Biobanks play an essential role in biomedical research by collecting, storing, and distributing biospecimens and associated data. Understandably, there are strict regulations on how biobanks can handle samples and data donated by humans. Biobanking regulations vary across different regions around the world, but here are some of the most important laws and international standards for biobanks.
What is the ISO 20387 Standard for Biobanking?
The International Organization for Standardization (ISO) publishes international standards to help maintain quality, safety, and efficiency across a wide range of industries. In response to the growing role of biobanks within the life science industry, ISO has published a standard, ISO 20387:2018, specifically for biobanks. ISO 20387:2018 defines general requirements for biobanking and spans all requirements of managing biobanks, including structural requirements, resource requirements such as personnel, facilities, and equipment, process requirements, and quality management system requirements.
To achieve accreditation, biobanks must establish clear organizational goals, define procedures for document and record management, create standard operating procedures (SOPs) for staff training and equipment maintenance, and conduct regular internal audits to assess the effectiveness of biobanking practices. Proper storage is a key requirement, with techniques like cryopreservation employed to maintain the original properties of the biomaterials and prevent deterioration. Equally important is the handling of samples during retrieval, use, and return to storage. Procedures must be in place to prevent quality compromise during these processes, including careful thawing, the use of appropriate reagents, and maintaining conditions that ensure the samples remain viable for future use. Additionally, ISO 20387 emphasizes thorough documentation and annotation of each sample’s handling history. Accurate record-keeping supports adherence to quality procedures and enables the disposal of samples that have reached the end of their usable life due to spoilage, expiration, or overuse. The choice of biobank management software is an important part of satisfying ISO requirements.
What are HIPAA and HITECH?
Both the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH) regulate how companies in the U.S. collect, store, use, and disclose any individually identifiable health information, such as electronic health records. Biobanks must encrypt all Protected Health Information (PHI) and securely store this information in HIPAA and HITECH-compliant data centers.
Moreover, biobanks should collect only the necessary data from donors and ensure all data collection is done confidentially. Proper data storage is also paramount. It includes using coded or generalized formats for identifying donors to prevent immediate identification. For instance, donors can be classified by birth year rather than using specific dates. Biobanks must also implement controlled access measures, granting permission to access identifiable information only to users who need it and limiting the scope of accessible data to what is necessary for their work. Furthermore, each time an authorized staff member views or edits PHI, it should be recorded in the PHI audit trail.
What is 21 CFR Part 11?
CFR stands for Code of Federal Regulations. 21 CFR Part 11, a standard issued by the US FDA, establishes requirements for electronic records and electronic signatures used by biobanks and other organizations in the U.S. These regulations ensure that electronic records and signatures are secure, trustworthy, and as good as paper records and handwritten signatures.
To adhere to 21 CFR Part 11, biobanks need to implement several critical measures. These include assigning unique logins, passwords, two-factor authentication mechanisms, and biometric identifiers to ensure that each user’s identity can be verified. Additionally, systems must have mechanisms to detect any tampering with records, such as alterations or invalid entries, thereby ensuring the reliability of electronic data. Regular device checks and activity tracking are also necessary to monitor for unauthorized access and capture metadata related to user activities, such as timestamps, actions performed, and electronic signatures. Personnel handling electronic data must be adequately trained, with their competence regularly assessed to maintain compliance. There should also be accountability measures in place for users who hold electronic signatures.
Compliance with 21 CFR Part 11 requires ongoing validation of systems to confirm they function correctly, the implementation of mechanisms to restrict user access with audit trails to track all changes, and the conducting of authority checks for data approvals. Regular audits are essential to identify and address any potential compliance issues.
Using biobank management software designed to meet 21 CFR Part 11 compliance can significantly reduce the risk of violations.
What is the Common Rule (45 CFR 46.116)?
The Federal Policy for the Protection of Human Subjects, also called the Common Rule, is another part of the U.S. Code of Federal Regulations (45 CFR 46), with specific provisions like 46.116 addressing informed consent. It covers general requirements for informed consent when using identifiable biological specimens or data from human donors. This policy includes information about when it is and is not appropriate to ask for broad consent for multiple research uses.
To comply with 45 CFR 46.116, biobanks must ensure that each biological sample is accompanied by a consent form that explicitly outlines the intended use of the sample. Consent should be obtained specifically for the designated research purpose rather than relying on broad consent when it is only applicable to a single study. Biobanks are responsible for releasing samples only for the uses described in the consent form, ensuring adherence to donor agreements. Additionally, it is essential to confirm that donors provide consent voluntarily, without coercion or misleading information. Biobanks should also conduct regular reviews to verify that all stored samples match with the appropriate consent documentation. Institutional Review Boards (IRBs) play an important role in overseeing the consent process, ensuring that ethical standards are upheld, and guiding compliance with the requirements set forth in 45 CFR 46.116.

What is CAP Accreditation?
The College of American Pathologists (CAP) launched the Biorepository Accreditation Program in 2012 to enhance the quality and consistency of biorepositories. The program is designed to establish standardized processes that ensure the availability of high-quality human specimens and genetic materials, such as DNA, to support research, drug discovery, and precision medicine.
CAP’s biorepository accreditation is a prestigious recognition that demonstrates a biobank’s commitment to maintaining the highest standards in the management and quality of biospecimens. This accreditation covers the entire spectrum of biobanking activities, including receiving, processing, storing, and distributing biospecimens, as well as managing the relevant data.
Accreditation by CAP provides several important benefits, such as ensuring biospecimens used in IRB-approved research follow robust ethical and legal frameworks. The program emphasizes control over pre-analytic variables, which is crucial for reliable scientific research and biomarker development. Rigorous chain-of-custody protocols help reduce the risk of specimen misidentification, while continuous monitoring ensures that biospecimens are stored under optimal conditions, preserving their integrity over time. Additionally, the accreditation process establishes best practices for the release of samples, quality assurance measures, and data management best practices, enhancing the reliability of biospecimens for downstream applications like precision medicine and research. Histologic quality checks further confirm that samples, such as tumor tissues, are suitable for subsequent assays.
Though voluntary, CAP accreditation distinguishes biorepositories by demonstrating adherence to a peer-reviewed, evolving quality framework that fosters excellence.
What is GDPR for Biobanks?
The EU General Data Protection Regulation (GDPR) regulates how individuals or organizations, such as biobanks, collect and use the personal data of European Union citizens. Personal data means any data linked to a person. This regulatory requirement for biobanks is built on seven key principles that guide the ethical and secure management of personal data, with significant consequences for non-compliance:
- Biobanks must adhere to the principles of lawfulness, transparency, and fairness in data handling, ensuring that all personal data is collected and used according to clearly stated purposes.
- Purpose limitation stipulates that data should only be processed for the specific objectives for which it was collected.
- Data minimization ensures that only the minimum amount of data necessary is processed, reducing the risk of excessive data collection.
- Accuracy is important for compliance, requiring biobanks to maintain correct and up-to-date information.
- Storage limitations mandate that personal data be retained only for as long as necessary, after which it should be securely disposed of or anonymized.
- Integrity and confidentiality must be maintained throughout all stages of data handling by implementing robust security measures to protect against unauthorized access and data breaches.
- A core component of GDPR is accountability, which requires biobanks to demonstrate compliance through proper documentation, regular audits, and implementation of GDPR-aligned policies. This involves obtaining comprehensive consent forms from donors that address all relevant data protection clauses and storing information securely, often with encryption, to limit access to authorized personnel only.
How Does a Laboratory Information Management System (LIMS) Support Compliance with Biobanking Regulations and Standards?
A biobanking LIMS supports biobanks in complying with regulations and standards by streamlining compliance processes and ensuring the quality and security of biospecimen data. It automates data management tasks, enabling biobanks to maintain accurate records of sample collection, processing, and storage while adhering to regulatory requirements. A LIMS facilitates secure data handling through audit trails, user access controls, electronic signatures, two-factor authentication, PHI anonymization, and data encryption and backups, which help protect sensitive information and demonstrate accountability. Additionally, it supports quality assurance by enabling real-time monitoring of storage conditions by integration with temperature monitoring systems, tracking chain-of-custody, automating document management processes, managing staff training, and scheduling equipment calibration and maintenance, thus enhancing compliance with best practices and regulatory guidelines.
Conclusion
Laws and regulations change over time. Therefore, it is very important for biobanks to regularly check their compliance. Moreover, we are living in times of growing emphasis on data privacy. These times demand that biobanks uphold the highest standards for data privacy and follow sample management best practices. Adhering to a variety of international standards and regulations, such as ISO 20387, GDPR, HIPAA, 21 CFR Part 11, and CAP accreditation, is essential for ensuring the ethical handling of biospecimens and associated data. Biobank management software can help biobanks meet regulatory requirements by streamlining data management, enhancing sample tracking, and managing informed consent of donors, thus fostering trust with donors and research partners.
CloudLIMS enables biobanks to comply with regulations and international standards. Contact us for more details on how CloudLIMS can help biobanks maintain regulatory compliance.
Customer Login 
