REGULATORY WATCH BRIEF High 72 ⚖️ Dpa Action decided

Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data

The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.

ImpactHigh 72
Type⚖️ Dpa Action
Statusdecided case outcome
JurisdictionEU-IT
Effective23 September 2026

What happened

The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention measures. The decision, dated 23 September 2026, requires IQVIA to achieve GDPR compliance within 120 days or have anonymisation carried out by the general practitioners.

Penalty

EUR 7 000 000

Why it matters for trust and compliance

  • Its status is decided. The case has an outcome that others may cite.
  • The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.
  • Takes effect September 23, 2026.
  • Penalty: EUR 7 000 000.
  • It relates to GDPR. The regulations library explains what that law requires.

Who is affected

healthcare technology controller processor IQVIA Solutions Italy S.r.l.

Recommended actions

  1. Check that privacy notices describe the practices this addresses.
  2. Revisit retention schedules and data minimisation for the data involved.
  3. Map the security requirements to existing controls and close gaps.
  4. Schedule or refresh the risk or impact assessments this calls for.
  5. Confirm handling of sensitive data categories meets the stricter rules.