← All articles

consultant

CNIL fines IQVIA €5M: health data warehouses under high scrutiny

On May 26, 2026, the CNIL fined IQVIA €5M for breaching authorizations and Articles 14 and 25 GDPR across two health data warehouses. Clear message: effective notice, operational opt-out, and privacy by design are non-negotiable.

Excerpt — On May 26, 2026, the CNIL fined IQVIA €5M for failing to comply with authorizations and breaching GDPR Articles 14 and 25 across two health data warehouses (LRX, EMR). Takeaway: effective notice, operational opt‑out, and privacy by design are non‑negotiable. CNIL, 26/05/2026.

The case

The CNIL’s restricted committee sanctioned IQVIA OPERATIONS FRANCE with a €5,000,000 fine and injunctions under penalty (€10,000/day) for several infringements relating to two health data warehouses: LRX (fed by ~14,000 pharmacies) and EMR (GP medical records). Key findings: failure to comply with CNIL authorization conditions (French LIL art. 66), insufficient information to data subjects in indirect collection (GDPR art. 14), and shortcomings in “data protection by design and by default” (GDPR art. 25). See CNIL release and the full SAN‑2026‑008 decision.

  • Duty to provide accurate and complete information (including retention periods) to patients whose data are collected indirectly via EMR (art. 14 GDPR).
  • Need to ensure an effective right to object, including at pharmacy and practice level (e.g., objection recorded by the physician).
  • Prohibition on certain studies using LRX without a CNIL authorization or alignment with MR‑004.
  • Technical/organizational measures to prevent extraction if a pharmacist refused transmission to IQVIA (art. 25 GDPR).

Procedural note: the investigation followed complaints after a TV report. While security and confidentiality had improved, the CNIL upheld the fine and injunctions on information duties, authorization compliance, and operational opt‑out. Source.

Legal reasoning

  • Health data = special category (art. 9(1) GDPR): processing is prohibited unless art. 9(2) exceptions apply, with enhanced safeguards. Duties on indirect notice (art. 14) and privacy by design/by default (art. 25) apply cumulatively. GDPR text.
  • Specific authorizations / reference methods: in France, some health processing requires CNIL authorization (LIL art. 66) or MR‑004. CNIL found non‑compliance with granted authorization conditions. SAN‑2026‑008.
  • Article 14 notice: for indirect collection (pharmacies/practices), provide complete, timely information (purposes, legal bases, retention, recipients, rights). Article 14.
  • Article 25 GDPR: build in technical and organizational safeguards and protective defaults (minimization, limited access, truly enforceable opt‑out). See EDPB Guidelines 4/2019.
  • Luxembourg perspective: CNPD — health data requires maximum vigilance; high‑risk processing often triggers a DPIA (art. 35) and tighter control of post‑authorization changes. CNPD resources.

What this changes in practice (Luxembourg and BE/FR/DE cross‑border)

  • Health warehouses and pharma/retail analytics: the opt‑out must technically block processing across the pipeline (synced objection lists, source‑side filtering, ingestion controls, audit‑grade logging). CNIL decision.
  • Industrialized Article 14 notice: implement multi‑channel information journeys (posters, leaflets, QR codes, up‑to‑date website) with timestamped evidence; include retention periods. Reference.
  • Governance by design (art. 25): require blocking controls from vendors/integrators; test and evidence them. Reference: EDPB 4/2019.
  • Authorizations and scope: in Luxembourg, high‑risk health processing needs a DPIA; if residual risk remains, prior consultation (art. 36). Any expansion of purposes/use must be reassessed and, where required, re‑authorized. CNPD.
  • Legal basis and art. 9(2): avoid relying on “legitimate interests” for health data without a clear art. 9(2) derogation. Proportionality and minimization are key. GDPR.

Concrete IT example

  • Pre‑extraction: real‑time check of a source‑fed opt‑out table; source‑side pseudonymization with a key held by a trusted third party; application block if status = "OPPOSED=true".
  • Ingestion: automatic reject and logging of any line matching the objection list; SOC/DPO alert on abnormal failure volumes to detect opt‑out bypass (arts. 25 and 32). EDPB 4/2019.

Frequent pitfalls seen in audits

  1. Theoretical opt‑out not technically enforced (sanctionable under art. 25). IQVIA decision.
  2. One‑size‑fits‑all privacy notice not tailored to actual data flows (sources, recipients, retention) — non‑compliant with art. 14.
  3. Mismatch between authorizations/frameworks and practices (new studies, new recipients) — a decisive factor in the case.
  4. Confusing pseudonymization with anonymization — hashing alone does not anonymize; assess re‑identification risk.
  5. One‑off DPIA not revisited upon substantial changes — CNPD expects reassessment and, where needed, prior consultation.

Official sources

  • CNIL — “Health data: €5M fine against IQVIA” (press release, May 26, 2026). cnil.fr
  • Legifrance — CNIL Decision SAN‑2026‑008 (IQVIA), May 26, 2026. legifrance.gouv.fr
  • Regulation (EU) 2016/679 (GDPR) — Articles 9, 14, 25. eur-lex.europa.eu
  • EDPB — Guidelines 4/2019 on Article 25. service.betterregulation.com
  • CNPD Luxembourg — DPIA: when and how to conduct; post‑authorization changes. cnpd.public.lu

Key takeaway and next steps

For Luxembourg executives/DPOs/CISOs, the IQVIA case signals an operational shift: you must evidence, with logs, that objections block both collection and use — by design and by default. To structure this, an external DPO mandate can help industrialize Article 14 notice, DPIAs, and authorization reviews, aligned with the GDPR framework. If you operate in the Grand Duchy, strengthen your CNPD compliance in Luxembourg. Need a quick assessment? Talk to our team.

Luxgap regulatory expertise article. For personalised guidance on this topic, contact us or configure your online quote.

LUXGAP NEWSLETTER

Get our analyses the moment they drop.

GDPR, NIS 2, AI expertise articles, plus invitations to free webinars + trainings at Luxgap. 1 to 2 emails per week max, one-click unsubscribe.

Your data is never shared. GDPR-compliant (we're DPOs after all).

A question on this topic?

Our team usually replies within one business day. Configure your quote or write to us.

Build my quote →