TL;DR for the DPO
The French authority fined IQVIA (EUR 5 million), reaffirming that pseudonymising health data is NOT enough to escape the GDPR. Pseudonymised data remains personal data (Recital 26) because it can be re-identified: pseudonymisation is a security measure (Art. 32), not a way out of the Regulation.
The three points that matter
- Pseudonymisation is not anonymisation: the first is reversible and the data stays personal; only irreversible anonymisation leaves the GDPR behind. Confusing them is a costly mistake.
- Health data = Art. 9: even pseudonymised it requires a proper legal basis and enhanced measures. Technical 'protection' does not erase the data category.
- Accountability: if you claim data is anonymous, you must be able to prove it with a re-identification risk assessment. Absent that, it is presumed personal.
What to do now, in practice
When a client says 'it's anonymised anyway', actually test re-identifiability: who holds the key? how much effort to get back to the person? If it is only pseudonymisation, the GDPR fully applies - legal basis, notice, measures, possibly a DPIA. Always document the assessment: it is the difference between a defensible choice and a gamble.
Why it matters for your clients
It is a very common misunderstanding in healthcare, research and marketing: 'I anonymised it' when in fact it is only pseudonymised. The result is skipping key obligations while believing you are out of scope. For a DPO it is a concrete argument to bring to anyone handling health data or building 'de-identified' datasets.
Official source:CNIL (France) - IQVIA fine, June 2026Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free