Cegedim – €800,000 Fine (France, 2024)

€800,000Commission Nationale de l'Informatique et des Libertés5 September 2024France
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Cegedim was fined EUR 800,000 for mishandling patient data in its healthcare software. This case is significant because it shows that even anonymized data can still be considered personal data under GDPR if it can be re-identified. Companies must be careful with how they handle such data.

What happened

Cegedim processed pseudonymized patient data without properly assessing the risk of re-identification.

Who was affected

Patients whose data was processed by Cegedim's software were affected.

What the authority found

The French data protection authority found that Cegedim's handling of pseudonymized data violated GDPR because it could still lead to identifying individuals.

Why this matters

This case serves as a warning to companies that they must understand the implications of data processing, even for anonymized data. Businesses should review their data handling practices to ensure compliance.

GDPR Articles Cited

AI-verified

Art. 5(1)(a) GDPR
Art. 82 Loi Informatique et Libertés GDPR
View original scraped data
Art. 5(1)(a) GDPR
Art. 82 Loi Informatique et Libertés

Original data from scraper before AI verification against source document.

National Law Articles

AI-identified

Article 66 Loi n° 78-17 du 6 janvier 1978 relative à l'informatique, aux fichiers et aux libertés (Law no. 78-17 of January 6, 1978 on data processing, data files and individual liberties)
Source verified 5 March 2026
articles corrected
national law identified
Full Legal Summary
Detailed

Cegedim is a company providing IT products and services for healthcare professionals, inter alia, a software enabling doctors to manage patients’ data (basic identification data, as well as health history, diagnoses, prescribed medicines or procedures; and the data coming from third-parties, including HRI system, i.e. the national health identifier system). The users of the software were offered an option to enrol for research (health-sector studies and statistics) performed by Cegedim and their business partners. In exchange for access to patients’ data, the software users received a discount on the license and access to statistics created by Cegedim. To enable the transfer of data from the users’ software, Cegedim encrypted patient data and assigned each patient an unique identifier. The identifier informed about the category of doctor visited which made a cross-doctor data examination possible every time the patient visited a same kind of doctor, regardless its location. The patients’ data collected by Cegedim was stored for three months and then transferred to Cegedim business partners. According to Cegedim, since the patients’ data was anonymised, the GDPR was no longer applicable to the processing at hand. The French DPA (CNIL) initiated ex officio investigation to examine the practices of Cegedim. The DPA rejected Cegedim interpretation suggesting they processed anonymised data. Under Recital 26 GDPR, quoted by Cegedim, the pseudonymised data was still personal data covered by the GDPR. It was clear for the DPA that Cegedim processed personal data which were only pseudonymised. That was because the identifiers assigned to patients’ data allowed Cegedim to identify each patient. Also, as proved during the investigation, it was possible to re-identify a patient using reasonable means and data processed by Cegedim, even without access to additional information. Hence, Cegedim failed to assess the risk of re-identification. Regarding the nature of Cegedim

Related Enforcement Actions (0)

No other enforcement actions found for Cegedim in FR

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

5 September 2024

Authority

Commission Nationale de l'Informatique et des Libertés

Fine Amount

€800,000

GDPRhub ID

gdprhub-8298

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. Cegedim - France (2024). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: