Italian DPA fines IQVIA EUR 7,000,000 for unlawful processing of patients' health data
Original title: Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data
The Italian Data Protection Authority fined IQVIA Solutions Italy EUR 7,000,000 for unlawfully processing health data of approximately one million patients from 800 general practitioners' practices without adequate legal basis or transparency. The DPA found that IQVIA falsely claimed the data were anonymous when persistent identifiers and detailed patient information (including age, sex, diagnoses, prescriptions, and location) allowed re-identification using reasonably available means. Organizations processing health data must establish proper legal bases, provide transparent information to data subjects, conduct data protection impact assessments, define appropriate retention periods, and implement adequate security and privacy-by-design measures.
What changed
- IQVIA was found to have processed special category personal data (health information) without a lawful basis or appropriate legal justification, violating GDPR Article 9 requirements for processing health data
- IQVIA failed to provide data subjects with mandatory information required under GDPR Article 13, leaving patients unaware of how their health data was being collected and used
- IQVIA falsely classified health data as anonymous despite the presence of persistent identifiers and granular patient information that enabled re-identification through reasonably available means, contrary to GDPR anonymisation standards
- IQVIA did not conduct a Data Protection Impact Assessment (DPIA) as required by GDPR Article 35 before processing large-scale health data, nor did it implement data protection by design and by default measures
- IQVIA failed to establish appropriate data retention periods and implement adequate security safeguards, and there was a personal data breach affecting the dataset
Who is affected
Healthcare data processors and analytics companies operating in the EU, particularly those processing health data from medical practices for research or commercial purposes; organizations subject to GDPR in the health and clinical research sectors
Summary generated by a language model; the official text prevails. Not legal advice.