[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGfD0b8VF1P4QifEyhCVwI1RkSBWiPih1XCkWE8ejBmM":3},{"article":4,"iocs":41},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":28},"6c725494-155c-4735-8b8e-2f73d75fcf35","Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data","italian-dpa-fines-iqvia-eur-7-000-000-for-unlawful-processing-of-patients-health-93d883","Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data ikerinar Fri, 09\u002F10\u002F2026 - 10:02","The Italian Data Protection Authority (DPA) has fined IQVIA Solutions Italy S.r.l. EUR 7 million for unlawfully processing the health data of approximately one million patients. The DPA found that the data, used for health analytics and clinical research, was not adequately anonymized and IQVIA failed to establish a proper legal basis, provide sufficient information to patients, and implement adequate security measures. IQVIA has 120 days to comply with GDPR requirements or anonymize the data.","Italian DPA fines IQVIA EUR 7M for unlawful processing of patient health data.","Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data National News 09 October 2026 it Background informationDate of final decision: 23 September 2026National caseController: IQVIA Solutions Italy S.r.lLegal Reference(s): Article 5 (Principles relating to processing of personal data), Article 9 (Processing of special categories of personal data), Article 13 (Information to be provided where personal data are collected from the data subject), Article 25 (Data protection by design and by default), Article 28 (Processor) and Article 35 (Data protection impact assessment)Decision: Administrative fineKey words: Data protection impact assessment, Health and research, Anonymisation\u002Fpseudonymisation, Privacy by design and by default, Fines, Basic principles and Controller\u002FprocessorSummary of the DecisionOrigin of the caseThe Italian Data Protection Authority (DPA) carried out an investigation into IQVIA Solutions Italy S.r.l., a company belonging to a multinational group active in health data analytics and clinical research. The investigation concerned a database containing health information relating to approximately one million patients of 800 general practitioners, used for studies commissioned also by pharmaceutical companies. The investigation, which followed inspections carried out in April 2025, was joined with proceedings concerning a personal data breach notified by IQVIA.Key FindingsThe Italian DPA found that the data were not anonymous, as claimed by IQVIA. A persistent identifier assigned to each patient allowed individuals to be tracked over time and, combined with detailed information including year of birth, sex, diagnoses, symptoms, prescriptions, examinations, vaccinations and location data, made it possible to single out and potentially re-identify patients using reasonably available means.The Italian DPA found that IQVIA, as controller, processed health data without an appropriate legal basis and without providing adequate information to patients. It also failed to establish appropriate retention periods, carry out a data protection impact assessment and implement adequate security measures. The database also contained directly identifying information relating to approximately 3 370 patients, including health data for approximately 3 080 of them.DecisionThe Italian DPA imposed an administrative fine of EUR 7 000 000 on IQVIA Solutions Italy S.r.l.If IQVIA intends to continue the processing, it must bring it into compliance with the GDPR within 120 days, including by identifying an appropriate legal basis, complying with its information obligations towards patients, carrying out a data protection impact assessment and appointing the general practitioners as processors. Alternatively, the anonymisation process must be carried out independently by the general practitioners in accordance with the safeguards specified by the Italian Authority.In determining the amount of the fine, the Italian DPA took into account, among other factors, the large number of data subjects involved, the sensitive nature of the data, as well as mitigating factors including the suspension of data transfers by general practitioners and IQVIA’s cooperation during the proceedings.For further information: COMUNICATO STAMPA - Dati sanitari: 7 milioni di euro di sanzione Relevant topics Data protection impact assessment Health and research Anonymisation \u002F pseudonymisation Privacy by design and by default Fines Basic principles Controller\u002Fprocessor Latest news RSS Feed National News it Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data09 October 2026 National News it Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing09 October 2026 National News it Italian DPA fines security company EUR 39 000 for violations concerning employees’ data09 October 2026All news","https:\u002F\u002Fwww.edpb.europa.eu\u002Fnews\u002Fitalian-dpa-fines-iqvia-eur-7-000-000-for-unlawful-processing-of-patients-health-data_en",null,"2026-10-09T08:02:05+00:00","2026-10-09T10:00:18.649533+00:00",8,[18,21],{"name":19,"type":20},"IQVIA","vendor",{"name":22,"type":23},"database","product","d95477d7-eb04-4fad-a2dc-be1428040ce7",{"id":24,"icon":13,"name":26,"slug":27},"Privacy Fines","privacy-fines",[29,34,39],{"category":30},{"id":31,"icon":13,"name":32,"slug":33},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":35},{"id":36,"icon":13,"name":37,"slug":38},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":40},{"id":24,"icon":13,"name":26,"slug":27},[]]