Find notable cyber news and cases, enriched with sources, timelines, and signals.

Italy's Data Protection Authority (GPDP) €7 million fine and compliance order within 120 days on remediate health-data processing and anonymization failures

Regulatory/Legal Action
First reported
Last updated
Happening score
H score 21
1 unique sources, 1 articles

Summary

Hide ▲

Italy's GPDP fined IQVIA and ordered compliance after finding GDPR violations in health-data processing that could expose and de-anonymize roughly one million patients. The authority said the company's Italian division used detailed records and unique codes that made reidentification possible over time. It also said the processing lacked an adequate legal basis and patient notice, with a 120-day deadline to fix the practices.

Timeline

  1. 05.10.2026 20:19 2 articles · 2h ago

    GPDP fines IQVIA €7 million over health-data anonymization failures

    Legal Policy Action Update

    Italy's Data Protection Authority (GPDP) fined IQVIA €7 million ($7.8M) after finding that its Italian division's health-data processing could let roughly one million patients be tracked and de-anonymized. The agency also said a subset of 3,300 patients' records included names, tax identification numbers, addresses, and contact details, and it ordered IQVIA to bring its practices into compliance within 120 days.

    Show sources