Italy's data protection authority, the Garante per la protezione dei dati personali, has fined IQVIA Solutions Italy S.r.l. €7 million over a database built from the records of about one million patients of roughly 800 general practitioners. The company had argued that the data it received was anonymous. The authority found otherwise. The decision, no. 710, was adopted on September 23, 2026 and announced in a press release dated October 2, 2026. It is among the first enforcement decisions to test the European Court of Justice's September 2025 EDPS v SRB ruling on pseudonymised data against a commercial health data business, and the Garante rejected the company's reliance on it.

In Short

Italian family doctors used free software that sent their patients' medical records to IQVIA, a health data company, which said the records were anonymous because names were removed. Italy's privacy regulator said each patient kept the same code over time, so the records could be traced back to real people, which makes them personal health data that needs a legal basis and patient information. IQVIA must pay €7 million and, if it wants to keep running the database, change how it is fed within 120 days.

What the Garante decided

The decision, signed in Rome by president Pasquale Stanzione, rapporteur and vice president Ginevra Cerrina Feroni and secretary general Luigi Montuori, with board member Agostino Ghiglia taking part, finds that IQVIA Solutions Italy breached Articles 5(1)(a), 5(1)(e), 5(1)(f), 5(2), 9, 13, 25, 28, 32 and 35 of the GDPR. The fine is imposed under Article 83(4)(a) and Article 83(5)(a) and (b).

In plain terms, according to the Garante, the company processed health data without a valid legal basis, did not inform patients, kept data with no defined retention period, failed to secure it, never appointed the participating doctors as processors, did not carry out a data protection impact assessment and could not demonstrate accountability or data protection by design.

The press release summarised the core finding in two sentences. "For the Garante, the data used was not anonymous, as the company claimed. The code associated with each patient made it possible, in fact, to follow them over time," according to the Garante. All quotations from the decision and the press release in this article are PPC Land's translations from the Italian originals.

The database was used, according to the press release, "for studies commissioned also by pharmaceutical companies." The decision describes them as retrospective observational studies requested by pharmaceutical firms, delivered as aggregated reports.

How the database worked

The system was not new. According to the decision, the Italian Society of General Medicine and Primary Care (SIMG) and the Health Search association conceived a project to pool data from family doctors' routine clinical work. It was later sold, in an early form, to a company in the French Cegedim group. The asset passed from Cegedim to IMS Health, which later took the name IQVIA. IQVIA's own accounts of the timing differ inside the decision itself: at inspection, the company said it took over the SIMG collaboration after acquiring Cegedim "in 2015," while its written defence put the takeover in 2017.

The mechanics were the same throughout. Participating doctors used a practice management software package, whose name is redacted in the published decision. IQVIA had an add-on installed on that software to extract patient data. In return, according to the company's statements to inspectors, the doctor received the software subscription free of charge, and IQVIA paid the vendor. The extracted records flowed into a database IQVIA called LPD, for Longitudinal Patient Data.

IQVIA told inspectors that the database was split into tables covering demographics, prescriptions, diagnoses, tests and visit counts. "The patient is always recorded with the same Pat ID over time, since it is necessary to 'follow' them longitudinally," the company said, adding that the table held "millions of records" for "over approximately one million patients for approximately eight hundred" doctors.

The patient code itself was technically random. According to a company note quoted in the decision, the Pat ID was a UUID, "a 16-byte number," rendered as a string of 22 alphanumeric characters and generated by the add-on using the vendor's proprietary algorithm. The doctor could not see it. Dates of birth were set by default to the first day of the month. The code changed only if a patient switched doctors or the doctor replaced their computer. Even then, IQVIA told inspectors, "the informational potential, given the information needs of pharmaceutical companies, remains adequate."

During the inspection, IQVIA showed a presentation of "a patient who appears 34 times in the DB table relating to medical prescriptions, and whose clinical history it is therefore possible to trace," according to the decision. The demonstration was meant to illustrate the database's value. It became one of the facts the Garante relied on.

The contracts that made IQVIA the controller

Much of the decision turns on a single question: who decided why and how the data was processed? IQVIA's answer was SIMG, the doctors and the software vendor. At a hearing, the company stated that "IQVIA does not manage the data anonymisation application and does not define the aspects of the related anonymisation process. The technology is supplied by others; IQVIA's role is economic support, and this does not imply that IQVIA can be considered a data controller."

The Garante read the contracts differently. In the collaboration agreement with SIMG, IQVIA committed to "continue to provide specific instructions" to the vendor "so that the initially sensitive data entered by GPs through the software" would be "made anonymous before their insertion in the LPD database," according to the decision. The vendor, questioned separately, said that "the Software was created by XX based on IQVIA's requests," and produced a contract with IQVIA dated February 26, 2020. Clause 2.6 of that contract stated that data extracted through the software "will undergo an anonymisation process before being sent to IQVIA's infrastructure, as described in Annex A," an annex the Garante says IQVIA itself proposed. The vendor also said IQVIA had appointed it as a processor under Article 28.

The Garante also found that SIMG never had a "primary role in guiding the project," as IQVIA claimed. SIMG's role, according to the decision, was to recruit doctors and replace inactive ones, in exchange for access to the data for its own scientific publications. The doctors, for their part, were controllers of patient records for care purposes only. "This 'anonymisation' operation is in fact carried out solely and exclusively for the benefit of IQVIA," according to the decision.

The authority concluded that IQVIA was the controller "from the collection of the data" at the doctors' practices, a point repeated in the press release. The finding matters for everything that follows. A controller that designs and commissions the pseudonymisation process cannot then claim, as a downstream recipient might, that it lacks the means to undo it.

Why the SRB defence did not work

IQVIA's central legal argument rested on the Court of Justice's judgment of September 4, 2025 in case C-413/23 P, EDPS v SRB. PPC Land covered that ruling the day after it was handed down: the Court held that pseudonymised data is not necessarily personal data for every holder, and that for Deloitte, which received comments without the keys to identify their authors, the information was not personal data.

According to the decision, IQVIA argued that following the judgment, data is anonymous where all means of identification have been removed, are prohibited by law or would be practically impossible to use because of time, cost and labour. It said it had no access to doctors' computers, no contractual right to the "pseudonymisation secret" held in the vendor's software, and no external dataset that would allow linkage. A re-identification risk document IQVIA submitted in 2026 gave the risk "a final value equal to 3," which the company described as a low and non-significant threshold.

The Garante set out its own reading of SRB. A recipient can treat pseudonymised data as non-personal only if it cannot influence or alter the measures applied by the original controller, cannot re-identify the person through other means such as cross-checking, and, in the authority's formulation, cannot pass the data on to another party. The Garante also stressed that the Court "did not intend to mark a break" with its earlier case law.

None of those conditions fit IQVIA, according to the authority. The company "cannot be considered a simple recipient of pseudonymised data, but must be considered responsible for the entire processing carried out, and this from the phase of collecting the data from the GPs," the decision states.

The Garante then addressed capability rather than intent. "It is in fact sufficient that it has the capacity to re-identify them, by reasonable means, for the data in question to be qualified as personal data," according to the decision, which cites the EDPB's binding decision 1/2021 on WhatsApp Ireland and a decision by France's CNIL against IQVIA's French subsidiary dated May 26, 2026.

What the records contained

The decision lists the information attached to each Pat ID: year of birth, sex, marital status, number of children, socio-professional category, visit dates, diagnoses, symptoms, allergies, weight, height, prescriptions, vaccinations, tests and sickness certificates, plus location data. With that, according to the Garante, the processing does "not withstand the risk of individualisation," including through recourse to external sources.

There is a small inconsistency in how birth data is described. The press release and paragraph 101 of the decision refer to year of birth. IQVIA's own submissions, recorded elsewhere in the decision, say the add-on transmitted month and year, with the day set to the first of the month. Either way, the Garante's reasoning did not depend on the date field.

The problem with hashing and k-anonymity

The technically most detailed part of the decision addresses why the measures IQVIA relied on were not enough. The company had commissioned two assessments, carried out by a company in the IQVIA group, on k-anonymity, a model that requires each combination of certain attributes, such as location and age, to be shared by at least k individuals.

According to the Garante, that constraint applies only to quasi-identifiers, not to the whole record. A group of patients can meet the numerical threshold for age and location while each record remains unique once diagnoses, hospital admissions or medication patterns are taken into account. "An attacker able to independently observe or measure these parameters and refer them to a specific subject could identify that subject, rendering the protection offered by k-anonymity ineffective," according to the decision.

Hashing fared no better. "Simple hashing of identities does not mitigate this risk, since it does not remove singularity (indeed, it is built to maintain it so as to refer the clinical history to a specific subject)," the Garante wrote. A stable pseudonym is precisely what allows a record to be followed over time, and that, in the authority's analysis, is what keeps it personal data.

The decision also notes that the company's assessments were not enough on their own. IQVIA, according to the Garante, relied "exclusively on the generic assessments conducted by the Canadian company," accepting "passively" the claimed anonymity of the data it received. The authority faulted IQVIA for not measuring the actual percentage of single-out cases quantitatively, given the large scale of the processing.

The free-text breach

The case also includes a data breach that IQVIA notified under Article 33 after the inspections. The company reported that the add-on had extracted free-text fields from the doctors' software, which contained directly identifying information that was meant to be stripped. According to the decision, the breach involved names, dates of birth, tax codes, postal addresses, email addresses and phone numbers of 3,370 patients, and health data of 3,080 of them. The data reached IQVIA every working day over a period whose dates are redacted, and was then passed to SIMG, which deleted it at IQVIA's request.

IQVIA argued that the doctors had used the fields incorrectly. The Garante disagreed. Doctors adding notes to their own clinical software for care purposes could not be considered an error, according to the decision; responsibility lay with IQVIA, which "did not verify" that the add-on did not extract free-text fields "not relevant for the purposes of the Project." The press release rounds the figures to "over 3,300 patients, of which more than 3,000 together with health data."

Retention and the missing impact assessment

The press release states that the data "dated back to 2001." The year is redacted in the published decision, which says only that IQVIA told inspectors it was "not aware of a data deletion policy" and that data older than ten years was generally not used for studies. A retention policy the company later produced covered faxes, emails, microfiche and similar business records, which the Garante called "entirely irrelevant." After the inspection, IQVIA set a ten-year retention period.

On the impact assessment, IQVIA argued first that none was needed for anonymous data, and second that it began processing in 2017, before the GDPR applied in 2018. The Garante found that two EDPB criteria for mandatory assessments were "certainly" met, sensitive data and vulnerable data subjects, with large-scale processing and innovative technology potentially also applicable. It also wrote that the processing began "from 2015." At inspection, the company said its assessment "is being drafted" and had "not yet been formalised."

How the €7 million was set

Because IQVIA Solutions Italy is wholly owned by IQVIA Holdings Inc., the Garante treated the two as a single economic undertaking and used the group's latest consolidated turnover to set the ceiling at 4 percent of worldwide annual revenue, since that exceeded €20 million. The year and amount of the turnover figure are redacted. When France's CNIL fined IQVIA's French subsidiary €5 million in May, PPC Land reported that the CNIL used group revenue of $15 billion for 2023. On that figure, the theoretical maximum would be around $600 million; this is PPC Land's calculation, not the Garante's.

The decision lists one aggravating factor, the negligent character of the infringement, alongside the gravity of the breaches, the number of people affected and the sensitivity of health data. The mitigating factors are more numerous: IQVIA had carried out re-identification assessments over time, the doctors had stopped sending data, pseudonymisation measures had been strengthened, there were no prior relevant violations in Italy, no complaints from data subjects, and the company cooperated.

The Garante also weighed the fact that the LPD database "was created as a reference resource for health information in Italy and internationally," used for health economics and pharmacoepidemiology studies, and set the fine "also in order to limit the economic impact of the sanction on the organisational and functional needs of the Company."

The press release presents a narrower list. It says the authority took into account the number of patients, the nature of the data, the end of transmissions by doctors "from 2023" and the company's cooperation. It does not mention the absence of complaints, the prior assessments, the absence of earlier violations, or the explicit balancing intended to limit the fine's economic impact. The year 2023 appears only in the press release; the decision redacts the date.

IQVIA must pay within 30 days of notification. Under Article 166(8) of the Italian Privacy Code, it may instead settle by paying half, €3.5 million, within the deadline for an appeal. An appeal to the ordinary courts must be filed within 30 days of the decision being communicated, or 60 days for a party resident abroad. The decision will also be published on the Garante's website as an additional sanction.

The 120-day order and its technical conditions

Beyond the fine, the Garante issued corrective orders that apply if IQVIA wants to continue the activity. Within 120 days of notification, the company must identify a valid legal basis for processing patient data, including any anonymisation; inform patients under Article 13; carry out an impact assessment; and appoint the participating doctors as processors under Article 28. It must report back to the authority, with documentation, within the same 120 days.

The alternative is more prescriptive, and arguably more interesting for anyone who handles pseudonymised data. Anonymisation could instead be carried out by the doctors themselves, under conditions the Garante spelled out:

  • Independent pseudonymisation. IQVIA must not determine the pseudonymisation method. Doctors must choose which attributes to pseudonymise, for example by hashing, and apply coding with a documented random element so that, from IQVIA's perspective, the value is a sequence with no semantic meaning.
  • Equivalence classes of at least 10. IQVIA and the doctors may agree in advance which attributes count as quasi-identifiers. Each resulting equivalence class must contain no fewer than 10 people.
  • Residual variables. Every other variable must be assessed for whether IQVIA could observe or measure it. If it could contribute to identification, it must either be added to the quasi-identifiers, be processed through techniques such as secure multiparty computation so that IQVIA never holds the full value in clear, or be removed.
  • Onward transfers. If IQVIA passes the data to third parties, it becomes subject to the same conditions as the doctors.

The order effectively translates the EDPB's draft anonymisation guidelines into operational requirements. Those Guidelines 02/2026, adopted on July 7, 2026, replaced the 2014 Article 29 Working Party test with a three-part framework of no record isolation, no linkage and no inference, and remain open for comments until October 30, 2026. The Garante quotes them directly: "If any criterion is not met, further analysis is necessary to determine whether the data can nonetheless be considered anonymous."

A second IQVIA decision in four months

The Italian decision did not arrive in isolation. On May 26, 2026, France's CNIL fined IQVIA's French operations €5 million over health data warehouses fed by pharmacies and physicians. PPC Land's coverage of that decision noted that IQVIA had also invoked the SRB ruling in France, and that the CNIL rejected it because IQVIA designed and controlled the pseudonymisation pipeline. A CNIL rapporteur showed that public Facebook groups for patients with spinal muscular atrophy contained enough detail to isolate one patient in the database within minutes.

The Garante cites the French decision twice, once on the capacity to re-identify and once to note that IQVIA had disregarded "previous administrative and judicial measures" on the subject, "not only at national level but also at European level, where the IQVIA group carries out similar activities."

Italy had its own precedent. The decision refers to a Garante decision of June 1, 2023, no. 226, and a Milan court judgment of May 10, 2024, involving a company called THIN srl. According to IQVIA's own statements, the database stopped receiving doctors' data after those rulings. At the hearing, IQVIA tried to distinguish its case: THIN had chosen its technology partner and anonymisation method, while IQVIA said its data arrived "already anonymised with a procedure already decided."

Commentary: the recipient perspective

Otto Michelsen, a senior associate at Eversheds Sutherland Finland who describes himself on LinkedIn as an attorney-at-law specialising in technology, commercial and data protection law, framed the decision as a test of where the SRB principle stops. "The line between anonymised and pseudonymised data has been one of the more interesting GDPR questions since the CJEU's EDPS v SRB judgment. Now, a EUR 7 million fine from the Italian Data Protection Authority Garante adds another important piece to the puzzle," he wrote in a post that links to the Garante's press release.

Michelsen summarised SRB as holding that "identifiability must be assessed in context and from the perspective of the party receiving the data," and that additional information held by someone else "does not automatically mean that the dataset is personal data in the hands of every recipient." He wrote that the Garante "argued that IQVIA was not simply an independent third party receiving an already pseudonymised dataset" and played "a central role in determining the purposes and means of the processing."

His conclusion: "it may not be enough to look at a dataset in isolation and ask whether the recipient can identify an individual. The wider processing architecture, available means of re-identification and the roles of the different parties may also matter."

That reading matches the decision. Michelsen's post refers to "more than one million patients," while the press release says "one million" and the decision records IQVIA's own figure of "over approximately one million." His post does not mention the third condition the Garante drew from SRB, that a recipient must not be able to transfer the data onward, or the free-text breach. The post had drawn 106 reactions at the time it was captured.

Why this matters for advertising and marketing

The case concerns pharmaceutical research, not ad targeting. But the arguments IQVIA made are the same arguments that underpin much of the data-sharing infrastructure in digital advertising: that a stable, random identifier with names removed is not personal data in the hands of the party receiving it.

The Garante's position on hashing goes to the core of that claim. A hashed or random identifier that persists over time is, in the authority's words, "built to maintain" singularity. That is what makes it useful for measurement, frequency management and audience building. It is also, in this analysis, what keeps it within the scope of the GDPR when the party holding it shaped the system that generated it. PPC Land has documented the same tension in the EDPB's pseudonymisation guidance, published in January 2025, which treats pseudonymisation as a security measure, not a route out of the regulation.

Health data adds another layer. Diagnoses and prescriptions are special category data under Article 9, which prohibits processing unless a specific exception applies. The Garante found that no such exception existed here, and that a contract between IQVIA and the doctors could not supply one, since patients "are not party to the contract but their data is its object." Regulators have applied that logic to marketing tools before. Sweden's IMY fined pharmacy chains Apoteket and Apohem a combined SEK 45 million in 2024 after the Meta pixel's advanced matching sent purchase data on health products to Meta. In the United States, a federal jury found in August 2025 that Meta violated California's wiretapping law by collecting data from the Flo period-tracking app.

The legislative backdrop is moving in the opposite direction. The European Commission's Digital Omnibus proposed in November 2025 to rewrite the GDPR definition of personal data so that information would not be personal for an entity that cannot identify the person, a change drawn from SRB. In February 2026, the EDPB and EDPS warned that the change would significantly narrow the concept of personal data. The IQVIA decision shows how a national authority applies SRB under the current text: the relative approach helps a genuinely independent recipient, but not a company that commissioned, financed and specified the pipeline.

There is also a question of durability. A PPC Land analysis of Alliance Risk data published in May found that nearly 40 percent of the €7.1 billion in GDPR fines announced since 2018 had been annulled or was under challenge. The Garante itself lost its €15 million fine against OpenAI in March 2026, when a Rome court annulled it on jurisdictional grounds without ruling on the substance. The IQVIA case has no obvious cross-border competence issue of that kind, since the processing involved Italian doctors and an Italian subsidiary, but IQVIA retains the right to appeal.

What remains unknown

The published decision redacts most dates, including the inspection days, the period of the breach, the date transmissions stopped and the year of the oldest data. The press release fills some of those gaps (April 2025 for the inspections, 2023 for the end of transmissions, 2001 for the oldest data) but the decision text cannot be used to check them. The name of the software vendor is also redacted, though the decision names the group company behind the risk assessments as Privacy Analytics in its list of mitigating factors and elsewhere refers to it as "the Canadian company."

Two dates for IQVIA's final re-identification document appear in the decision: paragraph 98 refers to a document acquired on May 1, 2026, while the mitigating factors cite a document "last transmitted on May 25, 2026." It is not clear whether these are the same document.

The materials reviewed contain no public statement from IQVIA on the decision, and none indicate whether the company will pay, settle at half or appeal.

Timeline

Summary

Who: Italy's data protection authority, the Garante per la protezione dei dati personali, and IQVIA Solutions Italy S.r.l., a wholly owned subsidiary of US-based IQVIA Holdings Inc. The Italian Society of General Medicine (SIMG), about 800 family doctors and an unnamed software vendor were also part of the data flow. Otto Michelsen of Eversheds Sutherland Finland commented on the case.

What: The Garante fined IQVIA €7 million for processing health data on about one million patients without a legal basis, without informing patients, without retention limits, adequate security, processor contracts or an impact assessment. It rejected IQVIA's argument, based on the EDPS v SRB judgment, that the data was anonymous, finding that a persistent patient code combined with detailed clinical records made re-identification possible and that IQVIA was the controller from collection. A separate breach exposed identifying data on 3,370 patients. IQVIA has 120 days to bring the processing into line if it continues.

When: The decision, no. 710, was adopted on September 23, 2026 and announced on October 2, 2026. The inspections took place in April 2025, according to the press release.

Where: Italy, with the Garante in Rome and IQVIA Solutions Italy in Milan. The data came from general practitioners across the country.

Why: The decision shows how a national regulator applies the SRB ruling: the recipient-based approach does not protect a company that designed, financed and specified the pseudonymisation process. Its reasoning on hashed and persistent identifiers is relevant to any business, including advertising and measurement platforms, that treats stable pseudonymous IDs as outside the scope of the GDPR, while the EU debates writing a relative definition of personal data into law.