CNIL Fines IQVIA EUR 5 Million Over Anonymization

Short & clear answers
Frequently asked questions about this incident
As a website operator, am I affected by this case?
Potentially yes, if you aggregate, analyse or use customer or user data for statistics and wrongly assume it is anonymised. Typical risk cases include analytics tools that store pseudonymised user IDs but label them 'anonymous statistics', or data sharing with providers under the label 'anonymised' despite a re-identification risk. The case explicitly applies not only to healthcare companies.
What is the difference between pseudonymisation and anonymisation?
With anonymisation, a link to a person can no longer be restored with reasonable effort – such data falls outside the scope of the GDPR. With pseudonymisation (Art. 4(5) GDPR), only direct identifiers like the name are replaced by a code, but the personal reference remains in principle restorable. Pseudonymisation is a security measure, not a free pass out of the GDPR.
How do I check whether my data is really anonymous?
First check your record of processing activities (ROPA) for pseudonymised data that is wrongly classified as 'anonymised'. Then run a re-identification risk test based on the EDPB Guidelines 02/2026, specifically for the three risks of singling-out, linkability and inference. A persistent, unique identifier per person combined with detailed data almost always points to mere pseudonymisation.
What exactly do I need to do now?
Strengthen technical security with multi-factor authentication (MFA) and regular monitoring of access logs – exactly what was missing at IQVIA. Update your privacy policy and data subject information to comply with Art. 13 and 14 GDPR, and set up processes that let people easily exercise their right to object. Also ensure that a valid legal basis under Art. 6 (and Art. 9 for sensitive data) is documented for all pseudonymised datasets.
What penalties are there for misclassifying data?
The CNIL fined IQVIA 5 million euros plus a daily penalty of 10,000 euros if the shortcomings in patient information and objection rights are not fixed within six months. The violations concerned Art. 9, 14, 25 and 32 GDPR. Across Europe, GDPR fines rose by nearly 400 percent in the first quarter of 2026 to over 68 million euros.
More security news
You might also be interested in
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.