Italy’s Data Protection Authority (GPDP) fined IQVIA €7 million for data-processing practices that allegedly exposed and could have enabled the re-identification of roughly one million patients. The agency said IQVIA also processed health data without a proper legal basis, failed to inform patients, and kept records dating back to 2001 without adequate retention controls. #IQVIA #GPDP #GDPR
Keypoints
- GPDP fined IQVIA €7 million over healthcare data-processing violations.
- Roughly one million patients were affected by the disputed database.
- The agency said anonymized codes could still be used to reidentify patients.
- IQVIA allegedly processed data without a legal basis and without notifying patients.
- Italian authorities ordered IQVIA to comply with the ruling within 120 days.