Italy's data protection authority has fined IQVIA Solutions Italy seven million euros over a database built from the health records of a million patients of eight hundred general practitioners, on a finding that the records were not anonymous even though the company treated them that way. The authority, the Garante per la protezione dei dati personali, published the decision on Oct. 2. The order it describes, number 710, is dated Sept. 23 and closes an inquiry that began with inspections in April 2025 and later absorbed a separate proceeding over a personal data breach that the company itself had reported.
The case is worth reading closely because of where the violation sits. Nothing in the Garante's account turns on a stolen laptop or an outside intruder. The failure was in a legal label. IQVIA built a research asset, described it as anonymous, and the authority concluded that the description was wrong. That is a narrower accusation than a breach and, for every company running a health data warehouse, a more portable one.
The patient code is what undid the anonymity claim
The Garante's reasoning comes down to a single design choice. The code assigned to each patient allowed the same person to be followed over time, and the file around that code was unusually rich: year of birth, sex, diagnoses, symptoms, prescriptions, exams and vaccinations, plus location data. Put together, the authority found, the combination made it possible to isolate individual patients and re-identify them by reasonable means. Data that can be re-identified by reasonable means is personal data under European law, and personal data carries obligations that an anonymous file does not.
That is a stricter test than the word "anonymous" suggests to most readers, and it is the test the company's own description failed. The authority is not saying that names were exposed for all million patients, or that anyone outside the company could look up a neighbour. The claim is narrower and harder to design around: with that much clinical detail attached to a stable code, a patient remains findable, and the law follows the patient rather than the identifier.
In its response, IQVIA said its safeguards include pseudonymization and encryption, which is true of many warehouses of this kind. Pseudonymization is a security measure. It is not a determination that the data falls outside the privacy rules, and the Garante treated the two as different things.
What the authority says the file contained
The scale matters to the penalty. According to the Garante, the database held information on a million patients drawn from eight hundred general practitioners and was used for studies commissioned by drug companies among others. ANSA's account adds a detail that sharpens the anonymity finding: identifying information such as names, tax codes, addresses and contact details for more than 3,300 patients had also flowed into the database, and in more than 3,000 of those cases that information sat alongside health data.
The other findings form a list that compliance officers will recognize. No retention periods had been defined, and the authority says some data dated to 2001. No data protection impact assessment had been carried out. The security measures were judged inadequate. IQVIA was held to be the controller from the moment the data was collected from the doctors, which matters because it fixes responsibility upstream of the practices that supplied the records. And the authority found that health data had been processed without an adequate legal basis and without patients being properly informed.
IQVIA disputes the framing rather than the facts as reported. Its statement, carried by Quotidiano Sanità, says the company takes note of the decision and reserves the right to appeal, and that the dataset in question "is not related to the conduct of clinical trials for sponsors." The company also says the authority recognized the scientific value of the database for research, and that it has already taken the steps needed to comply.
France reached the same conclusion about the same company in May
Italy is not the first regulator to look at an IQVIA warehouse and reject the word anonymous. In May, the French authority fined IQVIA Operations France five million euros over two health data warehouses, one authorized in 2018 and supplied by roughly 14,000 pharmacies, the other authorized in 2021 and supplied by several thousand doctors. The CNIL's restricted committee, deciding on May 26 and announcing on May 28, rejected the company's argument that the data fell outside the privacy rules and held that it was pseudonymous.
The French reasoning runs parallel to the Italian one, down to the mechanism, and it arrived at a moment when the question was being argued across Europe. After the Court of Justice of the European Union issued its SRB judgment in September 2025, IQVIA contended in France that the warehouse data was anonymous and therefore outside the rules altogether. The restricted committee answered that the data was pseudonymous, so the rules applied.
The CNIL pointed to a unique patient identifier, to the depth of the data collected, and to the possibility of identifying people by joining IQVIA's records with publicly available information. It also noted that the company had never previously disputed that it processed personal data, and had sought and obtained authorizations that it was then bound to honor. Its order gave six months to fix the breaches, backed by a penalty of 10,000 euros for each day of delay, and the fine was sized partly around the tens of millions of people whose records were involved.
Two authorities, two countries, two subsidiaries, one defense and one answer. In both cases the hinge was the identifier that persists across time. A file can be stripped of names and still fail the anonymity test if the remaining fields are detailed enough to single people out, and a warehouse that keeps a stable code per patient is, by design, a record of that patient's care over years.
The 120-day order puts the next move on doctors
The Italian decision ends with a choice the company has not yet made public. Within 120 days, IQVIA must bring its processing into line with the authority's prescriptions if it wants to continue the activity. The alternative is that anonymization be carried out by the doctors themselves, under guarantees the Garante specifies. Either path is available, which means the compliance cost may be paid at eight hundred practices rather than at one company.
Doctors' representatives have been quick to say where they think the responsibility sits. Filippo Anelli, president of the federation of physicians' and dentists' orders, told ANSA that the company should have guaranteed the privacy principles and that patients "did not know that their data had not been anonymized." He also said his concern was whether any liability attached to the doctors, and concluded none does, while adding that practices still have to be careful.
His reading captures the awkwardness of the remedy. General practitioners supplied records to a vendor that told them the output was anonymous, and the authority's own account places responsibility for that representation on the company. If the fix instead runs through the practices, it lands on the smallest organisations in the chain, most of which have no privacy officer and no way to test whether a pseudonymized extract can be reversed. Anonymizing at source, before records leave a practice, is technically harder than it sounds, and it is the option the Garante has put on the table.
The penalty credits cooperation and a supply that had stopped
The size of the fine is as informative as the findings. The Garante says it weighed the number of patients involved and the nature of the data, then credited two things: the doctors had stopped sending data in 2023, and IQVIA cooperated throughout the proceeding. Cooperation reducing a penalty is standard practice across European regulators and it tells companies what the process rewards, which is candour after a finding rather than a defence of the label.
The unresolved argument is about the research itself, and both sides have a real case. IQVIA's position is that studies built on data at this scale support work that smaller datasets cannot, including safety signal detection and epidemiological research, and the company says the authority acknowledged that value. The regulators' position, laid out in both decisions, is that scientific use changes none of the underlying duties: a legal basis is still required, patients still have to be told, retention still has to be defined, and an impact assessment still has to be done. Nothing in either decision forbids the research. Both require that it be built on records that patients know about.
Where the risk now sits for everyone else
For any organisation holding health records, the two decisions locate the exposure with uncomfortable precision. It is not mainly in the firewall or the encryption. It is in the descriptor chosen for the file, in the retention schedule that was never written, and in what patients were told at the point their data was collected. A durable patient code plus a rich clinical record is what turned two ordinary warehouse designs into enforcement cases, and neither regulator had to find a hacker to get there.
IQVIA's Italian arm now has about four months to decide which of the Garante's two routes it will take, and its public statement keeps the appeal open. Whichever it chooses, the reasoning behind the fine will outlast the case. The next company that calls a warehouse anonymous will have to explain why the code inside it cannot follow a patient through twenty years of care.
Primary sources
- Garante per la protezione dei dati personali, Dati sanitari: il Garante privacy sanziona IQVIA per 7 milioni di euro, press release, Oct. 2, 2026, for the seven million euro fine, decision number 710 of Sept. 23, 2026, the April 2025 inspections, the merger of the breach proceeding, the findings on anonymization, retention, impact assessment and security, and the 120-day order.
- ANSA, In chiaro i dati sanitari di un milione di pazienti, Oct. 2, 2026, for the contents of the database, the identifying information of more than 3,300 patients, and the reaction of the physicians' federation president.
- Quotidiano Sanità, Dati sanitari. Il Garante privacy sanziona Iqvia per 7 milioni di euro, Oct. 2, 2026, for the decision number and the summary of the findings as published.
- Quotidiano Sanità, La replica di Iqvia: Ci riserviamo diritto a presentare ricorso, Oct. 2, 2026, for the company's statement in response to the decision.
- CNIL, Health data: fine of 5 million euros against IQVIA, news release, May 28, 2026, for the decision against IQVIA Operations France, the two warehouses and their sources, the pseudonymity finding, and the orders with their daily penalty.