CNIL decision of 26 May 2026 – SAN-2026-008 (IQVIA Operations France)
Anyone consolidating health data at scale cannot fall back on the argument that the result is “anonymous” and therefore outside the scope of the GDPR. That calculation did not work out for IQVIA’s French entity: the CNIL imposed a fine of EUR 5 million.

The facts in brief
IQVIA produces studies for the pharmaceutical industry and operated two health data warehouses for this purpose, both previously authorised by the supervisory authority. They were fed from roughly 14,000 pharmacies and from several thousand physicians. The inspection revealed that data subjects were not properly informed, that data subject rights were ineffective in practice, and that the technical safeguards fell short of what was required.
The company’s line of defence: the datasets were anonymous, so data protection law did not apply in the first place.
Why the authority saw it differently
In the CNIL’s assessment the datasets were not anonymous but pseudonymised, because tracing them back to individuals remained possible with reasonable effort. Three considerations carried that finding:
- A persistent identifier per patient, tying every data point of an individual together.
- The level of detail held – including year of birth, sex, treating general practitioner, prescriptions, diagnoses, symptoms, allergies, body measurements, vital signs, vaccination status, examinations performed and periods of sick leave.
- The ability to combine the data with publicly accessible sources. How low that threshold actually sits was demonstrated in the proceedings: through a patient support group on a social network, a study participant was matched within minutes.
Two further points matter particularly for day-to-day practice:
- Contractual re-identification bans are not enough. Prohibiting partners from re-identifying by agreement does not change the objective possibility. A statutory prohibition may be assessed differently – a contract clause is no substitute.
- Intention is irrelevant. The fact that nobody in the organisation wanted to re-identify anyone was expressly treated as immaterial. What counts is whether it could be done.
How this sits alongside the CJEU’s SRB judgment
The company was able to invoke a line of authority that is genuinely favourable to data recipients: on 4 September 2025 (C-413/23 P, SRB), the CJEU confirmed a relative standard. The same pseudonymised dataset may constitute personal data in the hands of the party holding the key while being anonymous for a third party with no means of attribution.
The CNIL draws the line where the role changes: IQVIA was not a recipient at the end of a chain but controller of the entire processing operation from the point of collection onwards – and the party creating the linkage in the first place. The relativity established in SRB relieves the third party without the key. It does not relieve the party that designs the warehouse, populates it and controls the linking logic.
The additional findings
Beyond the anonymity question, the authority criticised concrete implementation gaps: access logs were not reviewed systematically, multi-factor authentication was absent, patient information was inaccurate, and no functioning objection procedure was in place. On top of that, some pharmacies failed to inform their own customers correctly about the transfer, and the pharmacy software transmitted patient data without consent – a textbook privacy-by-design failure already built into the product architecture.
In setting the amount, the sensitivity of the category, the volume (several tens of millions of data subjects), the market position and the financial strength of the company were treated as aggravating. The pseudonymisation actually carried out was recognised as mitigating, since it did rule out direct identification.
Dos
- Derive anonymity demonstrably rather than asserting it. Document, for each dataset, which attack scenarios (singling out, linkability, inference) you tested and how you excluded them.
- Differentiate by constellation. What may be anonymous vis-à-vis an external recipient remains personal data internally. Determine the status separately for each recipient role.
- Attack the identifier, don’t just mask it. Consider aggregation, k-anonymity, noise, generalisation of date fields, and breaking up longitudinal records.
- Actively limit data depth. Every additional attribute – a vital sign, a prescription, the treating clinician – shrinks the comparison group. Fewer attributes is the legally more robust design here as well.
- Get the basics working: intelligible patient information, a functioning objection route, systematic review of access logs, MFA on privileged accounts.
- Think upstream. Where clinics, practices or pharmacies collect on your behalf, their information and legal basis chain is your risk – down to the configuration of the software they use.
- Keep authorisations current. A regulatory approval protects you only to the extent that actual practice matches it.
Don’ts
- Don’t rely on SRB if you are the one performing the consolidation. The relative standard helps the third party without means of attribution – not the operator of the dataset.
- Don’t treat contractual clauses as an anonymity argument. A re-identification ban is a sensible addition, but no substitute for technical effectiveness.
- Don’t argue absence of intent. What is assessed is the possibility, not the motive.
- Don’t use “pseudonymised” and “anonymous” interchangeably – not internally, and not in records of processing, privacy notices or customer-facing statements.
- Don’t ignore publicly available sources. Social networks, patient forums and public registers belong in the risk assessment.
- Don’t treat AI training data as a special case. The same standard applies to real-world evidence products, registry analyses and model training.
What this means for MedTech specifically: this affects anyone maintaining post-market surveillance data, device telemetry, registry data or RWE datasets with stable identifiers over time. The combination of a persistent identifier and an expanding set of attributes is precisely the pattern the CNIL held to be incapable of anonymisation here.
CNIL decisions are open to judicial review, so the case is not necessarily settled. For practical purposes, that changes little about the analytical framework applied.




