
Compliance: an obligation and an opportunity
Our compliance with regulations such as MDR and GDPR supports your ability to operate legally and effectively in the modern healthcare environment while keeping data safe and private.
Rigorous regulation for clarity and assurance
The European regulations that apply to Resmed, notably GDPR for data protection and MDR for device safety and performance, are designed to be demanding. As a result, you can feel confident about the quality, robustness and rigour of our security and privacy systems, processes and protocols and the quality, safety and performance of our medical devices.

MDR, to improve quality and safety
The European Medical Device Regulation (MDR) is an EU regulation that governs the design, production and distribution of medical devices in Europe. It is due to come into force in May 2021. MDR requires medical device manufacturers, importers and distributors to gather, record and analyse data on quality, usability and safety across each device’s lifespan in order to manage risks and improve performance.
To comply with MDR, Resmed’s Quality Management System (QMS) will process real-life data from our devices for our post-market surveillance system (PMSS). This is in addition to the passive data (e.g. complaints, field reports, audits) and proactive data (e.g. clinical studies, customer surveys, research publications) that is already collected. Processing real-life data will enable us to better meet our regulatory obligations under MDR and continuously improve our standards of product quality and safety.

GDPR, to ensure data protection and privacy
The General Data Protection Regulation (GDPR) is an EU regulation on data protection and privacy that applies to all individuals within the European Union (EU) and European Economic Area (EEA). It is one of the toughest privacy and security laws in the world. Resmed aims to comply in full with the challenging demands of GDPR. This enables us to protect the data of our healthcare partners and their patients and provide reassurance and support relative to their own GDPR responsibilities.