Summary
- Italy’s Garante fined IQVIA Solutions Italy €7 million over health information from around one million patients.
- The regulator found recurring patient identifiers and detailed medical data could allow individuals to be singled out and reidentified.
- The database contained information originating from around 800 family doctors.
Italy’s privacy regulator has fined IQVIA Solutions Italy €7 million after concluding that a health database covering around one million patients was not genuinely anonymous and therefore remained subject to European data protection law.
The Garante per la protezione dei dati personali said the database contained information originating from around 800 family doctors and had been used for research activities, including work commissioned by pharmaceutical companies.
IQVIA treated the material as anonymised, but the regulator found that recurring identifiers allowed records belonging to the same patient to be linked over time. Combined with detailed clinical and demographic information, those identifiers could allow individual patients to be singled out and potentially reidentified.
Anonymisation carries a higher threshold than simply removing a person’s name or replacing it with a code. Information that can no longer reasonably be connected with an identifiable person falls outside the GDPR, whereas pseudonymised information remains personal data if the individual can still be identified through additional information or analysis.
The IQVIA database contained longitudinal records including diagnoses, symptoms, prescriptions, examinations, vaccinations, sex, birth information and geographic data. By assigning a persistent code to the same patient, the dataset retained the ability to follow clinical events across time, preserving much of its analytical usefulness.
That continuity also contributed to the regulator’s finding that the information could not be treated as anonymous from IQVIA’s perspective. A recurring identifier does not reveal a name directly, but it can allow multiple pieces of information to be assembled into a distinctive history belonging to one person.
The Garante’s investigation followed inspections carried out in April 2025 and was combined with an inquiry into a personal data breach notified by the company. The final decision identified wider compliance failures alongside the anonymisation issue, including concerns involving the legal basis for processing, transparency, retention, security measures and data protection impact assessment.
Direct identifiers were also present in a smaller subset of records. According to the regulator, more than 3,300 patients had information such as names, tax codes or addresses included in the dataset, with health information associated with more than 3,000 of those cases.
Health information receives additional protection under European law because misuse can have consequences for employment, insurance, discrimination and personal privacy. The regulatory question was therefore wider than whether the research itself had a legitimate purpose, extending to whether the underlying information could lawfully be treated as outside the GDPR.
Longitudinal medical datasets make that assessment particularly difficult because combinations of dates, treatments, locations and demographic characteristics can become identifying even when obvious fields have been removed. As the dataset becomes richer, maintaining analytical value while reducing the possibility of reidentification becomes progressively harder.
The issue is increasingly relevant as health information is reused for analytics, pharmaceutical research and artificial intelligence. Organisations can apply pseudonymisation, aggregation and other safeguards, but none of those techniques automatically removes the data from the scope of privacy law.
From an operational perspective, the Garante’s decision also reinforces the importance of assessing anonymisation against the environment in which the organisation actually works. A dataset may appear anonymous to an external observer while remaining identifiable to an organisation that holds additional records, persistent identifiers or technical means capable of reconnecting the information.
The ruling applies to IQVIA Solutions Italy and the particular processing examined by the regulator, rather than establishing that every coded health dataset is identifiable. It does, however, place the burden on organisations claiming anonymisation to demonstrate that reidentification is no longer reasonably possible.
Corrective requirements accompany the financial penalty, and IQVIA can challenge the decision through the applicable Italian procedure. The enforcement action arrives as European healthcare and life sciences organisations continue expanding secondary uses of clinical data, increasing the consequences of misclassifying information that remains personal.
Where a dataset contains years of linked medical history, the absence of a visible name may therefore be only the beginning of the privacy assessment rather than its conclusion.





