Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data
Italy's data protection authority fined IQVIA Solutions Italy €7 million following a finding that the company processed patients' health data without a lawful basis. The decision cited violations across multiple GDPR provisions, including rules on sensitive data, transparency, data protection by design, and impact assessments.
Why this matters: Health data is the most sensitive category GDPR recognizes, and IQVIA is in the business of collecting and analyzing it at scale across the pharmaceutical and life sciences sector. Patients whose records fed into that system likely had no idea their data was being used, or how. The breadth of violations here — missing impact assessments, flawed processor relationships, no proper transparency — suggests this was not one bad decision. It was a process built without patients in mind. A seven-million-euro fine is the consequence. Loss of control over your own medical history is the actual harm.
Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · AI governance · General readers · Policy
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.