Italy's privacy regulator fines IQVIA €7m over patient database
EditorialBy TrustList Editorial
The Garante found the records of one million patients from 800 family doctors could be traced back to individuals. IQVIA has 120 days to comply and says it may appeal.
- Italy
- GDPR Compliance
- Data Privacy Law
- Regulatory Compliance
About Italy's privacy regulator fines IQVIA €7m over patient database
Italy's privacy regulator fines IQVIA €7m over patient database
2 October 2026: Italy's data protection authority, the Garante, has fined IQVIA Solutions Italy S.r.l. €7m after finding that a database of health records covering about one million patients was not anonymous, as the company had claimed. The decision, dated 23 September 2026, gives IQVIA 120 days to bring the processing into line and report back in writing.
Not yet independently verified. The decision text was read on a third-party mirror of the Garante register because the regulator's own site was not reachable. We will link the Garante page when we can open it. We will update this when it can be confirmed, and remove this note.
The database was built from the records of 800 general practitioners and used for studies, some of them commissioned by pharmaceutical companies. The Garante found that the code attached to each patient allowed the person to be followed over time, and that, combined with year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations and location data, it made individual patients identifiable by reasonable means.
BleepingComputer, summarising the decision, reports further findings: the processing had no legal basis and patients were not told about it, no retention periods had been set, records went back to 2001, and for 3,300 patients the database held names, tax identification numbers, addresses and contact details. The decision text lists breaches of GDPR Articles 5, 9, 13, 25, 28, 32 and 35, which cover lawfulness, special-category data, information duties, data protection by design, processor obligations, security and impact assessments.
What IQVIA must do
The Garante ordered the company to stop the unlawful processing, apply security measures and pseudonymisation, complete a data protection impact assessment, update its privacy notices, delete data held beyond ten years, and inform patients through their doctors' software. The decision is to be published on the Garante's website.
IQVIA told BleepingComputer that it uses pseudonymisation and encryption, reserves the right to appeal, and did not use the dataset for clinical research services or clinical trials.
The case turns on a claim that many analytics and data-sharing suppliers make, that removing names makes a dataset anonymous. The regulator's test was whether a patient could be isolated and re-identified by reasonable means, not whether names were present.
Sources
Categories & features
- Italy
- GDPR Compliance
- Data Privacy Law
- Regulatory Compliance
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More ItalyThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.