Removing names and tax IDs from a dataset does not make it anonymous. Italy's data protection authority has just fined a company €7 million for treating it as if it did. The Garante per la protezione dei dati personali says IQVIA Solutions Italy built a database from the records of about one million patients of 800 family doctors, described it as anonymous, and used it for studies commissioned by pharmaceutical companies. The authority disagrees on the central point: the data, it says, was pseudonymous at best.
This is a privacy ruling, not a hacking story, but it has a direct lesson for anyone who sends datasets, extracts or exports to another party: the thing that makes the data usable is also the thing that makes it identifiable.
What the Garante decided
According to the authority's decision no. 710 of 23 September 2026, announced on 2 October, the data could not be considered anonymous. Each patient carried a code that let their information be followed over time, and that code sat alongside detailed health data: year of birth, sex, diagnoses, symptoms, prescriptions, examinations, vaccinations and location information. The Garante concluded that this made it possible to single out individual patients and, with reasonable means, to re-identify them.
The test it applied is the practical one in EU data protection law: whether a person can be identified by reasonable means, not whether anyone has actually done it. Italian legal press reporting on the decision adds that a stable identifier tied to one doctor's practice let the same patient appear across many visits, and that combinations of ordinary attributes can be distinctive enough to isolate someone, especially with rare diagnoses or unusual prescription histories.
The authority found that IQVIA could not rely on anonymisation to take the data outside the GDPR. Reporting on the decision lists further problems, including the lack of a lawful basis for the health data, incomplete information to patients, a missing or incomplete data protection impact assessment and undefined retention. The sources differ on the exact list, so check the decision itself for the formal findings. The Garante gave the company 120 days to comply, including by putting a lawful basis in place, informing patients and anonymising the data to the authority's standards. One report describes a threshold of at least ten people per combination of identifying attributes.
The investigation began with inspections in April 2025 and, per the reporting, took in a data breach notification IQVIA had made itself. IQVIA has not, in the material we read, explained its position at length; one report says it reserves the right to appeal.
What is not established
- Any actual re-identification or misuse. The decision turns on whether identification was reasonably possible, not on someone having done it. No source we reviewed says patients were harmed.
- The final outcome. The decision can be appealed, and we have not read the full text, only the authority's announcement and press and legal coverage of it.
- The other details. Some figures, such as how many patients carried directly identifying data, come from a single legal commentary and we have left them out.
The lesson for people who share data
Most organisations are not building pharma research databases. But many send exports to an analyst, an agency, a vendor or a researcher, and the same mistake travels easily: remove the obvious fields, call it anonymous, and send the rest.
- A code that persists is a key. If the same identifier follows a person across rows, anyone holding another dataset that shares the attribute can join them. Treat any linking key, and any table that maps codes back to people, as a secret in its own right.
- Several harmless fields can add up to a fingerprint. Birth year, sex, location and a rare diagnosis may each look benign. Count how many people share each combination before you share it.
- Send less. The safest field is the one that was never exported. Ask what the recipient needs to do their job and cut everything else.
- Decide how long it lives. The Garante cited retention. An extract sitting in a shared folder or an inbox for years is exposure with no purpose.
- Know who the controller is. The authority treated IQVIA as responsible from collection onward. Handing data to a processor does not remove your own obligations.
What to do
- List the datasets you send outside the organisation and mark which ones you describe as anonymous. For each, write down how a motivated third party could single out a person.
- Separate the linking key from the data. Keep the mapping between codes and people in a different system with different access, and give it an owner.
- Apply a minimum group size. Remove or generalise fields until no combination identifies fewer people than a threshold you can defend.
- Document the lawful basis, the patient or customer information and the impact assessment before the data leaves, not after a complaint.
- Set retention and delete on schedule, for both the dataset and the copies recipients hold.
- Move the access path out of email. Share extracts through a controlled location with expiry, and send passwords, decryption keys and linking-table credentials separately, not in the same message as the file.
Where Secretus fits, and where it does not
Secretus helps with the narrow secret around the dataset: the password to an encrypted archive, a decryption key, the credential for the mapping table. The sender encrypts it in the browser and shares a link that stops working after the expiry they chose or the first successful open, so the value is not left in an email thread beside the file.
It is not an anonymisation tool, a data protection impact assessment or a legal opinion. It cannot tell you whether a dataset is anonymous, remove identifying fields, enforce retention on a recipient's copy or make a transfer lawful. Those need your privacy and legal team and the decision text itself. Use a one-time link for the moments where a person hands another a key.
Sources
- Diritto Mercato Tecnologia: non-anonymous health data, the Garante fines IQVIA €7 million (decision no. 710 of 23 September 2026)
- Il Sole 24 Ore (Radiocor): Garante privacy, health data, IQVIA fined €7 million, 2 October 2026
- Sbircia la Notizia: why the Garante considers the data of more than one million patients identifiable, 3 October 2026
