IQVIA Fined €7 Million in Italy for GDPR Breach on Coded Patient Data
Dposphere
Italian data protection authority has imposed a €7 million fine on IQVIA for violations of the General Data Protection Regulation (GDPR). The penalty follows an investigation into the company’s handling of coded patient records, which were found to be inadequately protected and improperly processed.
IQVIA’s breach involved the use of anonymised data that could still be re‑identified, contravening GDPR principles on data minimisation and security. The fine underscores the importance of robust safeguards when dealing with health information and signals regulators’ willingness to enforce compliance in the life‑sciences sector.
Dposphere
Recent Post
DTU data breach triggers investigations by Denmark’s Datatilsynet and Norway’s NSK, focusing on GDPR compliance and
GDPR now applies to Catholic baptism registers, requiring churches to safeguard personal data and comply with
CNIL and Cybermalveillance.gouv.fr unveil a new guide to help people react to personal data breaches during
