← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

IQVIA fined $7.8 million by Italian DPA for inadequate health data anonymization

🔄 Updated 52m ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • IQVIA fined €7 million ($7.8M) by Italian GPDP.
  • Data of one million patients at risk of de-anonymization.
  • Violations include inadequate anonymization and GDPR non-compliance.
  • Ordered to comply with regulations within 120 days.

Italian DPA Imposes Fine on IQVIA

Italy's Data Protection Authority (GPDP) has issued a fine of €7 million ($7.8M) against IQVIA, a multinational healthcare data analysis company. The penalty stems from findings that IQVIA's data-processing practices were insufficient, potentially compromising the privacy of approximately one million patients.

Data Anonymization Failures Identified

The GPDP's investigation, initiated in April 2025, concluded that IQVIA's Italian division created a database of health information for about one million patients by aggregating data from 800 general practitioners. Although the company used unique codes instead of patient names, the GPDP determined these codes, combined with detailed information like year of birth, sex, diagnoses, and location data, could enable tracking and re-identification of individual patients over time.

For a subset of 3,300 patients, the database also included names, tax identification numbers, addresses, and contact details, further exacerbating the privacy risks.

GDPR Violations and Lack of Data Retention

Beyond the anonymization issues, IQVIA was found to have processed patient data without an appropriate legal basis and without informing the patients, which constitutes a violation of the General Data Protection Regulation (GDPR). The GPDP also noted that IQVIA did not establish or follow any data retention periods, with some records dating back to 2001.

Compliance Order Issued

In addition to the financial penalty, Italian authorities have ordered IQVIA to bring its data processing practices into compliance with regulations within 120 days. IQVIA stated it is committed to responsible data use and continues to cooperate with the Authority, maintaining robust safeguards including pseudonymization and encryption.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 05

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Italy's Data Protection Authority (GPDP) fined IQVIA €7 million ($7.8M) for failing to properly anonymize health data, potentially exposing one million patients to re-identification. The company's practices violated GDPR by allowing patient tracking, lacking a legal basis for processing, and not adhering to data retention periods.