Computers

Italy Fines IQVIA €7 Million Over Health Data Anonymization

Italy's data protection authority said IQVIA processed health data of about 1 million patients without a legal basis and without informing them.

Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8 million) over poor data-processing practices, according to bleepingcomputer.com. The regulator said the company's Italian division violated the GDPR.

The GPDP found that IQVIA's Italian division built a database containing health information of roughly 1 million patients by aggregating data from 800 general practitioners. Patients could be tracked and de-anonymized over time using a unique code combined with detailed health information, the authority determined.

The regulator said IQVIA processed the data without an appropriate legal basis and without informing patients, breaching GDPR requirements. The GPDP ordered the company to bring its practices into compliance within 120 days.

Earlier scrutiny and gaps in anonymization

In April 2025, Italian authorities investigated IQVIA's data-processing practices. Last month, the GPDP decided that IQVIA did not provide adequate health-data anonymization warranties.

The GPDP also found records dating back as far as 2001 in IQVIA's database. For a subset of 3,300 patients, the company included names, tax identification numbers, addresses, and contact details.

Quick answers

How much was IQVIA fined by Italy's data protection authority?

The GPDP fined IQVIA €7 million ($7.8 million).

What did the GPDP say IQVIA did wrong?

The regulator said IQVIA processed health data of roughly 1 million patients without an appropriate legal basis and without informing them, and that patients could be tracked and de-anonymized over time.

What did the GPDP order IQVIA to do?

The GPDP ordered IQVIA to bring its practices into compliance within 120 days.

Source