Italy's Data Protection Authority fines IQVIA €7 million over data protection breach
The following is a machine translation of a press release by Italy’s privacy guarantor:
Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The data of one million patients of 800 family doctors are not anonymous. The Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million. The company, part of a multinational group active in healthcare data analysis and clinical research, had created a database containing health information on one million patients of 800 general practitioners , which was used for studies commissioned by pharmaceutical companies. The provision (no. 710 of 23 September 2026) was adopted following an investigation initiated following inspections carried out in April 2025, which included proceedings relating to a personal data breach notified by the same company. According to the Guarantor, the data used was not anonymous, as the company claimed. The code associated with each patient allowed them to be tracked over time. Combined with highly detailed information (year of birth, sex, diagnosis, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to isolate individual patients and, with reasonable means, re-identify them. The Authority also deemed IQVIA the data controller from the time the data was collected from physicians. The company processed health data without an appropriate legal basis and without adequately informing patients. It did not define retention periods: the data dated back to 2001. It failed to carry out an impact assessment and failed to take adequate security measures. The database also included identifying information (names, tax codes, addresses, details) for over 3,300 patients, more than 3,000 of which were linked to health data. Within 120 days, the company must adapt its processing practices, if it intends to continue operating, in compliance with the Authority’s requirements. Alternatively, the anonymization must be carried out independently by the doctors, in accordance with the guarantees indicated by the Authority. In determining the fine, the Authority took into account the number of patients involved, the nature of the data processed, the cessation of their transmission by doctors starting in 2023, and the cooperation provided by the company during the proceedings. Rome, October 2, 2026
Healthcare data: The Privacy Guarantor fines IQVIA 7 million euros. The data of one million patients of 800 family doctors are not anonymous.
The Italian Data Protection Authority has fined IQVIA Solutions Italy Srl €7 million. The company, part of a multinational group active in healthcare data analysis and clinical research, had created a database containing health information on one million patients of 800 general practitioners , which was used for studies commissioned by pharmaceutical companies.
The provision (no. 710 of 23 September 2026) was adopted following an investigation initiated following inspections carried out in April 2025, which included proceedings relating to a personal data breach notified by the same company.
According to the Guarantor, the data used was not anonymous, as the company claimed. The code associated with each patient allowed them to be tracked over time.
Combined with highly detailed information (year of birth, sex, diagnosis, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to isolate individual patients and, with reasonable means, re-identify them. The Authority also deemed IQVIA the data controller from the time the data was collected from physicians.
The company processed health data without an appropriate legal basis and without adequately informing patients. It did not define retention periods: the data dated back to 2001.
It failed to carry out an impact assessment and failed to take adequate security measures.
The database also included identifying information (names, tax codes, addresses, details) for over 3,300 patients, more than 3,000 of which were linked to health data.
Within 120 days, the company must adapt its processing practices, if it intends to continue operating, in compliance with the Authority’s requirements. Alternatively, the anonymization must be carried out independently by the doctors, in accordance with the guarantees indicated by the Authority.
In determining the fine, the Authority took into account the number of patients involved, the nature of the data processed, the cessation of their transmission by doctors starting in 2023, and the cooperation provided by the company during the proceedings.
Rome, October 2, 2026
Headline corrected post-publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
