Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data

  • National News
  • it

Background information

  • Date of final decision: 23 September 2026
  • National case
  • Controller: IQVIA Solutions Italy S.r.l
  • Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 9 (Processing of special categories of personal data),  Article 13 (Information to be provided where personal data are collected from the data subject), Article 25 (Data protection by design and by default), Article 28 (Processor) and Article 35 (Data protection impact assessment)
  • Decision: Administrative fine
  • Key words: Data protection impact assessment, Health and research, Anonymisation/pseudonymisation, Privacy by design and by default, Fines, Basic principles and Controller/processor

Summary of the Decision

Origin of the case

The Italian Data Protection Authority (DPA) carried out an investigation into IQVIA Solutions Italy S.r.l., a company belonging to a multinational group active in health data analytics and clinical research. The investigation concerned a database containing health information relating to approximately one million patients of 800 general practitioners, used for studies commissioned also by pharmaceutical companies. The investigation, which followed inspections carried out in April 2025, was joined with proceedings concerning a personal data breach notified by IQVIA.

Key Findings

The Italian DPA found that the data were not anonymous, as claimed by IQVIA. A persistent identifier assigned to each patient allowed individuals to be tracked over time and, combined with detailed information including year of birth, sex, diagnoses, symptoms, prescriptions, examinations, vaccinations and location data, made it possible to single out and potentially re-identify patients using reasonably available means.

The Italian DPA found that IQVIA, as controller, processed health data without an appropriate legal basis and without providing adequate information to patients. It also failed to establish appropriate retention periods, carry out a data protection impact assessment and implement adequate security measures. The database also contained directly identifying information relating to approximately 3 370 patients, including health data for approximately 3 080 of them.

Decision

The Italian DPA imposed an administrative fine of EUR 7 000 000 on IQVIA Solutions Italy S.r.l.

If IQVIA intends to continue the processing, it must bring it into compliance with the GDPR within 120 days, including by identifying an appropriate legal basis, complying with its information obligations towards patients, carrying out a data protection impact assessment and appointing the general practitioners as processors. Alternatively, the anonymisation process must be carried out independently by the general practitioners in accordance with the safeguards specified by the Italian Authority.

In determining the amount of the fine, the Italian DPA took into account, among other factors, the large number of data subjects involved, the sensitive nature of the data, as well as mitigating factors including the suspension of data transfers by general practitioners and IQVIA’s cooperation during the proceedings.

For further information: 

Relevant topics
Data protection impact assessment
Health and research
Anonymisation / pseudonymisation
Privacy by design and by default
Fines
Basic principles
Controller/processor

Latest news

  • National News
  • it

Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data

  • National News
  • it

Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing

  • National News
  • it

Italian DPA fines security company EUR 39 000 for violations concerning employees’ data