Skip to content

Regulatory Pulse

Garante fines IQVIA €7 million: coded health records were not anonymous

A €7 million decision against IQVIA challenges claims of anonymous health analytics and requires lawful processing or independently performed anonymisation.

Italy / European Union
Health data, anonymisation and privacy operations
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Official enforcement development · Reviewed 10 October 2026 · 7 min read

The 60-second summary

A €7 million decision against IQVIA challenges claims of anonymous health analytics and requires lawful processing or independently performed anonymisation. The Garante found that persistent patient codes and detailed records could support identification, despite an anonymity claim. The decision covers lawfulness, patient information, retention, DPIAs, security and controller/processor responsibilities. The order gives IQVIA 120 days to bring processing into compliance if it continues, or use independent anonymisation by practitioners. This is a case-specific order, not a new general deadline.

Timeline that matters

  1. 23 September 2026

  2. 2 October 2026; EDPB summary 9 October 2026

What changed

The Garante found that persistent patient codes and detailed records could support identification, despite an anonymity claim.The decision covers lawfulness, patient information, retention, DPIAs, security and controller/processor responsibilities.The order gives IQVIA 120 days to bring processing into compliance if it continues, or use independent anonymisation by practitioners. This is a case-specific order, not a new general deadline.

Who should care

Health analytics and research teamsPrivacy and security leadersData engineers and sensitive-data discovery teamsVendor-risk and legal specialists

Why this matters for global organisations.

Replacing names with codes does not establish anonymity. Analytics projects need tested identifiability assumptions, documented data provenance, retention limits and clear responsibility across the supply chain.

13 actions to start now

  1. Inventory datasets, identifiers and linkable attributes across collection, analytics and exports.
  2. Identify health and other sensitive fields in structured records and free text.
  3. Test singling out, linkage and re-identification against reasonably available information.
  4. Separate pseudonymisation from evidenced anonymisation in project and vendor documents.
  5. Record the legal basis and special-category condition for each processing purpose.
  6. Review patient notices against actual collection, recipients and uses.
  7. Complete or refresh the DPIA before continuing high-risk analytics.
  8. Determine controller and processor roles from actual decisions and instructions.
  9. Validate supplier contracts against the role assessment.
  10. Set retention periods tied to each justified purpose.
  11. Find and remove unintended direct identifiers from analytical datasets.
  12. Test access controls, exports and incident escalation.
  13. Require independent review of anonymity claims and retain repeatable testing evidence.

Evidence worth retaining

  • Data inventory and provenance register
  • Identifiability assessment and test results
  • DPIA and legal-basis assessment
  • Notices and processor agreements
  • Retention schedule and deletion logs
  • Access and export testing
  • Remediation approvals

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Is the dataset anonymous for each recipient and use, considering reasonably available means?
  • What legal basis and special-category condition support collection and analytics?
  • Who determines purposes and means at each stage?
  • Does the order’s 120-day period run from notification, and what evidence is required?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.