Italy's Data Protection Authority (GPDP) has issued a fine of €7 million ($7.8M) against IQVIA, a multinational healthcare data analysis company. The penalty stems from findings that IQVIA's data-processing practices were insufficient, potentially compromising the privacy of approximately one million patients.
The GPDP's investigation, initiated in April 2025, concluded that IQVIA's Italian division created a database of health information for about one million patients by aggregating data from 800 general practitioners. Although the company used unique codes instead of patient names, the GPDP determined these codes, combined with detailed information like year of birth, sex, diagnoses, and location data, could enable tracking and re-identification of individual patients over time.
For a subset of 3,300 patients, the database also included names, tax identification numbers, addresses, and contact details, further exacerbating the privacy risks.
Beyond the anonymization issues, IQVIA was found to have processed patient data without an appropriate legal basis and without informing the patients, which constitutes a violation of the General Data Protection Regulation (GDPR). The GPDP also noted that IQVIA did not establish or follow any data retention periods, with some records dating back to 2001.
In addition to the financial penalty, Italian authorities have ordered IQVIA to bring its data processing practices into compliance with regulations within 120 days. IQVIA stated it is committed to responsible data use and continues to cooperate with the Authority, maintaining robust safeguards including pseudonymization and encryption.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Italy's Data Protection Authority (GPDP) fined IQVIA €7 million ($7.8M) for failing to properly anonymize health data, potentially exposing one million patients to re-identification. The company's practices violated GDPR by allowing patient tracking, lacking a legal basis for processing, and not adhering to data retention periods.