Skip to content

CNIL Fines IQVIA €5 Million Over Health Data Warehouse Compliance Failures

June 27, 20262 minute read

€5 million. Tens of millions of patient records. And a compliance argument that failed at first contact with a regulator.

France’s CNIL fined IQVIA Operations France for breaches in two health data warehouses — one fed by 14,000 pharmacies, one by thousands of doctors.

IQVIA’s defence: the data is anonymous. We cited a 2025 CJEU ruling.

CNIL’s finding: the data is pseudonymous. IQVIA itself holds the key that links records back to individuals. That means the data is still personal data — and every GDPR obligation applies.

The CNIL also found failures on patient information, consent documentation, and security safeguards. And issued a six-month compliance order — with a €10,000 per day penalty if the breaches aren’t remediated on time.

The details that matter:
→ “Anonymous” is a legal conclusion — not a technical classification. If you hold the key, it’s pseudonymous.
→ CNIL authorised these warehouses. That authorisation covered the original setup — not ongoing compliance. Approval is not a permanent pass.
→ 102 operators share the same warehouse architecture. This decision lands on all of them — not just IQVIA.
→ Health data triggers the highest scrutiny under GDPR. The same logic applies to biometric, genetic, and financial data.

The compliance failure wasn’t in the technical design. It was in the assumption that “we were authorised” meant “we’re compliant.”

At S8fe.ai, we help organisations maintain the ongoing compliance posture that authorisation requires — not just the point-in-time assessment that gets you through the door.

Sources:
• https://www.cnil.fr/en/health-data-fine-5-million-euros-against-iqvia
• https://ppc.land/cnil-fines-iqvia-eur5m-for-health-data-warehouse-breaches/
• https://acompli.ie/news/cnil-iqvia-health-data-fine-2026/

Share this article

Back To Top