Italy Fines IQVIA €7M Over "Anonymous" Health Data
Italy's data protection authority has fined IQVIA €7 million after ruling that a database of roughly 1 million patients' "anonymised" health records was in fact re-identifiable — a landmark on where pseudonymisation ends and true anonymisation begins under the GDPR.
Why It Matters
On 2 October the Garante announced a €7,000,000 fine against IQVIA Solutions Italy (decision n. 710, adopted 23 September) over its Longitudinal Patient Data database, built from the records of about 1 million patients treated by some 800 general practitioners. IQVIA had treated the dataset as anonymous. The Garante found that a persistent patient code (Pat ID) kept a one-to-one link across detailed clinical histories, so the data remained personal data — and, being health data, special-category data under Article 9 GDPR.
The authority also found IQVIA had no adequate legal basis and had fallen short on transparency, retention limits, data-protection-by-design, processor obligations, security and a required impact assessment; a software fault additionally exposed direct identifiers of more than 3,300 patients. IQVIA was given 120 days to bring the processing into compliance and says it will appeal (the penalty can be settled at €3.5 million within the appeal window).
For compliance teams, CISOs and legal departments, the decision is a warning that persistent coded identifiers over rich, longitudinal records do not take data outside the GDPR. The "reasonable means" test for re-identification is doing real work — and health and analytics datasets that lean on consistent keys are squarely in scope.
Action Items
Re-examine your "anonymised" datasets — flag any that rely on a persistent or consistent identifier across records and ask whether re-identification is possible by reasonable means.
Treat re-identifiable clinical data as special-category — where a dataset fails the test, apply Article 9 safeguards: documented legal basis, transparency notice, retention limits and a DPIA.
Check processor contracts and pipelines — confirm Article 28 agreements are in place and that extraction pipelines do not leak direct identifiers into free-text fields.
Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.
Subscribe to Pro to read the rest.
Become a paying subscriber of Pro to get access to this post and other subscriber-only content.
UpgradeA subscription gets you:
- Deep dives of each updated regulation
- Source verification documents
- Extended jurisdiction-specific analysis
- Compliance deadline tracker
- Regulation crosswalk