Italy's Data Protection Authority (GPDP) €7 million fine and compliance order within 120 days on remediate health-data processing and anonymization failures
Regulatory/Legal Action
Summary
Hide ▲
Show ▼
Italy's GPDP fined IQVIA and ordered compliance after finding GDPR violations in health-data processing that could expose and de-anonymize roughly one million patients. The authority said the company's Italian division used detailed records and unique codes that made reidentification possible over time. It also said the processing lacked an adequate legal basis and patient notice, with a 120-day deadline to fix the practices.
Timeline
-
05.10.2026 20:19 2 articles · 2h ago
GPDP fines IQVIA €7 million over health-data anonymization failures
Legal Policy Action UpdateItaly's Data Protection Authority (GPDP) fined IQVIA €7 million ($7.8M) after finding that its Italian division's health-data processing could let roughly one million patients be tracked and de-anonymized. The agency also said a subset of 3,300 patients' records included names, tax identification numbers, addresses, and contact details, and it ordered IQVIA to bring its practices into compliance within 120 days.
Show sources
- IQVIA fined $7.8 million for failing to properly anonymize health data — www.bleepingcomputer.com — 05.10.2026 20:19
- IQVIA fined $7.8 million for failing to properly anonymize health data — www.bleepingcomputer.com — 05.10.2026 20:19