The decision in brief
Italy’s data protection authority, the Garante per la protezione dei dati personali, fined IQVIA Solutions Italy €7 million (about $7.8 million), announcing the decision on 2 October 2026. The company had built a database of health information on roughly one million patients of 800 general practitioners, used for studies commissioned by pharmaceutical companies. IQVIA treated the data as anonymous. The regulator disagreed: each patient carried a persistent code that allowed their records to be followed over time, and combined with detailed clinical attributes, individuals could be singled out and re-identified “with reasonable means”.
Because the data was personal data, every GDPR obligation applied — and the Garante found most of them missing: no adequate legal basis, insufficient information to patients, no retention periods (records went back to 2001), no data protection impact assessment and inadequate security. IQVIA has 120 days to bring the processing into line if it wants to keep using the data flow.
For anyone building GDPR-compliant data products, the lesson is blunt: anonymization is a legal outcome you have to prove, not a label you attach to a pipeline after hashing the name column.
What did the Garante find?
The data flowed from general practitioners’ practice software into an IQVIA database used for pharmaceutical market and outcomes studies. The Garante concluded that IQVIA was the data controller from the collection stage onward, not a passive recipient of already-anonymous extracts. That classification matters: it put the company on the hook for legal basis and patient information at the point where data left the doctor’s office.
Each record held year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data. On top of that, the regulator found full identifying details — names, tax codes, addresses and contact information — for more than 3,300 patients, over 3,000 of which were tied to health information. Il Sole 24 Ore, which reported the decision on 3 October, also highlighted shortcomings in how the data was protected.
IQVIA said it had cooperated constructively with the authority, maintains safeguards including pseudonymization and encryption, and reserves the right to appeal. It also stated that the dataset in question was not used for its clinical research or trial services. The Italian doctors’ federation FNOMCeO stressed that GPs bore no responsibility and that ensuring compliance had been the company’s job.
Why weren’t the records anonymous?
GDPR draws a hard line between two things engineers often blur. Pseudonymized data has direct identifiers replaced with a code, but a person can still be re-identified with extra information or reasonable effort — it stays personal data under Article 4(5). Anonymous data, per Recital 26, is data where no one is identifiable by any means reasonably likely to be used; only that falls outside the regulation.
The IQVIA dataset failed the anonymity test on two classic vectors. First, linkability: a stable patient key let every visit, prescription and test be stitched into a longitudinal profile. Second, singling out: birth year, sex, location and a specific diagnosis or vaccination history narrow a population quickly, especially in smaller towns or for rare conditions. The richer and longer the record, the more unique it becomes — which is precisely what makes it valuable for research and dangerous for privacy.
This is consistent with the European Data Protection Board’s guidelines on pseudonymisation adopted in January 2025, which treat pseudonymization as a security measure that reduces risk, not as an exit from GDPR. The Garante has now attached a seven-figure price to confusing the two.
Is HIPAA-de-identified data safe under GDPR?
Not automatically, and this is where US teams get caught. HIPAA offers two routes to de-identification: Safe Harbor, which removes 18 listed identifiers, and Expert Determination, where a qualified statistician certifies a very small re-identification risk. Safe Harbor still allows a persistent re-identification code under conditions, and it does not require generalizing every rich clinical field.
A dataset that satisfies Safe Harbor can therefore still be pseudonymized personal data in the eyes of a European regulator if it keeps longitudinal keys and detailed attributes — exactly the IQVIA pattern. For US vendors in HealthTech licensing real-world data, running EU patient analytics or training models on European clinical records, the safe assumption is that GDPR obligations apply unless a GDPR-specific anonymization assessment says otherwise.
What it means for US & EU software teams
“Anonymous” in a contract is not a defense. Data-sharing agreements and vendor questionnaires routinely describe feeds as anonymized. The Garante looked at the actual fields and keys, not the paperwork. If your platform ingests partner data marked “anonymous”, validate it yourself; if it turns out to be personal data, you may be a controller too.
AI training sets inherit the problem. Health records used to train or fine-tune models are under the same test. Models can memorize rare combinations, and a training corpus with stable patient IDs is pseudonymized data with all the duties that come with it — legal basis, DPIA, retention and, increasingly, EU AI Act data-governance requirements for high-risk medical AI.
Retention is an architecture decision. Twenty-five years of records with no deletion policy was one of the findings. Retention limits have to be enforced by the pipeline — partitioned storage, scheduled purges, lineage that shows what was deleted — not written into a policy nobody executes.
Enforcement on health data is getting more specific. Regulators are no longer only fining breaches; they are auditing data-engineering choices such as tokenization schemes and quasi-identifier granularity. Expect procurement teams at pharma and health systems to ask vendors for re-identification risk assessments, not just SOC 2 reports.
An engineering checklist for “de-identified” health data
This is not legal advice, but it reflects the technical controls the IQVIA decision shows regulators will examine:
- Classify honestly. Any dataset with a persistent person-level key is pseudonymized personal data until a documented re-identification risk assessment proves otherwise.
- Break linkability where you can. Use per-study or per-recipient tokens (keyed hashing with separate secrets) instead of one global patient ID shared across every extract.
- Generalize quasi-identifiers. Coarsen birth year into bands, location to region, and suppress or group rare diagnoses; measure uniqueness with k-anonymity or similar metrics before release.
- Separate identity from clinical data. Keep direct identifiers in a distinct, access-controlled store; the 3,300 named records in IQVIA’s database are exactly what this prevents.
- Enforce retention in code. Define retention per purpose and implement automated deletion with logs.
- Run a DPIA before go-live. Large-scale processing of health data almost always requires one under Article 35; its absence was cited here.
- Audit inbound feeds. Re-test partner data labeled anonymous, and make sure your contracts allocate controller roles correctly.
Frequently asked questions
Why was IQVIA fined €7 million in Italy?
Italy’s data protection authority (Garante) found that IQVIA Solutions Italy built a database of health records on roughly one million patients of 800 general practitioners, used for studies commissioned by pharmaceutical companies, and treated it as anonymous when it was not. A persistent code per patient, combined with year of birth, sex, diagnoses, prescriptions, tests, vaccinations and location data, allowed individuals to be singled out and re-identified with reasonable means. The regulator also cited no adequate legal basis, insufficient patient information, no retention periods, no impact assessment and weak security.
What is the difference between pseudonymized and anonymized data under GDPR?
Pseudonymized data has direct identifiers replaced by a code or token, but individuals can still be linked or re-identified with additional information or reasonable effort. Under GDPR it remains personal data, so every obligation still applies: legal basis, transparency, retention limits, security and, for health data, a data protection impact assessment. Anonymized data is processed so that no one can be identified by any means reasonably likely to be used; only then does GDPR stop applying. Replacing names with stable IDs is pseudonymization, not anonymization.
Does the IQVIA decision matter for US companies?
Yes, for any US company that receives, buys or processes health data about people in the EU. GDPR applies based on whose data is processed, not where the company is incorporated, and the fined entity here is the Italian subsidiary of a US-listed group. Data that counts as de-identified under HIPAA, for example after Safe Harbor removal of 18 identifiers, can still be personal data under GDPR if records can be linked over time or combined with detailed attributes.
What should health-data and AI teams do now?
Treat any dataset with persistent patient keys as personal data unless a documented re-identification risk assessment proves otherwise. Generalize quasi-identifiers such as birth year, location and rare diagnoses, rotate or salt tokens per study, set retention limits, run a DPIA before processing, and keep direct identifiers physically separated with strict access control. The same rules apply to datasets used to train or fine-tune AI models.
Sources
Garante per la protezione dei dati personali — Dati sanitari: sanzione a IQVIA per 7 milioni di euro (2 October 2026)
Il Sole 24 Ore — Health data of one million patients exposed; Iqvia faces a fine of 7 million (3 October 2026)
BleepingComputer — IQVIA fined $7.8 million for failing to properly anonymize health data (5 October 2026)
MLex — IQVIA fined €7m in Italy for GDPR breach over identifiable patient data (October 2026)