grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

IQVIA Faces €7M GDPR Fine Over Health Data Anonymization

IQVIA GDPR fine
Published on
October 9, 2026

Italy's data protection authority has issued IQVIA a GDPR fine of €7 million, around $7.8 million, after ruling that a database holding the health records of roughly one million patients never qualified as anonymous. The Garante per la protezione dei dati personali adopted the decision on 23 September and published it on 2 October. It closes an investigation that began with on-site inspections in April 2025. IQVIA Solutions Italy had built the dataset from records supplied by 800 general practitioners, then used it for studies commissioned in part by pharmaceutical companies.

Scale is part of what makes the ruling significant, because the company operates in more than 100 countries. It says it handles 68 petabytes of data and 1.2 billion patient records, which places it among the largest health data businesses anywhere. The GDPR fine therefore reaches IQVIA at global scale. The reasoning behind it also sets out, in unusual detail, what European regulators expect before anyone calls a health dataset anonymous.

Why IQVIA Received a GDPR Fine

The regulator rejected the company's central claim. IQVIA had argued that the records carried no identifying information, because each patient appeared under a unique code rather than a name. The Garante found that the code itself defeated the argument. It stayed attached to the same person across every submission, so anyone with access could follow that patient overtime.

The surrounding data made the problem sharper. Each record held a year of birth, sex, diagnoses, symptoms, prescriptions, test results, vaccinations and location details. Put together, that combination let a reader isolate individual patients and, using reasonable means, work back to their identities.

That conclusion drives everything else in the decision. Truly anonymous data sits outside the GDPR, so none of the regulation's obligations apply to it. Coded data that still permits re-identification remains personal data, and every duty attached to health information comes back into force.

Where Anonymization Ends and Pseudonymization Begins

Recital 26 of the GDPR sets the test. It asks what a recipient or an attacker could achieve with reasonable effort, not what the controller intended. Swapping a name for a persistent identifier does not clear that bar on its own.

Rich longitudinal records tied to a stable code stay pseudonymized, and pseudonymized data remains regulated data. Any organization running analytics on so-called de-identified health records faces the same question. The GDPR fine against IQVIA rests on a technical judgment that other companies can apply to their own pipelines today.

Over 3,300 Patients Were Never Coded at All

Investigators also found a block of data carrying direct identifiers. More than 3,300 patients appeared in the database under their real names, with Italian tax codes, addresses and contact details attached. For over 3,000 of them, those identifiers sat beside health information.

That finding sits awkwardly next to the company's description of the dataset. A collection presented as anonymous contained thousands of fully named patients. No coding scheme stood between those records and the people behind them, and those entries weighed against IQVIA when the Garante calculated the GDPR fine.

The Regulator Named IQVIA the Controller

One of the decision's most consequential points has little to do with anonymization. The Garante concluded that IQVIA acted as data controller from the moment records left the doctors' practices, rather than as a processor working on behalf of the GPs. That designation carries much of the weight behind the GDPR fine IQVIA now faces.

Controllers hold the heavy obligations under European law. They must identify a lawful basis, inform the people concerned, set retention periods and run impact assessments. Analytics vendors across Europe often position themselves as processors in arrangements like this one, so the finding shifts where liability sits in a widespread commercial model. For IQVIA, controller status turned a data supply relationship into direct exposure to a GDPR fine.

The practical reading is straightforward for anyone buying or selling health analytics. A contract that labels the vendor a processor carries little weight if that vendor decides why the data gets collected and how it gets used. Regulators examine the actual decision-making rather than the paperwork around it.

Missing Legal Basis, Records Dating Back to 2001

The remaining violations follow from that designation. IQVIA processed health data without an adequate legal basis and without informing patients properly. It also skipped the data protection impact assessment that high-risk health processing demands.

Retention was a separate failure. The company had set no deletion schedule, and investigators found records going as far back as 2001. The Garante judged the security measures protecting the dataset inadequate as well, and each of those gaps fed into the GDPR fine IQVIA received.

A second thread ran into the same case. The authority merged a proceeding covering a personal data breach that IQVIA had notified itself. That case now sits inside the decision that produced the GDPR fine against IQVIA, though the published summary gives no detail on the scope or the cause of the incident.

What IQVIA Must Do Within 120 Days

Beyond the GDPR fine, IQVIA faces a corrective order with a hard deadline. The company has four months to bring its processing into line if it wants to continue the activity. The alternative puts anonymization back in the hands of the general practitioners. They would have to apply the safeguards the Garante has specified before any data reaches a commercial partner.

Several factors pulled the penalty down. Before setting the GDPR fine, the authority weighed the patient numbers and the nature of the data against the fact that doctors stopped sending records in 2023. It also credited IQVIA for cooperating throughout the proceeding.

IQVIA says it maintains pseudonymization and encryption safeguards, continues to work with the authority, and has already begun adopting the required measures. IQVIA also reserves the right to appeal the GDPR fine. The dataset plays no part in its clinical research services or in trials run for sponsors, the company says.

A Warning for Every Health Data Pipeline in Europe

The GDPR fine IQVIA received puts a price on a judgment call that thousands of organizations make quietly. Companies decide internally that a dataset counts as anonymous. They then build products, partnerships and revenue on that assumption, often without testing it against the re-identification standard a regulator would apply.

Supervisory authorities now have a detailed worked example to point to. Any business that aggregates patient-level records from multiple sources, keeps them for years and attaches a stable identifier to each person should expect the same analysis. The safer position starts with proving anonymity rather than asserting it.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.