Skip to content
TrustList
News

Italy's privacy regulator fines IQVIA €7m over patient database

Editorial

By TrustList Editorial

The Garante found the records of one million patients from 800 family doctors could be traced back to individuals. IQVIA has 120 days to comply and says it may appeal.

  • Italy
  • GDPR Compliance
  • Data Privacy Law
  • Regulatory Compliance

About Italy's privacy regulator fines IQVIA €7m over patient database

Italy's privacy regulator fines IQVIA €7m over patient database

2 October 2026: Italy's data protection authority, the Garante, has fined IQVIA Solutions Italy S.r.l. €7m after finding that a database of health records covering about one million patients was not anonymous, as the company had claimed. The decision, dated 23 September 2026, gives IQVIA 120 days to bring the processing into line and report back in writing.

Not yet independently verified. The decision text was read on a third-party mirror of the Garante register because the regulator's own site was not reachable. We will link the Garante page when we can open it. We will update this when it can be confirmed, and remove this note.

The database was built from the records of 800 general practitioners and used for studies, some of them commissioned by pharmaceutical companies. The Garante found that the code attached to each patient allowed the person to be followed over time, and that, combined with year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data, it made individual patients identifiable by reasonable means.

BleepingComputer, summarising the decision, reports further findings: the processing had no legal basis and patients were not told about it, no retention periods had been set, records went back to 2001, and for 3,300 patients the database held names, tax identification numbers, addresses and contact details. The decision text lists breaches of GDPR Articles 5, 9, 13, 25, 28, 32 and 35, which cover lawfulness, special-category data, information duties, data protection by design, processor obligations, security and impact assessments.

What IQVIA must do

The Garante ordered the company to stop the unlawful processing, apply security measures and pseudonymisation, complete a data protection impact assessment, update its privacy notices, delete data held beyond ten years, and inform patients through their doctors' software. The decision is to be published on the Garante's website.

IQVIA told BleepingComputer that it uses pseudonymisation and encryption, reserves the right to appeal, and did not use the dataset for clinical research services or clinical trials.

The case turns on a claim that many analytics and data-sharing suppliers make, that removing names makes a dataset anonymous. The regulator's test was whether a patient could be isolated and re-identified by reasonable means, not whether names were present.

Sources

Categories & features

  • Italy
  • GDPR Compliance
  • Data Privacy Law
  • Regulatory Compliance

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy