Italy’s Privacy Regulator Fines IQVIA €7 Million Over Health Data of 1 Million Patients
Key Takeaways
- Patient Data Was Not Anonymous: The Garante found that IQVIA’s coding system and detailed medical information made it possible to single out and potentially reidentify patients using reasonable means.
- 1 Million Patients Were Involved: The database contained health information from roughly 1 million patients of about 800 general practitioners and was used for research, including studies commissioned by pharmaceutical companies.
- GDPR Failures Went Beyond Anonymization: The regulator found problems involving legal basis, patient information, retention periods, security measures and the absence of a required data protection impact assessment.
- Identifiable Records Entered the Database: Identifying information for more than 3,300 patients was included, with more than 3,000 of those records also containing health information.
- IQVIA Has 120 Days to Comply: The company must bring the processing into compliance if it intends to continue the activity, or physicians must independently anonymize the data under the safeguards specified by the regulator.
Deep Dive
Italy’s privacy regulator has fined IQVIA Solutions Italy €7 million over a database containing the health information of roughly 1 million patients, finding that data the company regarded as anonymous could, in fact, be traced back to individuals.
The database was built from information supplied by about 800 general practitioners and used for research, including studies commissioned by pharmaceutical companies. IQVIA Solutions Italy is part of a multinational group active in health data analytics and clinical research. The case turned on what had been taken away from the records, and what remained.
Patients’ names may not have been the organizing principle of the database, but each patient was associated with a code that allowed the same person to be followed over time. Around that code sat a remarkably detailed medical history: year of birth, sex, diagnoses, symptoms, prescriptions, examinations, vaccinations and location information.
For the Garante per la protezione dei dati personali, that combination is important. It concluded that individual patients could be singled out and, using reasonable means, re-identified. The information therefore could not be treated as anonymous data outside the protections of the General Data Protection Regulation. That finding carried much of the rest of the case with it. Once the records were personal data, and particularly health data, the obligations surrounding their collection and use looked very different.
The Garante determined that IQVIA was a data controller from the moment the information was collected from the physicians. It found that the company had processed health data without an appropriate legal basis and had failed to adequately inform the patients whose information entered the system.
The records also had a long memory. IQVIA had not established retention periods, according to the authority, and some of the information stretched back to 2001. The regulator found further shortcomings in the safeguards surrounding the database. IQVIA had not carried out the required data protection impact assessment and had not adopted adequate security measures.
The investigation uncovered something a bit more immediate as well. Identifying information belonging to more than 3,300 patients had made its way into the database, including names, tax identification codes, addresses and contact details. For more than 3,000 of those patients, identifying information appeared alongside health data. The underlying enforcement order specifies approximately 3,370 affected patients, including 3,080 whose records also contained health information.
The €7 million penalty comes after an investigation that began after inspections carried out in April 2025. The Garante later joined that inquiry with a separate proceeding concerning a personal data breach that IQVIA itself had reported. The authority adopted its enforcement measure, No. 710, on Sept. 23, 2026. IQVIA now has 120 days to bring the processing into compliance if it intends to continue the activity. The Garante also left another route open, which is that the physicians themselves may independently anonymize the information before it reaches IQVIA, provided they do so under the safeguards set out by the authority.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

