The 60-second summary
A €7 million decision against IQVIA challenges claims of anonymous health analytics and requires lawful processing or independently performed anonymisation. The Garante found that persistent patient codes and detailed records could support identification, despite an anonymity claim. The decision covers lawfulness, patient information, retention, DPIAs, security and controller/processor responsibilities. The order gives IQVIA 120 days to bring processing into compliance if it continues, or use independent anonymisation by practitioners. This is a case-specific order, not a new general deadline.
Timeline that matters
23 September 2026
2 October 2026; EDPB summary 9 October 2026
What changed
The Garante found that persistent patient codes and detailed records could support identification, despite an anonymity claim.The decision covers lawfulness, patient information, retention, DPIAs, security and controller/processor responsibilities.The order gives IQVIA 120 days to bring processing into compliance if it continues, or use independent anonymisation by practitioners. This is a case-specific order, not a new general deadline.
Who should care
Health analytics and research teamsPrivacy and security leadersData engineers and sensitive-data discovery teamsVendor-risk and legal specialists
Why this matters for global organisations.
Replacing names with codes does not establish anonymity. Analytics projects need tested identifiability assumptions, documented data provenance, retention limits and clear responsibility across the supply chain.
13 actions to start now
- Inventory datasets, identifiers and linkable attributes across collection, analytics and exports.
- Identify health and other sensitive fields in structured records and free text.
- Test singling out, linkage and re-identification against reasonably available information.
- Separate pseudonymisation from evidenced anonymisation in project and vendor documents.
- Record the legal basis and special-category condition for each processing purpose.
- Review patient notices against actual collection, recipients and uses.
- Complete or refresh the DPIA before continuing high-risk analytics.
- Determine controller and processor roles from actual decisions and instructions.
- Validate supplier contracts against the role assessment.
- Set retention periods tied to each justified purpose.
- Find and remove unintended direct identifiers from analytical datasets.
- Test access controls, exports and incident escalation.
- Require independent review of anonymity claims and retain repeatable testing evidence.
Evidence worth retaining
- Data inventory and provenance register
- Identifiability assessment and test results
- DPIA and legal-basis assessment
- Notices and processor agreements
- Retention schedule and deletion logs
- Access and export testing
- Remediation approvals
Questions to take to counsel or your conformity team
These are discussion prompts, not legal advice or conclusions.
- Is the dataset anonymous for each recipient and use, considering reasonably available means?
- What legal basis and special-category condition support collection and analytics?
- Who determines purposes and means at each stage?
- Does the order’s 120-day period run from notification, and what evidence is required?
Official sources
- Garante announcement, 2 October 2026
- Garante decision No. 710, 23 September 2026
- EDPB national authority summary, 9 October 2026
PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.
PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.