A Patient Code Did Not Make IQVIA’s Health Database Anonymous
Italy’s privacy regulator focused on linkability, detailed records and the controller’s real role.
On 23 September, the Italian Garante ordered a €7 million fine against IQVIA Solutions Italy. It found that a stable patient code, combined with detailed health and location records, did not make the database anonymous. The project covered about one million patients of 800 GPs.
IQVIA argued that the data was anonymous and its role narrower. The regulator rejected those positions and treated the company as controller from collection. A separate free-text issue included direct identifiers for about 3,370 patients, around 3,080 with health information. That is not evidence that all one million records were directly exposed or that an external attacker was involved.
Before relying on anonymity, test the actual attributes, linkability, extraction path, controller role, lawful basis and DPIA evidence. This is an editorial inference from the case, not a new universal checklist. The 120-day compliance clock begins on notification, whose date is unknown. The fine was imposed; payment and judicial finality are unverified.
For wider context, read our European Health Data Space guide.
Source: Italian Garante order No. 710, decided 23 September 2026; announcement, dated 2 October 2026.


