On 23 September 2026, the Italian data protection authority (the Garante) fined IQVIA Solutions Italy €7 million under the GDPR. The decision concerns a database of patient records collected from around 800 general practitioners and covering around a million patients. IQVIA used the database for observational studies requested by pharmaceutical companies. IQVIA treated the data as anonymous. The Garante did not agree with this classification and considered that the data is, instead, pseudonymised patient-level personal data that is subject to the GDPR.
This decision by the Garante is particularly interesting. As we discussed in our earlier post on the EU Digital Omnibus, the EU is in the middle of a wider effort to simplify its digital rulebook. One of the changes on the table in the Digital Omnibus is a narrower concept of personal data, so that coded data in the hands of a company that has no realistic way of identifying who the patients are would fall outside the scope of the GDPR. The Garante decision shows, however, that, in the meantime, regulators are taking a strict and conservative approach to what constitutes personal data.
Continue Reading Pseudonymised, Not Anonymous: What the Italian Garante’s €7 Million IQVIA Fine Means for Health Data