The GPDP investigation, which began in April 2025, concluded that IQVIA's Italian division had created a database aggregating health information from 800 general practitioners. While the company argued the data was pseudonymized, the regulator determined that the approach did not meet GDPR requirements for anonymization.
"The code associated with each patient made it possible to track them over time," the GPDP said in its announcement. "Combined with a very detailed set of information (year of birth, sex, diagnoses, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to single out individual patients and, using reasonable means, reidentify them."
In addition to the anonymization issue, the authority found that IQVIA processed data without an appropriate legal basis and failed to inform patients. The company also did not follow any data retention schedule, with records dating back to 2001. For a subset of 3,300 patients, IQVIA had stored names, tax identification numbers, addresses, and contact details.
IQVIA said in a statement to BleepingComputer that it is "committed to the responsible use of data and information" and continues to cooperate with the authority. The company acknowledged the decision and reserves the right to appeal. It noted that the dataset in question is not used in clinical research services or clinical trials.
The GPDP has ordered IQVIA to bring its practices into compliance within 120 days.