P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Italy fines IQVIA €7 million after finding its 'anonymous' database of one million patients was not

Italy's data protection authority fined IQVIA €7 million on 23 September, finding that a database it called anonymous gave each of about one million patients a persistent code. The fine can be appealed and the finding concerns one dataset; UK lessons lie in the code, the clock and the controller.

By Parminder Kumar Sharma · · 23 min read

A general practitioner's consulting-room desk at night: an open laptop shows a patient-records table drawn as rows of blank pills, with a plain stethoscope coiled beside it and an examination couch dim in the background.

€7.00 a head, and one patient 34 times

Italy's data protection authority, the Garante, has fined IQVIA Solutions Italy S.r.l. €7,000,000 over a health database of about one million patients of about 800 family doctors. Divide one figure by the other and the fine is €7.00 a head. That is our arithmetic on the Garante's rounded numbers: it fined the company once, for a set of infringements, and apportioned nothing to patients. The sharper number is in the provision itself. At the April 2025 inspections IQVIA showed the inspectors a single patient who appeared 34 times in the prescriptions table of its database, so that the clinical history could be traced. The Garante's finding rests on that feature: a code that follows each patient through the record.

What that does not establish. The fine is not final. The provision allows 30 days from its communication to challenge it before the ordinary court, and IQVIA says it reserves the right to. The finding that the data was not anonymous is a regulator's assessment of this dataset, with IQVIA treated as controller from the point of collection. It is not a rule that every pseudonymised dataset is personal data, and the Garante itself accepts that the same data can be personal for one holder and anonymous for another. The published text reports no re-identification of a real person, and records that no complaints or reports from patients arrived. The personal data breach that opened the case is described only in outline, with its dates blanked.

How we read it. We read the Garante's press release of 2 October 2026 and the provision itself, no. 710 of 23 September 2026, in the original Italian and translated both ourselves. The published provision blanks the inspection dates, the breach period, the year of the oldest record, the turnover figure and the names of other companies. A DataBreaches.net post of 3 October pointed us to both. The EDPB draft guidance, the Court of Justice judgment, the ICO guidance and the UK legislation were read at source. IQVIA's response reaches us through Italian press reports and is labelled secondary.

What the Garante stated, and what it did not

The table sets the provision and the press release against the questions a reader will ask. Paragraph numbers are the provision's.

What the Garante's provision no. 710 and press release state, and what they do not. Read in Italian on 5 October 2026; paragraph numbers are the provision's.

  1. Question
    The fine
    Stated
    €7,000,000 on IQVIA Solutions Italy S.r.l. Provision of 23 September 2026, press release of 2 October.
    Not stated
    Whether it has been paid, settled at half price or challenged in court.
  2. Question
    Was the data anonymous
    Stated
    No. A code per patient allowed tracking over time. With birth year, sex, diagnosis, symptoms, prescriptions, tests, vaccinations and location it allowed patients to be isolated and, with reasonable means, re-identified (paras 100, 101).
    Not stated
    Any re-identification of a real person, or a measured rate of unique records. The Garante reasons from the structure of the data.
  3. Question
    Who is responsible
    Stated
    IQVIA is controller from collection, including for the anonymisation step run on the doctors' systems (paras 81, 99).
    Not stated
    Fault by the doctors or their society. The Garante says their reliance on the tool was legitimate (para 67).
  4. Question
    Retention
    Stated
    No retention periods set. The press release says the data went back to 2001.
    Not stated
    The oldest year in the provision (blanked), or whether old records have been deleted.
  5. Question
    Impact assessment and security
    Stated
    No impact assessment completed. No checks that would have found free-text fields (paras 134, 140).
    Not stated
    That files were sent unencrypted. Some headlines say so; the provision does not. IQVIA says it received encrypted files.
  6. Question
    The breach
    Stated
    Free-text fields carried direct identifiers of 3,370 patients, 3,080 with health data (paras 22, 23).
    Not stated
    The dates, the period, how many doctors were involved, and any onward disclosure beyond the doctors' society.
  7. Question
    Deadlines
    Stated
    120 days from notification to comply or hand anonymisation to the doctors. 30 days to pay. 30 days to appeal.
    Not stated
    The notification date. If it fell between 23 September and 2 October, the 120 days end between 21 and 30 January 2027.

The dataset as the Garante describes it

The database was called LPD inside IQVIA, for Longitudinal Patient Data. An add-on to the doctors' practice software extracted records and, IQVIA told the inspectors, removed names, surnames and addresses. Each patient received a Pat ID: a random 22-character code generated on the doctor's own system. IQVIA described it as random and not derived from anything about the patient. It changed if the patient moved to another doctor or the doctor replaced their computer, and otherwise it stayed the same, because, IQVIA said, the patient had to be followed longitudinally. The press release puts the Garante's conclusion in one sentence: the code allowed each patient to be followed over time.

Three columns. Left: about 800 GPs and about 1 million patients feed an extraction add-on that removes names and addresses, feeding IQVIA's LPD database. Centre: a record card with a random 22-character Pat ID that stays the same over time, plus 16 clinical and personal fields. Right: the Garante's findings that the code tracked patients, one patient appeared on 34 rows, and patients were re-identifiable with reasonable means. A band notes free-text identifiers for 3,370 patients.
Drawn only from the Garante's provision no. 710 of 23 September 2026 and its press release of 2 October 2026. Where the published text is blank, the diagram says so.

Paragraph 101 lists what each record held: year of birth, sex, marital status, number of children, socio-professional category, dates of visits, diagnoses, symptoms, allergies, weight, height, prescriptions, vaccines, tests and sick certificates, plus location data. IQVIA said birth dates were set to the first of the month and that only the patient's city and the doctor's province were kept.

Two technical points in the provision matter more than the headline. First, k-anonymity does not cover the whole record. The technique makes every combination of chosen attributes, such as age and place, shared by at least k people. The Garante notes that it acts only on those chosen attributes. Diagnoses, sequences of hospital admissions and drug patterns can still make a record unique, and an observer who could measure them independently could pick the person out (paras 95 to 97). Second, scrambling the code does not help. A code exists to keep one person's records together, so it preserves singularity by design (para 96).

IQVIA's own assessment scored the re-identification risk 3, which it called low (para 41). The Garante faulted generic assessments by a Canadian company in the IQVIA group, no measured rate of singling out and no check for free-text fields (paras 133, 134), though it counted the assessments in IQVIA's favour on the fine (para 156).

'Anonymous' was a clause in three contracts

The word did a great deal of work. The doctors' contract with IQVIA said the database guaranteed anonymity, with patients not identifiable by IQVIA or by third parties. The contract with the doctors' scientific society required IQVIA to make sure data were anonymised before they entered the database. The software supplier's contract required an anonymisation process before anything left a doctor's system. Doctors received their practice software free in return. IQVIA's position throughout was that it received only anonymous data, so it owed patients no legal basis and no notice (paras 11, 12, 29, 46, 65). The Garante's answer on the product is plain: it was presented as an anonymisation tool and could not do that job, though the doctors and their society were entitled to rely on it (para 67).

Four labels from the record, and what the Garante found. Provision no. 710, read in Italian.

  1. The label
    Patients are not identifiable by IQVIA or by third parties (the contract with doctors)
    What the Garante found
    A persistent code, rich clinical detail and location data left patients open to singling out and, with reasonable means, re-identification.
    Where
    Paras 12, 100, 101
  2. The label
    The add-on anonymises data before they leave the doctor's system
    What the Garante found
    Free-text fields passed through. Direct identifiers of 3,370 patients reached IQVIA.
    Where
    Paras 22, 23, 124
  3. The label
    The data are anonymous, so no consent, notice or legal basis is needed
    What the Garante found
    Health data processed without a legal basis. Patients were not adequately informed.
    Where
    Paras 105 to 112
  4. The label
    The re-identification risk is low, scored 3
    What the Garante found
    Generic assessments, no measured rate of unique records, no check for free text.
    Where
    Paras 41, 133, 134

The label is a switch. The Garante found infringements of ten provisions of the GDPR, across seven articles: lawfulness (5(1)(a) and 9), transparency (13), storage limitation (5(1)(e)), security (5(1)(f) and 32), processors (28), accountability and design (5(2) and 25) and impact assessment (35). IQVIA's defence ran through all of them by one route. If the data are anonymous the regulation does not apply, so there is no legal basis to find, no retention period to set and no impact assessment to complete (paras 29, 34, 35). Win the status argument and the rest falls away. Lose it and every duty arrives at once.

A fairness point. IQVIA's statement of 2 October lists "the use of pseudonymisation and encryption" (our translation) among its safeguards and says the Garante recognised the database's scientific value. The provision does weigh the database's role as a reference resource for health information against the size of the fine (para 157). We do not read IQVIA's wording as a concession on status. Under the GDPR and the UK GDPR alike, pseudonymised data is personal data.

The defence that failed, and what it leaves standing

IQVIA's main legal defence was the Court of Justice judgment of 4 September 2025, EDPS v SRB (C-413/23 P). The Court held that pseudonymised data need not be treated as personal data "in all cases and for every person". For a recipient the measures can mean the data is not personal, but only if the recipient cannot lift them during any processing under its control and the measures in fact stop it attributing the data to a person, including by cross-checking with other information (judgment, paras 77 and 86). IQVIA argued that it could not reach the doctors' computers or the key, so the data was anonymous in its hands (paras 28, 40).

The Garante did not reject that reasoning. It said the Court was continuing earlier law and that the test is case by case. It then found that IQVIA was not a mere recipient. IQVIA was controller of the whole processing from collection, played an active part in setting the anonymisation measures through its contracts, and so could not treat the data as objectively anonymous (paras 91 to 99). Ability is enough, it added: what matters is that IQVIA could re-identify with reasonable means, not whether it meant to (para 100).

The EDPB's draft Guidelines 02/2026 on anonymisation, adopted on 7 July 2026 for consultation, take the same two steps. Anonymity is relative, assessed from each relevant entity's perspective. But in the draft's worked example on SRB, the personal nature of the data is judged from the controller's perspective at the time of collection, because that is when the duty to inform arises. The draft also tells controllers to avoid labels such as "de-identified" for data that still identifies people (paras 14, 40). The 2014 Article 29 Working Party opinion (WP216), which the Garante also relies on, remains the adopted text until the EDPB finalises its update.

A second regulator reached a similar view four months earlier. On 26 May 2026 France's CNIL fined IQVIA Operations France €5 million, on several grounds, over two health data warehouses fed by about 14,000 pharmacies and several thousand doctors. IQVIA argued, citing SRB, that the data was anonymous. The CNIL found it only pseudonymous, because of a unique identifier for each patient, the depth of the data and the possibility of combining it with public data. The datasets and the other breaches differ. The shared point is the anonymity argument, and the Garante cites the CNIL decision (paras 100, 133).

An earlier case in the same sector. In June 2023 the Garante fined THIN S.r.l. €15,000 over a similar arrangement, an add-on meant to anonymise records before they reached the company, whose collection THIN said had not gone beyond a preliminary stage. The IQVIA provision cites a Milan court judgment of 10 May 2024 in the THIN case (para 90) and says IQVIA did not re-examine its position after earlier administrative and court decisions, in Italy and in Europe (paras 133, 134). The fines differ by a factor of about 467 (derived), and so do the datasets.

Twenty-five years, a ten-year statement and no deletion clock

The press release says the data went back to 2001 and that no retention periods had been set. Our arithmetic, labelled derived because the provision blanks the year and the press release gives no month: 22 years from 2001 to 2023, when doctors stopped sending data, 24 years to the April 2025 inspections and 25 years to the provision. By IQVIA's own account, studies generally did not use data older than ten years. Ten years before April 2025 is April 2015, so about 14 of those 24 years sat outside the window IQVIA described.

A to-scale timeline from 2001 to early 2027. A bar runs from 2001 to the April 2025 inspections, split at ten years before the inspections. Dimension lines show 22 years to 2023, 24 years to the inspections and 25 years to the provision. Markers show doctors stopping in 2023, the inspections, the provision of 23 September 2026 with the press release nine days later, and a 120 day deadline falling between 21 and 30 January 2027.
Drawn from the Garante's press release (2001, 2023) and provision no. 710 (April 2025 inspections, 23 September 2026, 120 days from notification, IQVIA's statement on ten years). Year counts are our arithmetic.

IQVIA told the inspectors it knew of no deletion policy and of no earlier assessment of whether to delete old records. The retention policy it later sent covered business documents such as faxes, memoranda and microfiche, post-dated the inspections, and the Garante called it irrelevant (paras 6, 17, 18, 115). After the inspections IQVIA said it would delete the data from the main database, keeping an archive copy only for the proceedings, and in its defence said it had set ten years (paras 19, 34). The Garante recorded the company's own statement that research needs no more than ten years of longitudinal data (para 116).

Stopping the feed is not deletion. The doctors stopped sending data, and at the inspections IQVIA said the database was no longer being fed but was still used, though less than before (para 4). A closed tap does not empty the tank. The same pattern runs through our briefing on a provider that still held customer records up to 33 months after the flow stopped and through the Danish university that deletes former users' addresses after six months but keeps national ID numbers for about 160,000 of them. Article 5(1)(e) bites only on data kept in a form that permits identification, so the status argument and the retention argument are one argument.

The breach that opened the case, in outline

The press release says the inspections took in a personal data breach that IQVIA itself notified. The provision gives IQVIA's account. The company said it had found, unexpectedly, that the database held personal information in free-text fields: doctors had typed details about patients, and a limited number of doctors, into notes that the add-on was supposed to strip. That process was not applied, so the text travelled in the extract. The provision lists the direct identifiers as names, dates of birth, tax codes, postal addresses, email addresses and phone numbers, for 3,370 patients, with health data for 3,080 of them. IQVIA received the files each weekday, for a period the published text blanks, and passed them to the doctors' society, which at IQVIA's request removed the identifiers and confirmed it had (paras 22, 23).

The Garante did not treat this as the doctors' error. A doctor entering notes in a care system is doing the job. Responsibility lay with IQVIA, which commissioned the add-on without checking that it would leave free-text fields behind and ran no automated checks that would have found them in its own database (paras 80, 132, 134). In proportion the numbers are small: 3,370 is 0.34 per cent of one million patients, and 3,080 is 0.31 per cent (derived, on the rounded total). The breach still touched health data for 3,080 people. The published text does not give the period, the number of doctors or any onward disclosure beyond the society. The ICO's draft research guidance makes the same point about unstructured material. Text, speech and images may still allow identification once the obvious identifiers are gone.

What the Garante ordered, and what the fine weighed

The press release says IQVIA has 120 days to adapt its processing if it wants to continue, or the doctors must do the anonymisation. The provision is more specific. If IQVIA continues it must find a legal basis for processing the patients' data, including any anonymisation, give patients the Article 13 information, complete an impact assessment and appoint the doctors as processors (para 144). The alternative, with the doctors anonymising under their own legal basis and notices, comes with a recipe (paras 145 to 149):

  • The doctors, not IQVIA, choose the attributes to pseudonymise and use a coding mechanism with a documented random element, so the code is meaningless to IQVIA and cannot be reversed by reasonable means.
  • Attributes treated as quasi-identifiers are generalised so that every equivalence class has at least 10 members.
  • Every other variable IQVIA could observe or measure that might help identify someone must join the quasi-identifiers, be processed in shares (for example by secure multiparty computation) so IQVIA never holds it in clear, or be removed.
  • If IQVIA passes the data on to third parties it takes on the doctors' obligations.

A class size of 10 is a condition of this fix, in this case, set by one regulator. It is not a general legal threshold for anonymity.

The money. The ceiling was not €20 million. The Garante treats IQVIA Solutions Italy and its US parent as one economic entity, and 4 per cent of the group's worldwide annual turnover exceeds €20 million, so that is the maximum (paras 153 to 155). The turnover figure is blanked. As an illustration only, using the $16,310 million revenue IQVIA reported for 2025 in its SEC filing of February 2026, 4 per cent is about $652 million, and €7 million is roughly 1.1 to 1.4 per cent of that at any euro-dollar rate from 1.0 to 1.3. That is our calculation, not the Garante's. It counted negligence against IQVIA, and in its favour the assessments, the suspension of transmissions, strengthened pseudonymisation, no earlier violations in Italy, no complaints from patients and cooperation (paras 156, 157). Our briefing on Sweden's fine on a data processor works the same per-head and ceiling arithmetic.

The clocks. Payment is due within 30 days of notification, unless the dispute is settled by paying half, €3.5 million, within the appeal period (para 162). That period is 30 days from communication of the provision. If communication fell between 23 September and 2 October, it closes between 23 October and 1 November 2026 (derived). The company must report to the Garante with documents within 120 days of notification, and failing to do so can bring a further fine (paras 150, 159).

The UK reading

The test is the same. The UK GDPR defines personal data and pseudonymisation in the same words as the EU text, and Recital 26 carries the same test of "means reasonably likely to be used", whether by the controller or by another person. The ICO's anonymisation guidance, published on 28 March 2025, says pseudonymised data remains personal data and warns that datasets are often called anonymised when they are only pseudonymised. It does not encourage "de-identified" as a synonym for either, because UK law does not define it. Its own example of data that may not be anonymisable is a health authority's dataset from medical records, where approximate dates, locations and treatment types may still allow re-identification.

The ICO makes the same two moves as the Garante. Its "whose hands" test lets the same data be personal in one organisation's hands and anonymous in another's. But the test applies only when disclosing to an organisation that is not a joint controller or processor: if data is personal in your hands, it is personal in a joint controller's whatever that party can do to identify anyone. Its draft guidance on anonymisation, pseudonymisation and research, out for consultation from 24 August to 19 October 2026, goes further on roles. An organisation with a tangible influence on purposes and means is a controller whatever the contract says, and one that uses a service provider to anonymise data for it remains a controller for that operation. That is close to the reasoning that decided the Italian case, though it is draft guidance with a final version due in winter 2026.

The Garante's decision is not UK law. It binds nobody here. The SRB judgment it leans on post-dates IP completion day, so UK courts are not bound by it and may have regard to it (European Union (Withdrawal) Act 2018, section 6). SRB concerned the EU institutions' own regulation (2018/1725), though the Garante and the EDPB read it across. Treat the Italian decision as a worked example of a test the UK shares.

What the Data (Use and Access) Act 2025 changed, and what it did not. From 5 February 2026 (S.I. 2026/82) the Act rewrote the research provisions. Scientific research now includes commercial research, but a public health study counts only where conducted in the public interest (new Article 4(2) and (3)). New Articles 84A to 84D require research safeguards that include data minimisation such as pseudonymisation. The duty to inform people can be disapplied for research where impossible or a disproportionate effort, but only with appropriate measures, including publishing the information (Articles 13 and 14 as amended). In the provisions we read, sections 67, 77 and 86 and the Act's contents list, we found no change to the definition of personal data or of pseudonymisation. The new safeguards apply to personal data, so they presuppose that the status question has been answered. The ICO flags its anonymisation guidance as under review because of the Act.

What IQVIA says about its UK data. IQVIA Ltd's privacy notice for IQVIA Medical Research Data says IQVIA is the controller. It describes "non-identified" GP records with year of birth, sex, symptoms, diagnoses with dates, prescriptions, immunisations and test results, and no names, addresses, NHS numbers or full dates of birth. It relies on legitimate interests and the research safeguards, and keeps data in line with Medical Research Council guidance of at least ten years after a study ends. A peer-reviewed profile of the database, published in February 2026 with authors from UCL and IQVIA, says each patient is assigned a unique ID within their practice, which links their records across data and over time, and that a family ID can link patients at one address. IQVIA's April 2024 fact sheet calls its UK Longitudinal Patient Data an "anonymised" dataset and says the product exists in nine countries, without naming them.

What nothing says. None of the sources we read says the Italian add-on, the Pat ID design or the free-text defect exist in any UK dataset. We found no assessment of IQVIA's UK datasets by the ICO or a UK court, and no ICO statement on the Italian decision. A stable per-patient code, long histories and dated clinical events, the features the Garante relied on, are features IQVIA itself describes in its UK research data. That does not predict a UK finding: the Italian case also turned on IQVIA's role, on location data, on a failed add-on and on an evidence record we have not seen for the UK. It does mean the question can be asked, and the answer sits in assessments that are not published.

What to check, in the order worth doing

For a UK data protection lead, whether the dataset is a patient register, a customer base or a research extract. The cheap, exposing steps come first.

Take this with you

In the order worth doing

  • List every dataset you hold or supply that is called anonymised, de-identified, non-identified or similar, and record who gave it that name and on what evidence.
  • For each, find the persistent keys: patient or customer codes, hashed identifiers, household or device identifiers. Ask whether the same key appears across tables or years. A key that follows a person is what the Garante counted.
  • Settle who is controller at the point of collection and at each later step, by who decides purposes and means rather than by the contract. If you are controller, the status of the data in your hands carries to joint controllers and processors.
  • Test identifiability on the whole record, not only the chosen quasi-identifiers. Diagnoses, medication sequences and event dates can single a person out after age and place are generalised. Ask for a measured rate of unique records and run a motivated intruder test from each recipient's position.
  • Search free-text fields, notes and attachments for names, numbers and contact details, before extraction and automatically afterwards.
  • Set a retention period for the dataset itself, not only for documents. Check the oldest record against the longest period the purpose needs, and confirm that stopping a feed was followed by deleting what it fed.
  • Complete the impact assessment before processing starts. Large-scale health data is named in Article 35(3)(b), and a draft in preparation is not an assessment.
  • Find the lawful basis and special category condition for the anonymisation step itself, and check what people are told. Under the ICO guidance anonymising is processing, and Article 84B now frames research processing.
  • Read supplier contracts for anonymisation warranties and ask whether you can verify them: who controls the extraction software, who tests it, who can see the key.
  • Diarise the consultations, ICO by 19 October 2026 and EDPB by 30 October 2026, and re-test when the final versions land.

What we could not verify

The question this leaves

A word in a contract told 800 doctors their patients could not be identified. A code in a table said otherwise. Which dataset do you call anonymous, what code in it follows a person from one year to the next, and who measured how many of its records are unique?

Key facts

Sources

  1. PrimaryPress release of 2 October 2026, doc web 10302141, read in Italian in full: the fine, the patient code, the 2001 date, the 3,300 identifying records, the 120 daysGarante per la protezione dei dati personaliaccessed 2026-10-05
  2. PrimaryProvision no. 710 of 23 September 2026, doc web 10302112, read in Italian in full (dates and company names blanked in the published text): facts, IQVIA's defences, reasoning, corrective measures, fine calculationGarante per la protezione dei dati personaliaccessed 2026-10-05
  3. PrimaryProvision no. 226 of 1 June 2023 on THIN S.r.l., read for the earlier GP-data anonymisation case, its EUR 15,000 fine and THIN's statements on its methodGarante per la protezione dei dati personaliaccessed 2026-10-05
  4. PrimaryGDPR text: Recital 26, Article 4(1) and (5), Article 5(1)(e), Article 9, Article 35, read in a browser because the page answers curl with an empty challengeEUR-Lexaccessed 2026-10-05
  5. PrimaryJudgment of 4 September 2025, EDPS v SRB, C-413/23 P: paragraphs 77, 86, 87 and 100 on pseudonymised data and the recipient's perspectiveCourt of Justice of the European Unionaccessed 2026-10-05
  6. PrimaryDraft Guidelines 02/2026 on Anonymisation, version 1.0 adopted 7 July 2026 for public consultation: relative anonymity, Example 2 on SRB, paragraphs 38 to 40European Data Protection Boardaccessed 2026-10-05
  7. PrimaryConsultation page for Guidelines 02/2026: feedback period 8 July to 30 October 2026European Data Protection Boardaccessed 2026-10-05
  8. PrimaryOpinion 05/2014 on Anonymisation Techniques (WP216), adopted 10 April 2014: pseudonymisation is not a method of anonymisation; singling out, linkability, inferenceArticle 29 Working Partyaccessed 2026-10-05
  9. PrimaryPress page of 28 May 2026 on deliberation SAN-2026-008 of 26 May 2026: EUR 5 million on IQVIA Operations France, data found pseudonymous not anonymousCNILaccessed 2026-10-05
  10. PrimaryAnonymisation guidance, introduction (published 28 March 2025, flagged under review): anonymous information, pseudonymisation, 'de-identified', the health authority exampleInformation Commissioner's Officeaccessed 2026-10-05
  11. PrimaryAnonymisation guidance on identifiability: singling out, linkability, 'whose hands', joint controllersInformation Commissioner's Officeaccessed 2026-10-05
  12. PrimaryConsultation page, 24 August to 19 October 2026, on draft guidance about anonymisation, pseudonymisation and researchInformation Commissioner's Officeaccessed 2026-10-05
  13. PrimaryDraft guidance 'Anonymisation, pseudonymisation and research', August 2026: controller tests, service providers, unstructured dataInformation Commissioner's Officeaccessed 2026-10-05
  14. PrimaryGuidance pipeline page: research anonymisation guidance, final version due winter 2026Information Commissioner's Officeaccessed 2026-10-05
  15. PrimaryUK GDPR Article 4 as it stands, with the definitions of personal data and pseudonymisationlegislation.gov.ukaccessed 2026-10-05
  16. PrimaryData (Use and Access) Act 2025, section 67: meaning of research, in force 5 February 2026 (S.I. 2026/82)legislation.gov.ukaccessed 2026-10-05
  17. PrimaryData (Use and Access) Act 2025, section 86: new Articles 84A to 84D, safeguards for researchlegislation.gov.ukaccessed 2026-10-05
  18. PrimaryData (Use and Access) Act 2025, section 77: information to data subjects, disproportionate effortlegislation.gov.ukaccessed 2026-10-05
  19. PrimaryEuropean Union (Withdrawal) Act 2018, section 6(1) and (2): UK courts and post-IP completion day EU case lawlegislation.gov.ukaccessed 2026-10-05
  20. PrimaryIQVIA Medical Research Data privacy notice: controller, non-identified data, legal basis, retention (IQVIA's own account)IQVIA Ltdaccessed 2026-10-05
  21. PrimaryData Resource Profile: IQVIA Medical Research Data (IMRD), published 2 February 2026, authors from UCL and IQVIA: unique patient ID within a practice, family IDClinical Epidemiology (Dove Medical Press)accessed 2026-10-05
  22. PrimaryUK Longitudinal Patient Data fact sheet, April 2024: 'anonymised' dataset, available in nine countries (IQVIA's own account)IQVIAaccessed 2026-10-05
  23. PrimaryFourth-quarter and full-year 2025 results: revenue of USD 16,310 million, used only for the ceiling illustrationIQVIA Holdings Inc. (SEC filing)accessed 2026-10-05
  24. Reported byReport of 2 October 2026 carrying IQVIA's statement: reserves the right to appeal; dataset not used in clinical research servicesLaPresseaccessed 2026-10-05
  25. Reported byIQVIA's full statement of 2 October 2026 as publishedQuotidiano Sanitàaccessed 2026-10-05
  26. Reported byPost of 3 October 2026 carrying a machine translation of the press release; used only as a pointer to the primariesDataBreaches.netaccessed 2026-10-05

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.