Published on 31 July 2026
A single word cost one company 5 million euros: anonymous. The French data protection authority CNIL has imposed a 5 million euro fine on the health data services provider IQVIA Operations France – because the company classified highly sensitive patient data from pharmacies and doctors' practices as anonymous, thereby assuming it fell outside the scope of the GDPR. The authority saw things differently: the data was not anonymous, but merely pseudonymised – and is therefore subject to the full protection of the General Data Protection Regulation. On 31 July 2026, the detailed legal analysis of the case was made public.
For you as a website or business operator, this case is far more than a footnote about a large corporation. It hits one of the most common and most expensive misconceptions in data protection: the confusion between pseudonymisation and anonymisation. Anyone who misjudges this distinction may lose their entire basis for GDPR compliance – without even noticing.
IQVIA Operations France is a globally operating provider of clinical research and health data analytics. The company operated two large so-called data warehouses (central repositories for large volumes of data):
These warehouses held highly sensitive information: year of birth, gender, diagnoses, symptoms, prescriptions and even socioeconomic status – of tens of millions of patients. The investigation was triggered, among other things, by a critical report by the French television programme "Cash Investigation" in May 2021, which led to numerous complaints from patients and associations.
IQVIA argued that this data was anonymised and therefore did not fall under the GDPR at all. On 26 May 2026, the CNIL imposed the fine – and made it clear: this assessment was wrong.
"The data was not anonymous, but merely pseudonymous, since re-identification of the data subjects was possible using reasonable means." – CNIL
The decisive technical and legal distinction deserves an explanation, because this is exactly where the mistake lay.
Anonymisation means: a link to a person can no longer be established, permanently and with reasonable effort. Truly anonymous data does in fact fall outside the scope of the GDPR – from a data protection perspective, it is "free".
Pseudonymisation (defined in Art. 4 No. 5 GDPR), by contrast, only means that direct identifiers such as the name are replaced by a code or an identifier. The link to a person, however, can in principle be restored. Pseudonymisation is a security measure – not a free pass out of the GDPR.
At IQVIA, the data was indeed pseudonymised by third parties before transmission. But: each record retained a persistent, unique identifier per patient – that is, a consistent identifier that linked all of a person's records together. If you combine this identifier with the enormous depth of detail in the data (diagnoses, prescriptions, age, gender, social status), an individual person can be filtered out again with reasonable effort.
In doing so, the CNIL relied on three recognised re-identification risks:
IQVIA invoked the CJEU's "SRB" ruling of September 2025 to support its anonymity claim. The CNIL rejected this: because IQVIA controlled the entire processing chain as the controller – that is, determined the purpose and means of the processing – the company was responsible for the re-identifiability.
The incorrect classification gave rise to violations of several GDPR articles at once:
In addition to the fine, the CNIL imposed a penalty payment of 10,000 euros per day should IQVIA fail to remedy the still-outstanding shortcomings in patient information and the implementation of the right to object within six months.
IQVIA is directly affected. But the real explosive force lies in the signal it sends. The law firm Stephenson Harwood sums it up:
"For organisations that process pseudonymised health data at scale […] this decision should trigger a careful review. The CNIL's analysis […] represents a strict application of established principles that other supervisory authorities are likely to follow." – Stephenson Harwood
This explicitly applies not only to health corporations. Every SME and every website operator that aggregates, analyses or evaluates user or customer data for statistics is potentially affected – wherever anonymisation is wrongly assumed. Typical examples:
"The IQVIA decision is a case study in what happens when an organisation's characterisation of its own data fails to withstand regulatory scrutiny. Calling data 'anonymous' does not make it so." – Acompli Editorial
Work through these four steps concretely:
If the review reveals a need for action, implement the following measures:
The IQVIA case falls in a period of significantly intensified enforcement. On 7 July 2026, the European Data Protection Board (EDPB) published the draft of its new Guidelines 02/2026 on anonymisation – a set of rules that underpins the CNIL's reasoning. In short, these guidelines make it clear: pseudonymisation is a security measure and does not result in anonymisation that would take data out of the scope of the GDPR.
The urgency is also borne out by the figures: in the first quarter of 2026, European data protection authorities imposed GDPR fines totalling 68.18 million euros – an increase of almost 400 percent compared to the first quarter of 2025. Supervisory authorities are cracking down noticeably harder on sensitive data.
An often-overlooked point with immediate practical relevance: if a data breach occurs with pseudonymised data, the 72-hour notification obligation under Art. 33 GDPR applies in full. Anyone who wrongly considers their data to be anonymous will miss this deadline in an emergency – and risk additional fines.
The 5 million euro penalty against IQVIA is a warning to everyone who works with aggregated data: a label changes nothing about reality. As long as individual persons can be filtered out again with reasonable effort – for example through persistent identifiers and depth of data – the data remains pseudonymised and thus fully subject to the GDPR.
The "pseudonymous = anonymous" fallacy is widespread and expensive. It leads companies to believe they need no legal basis, no data subject rights and no technical safeguards – and thereby lose their entire compliance at a stroke. Take the time to go through your data inventory using the four review steps above. If you find the word "anonymised" anywhere, ask critically: is that really the case – or is it merely pseudonymised? This one question can save you a great deal of trouble and very high fines.