All news
Enforcement May 26, 2026 7 min

France: EUR 5 million for IQVIA. The pharmacy software kept sending the data even when the patient had said no

The defence was that the data was anonymous and therefore outside the GDPR. The CNIL dismissed it in two words: pseudonymous, not anonymous

TL;DR for the DPO

Two lessons, both usable tomorrow morning. First: if a supplier's software sends the data anyway, the objection collected at the counter does not exist - and the infringement is of Art. 25, not Art. 6. Second: stating 'the data is anonymous' does not take processing outside the GDPR if a re-identification key survives somewhere.

The two warehouses

IQVIA Operations France provides consultancy and studies for pharmaceutical laboratories. To do so it relies on two health data warehouses: LRX, authorised in 2018, fed with data collected from around 14,000 pharmacies, and EMR, authorised in 2021, fed with data collected from several thousand doctors. Those figures explain the amount: it is not the gravity of a single operation, it is the scale.

14,000
pharmacies feeding the LRX warehouse

The objection that never arrived

The most concrete finding concerns how the practice management software installed in pharmacies worked: it transmitted customer data to IQVIA even where the customer had objected. The CNIL classifies this as an infringement of Art. 25, data protection by design.

Why Art. 25 and not Art. 6

The distinction is not formal. If the problem were the legal basis, it could be fixed by rewriting the notice or collecting consent. Here the problem is that the system had not been designed to respect the person's choice: the objection function existed on paper and had no effect in the data flow. No better notice would have cured that defect.

It is the kind of defect a DPO will not find by reading procedures, because the procedures say objections are honoured. You find it only by asking: technically, what happens when the operator ticks 'the patient objects'? Where does that flag go? Who reads it?

Anonymous or pseudonymous

IQVIA argued that the data in the warehouses was anonymous and therefore outside the scope of the GDPR. The CNIL rejected the argument: the data is pseudonymous, not anonymous. It is the same fault line that ran through the Dutch Enschede case last month, with the opposite outcome: there the authority lost because it had not established identifiability, here the controller lost because it asserted anonymity without discharging the burden.

What to do now, in practice

1) For every client claiming to process anonymous data, ask where the re-identification key is. If it exists anywhere - including at a third party, including 'only for technical support' - the data is pseudonymous and the GDPR applies in full. 2) Test objection and opt-out flows technically, not on paper: run a real case and follow the data. 3) If the client uses a vertical system supplied by a third party, Art. 25 still binds them as controller: ask the supplier for documentation of how objection is implemented, and file it. 4) Health data warehouses authorised years ago need re-examining: a 2018 authorisation does not describe how the system behaves in 2026.

Official source:CNIL - Health data: EUR 5 million fine against IQVIA (26 May 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min