TL;DR for the DPO
Two lessons, both usable tomorrow morning. First: if a supplier's software sends the data anyway, the objection collected at the counter does not exist - and the infringement is of Art. 25, not Art. 6. Second: stating 'the data is anonymous' does not take processing outside the GDPR if a re-identification key survives somewhere.
The two warehouses
IQVIA Operations France provides consultancy and studies for pharmaceutical laboratories. To do so it relies on two health data warehouses: LRX, authorised in 2018, fed with data collected from around 14,000 pharmacies, and EMR, authorised in 2021, fed with data collected from several thousand doctors. Those figures explain the amount: it is not the gravity of a single operation, it is the scale.
The objection that never arrived
The most concrete finding concerns how the practice management software installed in pharmacies worked: it transmitted customer data to IQVIA even where the customer had objected. The CNIL classifies this as an infringement of Art. 25, data protection by design.
Why Art. 25 and not Art. 6
The distinction is not formal. If the problem were the legal basis, it could be fixed by rewriting the notice or collecting consent. Here the problem is that the system had not been designed to respect the person's choice: the objection function existed on paper and had no effect in the data flow. No better notice would have cured that defect.
It is the kind of defect a DPO will not find by reading procedures, because the procedures say objections are honoured. You find it only by asking: technically, what happens when the operator ticks 'the patient objects'? Where does that flag go? Who reads it?
Anonymous or pseudonymous
IQVIA argued that the data in the warehouses was anonymous and therefore outside the scope of the GDPR. The CNIL rejected the argument: the data is pseudonymous, not anonymous. It is the same fault line that ran through the Dutch Enschede case last month, with the opposite outcome: there the authority lost because it had not established identifiability, here the controller lost because it asserted anonymity without discharging the burden.
What to do now, in practice
1) For every client claiming to process anonymous data, ask where the re-identification key is. If it exists anywhere - including at a third party, including 'only for technical support' - the data is pseudonymous and the GDPR applies in full. 2) Test objection and opt-out flows technically, not on paper: run a real case and follow the data. 3) If the client uses a vertical system supplied by a third party, Art. 25 still binds them as controller: ask the supplier for documentation of how objection is implemented, and file it. 4) Health data warehouses authorised years ago need re-examining: a 2018 authorisation does not describe how the system behaves in 2026.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free