Editor’s Note: A persistent patient code and a detailed clinical record were enough, in the Garante’s view, to keep health data identifiable. Italy’s data protection authority has fined IQVIA Solutions Italy 7 million euros after finding that records from about 1 million family-doctor patients, which the company treated as anonymous, remained personal data. France’s CNIL reached the same conclusion about two IQVIA warehouses in May.
For cybersecurity, data privacy, regulatory compliance and eDiscovery professionals, the reasoning outweighs the amount. The Garante accepted that anonymity can depend on who holds the data, but it found IQVIA had designed and instructed the de-identification, so the company could not claim to be a mere recipient under the Court of Justice’s SRB ruling. The authority also wrote working conditions into its remedy, including equivalence classes of no fewer than 10 and, for leftover variables that could help identify a patient, options such as secure multiparty computation.
Watch whether IQVIA challenges the order, which it has said it reserves the right to do, and watch the European Data Protection Board’s anonymization consultation, which closes Oct. 30.
Content Assessment: Italy's privacy regulator rejects IQVIA's anonymization claim and fines it 7 million euros
Information - 94%
Insight - 92%
Relevance - 92%
Objectivity - 93%
Authority - 92%
93%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Italy's privacy regulator rejects IQVIA's anonymization claim and fines it 7 million euros."
News Analysis – Data Privacy and Protection Beat
Italy’s privacy regulator rejects IQVIA’s anonymization claim and fines it 7 million euros
ComplexDiscovery OÜ Staff
Italy’s data protection authority has fined IQVIA Solutions Italy 7 million euros after concluding that health records from about 1 million family-doctor patients, which the company treated as anonymous, remained identifiable personal data.
The decision follows a similar finding by France’s data protection authority in May, when it concluded that two health data warehouses run by the group’s French subsidiary held pseudonymous data, not anonymous data. Within four months, two European regulators have rejected an IQVIA anonymization argument.
The Garante per la protezione dei dati personali, Italy’s privacy regulator, adopted the decision Sept. 23 and published it with a press release Oct. 2. The order, numbered 710, follows inspections in April 2025 and folds in a separate proceeding over a personal data breach that IQVIA itself notified. Vice President Ginevra Cerrina Feroni served as rapporteur.
Inside the patient records
The database at issue was fed from the practice-management software of about 800 general practitioners who belonged to the Italian Society of General Medicine and Primary Care (SIMG). An add-on installed on that software extracted patient records and sent them to IQVIA. The company kept them in a longitudinal patient database it calls LPD and used them for observational studies, including work commissioned by drugmakers, according to the decision.
Each patient carried a random code, called a Pat ID, so that a person could be followed over time. During the inspection, the company displayed one patient who appeared 34 times in the prescriptions table alone, which it said made it possible to trace that patient’s clinical history. The Garante said the code, combined with year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data, made it possible to single out individual patients and re-identify them by reasonable means.
Intent did not matter to that conclusion. It is enough, the decision said, that IQVIA had the capability to re-identify patients by reasonable means, whether or not it meant to. IQVIA had contested both the label and its own role.
Why the SRB argument did not carry
IQVIA argued first that it was not the controller at all: in its account, the SIMG had designed the project and the data reached IQVIA already anonymized. Its central argument, though, rested on the Court of Justice of the European Union’s Sept. 4, 2025, judgment in EDPS v. SRB, Case C-413/23 P, which interpreted the data protection rules for European Union institutions. That ruling held that pseudonymized data need not be personal data for every recipient, because a recipient without the means to reverse the pseudonymization may be unable to identify anyone. IQVIA also called it the Deloitte judgment during a hearing, the name Cybersecurity360 uses in its coverage.
The company argued that the Pat ID was generated on the doctor’s own system and that the re-linking key never reached IQVIA. It also submitted a risk assessment that scored the re-identification risk as low.
The Garante accepted the premise and rejected its application. The decision recognized that the same dataset can be personal data for one party and anonymous for another, depending on the means each can reasonably use. But it found IQVIA was not a mere recipient. Contracts in the record showed that IQVIA supplied the extraction software to doctors free of charge, contracted with the software developer and instructed that developer on how the data would be anonymized. The Garante also found IQVIA owned the database, though it noted that the collaboration contract the SIMG submitted described the two as co-owners. Together, the decision said, those facts made IQVIA the controller of the whole processing chain from the moment of collection, which placed it outside the situation the SRB court addressed.
The technical case fared no better. K-anonymity applied to quasi-identifiers such as age and location leaves the rest of the record untouched, the Garante said, and a clinical history observed over years can itself identify a person. Hashing a patient code protects the code, not the uniqueness of the record behind it.
The re-identification assessments IQVIA relied on came from a company in the IQVIA group, according to the decision, which names Privacy Analytics as their author in its penalty section. The Garante credited the assessments as a mitigating factor. It also faulted IQVIA for accepting their conclusions passively.
France reached the same answer in May
The Garante measured that passivity against the earlier rulings on the same question, in Italy and elsewhere in Europe, the most recent of them from Paris. France’s Commission nationale de l’informatique et des libertés (CNIL) fined IQVIA Operations France 5 million euros May 26, 2026, over two warehouses, one supplied by about 14,000 pharmacies and one by several thousand doctors. IQVIA raised the SRB judgment there as well. The CNIL’s restricted committee found the data pseudonymous rather than anonymous, pointing to the single identifier attached to each patient, how much the warehouses held on each person and the chance of matching that material against public information.
The CNIL also recalled that IQVIA had not contested the personal-data status of its French warehouses until the SRB ruling, and had sought the CNIL’s authorizations on that footing. The Garante cited the French decision twice: once on the capability standard, and once to argue that IQVIA should have re-examined its own position after earlier rulings in Italy and France.
The Garante writes the specification
The Italian order goes further than a finding. If IQVIA wants to keep running the program, it has 120 days from notification to put four things in place. It must establish a legal basis for the processing, including any anonymization, inform patients, complete a data protection impact assessment and designate participating doctors as processors.
Alternatively, the doctors themselves must carry out the anonymization, with their own legal basis and their own notice to patients, under conditions the Garante spelled out. IQVIA may not determine how the data is pseudonymized. Attributes treated as quasi-identifiers must yield equivalence classes of no fewer than 10. Any remaining variable, outside the pseudonymized fields and the equivalence classes, that IQVIA could observe or measure and that could help identify a patient must join the quasi-identifiers, go through secure multiparty computation or a similar technique that keeps the full data out of IQVIA’s hands, or be removed. If IQVIA passes the data on, it takes on the same obligations as a sender.
Read as a working specification, those conditions give practitioners a benchmark. An anonymization claim that cannot show who chose the pseudonymization method, how large its equivalence classes are and what happened to the rest of the record now has a documented counterexample.
The breach shows why the rest of the record matters, and it is where security teams come in. Doctors had typed names, tax codes, addresses and contact details into free-text fields, and the add-on extracted those fields. Directly identifying data for 3,370 patients reached IQVIA, including health data for 3,080 of them, and was passed on to the SIMG, which removed the identifying data at IQVIA’s request.
The Garante held IQVIA responsible for failing to verify that the extraction tool skipped free text. It rejected the view that the doctors had entered the data in error, since they used those fields for patient care. The decision also faulted IQVIA for running no automated checks on the database that would have flagged free-text content. And it found no record that IQVIA had estimated, as a percentage, how many records could be singled out; the company relied instead on checks the Garante called inadequate for large-scale processing.
In all, the Garante found violations of Articles 5, 9, 13, 25, 28, 32 and 35 of the General Data Protection Regulation (GDPR). They cover legal basis, transparency, retention, security, accountability, data protection by design, processor designation and impact assessment. The data went back to 2001, and IQVIA had not defined retention periods for it, the authority said. Of those findings, the anonymization ruling is the one that travels beyond this case.
What ‘we anonymized it’ now has to prove
For information governance teams, the decision turns anonymization from a conclusion into a contestable assertion. Organizations that retain, transfer or reuse data on the strength of de-identification should be able to show who designed the method, what the residual record contains and why reasonable means could not re-identify it. The Garante also treated anonymization as processing in its own right, with its own need for a legal basis, so the de-identification step is not a compliance-free exit. And an assessment prepared by an affiliate, accepted without challenge, drew criticism in this case even as it earned credit.
The same question reaches eDiscovery. Where a cross-border production rests on a dataset described as de-identified, or an analytics or AI training corpus is described as outside the GDPR because it was anonymized, the Garante’s reasoning may be relevant. It is one national decision, still open to challenge, and it turns on IQVIA having designed the de-identification itself. But on that reasoning, a party in the same position will find it hard to argue that the data is anonymous in its own hands.
The Garante reached IQVIA’s controller status through contracts in which IQVIA specified and instructed the anonymization. That raises a question for service providers that design de-identification for clients: whether their own contracts would read the same way. Legal teams should ask counterparties and vendors for the method, the equivalence-class sizes and the treatment of free text before accepting the label.
Technology buyers can put the same questions to providers that market anonymization or de-identification as a compliance basis. Both regulators pointed to the same combination: a persistent patient identifier attached to a detailed clinical record.
Fine, appeal window and two consultations
Back in Rome, the Garante priced IQVIA’s failures by starting with the group rather than the subsidiary. It set the ceiling on the fine at 4 percent of the worldwide turnover of IQVIA Holdings Inc., the U.S. parent. It treated the parent and its wholly owned Italian subsidiary as one economic unit. In settling on 7 million euros, it weighed the number of patients, the sensitivity of the data, the doctors’ halt to data transmission starting in 2023 and the company’s cooperation. It also said it balanced patients’ rights against the database’s role as a reference resource for health research, partly to limit the fine’s economic impact on the company.
IQVIA said it reserves the right to appeal, according to Il Sole 24 Ore’s Radiocor wire. The company said the dataset plays no part in its clinical research services or in trials it runs for sponsors. It said it had cooperated constructively and had already taken the measures needed to align with the authority’s directions. The two accounts can both hold. The Garante describes the work as observational studies, and IQVIA told inspectors the studies were retrospective and delivered to drugmakers as aggregate reports; neither describes clinical trials.
Under the decision, IQVIA may challenge the order in an ordinary Italian court within 30 days of being notified, or 60 days if it resides abroad. Italian law also lets it close the matter within that same window by complying with the Garante’s orders and paying half the fine, 3.5 million euros. Neither the decision nor the press release states when IQVIA was notified.
Beyond the parties, two outside voices addressed different parts of the case. Filippo Anelli, president of Fnomceo, Italy’s national federation of physicians, surgeons and dentists, said the participating doctors bore no responsibility, though doctors should still exercise caution, according to Il Sole 24 Ore. An analysis by Rosario Palumbo, a corporate legal and data protection specialist, published by Cybersecurity360, said the Garante rejected an expansive reading of the SRB ruling. It also said the decision lays out step by step how the anonymization should have been done.
Two European consultations were already open when the decision came down, and either could inform how similar cases are argued. Comments on the European Data Protection Board (EDPB) draft Guidelines 02/2026 on Anonymisation, which the Garante relied on, close Oct. 30. The board’s draft guidelines on whether to fine at all, on its own or combined with other corrective measures, take comments until Nov. 13. Both are consultation drafts of EDPB guidance rather than law, and the IQVIA order is now a worked example for anyone commenting on either.
If two regulators have now drawn the line at a unique identifier plus a rich clinical history, how many of the datasets your organization calls anonymous would survive the same test?

News sources
- Provvedimento del 23 settembre 2026 [10302112] (Garante per la protezione dei dati personali)
- Dati sanitari: il Garante privacy sanziona IQVIA per 7 milioni di euro (Garante per la protezione dei dati personali)
- Health data: fine of 5 million euros against IQVIA (CNIL)
- Guidelines 02/2026 on Anonymisation (European Data Protection Board)
- EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines (European Data Protection Board)
- Health data of one million patients exposed; Iqvia faces a fine of 7 million (Il Sole 24 Ore)
- Garante Privacy: Iqvia, sempre collaborato e adottate le misure necessarie (Il Sole 24 Ore Radiocor)
- IQVIA, 7 milioni di multa: il Garante spiega quando un dato sanitario è davvero anonimo (Cybersecurity360)
Assisted by GAI and LLM Technologies
Additional reading
- Europe’s draft cloud rule would put vendor ownership in the audit file
- The eight-hour clock starts today: EU e-evidence orders now land on covered U.S. providers’ EU addressees
- California’s AI Transparency Act arrives alongside Europe’s Article 50
- Federal magistrate judge treats LinkedIn’s Relativity aiR workflow as TAR
- One benchmark, three directions: 2026 legal rates rise, flatten and fall at once
- Confidence cools, commitment holds: full results from the 1H 2026 eDiscovery Business Confidence Survey
- Complete look: ComplexDiscovery OÜ’s 2025 to 2030 eDiscovery market size mashup
- The workstream of eDiscovery: Considering processes and tasks
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.



























