CNIL Fines IQVIA €5 Million Over Health Data Compliance Failures

  • Author: Arno Schlösser, DP-Dock GmbH
  • Last updated: July 2026
  • Category: Enforcement, Data Security

France's data protection authority (CNIL) has imposed a €5 million fine on IQVIA OPERATIONS FRANCE after finding multiple GDPR and French Data Protection Act violations relating to two large health data warehouses containing information from tens of millions of patients.

The investigation found several compliance shortcomings, including failures to properly inform patients that their pharmacy data was being shared with IQVIA, inadequate processes for individuals to exercise their right to object, and failure to adhere to conditions set out in the authorization to establish the warehouses, by the CNIL. This also included that several security requirements weren’t met, like the lack of measures to effectively detect abnormal activities. The supervisory authority also noted that, as the data controller, IQVIA was responsible for ensuring that data subjects were informed about the transfer of their data to IQVIA. However, none of the pharmacies informed their customers of this transfer. Further, the pharmacies software continued to transmit data even where individuals had objected.

The possibly most prominent aspect of the decision is the CNIL's position on anonymization, as it renders the data protection rules applicable, allowing the foregoing arguments to follow.
IQVIA argued that its datasets were anonymous. The CNIL disagreed, finding that the combination of detailed demographic and health information, unique patient identifiers, and the possibility of linking the data with other publicly available information meant that individuals could still be re-identified using reasonable means. As a result, the data was deemed pseudonymized and therefore remained personal data, making data protection laws applicable.

In addition to the financial penalty, the CNIL has ordered IQVIA to remedy several outstanding compliance issues within six months, with daily penalties of €10,000 for any delay.

This decision reinforces several important principles of data protection law. From a GDPR perspective, a number of requirements must be met before data can be considered truly anonymized. Without a careful assessment of all technical and organizational measures and the likelihood of re-identification, data described as "anonymized" may in fact only be pseudonymized. In that case, it remains personal data and continues to be subject to the GDPR. Further, the decision also emphasizes that controllers remain responsible for ensuring that data subjects are provided with the required information, even where personal data is collected on their behalf by third parties, and TOMs must operate effectively in practice, not just on paper.

We are happy to provide guidance on all these GDPR aspects under our external Data Protection Officer role, to assist staying compliant with data protection rules.

Patient data security concept with healthcare privacy protection secure medical records cybersecurity compliance encrypted health information access control and digital healthcare security management
© Toowongsa / stock.adobe.com | #2038712997

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed