China GCP 2026: Electronic Signatures and Data Governance for Clinical Trials
1. What changed in China's GCP on September 1, 2026
China's revised Good Clinical Practice guideline (GCP) took effect on September 1, 2026, replacing the 2020 version issued under Announcement No. 57 of 2020. The revision was jointly released in June 2026 by the National Medical Products Administration (NMPA) together with the National Health Commission (NHC), the National Administration of Traditional Chinese Medicine and the National Disease Control and Prevention Administration.
Two changes matter most to anyone running or supporting clinical trials that touch China: the new GCP adds a dedicated chapter on data governance (Chapter 5), and it makes the first explicit statement in a Chinese drug-regulation text that electronic signatures used in trials must comply with China's national requirements on electronic signatures. The revision also aligns the guideline's structure more closely with ICH E6(R3).
2. The electronic-signature requirement, article by article
The new GCP does not force anyone to use electronic signatures. It sets the conditions for using them: “If electronic signatures are used, they shall comply with China's relevant requirements on electronic signatures.” For global sponsors, CROs and sites, that sentence moves e-signature compliance from an optional digitalization choice to a documented regulatory expectation once a file is signed electronically.
Which requirements? The reference point is the Electronic Signature Law of the People's Republic of China. Article 13 defines a reliable electronic signature by four conditions:
- the signature-creation data is unique to the signatory;
- the creation data was, at signing time, under the sole control of the signatory;
- any change to the signature after signing can be detected;
- any change to the content or form of the data message after signing can be detected.
Article 14 gives a reliable electronic signature the same legal effect as a handwritten signature or a company seal. This mirrors the functional-equivalence logic familiar from 21 CFR Part 11 § 11.702 (biometric vs. non-biometric signatures) and from the EU's eIDAS Article 25(2), but the mechanism is Chinese: certification by a licensed CA under the commercial-cryptography regime, with validity verified against the Ministry of Industry and Information Technology (MIIT) certification-authority list.
3. Data governance chapter: what the articles actually require
The new data-governance chapter (Chapter 5) turns the ALCOA+ expectations that global monitors already apply into Chinese regulatory text:
- Article 51 — data obtained from any source, including data captured directly in computerized systems, must carry the corresponding metadata, including the audit trail.
- Article 53 — computerized systems used by any party in a trial must pass reliable system validation and implement complete user management, permission management and audit-trail functions, so that only authorized users can access and use the system and all access and operations are traceable.
- Article 9 — all paper and electronic source data must be properly recorded, processed and preserved, ensuring reliability and traceability.
- Article 29 — source records must meet attributability, legibility, contemporaneity, originality, accuracy and completeness — the ALCOA criteria.
- Article 32 and Article 36 — the sponsor is the final responsible party for trial activities; where the sponsor delegates to a service provider, it must supervise and manage those activities and bears final responsibility.
Article 29 also sets the retention horizon that makes e-signature vendor stability a compliance issue: records essential to a drug-registration application must be kept for at least five years after the investigational drug is approved for marketing. In practice a signed record can need to survive a decade or more of potential inspection.
4. China GCP vs. US 21 CFR Part 11 vs. ICH E6(R3): the three-way comparison
The table below maps the same compliance questions across the three regimes a global trial team is most likely to be asked about. It is a structural comparison, not legal advice for a specific study.
| Compliance question | China GCP 2026 | US 21 CFR Part 11 | ICH E6(R3) |
|---|---|---|---|
| Electronic signature validity | Reliable e-signature = same legal effect as handwritten signature/seal (Electronic Signature Law Art. 13–14) | E-signatures equivalent to handwritten signatures if Part 11 requirements met (§ 11.700–702) | E-signatures should be used with full traceability; principles-based |
| Signature mechanism | Licensed CA + commercial cryptography regime; verifiable against MIIT CA list | Open or closed system controls; identity verification required | Procedures to ensure authenticity of records and signatures |
| Audit trail | Mandatory metadata + audit trail for all data incl. computerized capture (Art. 51, 53) | Secure, computer-generated, time-stamped audit trails (§ 11.10(e)) | Data governance framework; audit trails for critical data |
| System validation | Reliable validation, user/permission management, traceability (Art. 53) | Validation of systems to ensure accuracy, reliability, consistent performance (§ 11.10(a)) | Risk-based approach to computerized systems |
| Source data quality | ALCOA criteria written into regulation (Art. 29) | Accurate and complete copies of records (§ 11.10(b)) | ALCOA+ principles embedded in data governance |
| Sponsor responsibility | Sponsor final responsible party; must supervise vendors (Art. 32, 36) | Sponsor accountable for study conduct and data integrity | Sponsor oversight of CROs and vendors |
| Retention | Essential records ≥ 5 years after drug approval (Art. 29) | Records retained per applicable predicate rules | Essential documents retention per GCP |
5. What a foreign sponsor or CRO should do now
- Inventory which China-touching documents are already e-signed. The trigger is factual: if a protocol, investigator's brochure, informed-consent form, CRF, safety report or deviation report is signed electronically, the signature must meet China's reliable-signature conditions.
- Verify the CA chain behind your e-signature tool. The certificate must be issued by a licensed CA (MIIT list) with the signing party identity fully matching the licensed CA name — no “platform-issued on behalf of” or “joint issuance” ambiguity — so the “signed by the actual person, content unaltered” claim can be proven in an inspection.
- Map the audit-trail and metadata evidence to Articles 51/53. Your system should expose per-user, per-action audit records (view, sign, withdraw, modify, download) with metadata, and the trail should survive vendor changes.
- Check vendor longevity against the 5-year-plus retention horizon. China's electronic-certification cleanup (MIIT T/CQAE 11034-2025 from January 2026, and the State Cryptography Administration measures effective July 1, 2026) is forcing CA consolidation; a vendor that loses its license creates an evidence-chain problem a decade later.
- Confirm who signs on the China side and with what. For China-domiciled sites, the recommended path is a China CA/electronic-seal workflow for the Chinese signers, keeping the cross-border evidence inside one retrievable record (see the China trust path explained in the cross-border guide linked below).
6. Frequently asked questions
Q: Does the new GCP require us to use electronic signatures? No. It requires that any electronic signature used in a trial comply with China's reliable-signature requirements. Paper workflows with wet-ink signatures and seals remain lawful.
Q: If our eClinical system is 21 CFR Part 11 compliant, are we automatically OK for China? Not automatically. Part 11 validation and audit trails address a large part of the functional requirement, but China's rule additionally anchors signature validity in the Electronic Signature Law and the licensed-CA regime. A Part 11-compliant system used for China-touching trials should still be checked for the China CA/certificate chain and for local retention and metadata expectations.
Q: What records must we keep, and for how long? Records essential to a drug-registration application must be kept at least five years after the investigational drug is approved for marketing (Article 29). Until approval, and across later inspections, the full chain of signed records, metadata and audit trails should remain retrievable.
Q: Do foreign CROs need a Chinese CA license? No. The license requirement applies to certification authorities and e-signature service providers operating in China. A foreign CRO's obligation is to use a compliant chain and to be able to demonstrate it — the same “final responsibility” logic that Articles 32 and 36 place on the sponsor for delegated activities.
7. Bottom line
China's GCP revision closes a gap that global teams often misread: Chinese inspection now has an explicit electronic-signature hook and a written data-governance chapter aligned with ICH E6(R3). For any study with a China site, sponsor or vendor, the compliance conversation should now include the CA chain, the audit trail's metadata completeness, and a retention plan measured in years — not just a Part 11 checkbox.
8. Related reading
- FDA 21 CFR Part 11 electronic signatures: a practical guide
- Interpreting FDA 21 CFR Part 11 compliance and electronic signature best practices
- Best e-signature software for clinical trials
- 21 CFR Part 11 for clinical trials and eConsent
- China cross-border e-signature: regulations and trust path
- China's new e-document rules (Order No. 22): what foreign trading partners must verify