Italy Italy Garante GDPR AI enforcement

Italy's €7 Million IQVIA Fine Shows 'Anonymised' Health Data Needs Proof, Not a Label

The Garante held that a persistent patient code made a million-patient health database re-identifiable, a warning for anyone training AI on 'anonymised' records.

Garante v. IQVIA Solutions Italy People of Internet Research · Italy €7M Fine imposed Decision no. 710 of 23 September 2… ~1M Patients in database Drawn from about 800 general pract… 2001 Oldest records retained No retention periods had been defi… 120 Days to comply Window to align practices if proce… peopleofinternet.com
Garante v. IQVIA Solutions Italy People of Internet Research · Italy €7M Fine imposed ~1M Patients in database 2001 Oldest records retained 120 Days to comply peopleofinternet.com

Key Takeaways

On 2 October 2026 Italy's data protection authority, the Garante, announced a €7 million fine on IQVIA Solutions Italy S.r.l. under decision no. 710 of 23 September 2026. The company had assembled a database of health records covering about one million patients of roughly 800 general practitioners, and used it for studies commissioned in part by pharmaceutical companies. The company's position was that the data was anonymised. The regulator disagreed.

What the Garante found

The core finding concerns one design choice. Each patient carried a code that let the same person be followed over time. Combined with detailed fields (year of birth, sex, diagnoses, prescriptions, tests, vaccinations, location), the Garante concluded that individuals could be singled out and re-identified by reasonable means, according to Sky TG24's report of the announcement. Once the data was personal data, the other failures followed. The Garante cited no adequate legal basis, inadequate patient information, no retention limits (records went back to 2001), no data protection impact assessment, and insufficient security.

Il Sole 24 Ore adds that names, tax codes, addresses and contact details were reportedly held for over 3,300 patients, more than 3,000 of whom were linked to health data. IQVIA says it uses pseudonymisation and encryption, that the dataset is not used in its clinical research services, and that it reserves the right to appeal. The investigation grew out of inspections in April 2025. Per BleepingComputer, IQVIA has 120 days to bring its practices into compliance.

The strongest case for the regulator

The regulator's case deserves a fair statement. Health records are among the most sensitive data people have. A longitudinal record with diagnoses, prescriptions and locations is close to a fingerprint, and the patients never knew their GP data fed commercial studies. If a company can call such a dataset 'anonymous' simply by removing names, the GDPR's strictest protections would depend on a label the company chooses. The GDPR's own test is functional. Recital 26 asks whether identification is possible by 'all the means reasonably likely to be used', judged on objective factors such as cost and time. A persistent code that links a person's records across two decades fails that test almost by construction.

Why this is an AI story

The case is not formally about AI. But health-data training sets for diagnostic models, drug-safety tools and clinical language models rely on the same premise: that the records have been de-identified enough to fall outside the GDPR. The Garante has shown that a longitudinal patient identifier undermines that premise, whatever the downstream use.

The EU's wider framework points the same way. The European Data Protection Board's Opinion 28/2024, issued in December 2024 at the request of the Irish authority, deals with anonymity of AI models and legitimate interest as a basis for training. Its approach is case by case, not categorical. The Court of Justice has also taken a contextual line on pseudonymised data. Its press release on EDPS v SRB (C-413/23 P) addresses when pseudonymised data transferred to third parties counts as personal data. Neither is a blanket rule, and the IQVIA decision is consistent with both. Whether data is anonymous depends on who holds it and what they can do with it.

Where proportionality matters

Our view is that the finding on anonymisation is sound, but the lesson should not become 'all medical data research is suspect'. Three points follow.

What builders should do now

Teams training models on health data should treat 'anonymised' as a claim to be tested. That means an adversarial re-identification assessment, and not relying on the absence of names. It also means a written DPIA, a retention schedule, and a legal basis that a regulator can read. The data is more valuable when it is defensible.

A fine of this size also tells investors and hospitals that provenance is now a diligence item. A model trained on a dataset a regulator later deems personal inherits the legal problem. The sensible response is better data governance up front, not less medical AI. The IQVIA decision is a costly but clear data point for how to do it.

Sources & Citations

  1. EDPB Opinion 28/2024 on AI models
  2. CJEU press release, EDPS v SRB (C-413/23 P)
  3. GDPR Recital 26
  4. Sky TG24 on the Garante fine
  5. Il Sole 24 Ore on IQVIA fine
  6. BleepingComputer on IQVIA fine