IQVIA Operations France – €5,000,000 Fine (France, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
IQVIA Operations France was fined €5 million for mishandling health data in its research activities. This is significant because it highlights the need for companies to follow strict rules when collecting and using sensitive health information. Businesses in the health sector should ensure they have proper data protection measures in place.
What happened
IQVIA Operations France was fined for not adequately protecting health data in its repositories.
Who was affected
Approximately 20 million patients whose health data was collected for research purposes were affected.
What the authority found
The Commission Nationale de l'Informatique et des Libertés found that IQVIA did not comply with GDPR requirements for health data processing.
Why this matters
This case serves as a reminder for companies handling sensitive data to prioritize compliance with data protection laws to avoid hefty fines.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
IQVIA Operations France, the controller, is a consulting firm conducting studies either on its own behalf or on behalf of pharmaceutical companies. The controller was authorised by the CNIL, the DPA, to establish two health data repositories for research, study and evaluation purposes: the LRX repository, based on pharmacy data, and the EMR repository, based on physicians’ consultation data. The LRX repository was intended to enable non-interventional studies on the real-world use of medicines, including persistence, adherence, compliance with prescriptions and contraindications. To build this repository, the controller collected medication sales data from approximately 14,000 partner pharmacies. Where the pharmacist agreed, the controller also collected a unique identification code enabling the longitudinal tracking of patients’ care pathways. According to the controller’s materials, this concerned “20 million anonymized patients tracked over time.” In practice, when a pharmacist recorded a medicine sale in pharmacy management software, an integrated module developed on behalf of the controller extracted the data and generated a “Pharmastat” data stream. This stream included medication sales data and a patient identification code generated through a hash function based on the INS-C, together with the patient’s first name, year of birth and gender. The code, combined with dispensing data, was transmitted to two trusted third parties designated by the controller, each of which re-hashed the identifier. The resulting pseudonymised data was stored in the LRX warehouse. The EMR repository was intended to support studies on the evaluation and analysis of general medical care practices. It was fed by two data streams derived from physicians’ consultation data. These streams were transferred to the “Hub EMR”, hosted by a certified health data hosting provider and trusted third party. One stream underwent pseudonymisation within the physician’s software and then by the trus
Related Enforcement Actions (0)
No other enforcement actions found for IQVIA Operations France in FR
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
26 April 2026
Authority
Commission Nationale de l'Informatique et des Libertés
Fine Amount
€5,000,000
GDPRhub ID
gdprhub-10032About this data
Cite as: Cookie Fines. IQVIA Operations France - France (2026). Retrieved from cookiefines.eu
Last updated: