All posts

From grey zone to guideline: what ICH E6(R3) Annex 2 means for digital health technologies

On 3 June 2026, decentralised trials, pragmatic designs and real-world data got their own good clinical practice rulebook. For the wearables, sensors and apps that power modern trials, it is a turning point.

For years, digital health technologies lived in a regulatory grey zone. Sponsors ran trials with wearables and remote visits, monitors worked out how to check the data, and everyone waited to see how an inspector would react. That wait is over. ICH E6(R3) Annex 2, adopted on 3 June 2026 and entering into force in the European Union on 15 January 2027, is the first global good clinical practice (GCP) text written specifically for trials that use decentralised elements, pragmatic designs and real-world data.

Annex 2 completes the modernised E6(R3) framework, joining the Principles and Annex 1 that have applied in the EU since July 2025. It does not ban anything or invent a new approval route. What it does is more useful: it names the practices that had been established informally and sets out what good looks like. For anyone building or deploying a digital health technology (DHT) in clinical research, three ideas in the text matter most.

A DHT is now a “data acquisition tool”

Annex 2 gives DHTs a job title. Where a wearable, sensor or app is used to collect participant data for a trial, the guideline treats it as a data acquisition tool and holds it to a clear standard. This is a quiet but important shift. The technology is no longer an accessory bolted onto a conventional trial; it is part of the evidence-generating machinery, and it is governed as such.
The definition is deliberately broad, covering mobile applications, wearables and sensors alike. It turns on what the technology does in the trial, not on how it is marketed. That distinction runs through the whole guideline, and it is where a lot of assumptions break.

Evidence must be fit for its intended purpose

Annex 2 asks sponsors to show that the data a DHT produces are fit for their intended purpose, and it defines that on two axes.

  • Reliability means accuracy, completeness, provenance and traceability: can you show where each data point came from and trust that it is right?

  • Relevance means the data actually contain what the scientific question needs, such as the right exposure, outcome and covariate information. 

The depth of proof scales with the stakes. A DHT feeding a key efficacy endpoint faces a higher bar than one supporting an exploratory measure.

A device clearance tells you the technology works for its intended purpose. Fitness for purpose tells you it works here: for this population, this endpoint, this question.

This is where DHT builders and the sponsors who use them most often talk past each other. A CE mark or an FDA clearance is genuinely useful evidence, but Annex 2 does not treat it as a substitute for trial-specific validation. A cleared consumer wearable can still be unfit for a frail elderly cohort or a novel endpoint, and a research-only sensor with no market authorisation at all can be perfectly fit for purpose when its validation is documented for the context of use. The guideline even asks, in section 3.5.1(b)(vii), that the validation status of collection tools be assessed as appropriate. Trial role and regulatory device status are two separate questions, and Annex 2 quietly insists you answer both.

Where DHTs cross different rules

Annex 2 is a GCP guideline, so it stops at the edge of its remit and leaves other frameworks to do their work. That creates seams that DHT teams have to map deliberately, because the guideline will not map them for you.

  • The first is device and software status: whether a DHT is a regulated medical device or software as a medical device depends on its intended purpose and differs between the EU and the US, so the same product can be in scope in one region and out in another. 

  • The second is artificial intelligence. Annex 2 says nothing about AI, so when an algorithm derives a digital endpoint from raw sensor data, the obligations arrive through the EU AI Act and the device rules layered on top. 

  • The third is data protection: consent, de-identification and the handling of real-world data are governed by GDPR and its equivalents, which Annex 2 explicitly defers to. None of these is a reason to slow down. 

They are a reason to design the evidence once, coherently, rather than three times in three registers.

Why this is bigger than a compliance update

It would be easy to file Annex 2 under housekeeping. That would miss the point. By naming remote consent, home-based procedures and DHT-collected data as legitimate, governed practice, the guideline gives sponsors the confidence to design trials around how people actually live rather than around the clinic. It rewards the teams that can produce a clean provenance trail, a documented validation, and a clear rationale for every design choice. And it raises the floor: undocumented sensor feeds and after-the-fact justifications will not survive the scrutiny that is now written down.

For DHT builders, the message is that credibility is now a documented property, not a claim. For sponsors, it is that the digital measures at the heart of a modern trial deserve the same evidentiary care as any other endpoint. The organisations that treat fitness for purpose as a design principle, not a paperwork exercise, will move faster through review, not slower.

What good looks like for a DHT in an Annex 2 trial
  • A documented reliability and relevance assessment tied to the specific context of use, not a generic spec sheet.

  • A validation-status record kept separate from, and additional to, any device marking or clearance.

  • A provenance chain that traces each data point from the sensor to the analysis.

  • A clear statement of the DHT's role in the trial and the endpoint it supports.

  • Early thought on the device, AI and data-protection frameworks that sit alongside GCP.

Where DEEP fits

DEEP Measures exists to take digital measures from definition through to regulatory acceptance, which is precisely the discipline Annex 2 now expects. The work of separating a measure's trial role from its device status, structuring the reliability and relevance evidence, and carrying a clear provenance trail into a dossier is the everyday substance of our platform and our regulatory team. Target Solution profiles and qualification protocols, in accordance with the stack model, can support DHT developers and sponsors to document validation standards to support ICH E6 (R3) Annex 2 requirements. Annex 2 has turned that way of working from a competitive advantage into a shared standard. We think that is good news for patients, for sponsors, and for the technologies that make decentralised research possible.



Preparing a digital endpoint for an Annex 2 trial?

The DEEP regulatory team can review a specific programme against Annex 2 and the device, AI and data-protection frameworks that sit alongside it.  Contact us here.



Sources

ICH E6(R3) Guideline for Good Clinical Practice, Annex 2, final version adopted 3 June 2026 (International Council for Harmonisation); ICH E6 Good Clinical Practice scientific guideline page (European Medicines Agency); E6(R3) Good Clinical Practice: Annex 2 guidance page (US Food and Drug Administration).

This article is general information and is not legal or regulatory advice. Regional effective dates outside the EU were not final at the time of writing and should be confirmed against the issuing authority.

Blog

More insights from experts

Discover related research in digital clinical innovation