Skip to content
Case Study

Karuna

Transforming Data Protection into Strategic Value

How Kirke’s expertise powered Karuna’s successful clinical trials and acquisition.

“We engaged Kirke in 2020 to guide us through our GDPR compliance implementation. Kirke developed a Privacy Program that was compliant with most data protection regulations around the globe and they acted as our DPO. During the acquisition process we went through with Bristol Myers Squibb (BMS), Kirke was instrumental in demonstrating that Karuna was compliant with data protection requirements. Subsequently, they played a key role in transitioning data protection policies, procedures and documentation to BMS.”

After initiating clinical trials at multiple sites across the European Union, Karuna quickly recognized the critical need to comply with the General Data Protection Regulation (GDPR) to secure regulatory approval and protect patient data. Although the program initially focused on GDPR compliance, it evolved into a comprehensive framework addressing data protection and privacy regulations worldwide. Without a robust and adaptable data protection program, Karuna risked not gaining approval to conduct their trials, jeopardizing both their research and business trajectory.

However, developing a comprehensive data privacy program presented significant challenges:

Compliance

Building a robust framework that adhered to stringent data protection regulations worldwide.

Organizational
Change Management

Creating a culture of privacy while integrating new data protocols into corporate processes.

Third-Party Vendor Management

Ensuring vendor agreements contained appropriate data protection clauses to fulfill Karuna’s data controller responsibilities.

Operational Efficiency

Scaling the program to accommodate varying international regulations without introducing inefficiencies or inconsistencies.

Recognizing these challenges, Karuna partnered with Kirke for its unparalleled expertise in global data protection and privacy regulations. Acting as Karuna’s Data Protection Officer, Kirke initially designed and implemented a robust Data Protection Program to meet GDPR requirements. As the program matured, it was expanded to comply with data protection and privacy regulations worldwide, ensuring comprehensive and sustainable compliance for clinical trial operations across the globe.

Data Mapping & Record-Keeping

Kirke conducted a comprehensive data mapping exercise to identify internal and external data repositories. This effort culminated in the
creation of a GDPR-compliant Record of Processing Activities (Article 30).

Risk Assessment &
Policy Development

A thorough Data Protection Impact Assessment (Article 35) helped identify potential risks, guiding the design of a Data Protection Governance Structure. Kirke also developed all the required policies and Standard Operating Procedures (SOPs) to support the data protection program and ensure ongoing compliance.

Vendor Compliance

Kirke meticulously evaluated third-party vendor agreements, ensuring they contained robust data protection clauses and secure data transfer mechanisms.

Certification Under EU-US
Data Privacy Framework

Kirke guided Karuna through the certification process under the EU-US Data Privacy Framework, a more efficient data transfer mechanism that allows companies to bypass standard contractual clauses. This certification streamlined the process of signing contracts with vendors and clinical sites, reducing lengthy review and negotiation periods.

Culture & Training

To foster long-term compliance, Kirke launched an organization-
wide training initiative that embedded a privacy-centric culture within Karuna.

Kirke Consulting
Let's find a time to connect and discuss how Kirke can support your goals.

Contact us

Ready to transform data complexity into clarity? Tell us about your privacy, AI, or data strategy needs and we'll schedule a time to discuss how we can help.