{"id":2830,"date":"2026-06-22T10:13:01","date_gmt":"2026-06-22T08:13:01","guid":{"rendered":"https:\/\/blog.eprivacy.eu\/?p=2830"},"modified":"2026-06-22T10:13:01","modified_gmt":"2026-06-22T08:13:01","slug":"a-pseudonym-is-not-the-same-as-anonymity-cnil-imposes-a-e5-million-fine-on-iqvia-and-what-the-cjeus-srb-ruling-has-to-do-with-it","status":"publish","type":"post","link":"https:\/\/blog.eprivacy.eu\/?p=2830","title":{"rendered":"A pseudonym is not the same as anonymity: CNIL imposes a \u20ac5 million fine on IQVIA \u2013 and what the CJEU\u2019s \u2018SRB\u2019 ruling has to do with it"},"content":{"rendered":"\n<p>CNIL, 26 May 2026 \u2013 SAN-2026-008 (IQVIA OPERATIONS FRANCE)<br>The French data protection authority, the CNIL, has imposed a fine of<strong>&nbsp;\u20ac5 million<\/strong>&nbsp;on the health data company IQVIA OPERATIONS FRANCE \u2013 primarily because it failed to comply with data subject protection requirements whilst operating health data warehouses.<br>IQVIA conducts studies for pharmaceutical companies, relying for this purpose on two health data warehouses (which had previously been authorised by the CNIL) containing data from around 14,000 pharmacies and several thousand doctors. During a subsequent audit, the CNIL found that, in practice, requirements regarding the provision of information to data subjects, the exercise of data subjects\u2019 rights and data security had not been met.<\/p>\n\n\n\n<p>IQVIA assumed that the data was anonymous and that data protection law therefore did not apply. The key argument in this regard could be the&nbsp;<strong>\u2018SRB\u2019 judgment of the European Court of Justice<\/strong>&nbsp;(4 September 2025, C-413\/23 P). This judgment described the personal nature of data as relative: according to it, the same pseudonymised data may be personal to the data controller who holds the key, whilst it may be anonymous to a third party without the means to re-identify it.<\/p>\n\n\n\n<p>However, the CNIL did not consider this to be the case here. It argued that the data in the warehouses was&nbsp;<strong>not anonymous, but merely pseudonymous<\/strong>, because re-identification was possible using reasonable means.<br>Three points were key to this conclusion:&nbsp;<\/p>\n\n\n\n<ul><li><strong>a unique identifier<\/strong>&nbsp;for each patient,<\/li><li>the&nbsp;<strong>depth of the data collected<\/strong>&nbsp;(e.g. year of birth, gender, prescriptions, diagnoses, symptoms, allergies, weight, height, pulse, vaccinations, examinations, sick notes) and<\/li><li>the possibility of identifying individuals by combining the IQVIA data with&nbsp;<strong>publicly available information.<\/strong><\/li><\/ul>\n\n\n\n<p>According to the CNIL, there were further factors that undermined the adequacy of anonymity:&nbsp;<\/p>\n\n\n\n<ul><li>The rapporteur in the proceedings clearly illustrated just how&nbsp;<strong>easy<\/strong>&nbsp;re-identification can be in practice using an example: a patient from a study was identified within a few minutes via a Facebook support group.<\/li><li>Even&nbsp;<strong>contractual prohibitions<\/strong>, such as those preventing partners from re-identifying individuals, did not mean that the data could be regarded as anonymous in this case. Although a statutory prohibition could render the appropriateness of the measures irrelevant \u2013 mere contractual agreements are not sufficient for this purpose.<\/li><li>In contrast to the SRB ruling, the company was not merely a recipient of pseudonymised data in this case, but was to be regarded as the controller of the entire processing operation from the moment the data was collected. According to the CNIL, this&nbsp;<strong>role as controller<\/strong>&nbsp;argues against treating the data as anonymous. The \u2018relativity\u2019 principle from the SRB judgement helps the third party without a key \u2013 not the company that set up the data warehouse itself and brings together the rich data.<\/li><li>The fact that IQVIA had no intention of re-identifying individuals is irrelevant \u2013 what matters is solely the&nbsp;<strong>possibility of re-identification.<\/strong><\/li><\/ul>\n\n\n\n<p>In terms of substance, the CNIL then criticised various&nbsp;<strong>security shortcomings<\/strong>(including, in some cases, a failure to regularly review access logs; a lack of multi-factor authentication; incorrect patient information; and the absence of an procedure for the right to object). In some cases, this was compounded by the fact that the pharmacies did not properly inform their customers about the transfer of data to IQVIA, and that the pharmacy software itself forwarded patient data without consent (a breach of \u2018Privacy by Design\u2019).<\/p>\n\n\n\n<p>The sensitivity of the health data and the volume of data played a central role. The CNIL emphasised these factors in relation to the protection requirements and explicitly took them into account when determining the<strong>&nbsp;amount of the fine<\/strong>&nbsp;\u2013 alongside the number of data subjects (several tens of millions), the company\u2019s market position and its financial strength. However, pseudonymisation itself was regarded as a mitigating factor, as it at least ruled out direct identification.<\/p>\n\n\n\n<p><strong>For companies in the e-health sector, this means<\/strong>&nbsp;that when pseudonymised (health) data is used in data warehouses, real-world evidence products or for AI training, anonymisation must be examined in detail. Data controllers who merge rich, longitudinal datasets containing unique identifiers will, in most cases, continue to be dealing with re-identifiable data. In such cases, companies will have no choice but to distinguish between individual scenarios based on the potential for re-identification. Only then can one be confident that the data is no longer subject to data protection requirements.<\/p>\n\n\n\n<p><em>Legal action may generally be taken against CNIL fines, meaning that the decision is not necessarily final.<\/em><br><br>(Dr. Marian Klingebiel, Unverzagt Law)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CNIL, 26 May 2026 \u2013 SAN-2026-008 (IQVIA OPERATIONS FRANCE)The French data protection authority, the CNIL, has imposed a fine of&nbsp;\u20ac5 million&nbsp;on the<\/p>\n<p class=\"link-more\"><a class=\"myButt \" href=\"https:\/\/blog.eprivacy.eu\/?p=2830\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/2830"}],"collection":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2830"}],"version-history":[{"count":1,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/2830\/revisions"}],"predecessor-version":[{"id":2831,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=\/wp\/v2\/posts\/2830\/revisions\/2831"}],"wp:attachment":[{"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eprivacy.eu\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}