teams can share documents with vendors, how patients and advocacy groups can review what a trial actually involves, and, as explored in an earlier piece on this blog about protocols and generative AI, what can safely be uploaded into an AI tool in the first place. This article stays deliberately narrower: not the AI question, but the underlying regulatory one. What does the law and GCP framework actually say is public, and what stays behind closed doors?

Confidentiality has a formal definition: it's narrower than people assume.

ICH's Good Clinical Practice guideline doesn't treat "the protocol" as a single confidential object. It defines confidentiality specifically as the prevention of disclosure, to anyone other than authorized individuals, of a sponsor's proprietary information or a trial participant's identity (ICH E6(R2), Section 1.16).

Read closely, that definition protects two distinct things:

  1. Participant identity and personal data. This is protected everywhere, always, without exception.
  2. The sponsor's proprietary information. This is a business judgment, not a fixed category. Sponsors decide what counts as proprietary, and increasingly regulators require them to publish most of it anyway.

The newer ICH E6(R3), which came into effect in mid-2025, keeps participant confidentiality as a core principle while also pushing harder on transparency: trial registration and results reporting are now framed as foundational obligations, not afterthoughts (ICH E6(R3) overview, EMA).

What regulators actively require to be made public

United States — ClinicalTrials.gov

Registration is mandatory before enrollment begins for applicable trials, and the registry record must include study design, interventions, and the full inclusion and exclusion criteria. Under the 2017 Final Rule, disclosure requirements were expanded further to include the complete protocol document and statistical analysis plan for many trials, not just a summary of eligibility criteria.

European Union — CTIS under Regulation 536/2014

The EU's Clinical Trials Regulation goes further still. Once a decision is made on a trial application, most of the submitted dossier, including the protocol, becomes publicly searchable through the Clinical Trials Information System. Article 81(4) of the regulation sets out the exceptions: information can be withheld only to protect confidential communications between member states, to safeguard effective supervision of trials, or to protect personal data and genuinely commercial confidential information.

The practical effect: in the EU today, the default is disclosure, and confidentiality is the exception a sponsor has to justify, a reversal from how most people still picture protocol secrecy.

Real, publicly posted protocols

It's worth actually looking at what a public protocol contains, rather than assuming. These are live examples on ClinicalTrials.gov:

Reading a few of these side by side is a useful exercise for anyone new to protocol structure: synopsis, objectives, endpoints, schedule of assessments, and, notably, a standing "Ethics and Regulatory Compliance" section that typically cites ICH E6, the applicable FDA CFR parts (21 CFR 50, 54, 56, 312), and, in many cases, HIPAA directly. These sections are a good primer on how confidentiality obligations are actually written into a protocol, rather than just assumed.

What still stays confidential, and why

Despite the trend toward disclosure, real categories of protocol content routinely remain restricted:

  • Novel biomarker strategy and analytical assumptions: especially in early-phase oncology, where the mechanism of patient selection may itself be the sponsor's competitive edge.
  • Adaptive design decision rules and interim analysis triggers: disclosing these in advance can bias investigator or patient behavior and undermine trial integrity, which is a scientific validity argument, not just a business one.
  • Manufacturing, quality, and financial arrangements: the EU CTR explicitly carves these out from public CTIS records.
  • Site- or vendor-specific contractual annexes: these usually sit outside the protocol proper but travel with it operationally, and are almost never intended for external release.

This is a genuinely different list from "the whole document," and the distinction is exactly what earlier confidentiality assumptions tend to flatten.

A simple way to think about it

Rather than asking "is this protocol confidential," a more accurate question is: which parts, for whom, and until when? Three practical categories tend to emerge from the regulatory landscape described above:

  • Structurally public: eligibility criteria, study design, primary/secondary endpoints, and (in the EU, and increasingly the US) the full protocol document itself, once registered and decided.
  • Operationally shared but not public: schedules of assessments, visit logistics, site training material; these circulate widely across sponsor, CRO, site, and vendor teams under confidentiality obligations, but were never intended for public release.
  • Genuinely restricted: biomarker and analytical strategy, adaptive design rules, financial and manufacturing detail, and anything that could identify a participant.

None of this removes the real governance work of managing who sees what, when. But it does mean the common assumption — "the protocol is confidential, full stop" — doesn't hold up against what regulators actually require sponsors to publish today. For the follow-on question of what that means for AI tools specifically, see the earlier discussion on this blog: Clinical Trial Protocol and ChatGPT: Why?

Build the Classification Into the Protocol Itself?

If confidentiality is really a matter of "which parts, for whom, until when" rather than a single yes/no label on the whole document, the practical next step is to stop treating that classification as an afterthought handled at submission time, and start building it into how the protocol is authored.

This is not a hypothetical. The EU already runs something close to it. Sponsors submitting to CTIS are required to prepare two versions of key documents, one "for publication" and one "not for publication" — with a stated justification attached to every piece of information withheld from the public copy. Two lessons from how that system actually works in practice are worth carrying into any internal proposal:

  • Regulators reward precision, not blanket labels. EMA has explicitly rejected redacting entire paragraphs or pages, and expects the published version to remain genuinely useful to readers, not a document full of blacked-out sections. A three-tier label -> non-confidential, partly confidential, fully confidential — is a reasonable starting classification for internal governance, but it should resolve down to field- or paragraph-level tags with a stated reason (commercial confidentiality, personal data, or trial-integrity risk such as unblinding), not a single stamp on the cover page.
  • Don't generate the public version by cutting the confidential one. Deriving a synopsis by deleting marked sections from the full protocol is fragile in practice: cross-references break (a visit table pointing to an assay defined in a now-removed section), and careful readers can often infer what was removed from the surrounding text even when the redacted content itself is gone. The more durable pattern, already used by both CTIS and ClinicalTrials.gov, is to author the public synopsis as its own structured document from the outset (design, objectives, endpoints, eligibility criteria), fed by the same tagged source, rather than manufactured by subtraction after the fact.

Put together, a workable internal standard might look like this:

  1. Classify at authoring time, not at submission or publication time. Each protocol section carries a confidentiality tag and, where restricted, a one-line justification category, mirroring the commercially-confidential-information / personal-data / trial-integrity distinctions regulators already use.
  2. Treat the public synopsis as a first-class deliverable, generated from the tagged non-confidential fields alongside the full protocol, not carved out of it afterward.
  3. Review classification at every amendment. A tag applied at protocol version 1.0 doesn't necessarily hold at version 3.0, new eligibility criteria, revised endpoints, or an added biomarker requirement all need the same tagging discipline applied to the change, with version control tying each public release to a specific protocol version.
  4. Keep the "fully confidential" category genuinely rare. If a protocol section can't be represented in any public-facing form, that itself is worth flagging to the study team early, it's often a signal that the sensitive content (e.g., detailed assay methodology) could be separated into its own restricted annex rather than embedded throughout the main body.

None of this requires waiting for a new regulation. It's a documentation and authoring discipline that any sponsor, CRO, or academic study team could adopt today, and it happens to be exactly the kind of structured, tagged input that would make protocols safer and more useful to work with using GenAI tools as well, which brings the discussion back to where this blog started.


Sources

Disclaimer: This article is an educational discussion prepared for informational purposes. It does not constitute legal or regulatory advice. Requirements vary by sponsor, country, and applicable law, always confirm current obligations with qualified regulatory counsel.

Comments

Popular posts from this blog

Project Management Software

Making Unaccounted Costs Accountable in Clinical Research

Clinical Research on Hypnosis: Evidence and Applications