Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data

The Italian Data Protection Authority (DPA) carried out an investigation into IQVIA Solutions Italy S.r.l., a company belonging to a multinational group active in health data analytics and clinical research. The investigation, which followed inspections carried out in April 2025, was joined with proceedings concerning a personal data breach notified by IQVIA. A persistent identifier assigned to each patient allowed individuals to be tracked over time and, combined with detailed information including year of birth, sex, diagnoses, symptoms, prescriptions, examinations, vaccinations and location data, made it possible to single out and potentially re-identify patients using reasonably available means. The database also contained directly identifying information relating to approximately 3 370 patients, including health data for approximately 3 080 of them. If IQVIA intends to continue the processing, it must bring it into compliance with the GDPR within 120 days, including by identifying an appropriate legal basis, complying with its information obligations towards patients, carrying out a data protection impact assessment and appointing the general practitioners as processors. In determining the amount of the fine, the Italian DPA took into account, among other factors, the large number of data subjects involved, the sensitive nature of the data, as well as mitigating factors including the suspension of data transfers by general practitioners and IQVIA’s cooperation during the proceedings.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source