CNIL Fines IQVIA €5 Million Over Health Data Compliance Failures
- Author: Arno Schlösser, DP-Dock GmbH
- Last updated: July 2026
- Category: Enforcement, Data Security
France's data protection authority (CNIL) has imposed a €5 million fine on IQVIA OPERATIONS FRANCE after finding multiple GDPR and French Data Protection Act violations relating to two large health data warehouses containing information from tens of millions of patients.
The investigation found several compliance shortcomings, including failures to properly inform patients that their pharmacy data was being shared with IQVIA, inadequate processes for individuals to exercise their right to object, and failure to adhere to conditions set out in the authorization to establish the warehouses, by the CNIL. This also included that several security requirements weren’t met, like the lack of measures to effectively detect abnormal activities. The supervisory authority also noted that, as the data controller, IQVIA was responsible for ensuring that data subjects were informed about the transfer of their data to IQVIA. However, none of the pharmacies informed their customers of this transfer. Further, the pharmacies software continued to transmit data even where individuals had objected.
The possibly most prominent aspect of the decision is the CNIL's position on anonymization, as it renders the data protection rules applicable, allowing the foregoing arguments to follow.
IQVIA argued that its datasets were anonymous. The CNIL disagreed, finding that the combination of detailed demographic and health information, unique patient identifiers, and the possibility of linking the data with other publicly available information meant that individuals could still be re-identified using reasonable means. As a result, the data was deemed pseudonymized and therefore remained personal data, making data protection laws applicable.
In addition to the financial penalty, the CNIL has ordered IQVIA to remedy several outstanding compliance issues within six months, with daily penalties of €10,000 for any delay.
This decision reinforces several important principles of data protection law. From a GDPR perspective, a number of requirements must be met before data can be considered truly anonymized. Without a careful assessment of all technical and organizational measures and the likelihood of re-identification, data described as "anonymized" may in fact only be pseudonymized. In that case, it remains personal data and continues to be subject to the GDPR. Further, the decision also emphasizes that controllers remain responsible for ensuring that data subjects are provided with the required information, even where personal data is collected on their behalf by third parties, and TOMs must operate effectively in practice, not just on paper.
We are happy to provide guidance on all these GDPR aspects under our external Data Protection Officer role, to assist staying compliant with data protection rules.