Italy's data protection authority on October 2, 2026 published a decision ordering IQVIA Solutions Italy S.r.l. to pay 7 million euros, having concluded that a research database assembled from the clinical records of about one million people treated by roughly 800 family doctors held personal information rather than the de-identified material the company had described. The Garante per la protezione dei dati personali adopted the measure on September 23, 2026 as decision n. 710 and gave the Milan subsidiary of US-listed IQVIA Holdings 120 days to put the data flow on a lawful footing if it intends to keep using it.
In Short
Italy's privacy regulator has told IQVIA, a company that analyses health information for drug makers and researchers, to pay 7 million euros over a database built from the records of about one million patients of 800 family doctors. IQVIA said names had been stripped out, but the regulator found that every patient kept the same code for years alongside diagnoses, prescriptions and location details, so individuals could still be picked out and the data counted as personal. Because IQVIA paid for the software that pulled the records and wrote the instructions for it, the regulator held the company responsible from the moment the data left each doctor's computer, a finding that matters to any business that designs a data pipeline and then treats its output as anonymous. IQVIA now has 120 days to fix the legal basis and patient information or hand the anonymising to the doctors themselves, and it can still go to court.
How the records left the doctor's surgery
The case concerns a database IQVIA calls LPD, short for Longitudinal Patient Data. According to the decision, it was fed by general practitioners belonging to the Società Italiana di Medicina Generale e delle cure primarie (SIMG), a scientific society of Italian family doctors, under a project known as Health Search. SIMG runs a research centre of the same name. The project's stated aims, as IQVIA described them in its defence, were to train doctors to record their clinical work in coded form, build a network of GP researchers representative of every macro-area of the country and create a reference database for primary care research.
The plumbing was compact. Every participating doctor used the same practice management software, whose vendor the published decision redacts. An add-on, installed on IQVIA's commission, extracted patient records from that software and transmitted them. In exchange, according to the decision, each doctor received the management software subscription free of charge while IQVIA paid the vendor. The contract between IQVIA and each GP committed the doctor to supply data accurately and continuously so that IQVIA could run statistical, epidemiological and market research for public bodies and private companies.
Records landed first in a temporary staging database. From there, according to IQVIA's written defence, they followed two routes: an extraction file sent to SIMG every six months for scientific use, and a second stream that IQVIA converted into its internal standard format, subjected to further privacy measures and loaded into the final Data Warehouse LPD, the reference database for the company's production work. IQVIA used that warehouse for retrospective observational studies requested by pharmaceutical companies, delivering results as aggregated reports.
During the inspection, IQVIA described LPD as a set of tables covering demographics, prescriptions, diagnoses, examinations and the number of visits. The prescription table alone held every medicine prescribed to every enrolled patient. The whole database ran to millions of records covering more than one million patients of about 800 GPs, according to the company's own account to inspectors.
The Garante's press release of October 2 states that the inspections took place in April 2025; the decision itself redacts the dates. The regulator later merged that file with a separate proceeding opened after IQVIA notified a personal data breach. Doctors stopped sending data from 2023, according to the press release. The decision adds that, following a Garante decision of June 1, 2023 (n. 226) and a Milan court judgment of May 10, 2024 in a case involving the company THIN srl, the database was no longer fed but was still used, to a lesser extent, for existing and new studies.
Three owners and two start dates
The database predates IQVIA. According to the Garante's reconstruction, SIMG and the Associazione Health Search conceived the project and, without the organisation or resources to run it, ceded an early version to a company in the French Cegedim group, which had built a similar product in France. The assets then moved from Cegedim to IMS Health, with ownership passing first to IMS Health Information Solutions Italy S.r.l. and then to IMS Health S.r.l., the entity that later took the IQVIA Solutions Italy name. The decision notes that the IQVIA group was previously known as Quintiles and IMS Health.
When did IQVIA's involvement begin? The documents disagree. In the inspection record, IQVIA told officials it took over the collaboration with SIMG after acquiring Cegedim "in 2015". Its written defence places the takeover of the Health Search database in 2017. The Garante, in its finding on the impact assessment, wrote that the processing began from 2015. The published decision does not reconcile the two dates.
A second figure also varies by source. The decision refers throughout to about 800 GPs. The European Medicines Agency's catalogue of real-world data sources lists a Health Search/IQVIA Health Longitudinal Patient Database, naming IQVIA Solutions Italy and SIMG as data holders and describing records from approximately 1,000 general practitioners distributed across Italy.
A random code that stayed with each patient
At the centre of the dispute sits the Pat ID. According to a note IQVIA sent to the Garante, the identifier was a UUID, a 16-byte number represented as a string of 22 alphanumeric characters, generated by the add-on with a proprietary algorithm belonging to the software vendor. The doctor could not see it in the application, and the underlying database was password-protected. As a further measure, the patient's date of birth was overwritten by default with the first day of the month. Because the code was random rather than derived from personal characteristics, a patient deleted and re-entered in the software would receive a new one.
The code changed in two other situations: when a patient moved to another GP, or when a doctor replaced the computer. IQVIA told inspectors this did not undermine the dataset's commercial value. In the company's words, quoted in the decision (PPC Land translation from the Italian): "Despite these events, the informative potential, given the information needs of pharmaceutical companies, remains adequate."
That stability was the point of the design. A patient, IQVIA explained, keeps the same Pat ID over time because the database needs to follow that person longitudinally. To illustrate the structure, the company showed inspectors a presentation with one patient who appeared 34 times in the prescriptions table, a record from which, according to the decision, it was possible to trace that person's clinical history.
The decision records one more inconsistency in how IQVIA described its own safeguards. On the second inspection day, the company listed the generalisation of age to the month of birth and "the removal of the city" among the measures applied in Italy. Its later defence stated that the add-on transmitted only the month and year of birth and that the patient's address was not sent, with only the city indicated, while the doctor's address was reduced to the province.
Names in the free-text fields
The inspection triggered a second problem. After the officials left, IQVIA notified the Garante under Article 33 of the GDPR that it had discovered, entirely unexpectedly by its account, that the data received through the add-on contained personal details of patients and some doctors inside free-text fields. The add-on was supposed to strip that content before export. It did not.
According to the decision, the unauthorised flow covered direct identifiers, including first and last names, dates of birth, tax codes, postal addresses, email addresses and phone numbers, of 3,370 patients. IQVIA's analysis found that the breach also involved health data for 3,080 of them. The company received the files daily, on working days, over a period the decision redacts, and forwarded them to SIMG. At IQVIA's request, SIMG removed all identifying data from its copy and confirmed the deletion.
IQVIA's defence attributed the incident to doctors misusing the free-text fields of their patient management software. The Garante disagreed. Doctors entering additional information into software they use for patient care could not be considered an error, the authority wrote, since that information is plainly relevant to treatment. The responsibility, according to the decision, lay with IQVIA, which had not verified, when commissioning security measures from the vendor, that the add-on did not also extract free-text content irrelevant to the project.
Why the records were not anonymous
The heart of the decision is an analysis of re-identification risk. IQVIA had commissioned two assessments from a company in its own group, whose name the decision redacts in most passages but gives in the penalty section as Privacy Analytics (spelled "Privacy Analitycs" in the text) and elsewhere describes as Canadian. Those assessments relied on k-anonymity, a model that requires every combination of certain attributes, such as location or age, to be shared by at least k individuals, creating so-called equivalence classes.
The Garante found two structural limits. First, the constraint applies only to a subset of attributes, the quasi-identifiers, and not to the whole record. A class can meet the numerical requirement while its members remain unique once other fields enter the picture: diagnoses, sequences of hospital admissions or patterns of drug intake. An attacker able to observe or measure those parameters independently and tie them to a specific person could identify that person, rendering the protection ineffective, the decision states.
Second, hashing an identity does not help. According to the Garante, a hash protects only the part of the record directly linked to identity, while it is built precisely to preserve uniqueness so that a clinical history can be attributed to one subject. Applying cryptographic functions to the Pat ID, the authority concluded, does not remove the one-to-one association between an individual and the code that represents that individual throughout the database. When the payload is rich in detail collected over a long observation period, elements such as conditions or prescriptions can themselves become strong identifiers.
The records in LPD were exactly that rich. The decision lists year of birth, sex, marital status, number of children, socio-professional category, dates of visits, diagnoses, symptoms, allergies, weight, height, prescriptions, vaccinations, examinations and sickness certificates, each tied to an identifier specific to a given doctor, with location data on top. That combination, according to the Garante, allowed IQVIA to isolate each individual and failed the singling-out test in the Article 29 Working Party's 2014 opinion on anonymisation techniques, a test restated in the European Data Protection Board's Guidelines 02/2026, adopted on July 7, 2026 and still under consultation.
Intent was irrelevant. "It is sufficient that it has the capacity to re-identify them, through reasonable means, for the data in question to be qualified as personal data," the decision states, citing the board's binding decision 1/2021 on WhatsApp Ireland and the French CNIL's May 26, 2026 decision against IQVIA's French operations.
IQVIA had argued otherwise to the last. A document it emailed late in the proceeding scored the overall re-identification risk at 3, which it described as a low threshold and therefore not significant. The company also maintained that no publicly available dataset or database accessible to it under existing legal titles would permit an effective match between LPD records and real identities.
The SRB defence
IQVIA's strongest legal argument rested on the Court of Justice's September 4, 2025 judgment in case C-413/23 P, the dispute between the European Data Protection Supervisor and the Single Resolution Board, which the company's lawyers called the Deloitte judgment. That ruling held that pseudonymised data need not be personal data for every party and that identifiability depends on the circumstances of each recipient. At its hearing, IQVIA said the technology came from others and that its own role was financial support. "IQVIA does not manage the data anonymisation application and does not define the aspects of the related anonymisation process," the company stated, according to the record of the hearing.
The Garante read the judgment as continuity with earlier case law rather than a break, and set out three conditions under which pseudonymisation could strip data of personal character for a recipient: the recipient cannot influence or alter the measures applied by the first controller; it cannot re-identify the person by other means, such as cross-checking with other information; and it cannot pass the data on to another party. IQVIA failed at the threshold. According to the decision, it was not a mere recipient of pseudonymised data but the party responsible for the entire processing from collection at the doctors' surgeries, with an active role in defining the purported anonymisation measures.
Paying for the software, writing the instructions
Who decided the purposes and means of processing? IQVIA's answer was SIMG, the doctors and the software vendor. The Garante's answer came from the contracts.
Every contractual document, the authority observed, described IQVIA as controller. The collaboration agreement with SIMG committed IQVIA to keep providing instructions to the vendor so that data initially entered by doctors would be rendered anonymous before entering the LPD database. The software vendor told the regulator that IQVIA had appointed it as processor under Article 28 of the GDPR for the onboarding of participating doctors, covering both doctors' and patients' data, and that the software had been built according to IQVIA's requests. A contract between IQVIA and the vendor dated February 26, 2020 contained a clause, numbered 2.6, under which the vendor guaranteed that extracted data would undergo anonymisation before reaching IQVIA's infrastructure, as described in an annex IQVIA proposed.
An earlier model agreement offered to doctors by IMS Health Information Solutions Italy went further. It stated that IMS had verified, through adequate technical and legal checks, that the guarantee of absolute anonymity removed any need for doctors to obtain their patients' explicit consent. The Garante also rejected the claim that SIMG held a primary role in steering the project. SIMG's contribution, according to the decision, was to help IQVIA recruit and retain enough doctors for a database representative of the Italian population, including through monitoring and publicity so that non-contributing doctors could be replaced.
The authority was blunt about the product doctors were offered. It "is presented differently from what it actually is," the decision states, since the add-on, sold as an anonymisation tool, could not achieve that objective. At the same time, the Garante accepted that IQVIA's standing and the technical expertise anonymisation requires had justified the legitimate reliance of doctors and SIMG on the tool.
The regulator relied on the Court of Justice's July 29, 2019 Fashion ID judgment (C-40/17), the case better known in advertising for defining joint controller liability for embedded social plugins, for the principle that processing can consist of several operations across several phases that cannot be assessed separately. Doctors, SIMG and the vendor all participated in a single processing chain whose purpose, feeding the LPD database, and means, the add-on, IQVIA had determined. The anonymisation, the decision adds, could not be attributed to the doctors, who process their patients' data for care, because it was carried out exclusively for IQVIA's benefit.
Seven provisions breached
The Garante found violations of Articles 5(1)(a), (e) and (f), 5(2), 9, 13, 25, 28, 32 and 35 of the GDPR. In substance, six failures.
Lawfulness. Health data falls within special category data under Article 9, which prohibits processing unless an exemption applies. No patient gave consent. A contract could not serve as the legal basis because the patients were not parties to the agreements between IQVIA and the doctors; their data was the subject matter. The Garante added that anonymisation is itself a processing operation that requires a legal basis, a position the European Data Protection Board took in a February 2, 2021 document on health research and the Milan court confirmed in May 2024.
Transparency. IQVIA provided no information notice of its own, on the assumption that it processed only anonymous data and that the doctors were controllers. The contractual obligation on doctors to tell patients their data would be anonymised could not discharge IQVIA's duty, and the notice used did not contain the elements Article 13 requires.
Storage limitation. IQVIA told inspectors it knew of no deletion policy and that data older than ten years was generally not used in studies. The oldest records dated back to 2001, according to the press release. The retention policy IQVIA produced covered faxes, emails, microfiche and administrative documents, and its validity period postdated the inspections. IQVIA's defence said it had set a ten-year retention period after the inspection.
Processor appointments. Doctors were never appointed as IQVIA's processors for transmitting their patients' data, a breach of Article 28. The Garante also found that IQVIA had effectively inserted itself into the contractual relationship between doctors and the software vendor, which acts as processor for the doctors who buy its product, to access information gathered during patient care.
Security, accountability and design. The free-text fields led to findings under Articles 5(1)(f) and 32. The authority added a broader charge under Articles 5(2) and 25: IQVIA ran no checks on the vendor's software before deployment and no automated checks on LPD afterwards that would have detected the free-text fields, relied passively on generic assessments, and never quantified the percentage of single-out cases despite processing at large scale.
Impact assessment. Health data and vulnerable data subjects, two of the board's criteria, applied with certainty, and large-scale processing and innovative technology potentially applied too. IQVIA had started drafting a data protection impact assessment but never completed one. Its defence argued that, having begun the processing in 2017, before the GDPR applied in 2018, it was not bound by the obligation. The Garante found a violation of Article 35, noting the processing had begun from 2015.
A prescription with a floor of 10
The corrective order is the most technical part of the decision. If IQVIA intends to continue, it must within 120 days identify a valid legal basis for processing patients' data, including any anonymisation; provide the information Article 13 requires; complete an impact assessment; and appoint the doctors as processors under Article 28.
The alternative moves the anonymisation to the doctors, in line with the board's Guidelines 02/2026, under three conditions:
- Independent pseudonymisation. IQVIA must not determine how data is pseudonymised. The doctors must select which attributes to pseudonymise, for example through hashing, and apply a documented coding mechanism with a random element of adequate complexity, so that the coded value appears to IQVIA as a sequence with no semantic meaning and no predictable or reversible pattern.
- Equivalence classes of at least 10. IQVIA and the doctors may agree in advance which attributes count as quasi-identifiers and how they are generalised, but every resulting equivalence class must contain no fewer than 10 records.
- Residual variables. Every other variable must be assessed for whether IQVIA could observe or measure it. Where it could and might contribute to identification, it must either join the quasi-identifiers within classes of at least 10, be processed through distributed techniques that give IQVIA only shares of the data, such as secure multiparty computation, or be removed.
If IQVIA passes the data on to third parties, it becomes a sender itself and faces the same requirements. Within 120 days of notification, the company must also report to the Garante, with documentation, on the steps taken. Failure to respond can attract a further fine under Article 83(5)(e).
The threshold of 10 is modest beside other recent anonymisation specifications. The European Commission's Digital Markets Act decision on Google Search data sharing set a hard floor of 1,000 users per group, with most users sitting in far larger groups. The Garante's order, however, does not rest on the class size alone. Its third condition targets exactly the clinical variables that sat outside the quasi-identifiers in IQVIA's original design.
How the regulator reached 7 million euros
Because the violations stemmed from a single course of conduct, Article 83(3) capped the penalty at the amount for the gravest breach: 20 million euros or, for undertakings, up to 4% of total worldwide annual turnover in the preceding financial year, whichever is higher. To determine which turnover counted, the Garante applied the competition law concept of an undertaking. IQVIA Solutions Italy is wholly owned by IQVIA Holdings Inc., a US company, and the group presents itself on its website as a single entity, processing more than 120 billion health data points a year and running more than 500 studies in more than 75 countries, according to the decision. Citing the Court of Justice's September 10, 2009 judgment in case C-97/08, the authority presumed that the parent exercises decisive influence and took the consolidated turnover in IQVIA Holdings' latest available accounts as the reference. The published text redacts the year and the figure.
For scale, the CNIL in May cited 2023 group revenue of 15 billion dollars, about 12.9 billion euros, when it penalised IQVIA's French subsidiary. On that figure, a 4% ceiling would exceed 500 million euros, and 7 million euros would amount to roughly 0.05% of group revenue.
The Garante weighed the gravity of the violations, their duration, the number of people involved and the sensitivity of health data, and treated the negligent character of the conduct as an aggravating factor. Mitigating factors included the re-identification assessments IQVIA commissioned over time, including a document sent on May 25, 2026; the suspension of data transmissions by doctors; reinforced pseudonymisation measures; the absence of prior relevant violations or earlier corrective orders in Italy; the absence of complaints from patients; and the company's cooperation. The authority also balanced patients' rights against the role of LPD as a reference resource for health information in Italy and internationally, used for studies, health economics and pharmacoepidemiology, and sought to limit the penalty's impact on IQVIA's organisation.
IQVIA must pay within 30 days of notification. Under Article 166(8) of Italy's data protection code, it can instead settle by paying half, 3.5 million euros, within the deadline for an appeal. That appeal, to an ordinary court, must be filed within 30 days of the decision's communication, or 60 days for an appellant resident abroad. The Garante also ordered publication of the injunction on its website as an accessory sanction, citing the health data of a large number of people. IQVIA said it takes note of the decision and reserves the right to appeal, according to a statement reported by the Italian news agency ANSA.
The decision was adopted by President Pasquale Stanzione, Vice President Ginevra Cerrina Feroni, who acted as rapporteur, and board member Agostino Ghiglia, with Secretary General Luigi Montuori.
Paris in May, Rome in September
Two regulators have now reached the same conclusion about the same group in four months. On May 26, 2026, the CNIL's restricted committee imposed 5 million euros on IQVIA OPERATIONS FRANCE over two authorised health data warehouses fed by about 14,000 pharmacies and up to 3,000 physicians. In both cases, IQVIA invoked the SRB judgment late in the proceedings. In both, the regulator replied that a company designing and controlling the pseudonymisation pipeline cannot claim the status of a recipient that lacks the means to re-identify.
The parallels extend to the data. The attributes the Garante lists for LPD, from marital status and number of children to sickness certificates, closely match those the CNIL recorded for the French EMR warehouse, where each patient also received an identifier unique to a given physician. The Garante cites the CNIL decision twice, once on the capacity to re-identify and once on IQVIA's failure to reassess its position after earlier rulings across Europe, where the group carries out similar activities.
The differences matter too. The French case turned largely on conditions attached to prior CNIL authorisations: multi-factor authentication, network segmentation, log analysis and patient notices at pharmacies. The Italian case had no such authorisation. It turned instead on whether the data was personal at all, and on who controlled it.
Why this matters for marketing and measurement
LPD is a pharmacoepidemiology database, not an advertising product. Yet the reasoning reaches well beyond clinical research, because advertising runs on the same claim the Garante dismantled: that a stable pseudonymous identifier attached to rich behavioural records is safe once names are removed. Hashed emails, publisher-provided IDs and clean room match keys all follow that pattern. The US Federal Trade Commission warned in July 2024 that hashing does not make data anonymous, and the Garante's language on hashing preserving uniqueness reads as its European counterpart.
The decision also sharpens a question the industry has been pressing in Brussels since the SRB judgment. Can a company treat data as anonymous because it cannot see the key? The Garante's answer is that the design role matters more than the key. The European Data Protection Board's anonymisation guidelines, which replaced the 2014 test with three criteria, No Record Isolation, No Linkage and No Inference, remain open for comment until October 30, 2026, and the Garante applied them before their adoption in final form. Meanwhile, the Council's draft of the Digital Omnibus moves the question into a new Article 25a, under which pseudonymised data would not be personal for a person unable to identify the individual concerned. The Garante's reasoning in this case did not turn on whether IQVIA could reverse the code, but on its role in building the pipeline and on the richness of the records it received.
The order's reference to secure multiparty computation also lands close to home. Google cited the same technique among the privacy-enhancing technologies behind its IP-based measurement and personalisation in the EEA, launched on August 3, 2026. A data protection authority has now written that technique into a remedy as an acceptable route for variables a recipient could otherwise observe.
Health marketers have a narrower stake. Pharmaceutical brands measure script lift using prescription datasets supplied by analytics firms that include IQVIA, among others. The Italian decision concerns the Italian subsidiary's research database rather than any measurement service, but it adds to scrutiny of how prescription and clinical records reach commercial datasets in Europe, and it arrives as the board's first standardised impact assessment template, adopted on March 10, 2026, sets a common baseline for the assessment IQVIA never finished.
For Italy, the decision extends a run of large penalties. The Garante imposed 31.8 million euros on Intesa Sanpaolo in March 2026 over an employee's access to customer records and 2 million euros on Lusha in July 2026, alongside an erasure order. Italian penalties have not always survived review: a Rome court annulled the authority's 15 million euro fine against OpenAI in March 2026 on jurisdictional grounds, and PPC Land's review of eight years of enforcement found that close to 40% of announced GDPR fines had been annulled or were under challenge. With IQVIA reserving its right to appeal, the 120-day clock and the 30-day appeal window will decide whether the Italian decision follows the French one into compliance or into court.
Timeline
- April 10, 2014 - Article 29 Working Party adopts Opinion 05/2014 on anonymisation techniques, setting the singling-out, linkability and inference criteria
- 2015 - IQVIA takes over the SIMG collaboration after acquiring Cegedim, according to the inspection record; the Garante dates the processing from this year
- 2017 - Date IQVIA's written defence gives for taking over the Health Search database
- February 26, 2020 - IQVIA and the software vendor sign a contract whose clause 2.6 guarantees anonymisation before data reaches IQVIA
- February 2, 2021 - European Data Protection Board document on health research treats anonymisation as a processing operation
- June 1, 2023 - Garante decision n. 226 in a case involving THIN srl
- 2023 - Doctors stop sending data to LPD, according to the Garante's press release
- May 10, 2024 - Milan court judgment in the THIN srl case
- July 24, 2024 - The FTC warns that hashing does not make data anonymous
- January 16, 2025 - The EDPB adopts Guidelines 01/2025 on pseudonymisation
- April 2025 - Garante inspections at IQVIA Solutions Italy, according to the press release
- September 4, 2025 - The Court of Justice rules in EDPS v SRB (C-413/23 P)
- February 10, 2026 - EDPB and EDPS reject the Commission's proposed personal data amendment
- March 10, 2026 - The EDPB adopts its first DPIA template
- March 18, 2026 - A Rome court annuls the Garante's 15 million euro fine against OpenAI
- March 26, 2026 - The Garante adopts its 31.8 million euro penalty against Intesa Sanpaolo
- May 1, 2026 - The Garante acquires an IQVIA document on reasonable means of re-identification
- May 25, 2026 - IQVIA sends a further document on re-identification risk
- May 26, 2026 - The CNIL imposes 5 million euros on IQVIA OPERATIONS FRANCE
- July 7, 2026 - The EDPB adopts Guidelines 02/2026 on anonymisation
- July 2026 - The Garante imposes 2 million euros on Lusha and orders erasure of Italian data
- August 3, 2026 - Google begins IP-based measurement in the EEA using privacy-enhancing technologies including multiparty computation
- September 2026 - The Council's Digital Omnibus draft adds Article 25a on pseudonymised data
- September 23, 2026 - The Garante adopts decision n. 710 against IQVIA Solutions Italy
- October 2, 2026 - The Garante publishes the decision and a press release
- October 30, 2026 - The EDPB consultation on Guidelines 02/2026 closes
- 30 days after notification - Deadline to pay 7 million euros, or 3.5 million euros to settle within the appeal window
- 120 days after notification - Deadline for IQVIA to comply with the corrective order and report to the Garante
Related PPC Land coverage
- CNIL fines IQVIA €5M for health data warehouse breaches - The French decision against IQVIA's pharmacy and physician data warehouses, where the group's SRB argument also failed.
- EDPB replaces 2014 anonymity test with 3-part framework for ad data - The Guidelines 02/2026 the Garante applied, with their No Record Isolation, No Linkage and No Inference criteria.
- Court clarifies personal data definition in pseudonymized transfers - The September 2025 Court of Justice judgment IQVIA invoked in both Italy and France.
- European data regulators release updated pseudonymisation guidelines for 2025 - The board's position that pseudonymised data remains personal data.
- Europe's privacy watchdogs reject Commission's plan to narrow GDPR protections - The February 2026 joint opinion on the Digital Omnibus personal data definition.
- EU Council draft drops unconditional opt-out from GDPR AI clause - The Council compromise that places pseudonymised data in a new Article 25a.
- Searches with words used by under 50 people won't reach Google rivals - The anonymisation design behind Google's DMA search data sharing, including its 1,000-user floor.
- FTC Warns: Hashed data not anonymous, companies risk deceptive practice claims - The US regulator's 2024 position on hashed identifiers.
- Google to bring IP-based ads to EEA publishers from August 3 - Google's use of secure multiparty computation and other privacy-enhancing technologies for EEA measurement.
- EDPB's first-ever DPIA template finally lands - but experts want more - The standardised impact assessment template adopted in March 2026.
- Italy's Garante fines Intesa Sanpaolo €31.8M - one employee, 3,573 victims - An earlier 2026 Italian penalty that also applied group-level reasoning on security and accountability.
- Italy fines Lusha 2 million euros, orders erasure of Italian contact data - The Garante's July 2026 action against a sales intelligence data broker.
- Eight years of GDPR: 40% of the €7.1B in fines annulled or under challenge - How often European penalties survive review, with Italy's enforcement record in context.
Summary
Who: Italy's Garante per la protezione dei dati personali sanctioned IQVIA Solutions Italy S.r.l., a Milan-based subsidiary wholly owned by IQVIA Holdings Inc. The case also involved the Società Italiana di Medicina Generale e delle cure primarie (SIMG), a software vendor whose name is redacted, and about 800 general practitioners whose patients' records fed the LPD database.
What: A 7 million euro penalty, a corrective order and publication of the injunction, after the Garante found that pseudonymised records on about one million patients were personal data, that IQVIA was the controller from collection onward, and that it breached Articles 5, 9, 13, 25, 28, 32 and 35 of the GDPR. The findings include a breach exposing direct identifiers of 3,370 patients, 3,080 of them with health data.
When: The decision was adopted on September 23, 2026 and published with a press release on October 2, 2026. IQVIA has 30 days from notification to pay, or to settle for half within the appeal window, and 120 days to comply with the corrective measures.
Where: Italy. The data came from family doctors' surgeries across the country, flowed through IQVIA's systems in Milan and was shared in part with SIMG. The penalty was calculated against the worldwide turnover of the US parent.
Why: The Garante concluded that a random but permanent patient code, combined with detailed longitudinal clinical records and location data, allowed individuals to be singled out by reasonable means, and that IQVIA, having funded and specified the extraction software, could not rely on the Court of Justice's SRB judgment as a mere recipient of pseudonymised data. The company processed health data without a legal basis, informed no patients directly, set no retention limits and never completed an impact assessment.
Discussion