On 23 September 2026, the Italian data protection authority (the Garante) fined IQVIA Solutions Italy €7 million under the GDPR. The decision concerns a database of patient records collected from around 800 general practitioners and covering around a million patients. IQVIA used the database for observational studies requested by pharmaceutical companies. IQVIA treated the data as anonymous. The Garante did not agree with this classification and considered that the data is, instead, pseudonymised patient-level personal data that is subject to the GDPR.
This decision by the Garante is particularly interesting. As we discussed in our earlier post on the EU Digital Omnibus, the EU is in the middle of a wider effort to simplify its digital rulebook. One of the changes on the table in the Digital Omnibus is a narrower concept of personal data, so that coded data in the hands of a company that has no realistic way of identifying who the patients are would fall outside the scope of the GDPR. The Garante decision shows, however, that, in the meantime, regulators are taking a strict and conservative approach to what constitutes personal data.
What did the Garante decide?
The database in question contained patient level data with direct identifiers such as names and addresses removed, and dates of birth reduced to month and year. Each patient was still given the same code over time so that their medical history could be followed from visit to visit. The Garante found that this code, together with detailed clinical, demographic and location information, allowed IQVIA to single out individual patients. In its view, it does not matter whether IQVIA ever intended to reidentify anyone. It is enough that it could do so using reasonable means.
IQVIA relied on the CJEU’s 2025 SRB judgment (see our blog on this decision), arguing that the data were anonymous from its point of view as a recipient. The Garante rejected this. It held that IQVIA was not simply a recipient of coded data but the controller of the whole processing from the moment the data were collected, because it owned the database. Notably, the Garante also considered that anonymization is itself a processing activity that needs a legal basis. The Garante relied heavily on the EDPB’s draft Guidelines 02/2026 on anonymization (see our blog on the draft Guidelines) and referred to a May 2026 decision of the French CNIL against IQVIA France. In that decision, the CNIL fined IQVIA France €5 million and, as in Italy, rejected the argument based on the SRB judgment that its health data warehouses contained anonymous data. As in the Garante’s decision, the CNIL held that re-identification of the data subjects was possible using reasonable means.
The Garante found breaches of the GDPR rules on lawfulness and transparency, special category data, information to patients, storage limitation, security, accountability, privacy by design, processor appointments and DPIAs. A data breach, in which free text fields in the extraction software meant that directly identifying details of 3,370 patients (including health data for 3,080) reached IQVIA, was also identified. The fine of €7 million was set below the legal maximum (4% of the IQVIA group’s worldwide turnover), taking into account IQVIA’s cooperation, the suspension of data flows and the absence of earlier violations within the Italian territory.
Why does this matter for life sciences companies?
This decision highlights the approach of the EU data protection authorities that “anonymous” is a high bar for health data and patient-level data is considered to be pseudonymised personal data (as opposed to anonymised).
We recommend that life sciences companies map the health data and secondary use datasets they hold, license or commission. In particular, companies should revisit any assumption that those data are anonymous, look closely at their own role in how the data are collected and coded, and make sure DPIAs, retention periods and other obligations are in place and complied with. Data sourcing contracts with vendors and healthcare providers are also worth a fresh look, so that roles, legal bases and transparency obligations are clearly set out.
We will keep following the IQVIA case and the Digital Omnibus negotiations and will report back on BioSlice as things develop.
The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.
[View Source]