IQVIA fined €7 million for inadequate health data anonymization in Italy
Italy's Data Protection Authority penalized IQVIA €7 million after discovering the company's Italian division stored health data of about one million patients with insufficient anonymization measures. The investigation revealed that despite using unique codes, the detailed information could enable re-identification of individuals over time, violating GDPR rules. The authority also found IQVIA processed data without proper legal grounds and failed to set clear data retention policies, with some records dating back over two decades.
GoKawiil's interpretation of the reporting above, not reported fact.
This case highlights the ongoing challenges in ensuring health data privacy, especially when large multinational firms operate across different legal jurisdictions. It underscores the importance of strict anonymization practices and legal compliance in handling sensitive health information, which could influence future regulatory scrutiny and industry standards.
- IQVIA's data practices faced regulatory action in Italy.
- Health data was insufficiently anonymized, risking re-identification.
- The incident emphasizes the need for strict GDPR compliance in health data handling.
Source: bleepingcomputer.com, 2026-10-05
Published there as: “IQVIA fined $7.8 million for failing to properly anonymize health data”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.