All news
Enforcement June 10, 2026 3 min

France fines IQVIA EUR 5M: pseudonymisation does not take you out of the GDPR

Pseudonymising health data is a security measure, not a free pass: the data stays personal and the GDPR fully applies

TL;DR for the DPO

The French authority fined IQVIA (EUR 5 million), reaffirming that pseudonymising health data is NOT enough to escape the GDPR. Pseudonymised data remains personal data (Recital 26) because it can be re-identified: pseudonymisation is a security measure (Art. 32), not a way out of the Regulation.

The three points that matter

  • Pseudonymisation is not anonymisation: the first is reversible and the data stays personal; only irreversible anonymisation leaves the GDPR behind. Confusing them is a costly mistake.
  • Health data = Art. 9: even pseudonymised it requires a proper legal basis and enhanced measures. Technical 'protection' does not erase the data category.
  • Accountability: if you claim data is anonymous, you must be able to prove it with a re-identification risk assessment. Absent that, it is presumed personal.

What to do now, in practice

When a client says 'it's anonymised anyway', actually test re-identifiability: who holds the key? how much effort to get back to the person? If it is only pseudonymisation, the GDPR fully applies - legal basis, notice, measures, possibly a DPIA. Always document the assessment: it is the difference between a defensible choice and a gamble.

Why it matters for your clients

It is a very common misunderstanding in healthcare, research and marketing: 'I anonymised it' when in fact it is only pseudonymised. The result is skipping key obligations while believing you are out of scope. For a DPO it is a concrete argument to bring to anyone handling health data or building 'de-identified' datasets.

Official source:CNIL (France) - IQVIA fine, June 2026

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min