CNIL (France) - SAN-2026-008
| CNIL - SAN-2026-008 | |
|---|---|
| Authority: | CNIL (France) |
| Jurisdiction: | France |
| Relevant Law: | Article 14 GDPR Article 25 GDPR Article 66 of Act n°78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 29.06.2021 |
| Decided: | 26.04.2026 |
| Published: | 28.04.2026 |
| Fine: | 5.000.000 EUR |
| Parties: | IQVIA Operations France |
| National Case Number/Name: | SAN-2026-008 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | French |
| Original Source: | CNIL (in FR) |
| Initial Contributor: | bms |
The DPA fined a pharmaceutical consulting firm €5,000,000 for insufficiently anonymising data processed in its pharmacy and medical-record data warehouse, allowing the unwanted identification of data subjects by singling them out. The DPA ordered the controller to bring its processing into compliance.
English Summary
Facts
IQVIA Operations France, the controller, is a consulting firm conducting studies either on its own behalf or on behalf of pharmaceutical companies. The controller was authorised by the CNIL, the DPA, to establish two health data repositories for research, study and evaluation purposes: the LRX repository, based on pharmacy data, and the EMR repository, based on physicians’ consultation data.
The LRX repository was intended to enable non-interventional studies on the real-world use of medicines, including persistence, adherence, compliance with prescriptions and contraindications. To build this repository, the controller collected medication sales data from approximately 14,000 partner pharmacies. Where the pharmacist agreed, the controller also collected a unique identification code enabling the longitudinal tracking of patients’ care pathways. According to the controller’s materials, this concerned “20 million anonymized patients tracked over time.”
In practice, when a pharmacist recorded a medicine sale in pharmacy management software, an integrated module developed on behalf of the controller extracted the data and generated a “Pharmastat” data stream. This stream included medication sales data and a patient identification code generated through a hash function based on the INS-C, together with the patient’s first name, year of birth and gender. The code, combined with dispensing data, was transmitted to two trusted third parties designated by the controller, each of which re-hashed the identifier. The resulting pseudonymised data was stored in the LRX warehouse.
The EMR repository was intended to support studies on the evaluation and analysis of general medical care practices. It was fed by two data streams derived from physicians’ consultation data. These streams were transferred to the “Hub EMR”, hosted by a certified health data hosting provider and trusted third party. One stream underwent pseudonymisation within the physician’s software and then by the trusted third party, while the other passed through the Hub EMR without any change to its format.
The EMR repository contained patient identification-related data, such as year of birth, gender, marital status, number of children and socio-professional category, as well as health data from consultations, including visit date, diagnosis, symptoms, allergies, weight, height, pulse, prescriptions, vaccinations, tests and sick leave. Each patient had a unique identifier for each doctor consulted, although the controller stated that no correlation was possible between different medical practices. The EMR warehouse contained data from approximately 2,000 physicians, while the controller’s brochure referred to 3,000 partner physicians.
Following media reports and several complaints, the DPA carried out inspections at the controller’s premises and at several partner pharmacies. During the proceedings, the controller argued, among other things, that the data contained in the LRX and EMR repositories was anonymous and that it was not responsible for the initial collection and transmission of data by pharmacies and physicians.
Holding
The DPA first held that the controller was responsible for the processing operations used to create both the LRX and EMR repositories. It considered that the different technical steps carried out by pharmacists, physicians, software providers and trusted third parties were not independent processing operations, but formed part of a single processing chain designed to create and populate the controller’s repositories. The DPA therefore held that the controller determined the purposes and means of the processing, starting from the collection of data at pharmacy or physician level.
The DPA also rejected the controller’s argument that the data in the LRX and EMR repositories was anonymous. It found that the data was pseudonymised, but still constituted personal data. In particular, the repositories enabled longitudinal tracking of patients through unique identifiers and contained rich health and identification-related data. The DPA considered that individuals could be isolated within the datasets and that re-identification could be possible by reasonable means, including by cross-referencing the data with external information. The DPA also noted that the controller’s intention or lack of intention to re-identify individuals was irrelevant for determining whether the data was personal data.
Regarding the EMR repository, the DPA found a breach of Article 66 of the French Data Protection Act. The controller had been authorised to create the EMR repository subject to specific conditions. However, the information notices provided to patients stated that their data would be retained for the duration of the studies and analyses conducted by the controller and its contractual partners, whereas the authorisation provided for retention in an active database for ten years before anonymisation or deletion. The DPA therefore considered that the information provided to patients was inaccurate. It also found that the controller had not ensured the effective exercise of patients’ right to object regarding data already collected in the EMR repository.
Regarding the LRX repository, the DPA found a breach of Article 14 GDPR. The controller relied on partner pharmacists to inform patients about the processing of their data. However, inspections at four pharmacies showed that patients were not provided with the required information notices and that the relevant information was not properly displayed. The DPA held that, irrespective of the practical channel used to provide the information, the obligation under Article 14 GDPR remained with the controller. The failure was particularly serious because patients had their health data processed without being aware of it and were therefore unable to exercise their rights.
The DPA further found a breach of Article 66 of the French Data Protection Act concerning studies carried out by the controller using the LRX warehouse. The DPA held that the authorisation granted for the LRX repository covered the creation of the warehouse only, and not the subsequent studies conducted using that warehouse. Those studies constituted separate processing operations involving personal health data. Since they had not been specifically authorised and did not validly comply with the MR-004 reference methodology, in particular due to the lack of prior and individual information to patients, the DPA found that they were unlawful.
Finally, the DPA found a breach of Article 25 GDPR. The pharmacy software modules systematically extracted and transmitted patient data to the first trusted third party even where the pharmacy had chosen not to transmit patient data for the LRX panel. The DPA considered that this filtering should have occurred upstream, at the pharmacy software level, so that unnecessary patient data would not be extracted or transmitted in the first place. The controller had therefore failed to implement appropriate technical and organisational measures to ensure data protection by design and by default.
The DPA imposed a fine of €5,000,000 on the controller for breaches of Article 66 of the French Data Protection Act and Articles 14 and 25 GDPR. It also ordered the controller to bring its processing into compliance, including by providing accurate information to EMR patients, ensuring the effective exercise of the right to object, ensuring that pharmacy patients are informed of the transfer of their data, ceasing unauthorised studies from the LRX warehouse, and preventing pharmacy software modules from extracting patient data where the pharmacist had refused such transmission. The order was subject to a daily penalty of €10,000 after six months. The decision was published, with the controller’s name to be removed after two years.
Comment
Share your comments here!
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the French original. Please refer to the French original for more details.
Decision SAN-2026-008 of May 26, 2026
In force
National Commission for Information Technology and Civil Liberties (CNIL)
Nature of the decision: Sanction
Date of publication on Légifrance: Thursday, May 28, 2026
Decision of the restricted panel No. SAN-2026-008 of May 26, 2026 concerning the company IQVIA OPERATIONS FRANCE
The sections of the decision containing personal data or secrets protected by law are replaced by the symbols […], [X], [Y], [Z], and [Z+].
The National Commission for Information Technology and Civil Liberties (CNIL), meeting in its restricted panel composed of Mr. Philippe-Pierre CABOURDIN, Chairman, Mr. Vincent LESCLOUS, Vice-Chairman, Ms. Laurence FRANCESCHINI, Ms. Isabelle LATOURNARIE-WILLEMS, and Mr. Didier KLING, Members;
Having regard to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data;
Having regard to Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties, in particular Articles 20 et seq.;
Having regard to Decree No. 2019-536 of 29 May 2019 implementing Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties;
Having regard to Decision No. 2013-175 of 4 July 2013 adopting the Rules of Procedure of the National Commission for Information Technology and Civil Liberties;
Having regard to Constitutional Council Decision No. 2025-1154 QPC of 8 August 2025;
Having regard to Decision No. 2021-125C of 29 June 2021 by the President of the National Commission for Information Technology and Civil Liberties (CNIL) instructing the Secretary General to conduct or have conducted an audit of the data processing operations implemented by or on behalf of IQVIA OPERATIONS FRANCE SAS, IQVIA HOLDINGS FRANCE SAS, and IQVIA RDS FRANCE, in any location likely to be affected by their implementation;
Having regard to the decision of the President of the National Commission for Information Technology and Civil Liberties (CNIL) of 18 July 2024 appointing a rapporteur to the restricted panel;
Having regard to the report of Mr. Claude CASTELLUCCIA, rapporteur, notified to IQVIA OPERATIONS FRANCE on 31 March 2025;
Having regard to the written observations submitted by IQVIA OPERATIONS FRANCE on April 30, 2025;
Having regard to the rapporteur's response to these observations, notified to the company on May 26, 2025;
Having regard to the further written observations submitted by IQVIA OPERATIONS FRANCE on June 26, 2025;
Having regard to the closure of the investigation, notified to the company on July 16, 2025;
Having regard to the letter from the chairman of the restricted panel dated July 16, 2025, informing the company that the case was placed on the agenda of the restricted panel hearing of October 16, 2025;
Having regard to the submission by the company, on October 7, 2025, of a document entitled "Analysis of the methods of pseudonymizing data in the LRX and EMR warehouses of IQVIA Opérations France, the possibilities of re-identifying individuals, and the classification of this data in light of the CJEU decision of September 4, 2025";
Having regard to the decision of the presiding judge of the restricted panel on October 10, 2025, to declare this document admissible and to postpone the closing of the investigation;
Having regard to the rapporteur's response to this new information, notified to IQVIA OPERATIONS FRANCE on November 24, 2025;
Having regard to the new written observations submitted by the company on December 23, 2025, and January 8, 2026;
Having regard to the closing of the investigation, notified to the company on February 16, 2026;
Having regard to the letter from the Chairman of the Restricted Panel, notified on the same day, informing the company that the case was placed on the agenda of the Restricted Panel hearing of March 26, 2026;
Having regard to the additional documents submitted by the company on March 24 and 26, 2026;
Having regard to the oral submissions made during the hearing of the Restricted Panel on March 26, 2026;
Having regard to the other documents in the file;
The following were present at the hearing of the Restricted Panel on March 26, 2026:
- Mr. Claude CASTELLUCCIA, Commissioner, who presented his report;
As representatives of IQVIA OPERATIONS FRANCE:
[…].
IQVIA OPERATIONS FRANCE, having been informed of its right to remain silent regarding the allegations against it, was given the last word;
The restricted panel adopted the following decision:
I. FACTS AND PROCEDURE
1. IQVIA OPERATIONS FRANCE (hereinafter, "the Company" or "IQVIA") is a simplified joint-stock company with a single shareholder, whose registered office is located at 17 bis place des Reflets in Courbevoie (92400).
2. It belongs to the US-based IQVIA group (formerly QUINTILES and IMS HEALTH, INC.), which operates in more than one hundred countries worldwide and describes itself on its website as the "world leader in clinical research and health data."
3. IQVIA OPERATIONS FRANCE's activities include consulting and conducting studies, both for its own account and for pharmaceutical companies. Within this framework, it analyzes pharmacy activity and monitors patient care pathways, using two health data warehouses that the French Data Protection Authority (CNIL) (hereinafter, "the CNIL" or "the Commission") authorized it to establish pursuant to Article 66-III of Law No. 78-17 of January 6, 1978, concerning information technology, data files and civil liberties (hereinafter, "the Data Protection Act" or "the amended Law of January 6, 1978"):
- the Longitudinal Prescription Data warehouse (hereinafter, "LRX"), populated with data collected from pharmacies and authorized by deliberation No. 2018-289 of July 12, 2018;
- The Electronic Medical Records (EMR) data warehouse, populated with data collected from physicians and authorized by deliberation no. 2021-015 of February 4, 2021.
4. In 2023, IQVIA OPERATIONS FRANCE generated revenue of €152.6 million and net income of €23.3 million. The group's parent company, IQVIA HOLDINGS INC., generated revenue of $15 billion (approximately €12.9 billion) and net income of $1.3 billion (approximately €1.1 billion) for the same year.
5. Following the broadcast of a report on a mainstream television channel, part of which focused on the data processed by IQVIA, the CNIL (French Data Protection Authority) published a statement on its website on May 17, 2021, reiterating the applicable legal framework and the conditions under which the company had been authorized to establish the LRX data warehouse. It specified that, in light of the information brought to the public's attention, audits would be conducted.
6. In parallel, after the broadcast of the report, the CNIL received several complaints and reports from individuals and associations concerning the data processing carried out by IQVIA.
7. On July 6 and 7, 2021, a delegation conducted an on-site inspection at the headquarters of IQVIA OPERATIONS FRANCE. This operation aimed to verify compliance with the provisions of the amended French Data Protection Act of 6 January 1978 and Regulation (EU) 2016/679 of 27 April 2016 (hereinafter, "the GDPR"). The official reports drawn up at the conclusion of these operations were sent to IQVIA OPERATIONS FRANCE on 15 July 2021.
8. The company provided the delegation with additional information on 28 July, 3 September, 16 December 2021, 11 February, and 4 October 2022.
9. Furthermore, on 24 September, 29 October, and 26 November 2021, on-site inspections were conducted at six Parisian pharmacies that were partners of IQVIA OPERATIONS FRANCE. The official reports drawn up at the conclusion of these inspections were also sent to the company.
10. For the purpose of investigating these matters, the Chair of the Commission appointed Mr. Claude CASTELLUCCIA as rapporteur on July 18, 2024, pursuant to Article 22 of the amended Law of January 6, 1978.
11. On March 31, 2025, following his investigation, the rapporteur notified the company of a report detailing the breaches of Articles 66 of the French Data Protection Act and 14 and 25 of the GDPR that he considered to have occurred in this case. This report recommended that the restricted panel impose an administrative fine on the company, as well as an order to bring its practices into compliance with the aforementioned provisions, subject to a penalty payment. It also recommended that this decision be made public, but that the company's name should no longer be identifiable after a period of two years from its publication.
12. Several exchanges of written submissions subsequently took place between the rapporteur and the company, until the closure of the investigation, which was notified to the company on February 16, 2026.
13. Following the written adversarial proceedings, the rapporteur and the company presented oral submissions at the hearing of the restricted panel.
II. REASONS FOR THE DECISION
A. On the Procedure
1. On the Alleged Violation of Article 6 of the European Convention on Human Rights
14. The company argues that the length of the proceedings against it is excessive and constitutes a violation of its right to a fair trial, as guaranteed by Article 6 of the European Convention on Human Rights (hereinafter, "ECHR"). Indeed, it considers that, in light of the criteria established by the European Court of Human Rights (hereinafter, "ECtHR") and the French Council of State, which allow for an assessment of the reasonableness of the length of proceedings, taking into account the complexity of the case, the conduct of the applicant, the conduct of the authority concerned, and the stakes of the dispute for the individual concerned, the period of three years and nine months that elapsed between the CNIL President's decision to conduct an audit on June 29, 2021, and the receipt of the sanction report on March 31, 2025, is not justified. It notes that this period is significantly longer than the average processing times for cases by the Commission, which, moreover, had all the information necessary to make a decision as early as October 4, 2022.
15. The company argues that, given these delays, it was unable to "have the time and resources necessary to prepare its defense," as it was not informed "within the shortest possible time" of "the nature and cause of the accusation against it." Nearly 21 months elapsed between its last contact with the CNIL and the notification of the appointment of a rapporteur, in addition to the eight months between the appointment of the rapporteur and the notification of the sanction report. In this regard, it indicates that the teams changed during this period, that several people present at the time of the audits (some of whom played a key role) left the company, and that it no longer has all the relevant information, which is likely to cause difficulties in preparing its defense.
16. In response to the rapporteur's observations, which argue that the guarantees of Article 6 of the ECHR only apply from the moment an accusation is brought against the person concerned (i.e., from the commencement of sanction proceedings), the company maintains, on the contrary, that these provisions also apply to the investigation phase. It considers this all the more relevant given that IQVIA was under suspicion even before the audits, due to the broadcast of the report by the magazine "Cash Investigations" and the complaints filed with the CNIL (French Data Protection Authority).
17. The company considers that the violation of the provisions of Article 6 of the ECHR invalidates the entire procedure and indicates that it reserves the right to pursue all remedies, including legal action.
18. The restricted panel recalls that, under Article 6, paragraph 1 of the ECHR, "everyone is entitled to a fair and public hearing within a reasonable time by an independent and impartial tribunal established by law. This tribunal will determine either his civil rights and obligations or any criminal charge against him." Paragraph 3 provides that "everyone charged with a criminal offence has the following rights in particular: (a) to be informed promptly, in a language which he understands and in detail, of the nature and cause of the accusation against him; (b) to have adequate time and facilities for the preparation of his defence […]."
19. The European Court of Human Rights has repeatedly clarified that the period to be taken into account when assessing the reasonableness of the time within which everyone is entitled to a fair hearing "necessarily begins on the day on which a person is accused, otherwise it would not be possible to determine the merits of the accusation" (ECtHR, Neumeister v. Austria, 27 June 1968, no. 1936/63, paragraph 18), this accusation being understood "as the official notification, emanating from the competent authority, of the allegation of having committed an offence" (ECtHR, Deweer v. Belgium, 27 February 1980, no. 6903/75, paragraph 46).
20. Regarding sanction procedures before the CNIL (French Data Protection Authority), Article 22 of the French Data Protection Act stipulates that the measures that may be imposed by the restricted panel are based on a report drawn up by one of the Commission's members, appointed by its Chair. It is therefore the responsibility of the rapporteur, after having carried out all necessary due diligence pursuant to Article 39 of Decree No. 2019-536 of May 29, 2019, implementing the French Data Protection Act, to determine whether breaches can be attributed to the person or organization concerned and to decide either to terminate the procedure or to draw up the aforementioned report, which includes the grievances against the individual or legal entity in question.
21. The Council of State thus ruled that "the principle of the rights of the defense applies only to the procedure initiated by the notification of the report provided for in Article 22 of the Law of 6 January 1978, under the conditions provided for in the first paragraph of that article and in Article 40 of the Decree of 29 May 2019, and not to the preliminary steps taken by the rapporteur or to the checks carried out at his request pursuant to Article 39 of that decree" (Council of State, 10th/9th Chambers, 14 May 2019, No. 472221, unpublished).
22. In accordance with this case law, it is only upon notification of the sanction report that the person concerned is considered "accused" and that the guarantees provided for in Article 6 of the ECHR, aimed in particular at ensuring the right of "everyone to have their case heard within a reasonable time," must apply.
23. In any event, the guarantees provided for in Article 6 of the ECHR cannot apply at the control stage, which by definition precedes the initiation of sanction proceedings and the notification of charges, and whose sole purpose is the collection of factual information relating to the practices in question. The European Court of Human Rights considers in this regard that "requiring such a preliminary investigation to be subject to the safeguards of judicial procedure laid down in Article 6 § 1 would, in practice, unduly hinder the effective regulation, in the public interest, of complex financial and commercial activities" (Saunders v. the United Kingdom, 17 December 1996, no. 19187/91, § 67; Fayed v. the United Kingdom, 21 September 1994, no. 17101/90, paragraph 62).
24. In the present case, on 18 July 2024, the President of the Commission referred the matter to the restricted panel and appointed a rapporteur to examine the case and draw up the report referred to in Article 22 of the French Data Protection Act. This report, which contains the grievances against IQVIA, was notified to the company on March 31, 2025. The restricted panel notes that less than a year elapsed between the notification of the report—the date on which an "accusation" was brought against the company within the meaning of Article 6 of the ECHR—and the hearing at which it examined the case, and twenty months between the appointment of the rapporteur and the aforementioned hearing. It considers that these timeframes, given in particular the complexity of the case (the architecture of the data processing systems implemented being highly technical), the number of breaches identified, the number of documents the rapporteur had to review, and the numerous exchanges that took place between the rapporteur and the company during the adversarial process, are in no way unreasonable.
25. The restricted panel further notes that, while the case was initially scheduled to be examined at the hearing on October 16, 2025, the company submitted an analysis on October 7, 2025, challenging the classification of the data stored in its warehouses as personal data (an argument it had never previously raised). Thus, it was only due to the submission of this new evidence that the chair of the restricted panel decided to postpone the closing of the investigation and that a new adversarial phase was initiated, allowing the rapporteur to respond and the company to submit final observations.
26. Furthermore, while the restricted panel regrets that a period of twenty-one months elapsed between the last contact between the inspection delegation and the company and the appointment of a rapporteur, it nevertheless considers, firstly, that such a period is not likely to constitute a violation of Article 6 of the ECHR, for the reasons set out above, and secondly, that this period can be explained in particular by the factors listed in paragraph 24 of this decision, such as the complexity of the case, the number of documents to be analyzed, and the multiple findings that may constitute breaches.
27. In addition, the restricted panel notes that the company had the one-month period stipulated in Article 40 of Decree No. 2019/536 to respond first to the sanction report, and then to the rapporteur's observations in response. The Council of State ruled that this timeframe allowed the defendants sufficient time to prepare and effectively present their defense (CE, 10th and 9th Chambers, June 19, 2020, No. 430810, Rec., point 13). It should also be noted that, as indicated in point 25 of this decision, the company submitted a new analysis on October 7, 2025, including new arguments, which the presiding judge of the restricted panel, pursuant to Article 40, III of Decree No. 2019-536 of May 29, 2019, decided to admit. The company was also able to respond to the rapporteur's latest observations regarding this analysis, bringing to four the number of written submissions filed by IQVIA in support of its defense. Consequently, the company was able to address all the allegations against it and provide specific and detailed evidence.
28. In light of the foregoing, the restricted panel considers that the rights guaranteed by Article 6 of the ECHR have not been infringed.
2. On the alleged breach of the CNIL's audit guidelines
29. The company argues that the processing times for the case violate the principles set out in the CNIL's audit guidelines, which stipulate that "an audit procedure is carried out as quickly as possible" and that "in exceptional circumstances that lengthen the processing time, a letter is sent to the audited organization to inform it that the investigation is still ongoing." She notes that in this case, no correspondence was sent to her between her last exchanges with the control delegation on October 4, 2022, and the letter informing her of the appointment of the rapporteur on July 29, 2024, and that she could therefore not expect to be subject to a sanction procedure.
30. The restricted panel notes that the CNIL's audit charter, published on its website, aims to ensure the smooth running of audit missions by raising awareness of them and outlining the most common practical procedures for conducting audits. The restricted panel considers that while this charter provides greater predictability regarding the methods used by CNIL auditors, it is not intended to replace the applicable legal provisions, which do not stipulate a specific timeframe between the audit procedure and the appointment of a rapporteur. The charter further specifies that while the investigation is carried out "as quickly as possible," it "nonetheless takes place over a period of several months." Given the specific circumstances mentioned above, the restricted panel considers that the duration of the investigation, although significant, does not appear excessive.
31. Furthermore, while the restricted panel regrets that the organization was not informed that the investigation was still ongoing, this circumstance cannot, however, render the procedure irregular in any way.
B. On the processing in question and the liability of IQVIA OPERATIONS FRANCE
32. The restricted panel notes that IQVIA was authorized by the CNIL (French Data Protection Authority) to establish two health data warehouses, LRX and EMR, for research, study, and evaluation purposes, and that the present procedure primarily concerns the potential non-compliance with the authorizations granted.
33. Following the "SRB" judgment rendered on September 4, 2025, by the Court of Justice of the European Union, the company introduced new arguments aimed at challenging the classification of the data contained in these warehouses as personal data. It also denies being responsible for the initial stages of the processing related to the creation of the data warehouses.
34. In light of this new information, the restricted panel considers that, before examining the complaints raised by the rapporteur, it is necessary, firstly, to present the purposes and methods of populating the LRX and EMR data warehouses (1), secondly, to examine IQVIA's responsibility in the creation of these data warehouses (2), and thirdly, to determine whether the data contained therein should be classified as personal data (3).
1. Presentation of the LRX and EMR data warehouses
a. On the LRX Data Warehouse
35. Resolution No. 2018-289 of September 12, 2018, stipulates that the LRX data warehouse "is intended to enable non-interventional studies aimed at evaluating the proper use of medication in real-world settings, and the scientific and statistical analysis of phenomena related to persistence, compliance, adherence to prescriptions, and contraindications."
36. To create this data warehouse, IQVIA collects data related to medication sales from approximately 14,000 partner pharmacies, as well as, when the pharmacist agrees (which is the case for approximately 10,000 pharmacies), a unique identification code allowing for longitudinal tracking of each patient's journey. In its presentation brochure for pharmacists, the company mentions "20 million anonymized patients followed over time."
37. In practice, the procedure implemented by IQVIA is as follows: when the pharmacist records medication sales in their pharmacy management software (hereinafter, "PMS"), a module integrated into this software (developed by the PMS vendor on behalf of IQVIA and according to specifications defined by the latter) extracts the data and generates a data stream called Pharmastat. This stream includes not only data relating to medication sales but also a patient identification code, generated by the extraction module using a hash function based on the INS-C (National Health Identifier assigned to individuals covered by health insurance, usable throughout the healthcare system and which links the patient to their health data), as well as the first name, year of birth, and gender of the individual concerned. Each patient is thus assigned a unique code, which is the same regardless of the partner pharmacy they visit.
38. This code, associated with product dispensing data, is transmitted successively to two trusted third parties designated by IQVIA: first, company [X], then company [Y]. Each of these third parties will perform a new hash of the identification code to reduce the risk of patient re-identification.
39. The pseudonymized data is then uploaded to the LRX data warehouse.
40. In exchange for providing this data, the company provides partner pharmacies with a dashboard of their sales data, allowing them to compare their activity with that of other pharmacies and manage their inventory.
b. On the EMR Data Warehouse
41. Resolution No. 2021-015 of February 4, 2021, stipulates that the EMR data warehouse must be used "to conduct studies on the evaluation and analysis of healthcare practices in general medicine."
42. This data warehouse is fed by two data streams collected from physicians:
- the "[Z+]" stream […], which contains data from consultations conducted by general practitioners and specialists using software published by [Z], which has a contract with IQVIA;
- the "DA" (disease analysis) stream, which contains data from consultations conducted by general practitioners using software published by […] and […]. To receive this data, IQVIA has contracted directly with each physician in the panel, within the framework of the "Medical 21" network.
43. These data streams are transferred to a platform called "EMR Hub," hosted by [Y], a certified "HDS" (health data hosting) trusted third party, which then uploads them to the EMR data warehouse.
44. Regarding the "DA" data stream, the data undergoes an initial pseudonymization process within the physician's software, followed by a second pseudonymization process performed by [Y] Company.
45. Regarding the "[Z+]" data stream, the data simply passes through the "EMR Hub" without any change to its format.
46. For patients, the following data is collected: identification data (year of birth, sex, marital status, number of children, socio-professional category) as well as health data from consultations (date of visit, diagnosis, symptoms, allergies, weight, height, pulse, prescriptions, vaccinations, examinations, sick leave, etc.).
47. Each patient has a unique identifier, which differs for each physician consulted. The company specified that no correlation is possible between different practices.
48. In exchange for providing this data to IQVIA, physicians participating in the panel can benefit from the company's publications and participate in interventional studies.
49. During the audit, the company indicated that the data in the EMR data warehouse, across all data streams, came from approximately 2,000 physicians. However, its brochure presenting the "Medical 21" observatory to physicians mentions 3,000 partner physicians.
2. On the responsibility of IQVIA OPERATIONS FRANCE with regard to the processing carried out for the purposes of establishing the LRX and EMR warehouses
50. Article 4, point 2 of the GDPR defines "processing" as "any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction". The Court of Justice of the European Union (hereinafter, "CJEU") has reiterated that "it follows from this definition that the processing of personal data may consist of one or more operations, each of which relates to one of the different stages that the processing of personal data may encompass" (CJEU, Second Chamber, 29 July 2019, Fashion ID GmbH, C-40/17).
51. Article 4(7) of the GDPR defines the controller as "the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data." Guidelines 07/2020 concerning the concepts of controller and processor in the GDPR, adopted on 7 July 2021 by the European Data Protection Board (hereinafter, "the EDPB"), specify that "determining the purposes and means amounts to deciding respectively on the 'why' and the 'how' of the processing: for a particular processing operation, the controller is the actor who has determined the reason why the processing takes place (i.e., 'for what purposes' or 'why') and how that objective will be achieved (i.e., what means must be implemented to achieve the objective)." These guidelines further reiterate that "the concepts of controller and processor are functional concepts: they aim to allocate responsibilities according to the actual roles of the parties. […] In other words, the allocation of roles should generally result from an analysis of the factual elements or circumstances of the case and, as such, is not negotiable" (paragraph 12). "All relevant factual circumstances must be taken into account to determine whether a given entity exercises decisive influence over the processing of personal data in question" (paragraph 25).
a. Regarding the LRX Data Warehouse
52. The rapporteur considers that IQVIA should be held responsible for all processing carried out to create the LRX data warehouse, from the moment the data is integrated into the pharmacy management software and transmitted to the first trusted third party, [X].
53. IQVIA maintains that pharmacists are solely responsible for transmitting their clients' data to [X], arguing that this transmission should be considered a separate processing operation, and not one step in a single processing operation, as suggested by the rapporteur. It therefore believes it cannot be held responsible for this operation, as the processing of the data in question only becomes its responsibility upon arrival on the platform of the second trusted third party, [Y]. In support of this analysis, the company refers to the clauses of the contract between the pharmacists and company [X] (which designates the latter as a subcontractor of the pharmacist, who is designated as the data controller). It also argues that, as healthcare professionals bound by professional secrecy, pharmacists are necessarily responsible for disclosing their clients' data to a third party.
54. The restricted panel notes first that IQVIA OPERATIONS FRANCE was authorized by the CNIL (French Data Protection Authority) to establish the LRX data warehouse as the data controller, based on its legitimate interests. The objective is indeed to allow the company, within the framework of its consulting and research activities, to "conduct non-interventional studies aimed at evaluating the proper use of medication in real-world settings, and the scientific and statistical analysis of phenomena related to persistence, compliance, adherence to prescriptions, and contraindications."
55. If, in order to create this data warehouse, the company has chosen to implement a procedure requiring the involvement of various actors (the pharmacist, company [X], company [Y], and IQVIA), who are successively required to physically process the data in question, the restricted panel notes that the operations carried out by these actors (the collection of the National Identification Number (NIR) associated with the prescription data, the calculation of the National Health Identifier (INS-C), the various hashing steps, the substitution of the patient identifier, the reception of the data on IQVIA's servers, and its storage) all pursue the same objective, determined by IQVIA, namely, to ultimately enable the creation of the data warehouse. They must therefore be considered as part of a single processing operation and cannot, contrary to the company's assertion, be considered in isolation.
56. This is particularly true of the operations carried out at the pharmacy level. Indeed, as recalled in paragraphs 37 to 39 of this decision, when the pharmacist records drug sales in their online pharmacy management system (LGO), a module integrated into this software extracts the data and generates a data stream called the "Pharmastat stream." This stream is then transmitted to the first trusted third party, company [X], whose role is to split this "Pharmastat stream" into several streams, including the "LRX stream," which feeds the LRX data warehouse (the other streams being used to populate other databases of the company IQVIA).
57. The restricted panel notes first that, in its second set of observations in response, submitted on June 26, 2025, the company itself admits to having "defined a comprehensive stream and pseudonymization process, via several processes and several trusted third parties." She thus criticizes the rapporteur for failing to consider this overall process and for isolating a part of it, namely the transmission of data by pharmacies to the first trusted third party, emphasizing that this "is not […] data processing as such."
58. The restricted panel then points out that the aforementioned extraction module is developed by LGO's publishers, exclusively for IQVIA, based on specifications drawn up by the latter. The contract between IQVIA and the publishers, which expressly designates the former as the data controller and the latter as its data processors, provides for the transfer by the publisher, to IQVIA, of the intellectual property rights to the modules in question, and specifies that the publisher must process the data only in accordance with IQVIA's written instructions, and in compliance with the Pharmastat standard (which defines the composition of the "Pharmastat flow").
59. Furthermore, it appears from the evidence gathered that this Pharmastat standard is defined by IQVIA, which specifies, in particular, the format and structure of the files (alphanumeric fields containing a list of defined characters, file compression before transmission), the frequency of collection and transmission, the handling of the data (destruction of files that have been successfully transmitted or, in the event of an incorrect transmission, retention for subsequent retransmission), as well as the procedures for their transmission to [X] (IP protocol configured directly by IQVIA with the pharmacist). IQVIA may also unilaterally modify this standard if business needs so require.
60. It follows from the foregoing that, from the moment the data is integrated into the pharmacist's LGO and processed by the extraction module on behalf of IQVIA, the latter must be considered responsible for the processing carried out in this way, insofar as it determines both the purpose (namely, the construction of an "LRX feed" to populate the LRX warehouse) and the means (namely, the methods of collecting and transmitting this data to successive trusted third parties, and in particular to [X]).
61. The restricted panel notes that this analysis is supported by various elements of the investigation, which designate IQVIA as responsible for all the processing implemented in the context of creating the LRX warehouse, without limiting this responsibility to certain stages of said processing. Thus, the patient information leaflet states that its purpose is "to present [them] with the conditions under which [their] data is collected and processed by IQVIA within the framework of the LRX project," the latter being defined as "a project of public interest, whose objective is to create a data warehouse dedicated to conducting research, studies, and evaluations in the field of health." It is specified that "the data collected by IQVIA is processed on the legal basis of IQVIA's legitimate interest (and the authorization granted by the CNIL […]), in its capacity as data controller." The restricted panel also notes that this information notice was prepared by IQVIA itself and that the contract between IQVIA and the pharmacists stipulates that the pharmacists' contractual obligation to display and provide it to their patients is "to enable IQVIA to fulfill its information obligations in accordance with the Regulations." Similarly, the Pharmastat network presentation brochure, prepared by IQVIA and intended for pharmacists, specifies that "Pharmastat is part of IQVIA" and invites individuals to contact IQVIA if they have "any questions about how [their] personal data may be processed within the Pharmastat framework." Furthermore, during the on-site inspection conducted on July 6, 2021, IQVIA confirmed that it was "responsible for the processing of the LRX data warehouse and its maintenance." However, the operations at issue in these proceedings, and in particular the collection of patient data through pharmacies, as well as its transmission to two successive trusted third parties, do indeed contribute to the input of data into the LRX data warehouse.
62. Regarding the pharmacists, whose responsibility is emphasized by the company in its pleadings, it should be noted that the purpose of these proceedings is to verify IQVIA's compliance with data protection regulations and the authorizations granted to it by the CNIL (French Data Protection Authority). Therefore, the restricted panel is not required to rule on the potential joint liability of the pharmacists, since no complaint has been made against them and, in any event, this potential joint liability would not limit or diminish IQVIA's liability for the alleged actions.
63. In conclusion, the restricted panel considers that IQVIA must be held responsible for all operations implemented in the creation of the LRX data warehouse, from the moment data is collected at the pharmacy level, notwithstanding the potential liability of other parties with whom the company has contracted.
b. On the EMR data warehouse
64. The rapporteur considers that, as with the LRX data warehouse, the company must be held responsible for the processing carried out in the creation of the EMR data warehouse.
65. IQVIA, on the other hand, maintains that the physician acts as the data controller with regard to the communication of their patients' data, and that IQVIA only intervenes once [Y], a trusted third party, receives the data.
66. The restricted panel notes that, as with the LRX warehouse, the company IQVIA was authorized by the CNIL to proceed with the creation of the EMR warehouse as data controller, on the legal basis of its legitimate interests, in order to allow it, within the framework of its activities, to "conduct studies on the evaluation and analysis of care practices in general medicine".
67. For the same reasons as those set out in paragraph 55 of the decision, it considers that all the operations carried out by the various actors involved in the physical processing of the data in question (the physician, and where applicable, company [Z], company [Y], and IQVIA) constitute a single processing operation, comprised of several stages, and that these stages cannot be considered in isolation.
68. It notes that IQVIA determines both the purpose (namely, to create a data flow to populate the EMR data warehouse) and the means of these operations (in particular by choosing which actors to contract with and by setting the collection methods for the "Medical 21" and "Disease Analyzer" standards). Furthermore, it is clear from the patient information leaflet prepared by IQVIA that the company presents itself as the data controller for the data collected for the purpose of creating the EMR data warehouse.
69. In these circumstances, the restricted panel considers that IQVIA must be held responsible for all operations carried out in the creation of the EMR data warehouse, from the moment the data in question was collected, notwithstanding the potential liability of other parties with whom the company contracted.
c. On studies conducted using the LRX and EMR data warehouses
70. Regarding the studies conducted using the LRX and EMR data warehouses, which constitute separate data processing activities, the company indicated that it is the data controller for the studies it conducts on its own behalf. These studies consist of analyzing patient care, according to the pathologies they present and the treatments they receive (for example, the analysis of the care of patients treated for idiopathic pulmonary fibrosis, the analysis of the care of patients treated with an antipsychotic, or the analysis of the therapeutic management of hypertension).
71. The restricted panel considers that, insofar as it determines both the purposes and the means, the company must be regarded as the data controller for the studies carried out on its own behalf using the LRX and EMR data repositories.
3. On the nature of the data contained in the LRX and EMR data repositories
72. Article 4, point 1 of the GDPR defines personal data as "any information relating to an identified or identifiable natural person [...]; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."
73. Article 4, point 5 of the GDPR defines pseudonymization as "the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person".
74. Recital 26 of the GDPR specifies that "personal data which have been pseudonymized and which could be attributed to a natural person by means of additional information should be treated as information relating to an identifiable natural person. To determine whether a natural person is identifiable, account should be taken of all the means reasonably likely to be used by the controller or by any other person to identify the natural person directly or indirectly, such as targeting. To determine whether means are reasonably likely to be used to identify a natural person, account should be taken of all objective factors, such as the cost of identification and the time required for such identification, taking into account the technologies available at the time of processing and developments therein. Therefore, the principles relating to data protection do not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person, nor to personal data which has been anonymized in such a way that the data subject is not or more identifiable. This Regulation therefore does not apply to the processing of such anonymous information, including for statistical or research purposes."
75. As early as 2014, the Article 29 Working Party on data protection (hereinafter referred to as "WP29"), which became the EDPB, adopted an opinion on anonymization techniques (Opinion 05/2014 of 10 April 2014), specifying that a process could, in particular, be considered anonymization when it withstands the following three types of risks:
- individualization, which corresponds to the possibility of isolating some or all of the records identifying an individual within a dataset;
- correlation, which consists of the ability to link at least two records relating to the same data subject or group of data subjects;
- Inference, which is the ability to deduce, with a high degree of probability, the value of an attribute from the values of a set of other attributes.
76. If these three types of risks cannot be met, the Article 29 Working Party (WP29) considers that data can still be considered anonymous if the data controller can demonstrate that re-identification is not possible by "reasonable means."
77. The Court of Justice of the European Union has also been called upon to rule on the concept of personal data on several occasions.
78. In the "Breyer" judgment, delivered under Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (CJEU, Second Chamber, 19 October 2016, C-582/14), the Court held that "in order to determine whether a person is identifiable, account must be taken of all the means which could reasonably be used, either by the controller or by another person, to identify that person" (paragraph 42).
79. This position was confirmed in the "OC v European Commission" judgment (CJEU, Sixth Chamber, 7 March 2024, C-479/22). In this case, the CJEU held that "all objective factors, such as the cost of identification and the time required for it, taking into account the technologies available at the time of processing and their evolution" must be considered (paragraph 50). The CJEU further clarified in this judgment that "it is inherent in the 'indirect identification' of a person that additional information must be combined with the data in question for the purpose of identifying the person concerned" (paragraph 55) and that "the applicant was not required to provide proof that she had actually been identified [...], since such a condition is not provided for in Article 3(1) of Regulation 2018/1725, which merely requires that a person be 'identifiable'" (paragraph 61) by "reasonable means".
80. Finally, in a judgment in "SRB" of 4 September 2025, the Court clarified that "pseudonymized data should not be considered as constituting, in any event and for any person, personal data for the purposes of the application of Regulation 2018/1725, insofar as pseudonymization may, depending on the circumstances of the case, effectively prevent persons other than the controller from identifying the data subject in such a way that, for them, the latter is not or is no longer identifiable" (paragraph 86). The Court considers in this regard that, while technical and organizational pseudonymization measures may cause data to lose their "personal character" for a recipient, this presupposes, however, that, firstly, that recipient "is not able to lift these measures during any processing [of said data] carried out under its control" and, secondly, that "the said measures [are] effectively […] capable of preventing [the recipient] from attributing the same [data] to the data subject also by using other means of identification such as cross-referencing with other elements, in such a way that, for that company, the data subject is not or is no longer identifiable" (paragraph 77) (CJEU, First Chamber, 4 September 2025, C-413/23).
81. For its part, the Council of State recently had the opportunity to rule on the nature of the data contained in databases fed by data collected from doctors and pharmacies, very similar to those created by the company IQVIA. It noted that the applicant companies "held a massive amount of data, collected from medical practices or pharmacies, […] [including] identifying information such as age, gender, or socio-professional category, as well as health data such as, in particular, medical records, prescriptions, sick leave, vaccinations, for data transmitted by doctors, and medications purchased and the prescriber, for data transmitted by pharmacies. […] In addition to [this] precise data on the individuals concerned […], the data collected includes information such as the date and sometimes the exact time of the medical visit or purchase, as well as direct or indirect information on the location or identification of the healthcare professionals involved." The Council of State thus emphasized that it was "possible, based on this data, to trace care pathways and to individualize clients and their pathologies," and that "such individualization within the data set required only a little time and resources." It considered that the CNIL had, in this case, "carried out a concrete assessment of the risk of re-identification of the data and established that it was possible to lift the pseudonymization of the persons concerned by reasonable means," and that it was therefore right to conclude that the "data in question, although pseudonymized, was not anonymized" (CE, 10th and 9th chambers, February 13, 2026, Nos. 498628, 498629 and 498749, T.).
82. The rapporteur considers that the data in the LRX warehouses is indeed personal data, and that the risk of re-identification of the individuals concerned is, in his view, very real.
83. In its latest observations in response, which are based on the report prepared on its behalf by the company […], the company maintains that the data in the LRX and EMR warehouses is anonymous and that, therefore, the obligations of the GDPR and the French Data Protection Act are inapplicable and the authorizations issued by the CNIL have, in effect, become moot. The company bases this analysis on the aforementioned SRB ruling, which, according to its interpretation, "clarified that the concept of personal data is relative and not absolute" and "that the same set of data can constitute personal data subject to all the constraints of the GDPR for entity A and perfectly anonymous data for another entity B, if the latter is unable to identify the data subjects using reasonable and lawful means." However, it considers that in this case, given the pseudonymization of the data in the LRX and EMR repositories, the means that IQVIA would have to implement to re-identify the data subjects would be either unreasonable or unlawful, and concludes that the data in question must be considered, in its view, not as personal data.
a. Regarding IQVIA's position up to the SRB ruling
84. The restricted panel notes first that, until the submission of the report prepared on its behalf by the company […], IQVIA had never disputed that the data contained in the LRX and EMR data warehouses constituted personal data. It was on the basis of this classification, and as the data controller, that it filed applications with the CNIL in 2017 and then in 2019 seeking authorization, pursuant to Article 66 of the French Data Protection Act, to implement "automated processing of personal data" for the purpose of creating these data warehouses.
85. The evidence gathered during the investigation establishes that the company had taken care to analyze the nature of the data processed within the various data warehouses it had implemented. She clarified, particularly during the on-site inspection conducted on July 6, 2021, that she considered the data comprising the "[Z+]" stream, originating from the medical software published by [Z] and intended to populate the EMR data warehouse, to be, in her opinion, not anonymous data, even though [Z] maintained the contrary. IQVIA had, in fact, informed the CNIL of this disagreement with [Z]. The restricted panel notes that, by a decision dated September 5, 2024, the patient data collected by [Z] (which had taken over the activities of [Z]) from physicians was considered to be personal data, and that a breach of Article 66 of the French Data Protection Act was established (CNIL, FR, Sanction, September 5, 2024, No. SAN-2024-013, published). This decision was upheld by the Council of State in a ruling dated February 13, 2026 (see point 81 of this ruling).
86. These elements demonstrate that, prior to the SRB ruling, the company had conducted an analysis leading it to conclude that the processing carried out within the framework of the LRX and EMR data warehouses did indeed constitute the processing of personal data. It is therefore necessary to examine the potential impact of the SRB ruling on the processing operations at issue in the present proceedings.
b. On the scope of the SRB judgment with regard to the processing carried out by IQVIA in connection with the creation of the LRX and EMR data warehouses
87. The company justifies its new analysis by stating that the SRB judgment, which it considers to be a "strong departure from the position of data protection authorities up to that date regarding the interpretation of the concept of personal data," has a direct effect on the assessment of the nature of the data contained in the LRX and EMR data warehouses.
88. The restricted panel notes, first of all, that this judgment clearly demonstrates that the CJEU did not intend to break with its previous decisions, but rather to maintain continuity with them. This is evidenced by the numerous references to the aforementioned Breyer and OC judgments (paragraphs 78 to 79 of this decision). While acknowledging that pseudonymized data could, in theory, lose its personal character, the Court reiterated that "the relevant perspective for assessing the identifiable nature of the data subject depends essentially on the circumstances characterizing the data processing in each particular case" (paragraph 100 of the judgment, emphasis added). It is therefore in light of the specific facts of the case, the characteristics of the processing in question, and the role played by the various actors involved in processing the data, that the personal nature of the data must be assessed. In this regard, the Court makes a distinction depending on whether the organization concerned is the data controller or simply the recipient of pseudonymized data, specifying that "pseudonymization may, depending on the circumstances of the case, effectively prevent persons other than the data controller from identifying the data subject in such a way that, for them, the data subject is not or is no longer identifiable" (paragraph 87 of the judgment, emphasis added).
89. In the case that gave rise to the SRB judgment, the Single Resolution Board (hereinafter, "SRB") launched a consultation phase with shareholders and creditors, collecting their written contributions. These comments were filtered, categorized, and aggregated, and each was assigned a randomly generated alphanumeric code (without it being possible to group all or part of the comments written by the same person). The pseudonymized data was then transmitted to an audit firm, acting as an independent evaluator. It is in this context that the Court considered that "as is normally the case for the data controller who has carried out the pseudonymisation, the CRU has, in this case, additional information enabling the comments transmitted [to the audit firm] to be attributed to the person concerned, so that, for it, these comments retain, despite the pseudonymisation, their personal character" (paragraph 76 of the judgment). "With regard to the audit firm to which the CRU transmitted pseudonymized comments, the technical and organizational measures [of pseudonymization] may […] have the effect that, for that company, these comments are not personal in nature. This presupposes, however, firstly, that [the audit firm] is not able to lift these measures during any processing of said comments carried out under its control. Secondly, said measures must effectively prevent [the audit firm] from attributing these same comments to the person concerned also by using other means of identification such as cross-referencing with other elements, in such a way that, for that company, the person concerned is not or is no longer identifiable" (paragraph 77 of the judgment).
90. However, in this case, the restricted panel notes that IQVIA is in a very different situation since, as demonstrated in paragraphs 54 to 63 and 66 to 69 of this decision, it is not simply a recipient of pseudonymized data, but must be considered responsible for the entire processing operation, from the initial data collection stage with pharmacies or doctors. As previously mentioned, the company itself admits to having "defined a comprehensive process of data flow and pseudonymization, via several processes and several trusted third parties." The restricted panel considers that this status as data controller alone precludes the data from being considered anonymous, given the circumstances of this case.
91. Furthermore, as will be demonstrated below, the data processed by IQVIA differs significantly from the comments submitted to the audit firm mentioned in the SRB judgment, particularly given its complexity and the fact that it allows for longitudinal monitoring of each patient via a unique identifier.
92. The restricted panel therefore considers that the quality of the organizations in relation to the data processed and the richness of the information examined in the context of these proceedings are too far removed from those that gave rise to the SRB judgment for a relevant comparison to be drawn.
c. On the risks of re-identifying individuals whose data are held in the LRX and EMR data repositories
93. The company argues that the means it would have to implement to re-identify individuals whose data are held in the LRX and EMR repositories would be either impractical (particularly because they would involve a disproportionate effort in terms of time, cost, and manpower) or unlawful, whether it be reconstructing the pseudonymization chain or cross-referencing this data with external data.
94. The rapporteur, on the contrary, considers that, given the wealth of data contained in these repositories and the very purpose of the processing, which is to perform longitudinal monitoring of each patient's care pathway and thus to be able to isolate each individual, it appears more than plausible to be able to lift the pseudonymization of the individuals concerned by reasonable means.
95. As a preliminary matter, the restricted panel recalls, firstly, that in assessing whether a set of data is personal or not, the intention, interest or motivation of the data controller or third party to re-identify the data subjects are not relevant factors to be taken into consideration. This notion of "intention" is therefore not found in either Article 4, point 1 of the GDPR or in recital 26. In a binding decision of July 2021, the EDPB recalled that "what is relevant for the GDPR to apply, i.e. for data to be considered 'personal', is rather whether the data relates to a person who can be identified, directly or indirectly, and whether the controller or a third party has the technical capacity to identify a data subject within a set of data. This possibility can materialize independently of whether this technical capacity is associated with the motivation to re-identify or identify a data subject" (Binding Decision 1/2021 concerning the dispute relating to the draft decision of the Irish supervisory authority concerning Whatsapp Ireland pursuant to Article 65(1)(a) of the GDPR, adopted on 28 July 2021). Thus, in this case, it is irrelevant whether IQVIA intends to re-identify the individuals whose data are contained in its LRX and EMR repositories—or even has an interest in doing so. It is sufficient that the company has the ability to re-identify them, using reasonable means, for the data in question to be classified as personal data.
96. Furthermore, the restricted panel notes that the company asserted, at the time of the audit, that the data contained in the LRX and EMR repositories were indeed personal data concerning individuals' health.
97. Primarily and firstly, the restricted panel notes that the very purpose of the processing at issue in the context of these proceedings is to ensure longitudinal monitoring of the individuals whose data are contained in the LRX and EMR repositories. To enable such monitoring, the company collects a significant amount of information relating both to patient identification and to their health. The EMR data warehouse contains, among other things, the patient's year of birth, sex, marital status, number of children, socio-professional category, date(s) of doctor's visit(s), diagnosis, symptoms, allergies, weight, height, pulse, medication prescriptions, vaccinations, examinations, and sick leave. The LRX data warehouse contains the individual's year of birth, sex, information about the prescribing specialist, and prescription details.
98. To isolate each individual within these data warehouses and track their progress over time, IQVIA has implemented a process to assign each individual a unique identifier (as described below), which is combined with all the aforementioned data.
99. Regarding the LRX warehouse, each pharmacy customer is assigned a unique identifier, which remains the same regardless of the partner pharmacy they visit. This code, combined with product dispensing data, allows for the grouping of all purchases made by the same customer at any IQVIA partner pharmacy.
100. Regarding the EMR warehouse, each patient also has a unique identifier for a given physician. While it is not possible to correlate data from different physicians for the same patient, the company can nevertheless use this code to track each patient's journey within the same practice.
101. The restricted training notes that location data is added to all of this information, allowing patients to be located by geographic zones composed of groups of nine pharmacies and five physicians of the same specialty.
102. Thus, the fact that each patient has a unique identification code, linked to numerous data such as their age, sex, all prescriptions they have received, and their geographical location, in order to allow society to track their care pathway over time, means that society can easily isolate each individual and that the treatments in question are vulnerable to the risk of individualization, as specifically mentioned in the aforementioned "G29" opinion (see points 75 and 76 of this decision). This point is not contested by society.
103. The restricted panel notes that, in a similar case, this accumulation of information on patient care, as well as the possibility of individualizing it, was extensively highlighted by the Council of State in its aforementioned decision of February 13, 2026 (see paragraph 81 of this decision), concluding that the data could not be considered anonymous.
104. Secondly, the restricted panel reiterates that, in order to assess the risk of re-identification of the individuals concerned, it is necessary to determine whether the pseudonymity can be lifted by reasonable means, including by cross-referencing non-directly identifying data with external data, particularly with information available on the internet.
105. In this case, while the data in the LRX and EMR repositories are not directly identifying (which is the nature of pseudonymization), the restricted panel notes that, given the wealth of information these repositories contain, the use of various external sources could easily allow for the re-identification of the individuals concerned.
106. The example given by the rapporteur in his third report illustrates this risk. He notes that the company conducts real-world studies on the management of patients treated for spinal muscular atrophy (SMA) using the LRX repository, through the analysis of the role of prescribers and the age of the patients treated (the list of studies conducted by IQVIA is publicly accessible on its website). As stated in the patient information sheet (also publicly available), "the study population consists of patients meeting the following selection criteria: at least one prescription for spinal muscular atrophy (SMA) dispensed by a community pharmacy during the period 2024." The rapporteur notes that, as with many rare diseases or diseases affecting children, there are numerous support and sharing groups on social media, sometimes revealing a significant amount of information about the locations and timeline of care, as well as the treatments administered. By browsing one of these groups on Facebook, the rapporteur was able to access a great deal of information […] [editor's note: this information includes a child's healthcare history, the locations of their care, their place of residence, and the full names of the mother and child]. The restricted panel agrees with the rapporteur that, based on this information, particularly the established chronology, the locations of care provided, and the medications dispensed, it would be easy to isolate the patient within the LRX database (which notably contains the patient's age, prescriptions issued, and geographic area) and thus re-identify her.
107. The restricted panel notes that the rapporteur states in his written submissions that these searches took only a few minutes with simple internet access. The company cannot therefore validly argue that such a cross-check would be impractical because it would involve lengthy and complex searches and constitute a disproportionate effort given the time, cost, and manpower required. The restricted panel reiterates, firstly, that the fact that IQVIA would derive no benefit from this operation is irrelevant (see point 96 of this decision) and, secondly, that it is sufficient for a single person to be re-identified by reasonable means for the data in the database to be classified as personal data.
108. The technical possibility of re-identification is further demonstrated by the fact that, when a patient wishes to object to the processing of data already in the EMR repository, they must provide the company with certain information (date and time of the appointment, content of the prescription) which allows the company to re-identify the person concerned and comply with their objection. The patient information leaflet confirms that, if they so wish, they have the option of "providing IQVIA with additional information that could help it to identify them, if necessary, in order to allow the exercise of their rights." These elements – even if they originate from the individuals concerned in these specific cases – demonstrate that, generally speaking, with some information regarding the consultations carried out, IQVIA is perfectly capable of removing the pseudonymization from the data stored in the LRX and EMR repositories.
109. Nor can the company argue that the aforementioned means of re-identification could not be considered "reasonable" on the grounds that they are "illegal" because they contravene, firstly, the stipulations of the contracts concluded by the company with its partners and, secondly, the rules governing data protection.
110. To assess this potential illegality, the restricted panel recalls that, in its Breyer judgment, the CJEU held that the means could not be considered reasonable "if the identification of the person were prohibited by law" (paragraph 46 of the judgment). This clarification was reiterated in paragraph 82 of the SRB judgment.
111. On the one hand, the restricted panel considers that by including contracts within what is "prohibited by law," as defined by the CJEU's case law, the company is misinterpreting the aforementioned judgments. Indeed, it cannot be considered that the company's conclusion of contracts with its partners that prohibit them from transmitting information enabling re-identification would have the effect of rendering the identification of the person "prohibited by law." The restricted panel considers that the legal prohibition mentioned by the CJEU cannot arise from the mere meeting of minds between two parties, as this risks allowing actors to easily circumvent the rules governing the protection of personal data, since they could simply stipulate, through contractual clauses, that such re-identification is prohibited, even though in practice the risk persists because it is technically feasible.
112. Furthermore, the identification of an individual by cross-referencing data in data warehouses with data available from open sources cannot be considered, in the absence of a specific and explicit prohibition to that effect, as "prohibited by law" within the meaning of this case law, even though the compliance of such open-source data collection practices with the GDPR may, in certain circumstances, be questionable. In this regard, the ease with which data can be obtained from open sources and cross-referenced with data in the LRX and EMR repositories, without resorting to any manifestly illegal means, suggests that the risks of re-identification are real.
113. It follows from all these elements that the pseudonymization measures implemented by IQVIA only reduce the risk of this data being linked to the identity of the individuals concerned, but do not eliminate it. The data in the LRX and EMR repositories must therefore be considered personal data, subject to the rules of the GDPR and the French Data Protection Act.
C. On the breaches of Article 66 of the French Data Protection Act concerning the establishment of the LRX and EMR data warehouses
114. The processing of personal data in the healthcare sector is governed by Articles 64 et seq. of the French Data Protection Act.
115. Article 66 of this law provides that:
"I - The processing operations covered by this section may only be implemented in consideration of the public interest purpose they serve. Ensuring high standards of quality and safety of healthcare and of medicines or medical devices constitutes a public interest purpose.
II - Standard frameworks and regulations, as defined in points b and c of paragraph 2 of section I of Article 8, applicable to the processing operations covered by this section, are established by the National Commission for Information Technology and Civil Liberties (CNIL), in consultation with the health data platform mentioned in Article L. 1462-1 of the Public Health Code and public and private bodies representing the stakeholders concerned.
Processing operations that comply with these frameworks may be implemented provided that their controllers first submit a declaration attesting to this compliance to the National Commission for Information Technology and Civil Liberties. […]
III - The processing operations mentioned in section I that are not compliant Data processing operations related to a standard mentioned in paragraph II may only be implemented after authorization from the National Commission for Information Technology and Civil Liberties (CNIL). The authorization request must be submitted in the manner prescribed in Article 33 […].
116. Thus, the processing of personal data in the health research sector may only be implemented after authorization from the CNIL, or on the condition that it complies with a standard mentioned in paragraph II of this article.
117. In this case, IQVIA was authorized by the CNIL, pursuant to Article 66 above (formerly Article 54), to establish two personal data warehouses, including health data.
118. These authorizations, formalized by resolutions no. 2018-289 of July 12, 2018, and no. 2021-015 of February 4, 2021, make the implementation of the processing operations in question subject to a number of safeguards, relating in particular to the information and rights of the data subjects, as well as to the security of the data processed. These safeguards are specifically designed to ensure compliance with the legal and regulatory provisions relating to the protection of personal data. They take into account the nature of the data in question, namely sensitive data relating to the health of the data subjects, as well as its volume.
119. In order to assess the merits of the complaints raised by the rapporteur against the company in connection with these obligations, the restricted panel will examine whether the establishment of the LRX and EMR data warehouses is carried out in accordance with the procedures set out in the aforementioned resolutions.
120. The restricted panel wishes to clarify that, for the sake of clarity in its decision, the breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) concerning studies conducted using the LRX data warehouse will be examined following the breach of Article 14 of the GDPR (see II., D. and E.).
1. Preliminary Observations
a. On the Distinction Between Authorization Request and Authorization
121. The company argues that it cannot be accused of a breach of Article 66 of the French Data Protection Act since its practices correspond to the commitments made in its authorization requests. It maintains that the information provided in support of these requests, which was not requested by the CNIL (French Data Protection Authority), should be considered validated and therefore constitute "part of the authorization." As an example, it argues that the information notice provided to individuals affected by the EMR processing is the same as the one it submitted to the CNIL in support of its authorization request, that this document did not elicit any comments from the Commission's services, and that it must therefore be considered compliant.
122. The restricted panel recalls that, pursuant to Article 66, III of the French Data Protection Act, processing operations involving data concerning individuals' health, when not compliant with a reference framework, may only take place after authorization from the Commission. These provisions specify that "the authorization request must be submitted in the manner prescribed in Article 33," which lists the information that must be provided in support of this request (purposes of the processing, personal data processed, categories of data subjects, data retention periods, measures taken to ensure the security of the data, etc.). Article 66, V of the French Data Protection Act (Loi Informatique et Libertés) stipulates that "the National Commission for Information Technology and Civil Liberties (CNIL) shall issue its decision within two months of receiving the request. However, this period may be extended once for the same duration by a reasoned decision of its president or when the Ethics and Scientific Committee for Research, Studies and Evaluations in the Field of Health is consulted pursuant to the second paragraph of Article 72. When the CNIL has not issued its decision within this period, the authorization request is deemed accepted. This provision does not apply, however, if the authorization is subject to a prior opinion pursuant to subsection 2 of this section and the opinion(s) issued are not expressly favorable."
123. In practice, when an authorization request is submitted to the CNIL, the Commission's services are responsible for processing it, in particular to verify that the application is complete. If these services consider certain elements to be imprecise or insufficient, they may request additional information from the organization regarding legal or technical points. Thus, while they are responsible for supporting stakeholders and preparing the application, the CNIL services do not have the authority to authorize or refuse the processing in question. This authority belongs to the CNIL's board (the body that constitutes the "National Commission for Information Technology and Civil Liberties," as defined in Article 9 of the French Data Protection Act), to which the application is submitted at the end of its review and which decides on the authorization request.
124. The restricted panel reiterates in this regard that the board is not bound by the processing implementation procedures outlined in the authorization request (its competence is not limited to "validating" or "invalidating" the application) and that it may, in its decision authorizing the processing, decide to strengthen certain requirements and define processing implementation conditions that differ from those set out in the authorization request submitted by the data controller.
125. It is therefore necessary to distinguish, on the one hand, the application for authorization submitted to the CNIL, which outlines the processing activities concerned and the safeguards that the data controller intends to implement and is reviewed by the CNIL's services, and on the other hand, the authorization itself, which takes the form of a decision adopted by the CNIL's board and is the only element that enables the processing activities to be carried out and thus has legal value within the meaning of Article 66 of the French Data Protection Act (unless the CNIL fails to respond within two months, in which case the application is deemed accepted pursuant to Article 66, V above). It is therefore this authorization and its terms that the organization concerned must comply with, and not the elements contained in its application (unless the decision expressly refers to them).
b. On the need to ensure data security despite the pseudonymization measures applied to them
126. The rapporteur notes that the data contained in the LRX and EMR repositories, given their sensitivity and volume, must be subject to particular vigilance, even with regard to the pseudonymization measures implemented, especially in order to prevent and detect any potential breaches.
127. In its defense, the company argues that the enhanced pseudonymization of data, a measure expressly cited in Article 32 of the GDPR, ensures the security and confidentiality of said data. It therefore considers that, even if unauthorized access to the data were to occur, it could not have negative consequences for the data subjects, given the impossibility for third parties to access or trace back to their identity. She adds that Article 34 of the GDPR stipulates that it is not necessary to inform data subjects of a data breach if the data in question is incomprehensible to any unauthorized person. In its second set of observations in response (before contesting the personal nature of the processed data), the company clarifies that it is well aware that pseudonymization can, by definition, be lifted, but disputes the likelihood of this happening.
128. The restricted panel recalls that Article 32 of the GDPR requires the controller to implement appropriate measures to ensure a level of security appropriate to the risk, "including, inter alia, as appropriate," four types of measures mentioned, including "pseudonymization and encryption of personal data."
129. Decision No. 2018-289 concerning the LRX data warehouse specifies that "in the current state of technology, and in light of the security measures implemented elsewhere, the Commission considers that the planned pseudonymization process is in line with the recommendations of the GDPR by reducing the possibilities of re-identifying individuals whose data is processed to what is strictly necessary in this context. The Commission nevertheless reiterates that pseudonymization is only a security measure aimed at reducing risks for the individuals concerned, and in no way exempts the data controller from its obligations." The authorization does indeed include other security requirements, contained in the section "on data security and traceability of actions."
130. The same applies to deliberation no. 2021-015 concerning the EMR data warehouse, which reiterates that "pseudonymization, even when enhanced, is only a security measure aimed at reducing risks for the individuals concerned and in no way exempts the various stakeholders from their obligations related to the protection of personal data." It also stipulates a number of security measures to be implemented, which are expressly mentioned in the aforementioned deliberation, such as network segmentation, strong authentication, and access logging.
131. Thus, while the enhanced pseudonymization measures implemented by the company contribute to ensuring data security and mitigating risks in the event of a breach, they are not sufficient, on their own, to consider that the security and confidentiality of the processed data are adequately guaranteed, as is also clear from the very wording of the deliberations adopted by the CNIL board on the processing operations in question.
132. It is therefore necessary to examine whether, beyond the pseudonymization measures implemented, the requirements stipulated in the authorization, particularly regarding data security, have been met by IQVIA.
3. On the LRX Warehouse: Data Security and Confidentiality
133. Article 32 of the GDPR stipulates that "1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks, of varying likelihood and severity, to the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia, as appropriate:
(a) the pseudonymisation and encryption of personal data;
(b) means to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
(c) means to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
(d) a procedure for regularly testing, analyse and assessing the effectiveness of the measures technical and organizational measures to ensure the security of the processing.
2. When assessing the appropriate level of security, particular account shall be taken of the risks presented by the processing, resulting in particular from the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed […].
134. In order to ensure compliance with these provisions, Decision No. 2018-289 of July 12, 2018, authorizing IQVIA to establish the LRX health data warehouse, includes a section on "data security and traceability of actions." Various safeguards are thus provided, such as rules relating to user authentication, connection logging and trace analysis, and network segmentation.
a. On Network Segmentation
135. Resolution No. 2018-289 of September 12, 2018, specifies that "measures are planned to ensure network security, in particular through the implementation of network segmentation."
136. In its IT hygiene guide, "Strengthening the Security of Your Information System in 42 Measures," published in January 2017 and designed to support organizations in securing their information systems, the French National Cybersecurity Agency (ANSSI) reiterates that, to secure a network, it is necessary to segment it and implement partitioning between zones. She explains that "when the network is 'flat,' without any segmentation mechanisms, every machine on the network can access any other machine. Compromising one of them then jeopardizes all the connected machines. An attacker can thus compromise a user workstation and then 'bounce' to critical servers. It is therefore important, from the initial design of the network architecture, to think in terms of segmentation into zones composed of systems with homogeneous security needs. For example, infrastructure servers, business servers, user workstations, administrator workstations, VoIP phones, etc., can be grouped separately. A zone is then characterized by dedicated VLANs and IP subnets, or even dedicated infrastructure depending on its criticality. Thus, segmentation measures such as IP filtering using a firewall can be implemented between the different zones. Particular attention should be paid to segmenting, as much as possible, the equipment and traffic associated with administrative tasks."
137. The rapporteur considers that a breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) is established since, contrary to the authorization issued by the CNIL (French Data Protection Authority), the findings of the inspection team reveal that no network segmentation has been implemented to limit access to the LRX warehouse database. He notes that this lack of segmentation facilitates a forward attack, potentially launched from other computers within the company, which could bypass the server's authentication mechanism. This risk appears all the more significant in his view, given that, in the absence of a multi-factor authentication policy for accessing the LRX warehouse, user authentication relies solely on logging into their Windows session.
138. In its defense, the company argues that its application for authorization did not specify that network segmentation would be implemented specifically for the LRX data warehouse, but rather that multiple security measures would be put in place to preserve the integrity of the servers. It maintains that the CNIL (French Data Protection Authority) granted its authorization on this basis, and that the authorization does not specify that the LRX data warehouse database should be located on a single subnet (hereinafter, "VLAN"). The company therefore believes that it is complying with its security commitments. Furthermore, regarding the potential risk of a rebound attack, the company details the measures implemented to mitigate this risk (defense in depth, principle of least privilege, and a procedure for defining the processes associated with the Security Information and Event Management (SIEM) system). Finally, it notes that the user authentication methods were expressly validated by the authorization, which does not require the implementation of multi-factor authentication.
139. First, the restricted panel refers, regarding the distinction between the authorization request submitted by the company to the CNIL and the authorization itself, to the discussion in paragraphs 121 to 125 of this decision. It notes that network segmentation is expressly required by the authorization, which then specifies that "subject to the preceding observations, the security measures described by the data controller are in line with best practices." The fact that the authorization specifically provides for network segmentation therefore required the company to take the corresponding measures to comply with this requirement, regardless of the information presented in the authorization request.
140. Secondly, the restricted panel reiterates that the authorization granted pertains to the creation of the LRX repository and that it is therefore this repository which, according to the terms of the decision, must be segmented in order to limit the impact of a potential breach by reducing the potential attack surface, so that the compromise of a workstation does not jeopardize the entire network. Indeed, the existence of an unsegmented network facilitates rebound attacks, which can be launched from other company computers used as "springboards" (all computers with access to the same network), by bypassing the server's authentication mechanism.
141. In this case, the lack of network segmentation means that as soon as a person logs into Windows on their computer connected to the company's internal network, or remotely via VPN, they gain access to the network on which the LRX data warehouse is located and can therefore launch an attack to bypass the authentication mechanism in order to access the data.
142. The restricted panel considers that this risk of a rebound attack is exacerbated by the absence of a multi-factor authentication policy, as access to the data warehouse relies, for authorized users, on authentication to their Windows session using a username and password, without any additional restrictions. While this lack of multi-factor authentication does not, in itself, contravene the requirements of the authorization of September 12, 2018 (the CNIL having considered that the authentication rules implemented by the company complied with deliberation no. 2017-012 of January 19, 2017, adopting a recommendation on passwords), it must be noted, as the rapporteur pointed out, that the consequences of the lack of network segmentation are exacerbated by these authentication methods, which no longer reflect current best practices.
143. In light of all these elements, the restricted panel considers that by failing to implement network segmentation on which the LRX data warehouse is located, the company has not complied with the terms of the authorization granted to it by the CNIL. It further notes that the measures implemented, primarily aimed at limiting intrusions from outside the company network, are not robust alternatives for preventing attacks originating from a compromised computer connected to the internal network. Under these circumstances, a breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) appears to have occurred.
144. The restricted panel notes, however, that in a letter sent to the CNIL on March 24, 2026, the company indicated that the LRX data warehouse had been moved to a secure enclave on a domain separate from the IQVIA domain, requiring two-factor authentication in addition to a connection to the IQVIA network from an enrolled machine.
145. The restricted panel acknowledges the implementation of these measures and, therefore, the company's compliance on this point.
b. On access traceability
146. Decision No. 2018-289 of September 12, 2018, stipulates that "logs of connections to the application, as well as of consultation, creation, modification, and deletion operations performed within the processing system, will be kept. Regular analysis of these logs should be carried out. In this regard, the Commission recommends that this log monitoring be performed automatically in order to detect abnormal behavior and raise alerts. The Commission notes that the data controller has committed to retaining the logs for a period of six months."
147. As early as 2013, in its technical note "Security recommendations for the implementation of a logging system," ANSSI emphasized that "event logs constitute an essential technical component for managing the security of information systems, regardless of their nature and size. Logs are a rich source of information that can be used proactively to detect security incidents. In this case, the events constituting the logs are consulted and analyzed in real time. Logs can also be used retrospectively to trace the results of a security incident; analyzing the logs of a set of components (workstations, network equipment, servers, etc.) can then make it possible to understand the path of an attack and assess its impact." This requirement is reiterated and detailed in the guide "Security Recommendations for the Architecture of a Logging System," published by ANSSI in January 2022. This guide emphasizes that "continuous analysis of event logs makes it possible to identify unusual activity. [...] In this sense, logging is also an essential prerequisite for implementing a capability to detect, analyze, and respond to security incidents."
148. The CNIL also reiterates, in its deliberation no. 2021-122 of October 14, 2021, adopting a recommendation on logging, that implementing a logging system contributes to compliance with the obligation to secure all processing of personal data. This security relies in particular on "real-time or short-term use of this data to detect abnormal operations in order to prevent attacks or intrusions, or to quickly remedy a computer incident by facilitating the identification of the problem. The Commission therefore recommends implementing a system for processing and analyzing the collected data and formalizing a process for generating alerts and processing them in the event of suspected abnormal behavior."
149. Regarding the methods for analyzing event logs, the Commission has taken into account whether they are manual or automated in the context of authorization requests or reference frameworks. Thus, for clarification, the guidelines for creating data warehouses in the healthcare sector, published in October 2021, stipulate that, with regard to logging, "a review of logs must be carried out regularly and at least every two months, as well as at the end of each authorization period related to a research project. This review must be performed by a solution that provides automatic monitoring with alerts that are manually processed by an authorized operator, or by semi-automated monitoring via the execution of programs that allow for the selection of abnormal logs, followed by manual review by an authorized operator."
150. Finally, the CNIL specifies on its website that the logging system must cover not only security-related anomalies and events (technical or "system" logs), but also users' business activities (application logs) and technical interventions (including those by administrators) (https://www.cnil.fr/fr/securite-tracer-les-operations).
151. The rapporteur notes that, contrary to the requirements of the authorization, the findings of the audit delegation indicate that the company does not implement any analysis of connection logs to trace access, creation, modification, and deletion operations performed within the data warehouse. He considers that while the security information and event management system in place detects technical anomalies, no monitoring is carried out with regard to business activities.
152. The company maintains that it has complied with the terms of the authorization granted by the CNIL by implementing a system to detect any abnormal behavior or misuse of data (SIEM). It further specifies that it has implemented monthly checks to verify that only authorized personnel connect to the LRX database. Finally, it considers that deliberation no. 2021-122 of October 14, 2021, concerning the adoption of a recommendation on logging, cannot be invoked against it, given that the checks carried out predate this decision.
153. As a preliminary matter, the restricted panel first notes that, while some of the recommendations referred to by the rapporteur in his written submissions, and which are incorporated into this decision, were made after the audit, these recommendations are not intended to establish the alleged breach (which can only be based on non-compliance with the authorization issued by the CNIL and on failure to comply with the obligations arising from the GDPR and the French Data Protection Act), but rather to explain the importance and substantial nature of the requirements set forth in the authorization.
154. Secondly, the restricted panel observes that the authorization granted to IQVIA explicitly stipulates that a regular analysis of the logs must be carried out. This requirement stems from the fact that such an analysis appears essential to identify unauthorized access to the processed data or its misuse.
155. During the audit, the delegation was informed that all queries performed on the LRX data warehouse were logged and stored in a dedicated database to facilitate their use. The company specified that the use of these logs was manual, with no automated processing mechanisms in place (for example, no automatic alerts were triggered after thresholds were crossed, such as those based on the number of queries performed or the volume of data displayed), and that on the day of the audit, the logs had only been used to detect anomalies related to data processing and that no investigation had been carried out to detect any abnormal use of this data.
156. While the company states in its defense submissions that it has implemented a system to detect potential abnormal behavior or data misuse (SIEM), the restricted panel notes that the documentation relating to this procedure, as well as the company's own statements, indicates that it only detects technical anomalies. Furthermore, the "monthly check" mentioned by the company is intended, according to the company, to verify that "only those authorized to access the LRX warehouse database are actually connecting to it."
157. These measures, the relevance of which is not disputed, do not, however, allow for the analysis of "connections to the application as well as the operations of consultation, creation, modification, and deletion" within the warehouse, as required by the authorization. As previously mentioned, it is indeed necessary to also monitor business activities in order to detect illegitimate requests made by someone authorized to access the data warehouse. For example, an IQVIA employee with data access could easily become aware of the entire (or almost the entire) medical history of a relative, even with very little initial information.
158. In light of all these factors, the restricted panel considers that by failing to implement a system allowing for regular analysis of the logs, the company has not complied with the terms of the authorization, which constitutes a breach of Article 66 of the French Data Protection Act.
159. The restricted panel notes, however, that in a letter sent to the CNIL on March 24, 2026, the company indicated that logging measures had been implemented to track all actions performed on data stored in the LRX and EMR warehouses, using the so-called "audit trail" functionalities, which allow logging of any action performed on the data via SQL queries. In addition, automatic alerts have been set up to inform support teams of any suspicious data activity.
160. The restricted panel acknowledges the implementation of these measures and, therefore, the company's compliance in this respect.
4. On the EMR warehouse
a. Regarding patient information
161. Article 14 of the GDPR stipulates that, where personal data has not been collected from the data subject, the controller must provide the data subject with certain information to ensure fair and transparent processing of their data. This information includes details on "the period for which the personal data will be stored or, where this is not possible, the criteria used to determine that period."
162. Decision No. 2021-015 of February 4, 2021, stipulates that "data subjects must be individually informed of the processing and that the various information materials must include all the information required by the provisions of the GDPR." It details, for each data stream, the procedures for providing this information.
163. Regarding the DA data stream, the authorization specifies that "IQVIA Opérations France will provide each partner physician contributing to the DA data stream with printed information leaflets to be given to each patient. This information is in addition to the general information that will be displayed by the physicians in their offices, also provided by IQVIA Opérations France, which will highlight the possibility for the individuals concerned to exercise their right to object. A QR code and a link to a website allowing each patient to access an information sheet on their mobile phone before the consultation will be displayed on these posters."
164. Regarding the [Z+] data stream, it states: "The Commission notes that IQVIA Operations France, having no direct contact with the professionals transmitting data within the [Z+] data stream, has sent [Z] an information notice for patients. It is [Z]'s responsibility to transmit this information to healthcare professionals to ensure that patients are properly informed prior to the processing of their data, in accordance with Article 14 of the GDPR."
165. As expressly stated in the authorization, these clarifications are intended, in particular, to ensure compliance with the provisions of the aforementioned Article 14 of the GDPR.
166. In this regard, the authorization issued by the CNIL stipulates that the EMR data warehouse "will be kept in active storage for a period of ten years. After this period, the data will be anonymized or deleted. In this regard, the Commission notes that this operation will be automated. The Commission considers that this data retention period does not exceed the time necessary for the purposes for which the data is collected and processed, in accordance with the provisions of Article 5(1)(e) of the GDPR."
167. The rapporteur notes that the information leaflet intended to inform patients about the processing carried out, both with regard to the DA and [Z+] data streams, contains inaccurate information, in that it states that the data is kept "for the duration of the studies and analyses carried out by IQVIA and its contractual partners," before being subjected to a "secure archiving procedure for a period compliant with applicable regulations." This information does not correspond to either the duration stipulated in the authorization or the duration actually used by IQVIA. It therefore considers that a breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) has occurred.
168. In its defense, the company argues that the information notice is the same as the one it submitted to the CNIL (French Data Protection Authority) in support of its authorization request and that it was not the subject of any comments, criticisms, or requests for modification by the CNIL. It therefore considers this notice to be compliant. Furthermore, the company notes that the authorization granted, although detailed regarding the information provided to individuals, does not specify any retention periods.
169. The restricted panel refers, with regard to the distinction between an authorization request and the authorization itself, to the discussion in paragraphs 121 to 125 of this decision.
170. It notes that, with regard to informing individuals, deliberation no. 2021-015 is worded in extremely clear terms, since it stipulates that "the various information materials must include all the information required by the provisions of the GDPR." This information expressly includes the data retention period or, where this is not possible, the criteria used to determine this period.
171. The restricted panel notes that, in this case, the notices prepared by IQVIA and intended to inform patients (regarding both the [Z+] and DA flows) are written in a question-and-answer format. To the question "How long is your data kept?", the notice states: "Your data is kept for the duration of the studies and analyses carried out by IQVIA and its contractual partners. It will then be subject to a secure archiving procedure for a period compliant with current regulations."
172. However, the restricted panel notes that the authorization granted stipulates not that the data are kept "for the duration of the studies and analyses carried out by IQVIA and its contractual partners," but that they are kept in an active database for a period of ten years, then anonymized or deleted. The company confirmed to the delegation that the data in the EMR repository was indeed kept for a period of ten years (not yet reached at the time of the audit).
173. It therefore appears that the information provided to patients is inaccurate, in that the period mentioned in the patient information leaflets issued by IQVIA does not correspond to that stipulated in the authorization, which the company indicates it is implementing.
174. The restricted panel reiterates that providing complete and accurate information to the individuals concerned is essential, as it is the only way for them to be aware that their health data is being entered into and stored in private research repositories for a relatively long period, and thus to exercise their rights if they so wish, in particular their right to object.
175. In light of all these elements, the restricted panel considers that by providing inaccurate information to the individuals whose data is being added to the EMR repository, the company failed to comply with the terms of the authorization granted, and therefore violated the provisions of Article 66 of the French Data Protection Act.
b. On the exercise of rights
176. Article 21(1) of the GDPR provides that "the data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims."
177. Article 17(1) of the GDPR provides that "the data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase such personal data without undue delay where […] (c) the data subject objects to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) […]".
178. To ensure compliance with these provisions, deliberation no. 2021-015 of February 4, 2021, states, with regard to the DA flow: "The Commission acknowledges that the patient's rights of access, rectification, and objection will be exercised with the physician using the professional software and participating in the care of the person concerned, or with the physician hosting the data for the company IQVIA. In this regard, it notes that the physician can formalize the patient's objection to the processing of their data in the data warehouse by means of a checkbox. The Commission therefore reiterates that a secure operational procedure must be implemented to ensure the removal of pseudonymity and the correct re-identification of the persons concerned, while respecting the confidentiality of the data processed. To this end, it recalls that measures similar to those provided for exercising rights within the framework of the IQVIA Oncology processing (deliberation no. 2017-347 of December 21, 2017) are applicable." could be implemented."
179. The rapporteur notes that, while the company has indeed implemented measures allowing patients to object, a priori, to the processing of their data by IQVIA, the situation is different with regard to data already collected. He considers that, contrary to the provisions of the authorization, the company has not provided any mechanism allowing for the lifting of pseudonymization and the effective re-identification of the individuals concerned, in order to allow for the respect of their right to object to the provision of additional information. He believes that, under these conditions, a breach of Article 66 of the French Data Protection Act has been established.
180. In its defense, the company argues, firstly, that its practices are consistent with the commitments made in its application for authorization, the file having always clearly stated that, with regard to data already collected and pseudonymized, respecting the right to object and the right to erasure appeared technically impossible. Since no remarks or criticisms were made on this point during the processing of its application, it considers that no wrongdoing can be attributed to it.
181. Secondly, the company reiterates that the entire design of the EMR data warehouse is based on the opacity of the patient's identity to IQVIA, as this re-identification is not necessary for the purposes of the processing. In this regard, it cites Recital 57 of the GDPR, which provides that "where the personal data which it processes do not enable it to identify a natural person, the controller should not be obliged to obtain further information to identify the data subject solely for the purpose of complying with the provisions of this Regulation. However, the controller should not refuse further information provided by the data subject to facilitate the exercise of those rights."
182. Third, in its second set of observations in response, the company states that it has indeed implemented a secure operational procedure to ensure the lifting of pseudonymization and the proper re-identification of the patient, as required by the authorization, by allowing the patient to provide additional information for identification purposes. It notes that the authorization does not refer to any particular technology or specific tool for achieving this re-identification (unlike the LRX authorization, which provides for the use of a barcode). It emphasizes that these elements were included in the submitted authorization request.
183. The restricted panel recalls that, pursuant to Article 21 of the GDPR, the right to object must be available for exercise at any time. The data subject must therefore have the opportunity to object to the processing of their data both before it is collected and afterward. Exercising the right to object means that, except in specific circumstances, the data controller will no longer process the personal data.
184. In this case, it appears from the case file that the company provides doctors with IT equipment that includes a feature for managing patient rights. Patients can therefore object, at the time of their consultation, to their data being added to the EMR data warehouse.
185. While these measures ensure the effective consideration of the right to object a priori (before the data reaches the EMR warehouse), the restricted panel notes that the company indicated during the audit that when a patient wishes to object to the processing of data already in the warehouse, they must send their request to the IQVIA Group's European Data Protection Officer. The company specified that this request must contain sufficient information (date and time of the appointment, content of the prescription) to allow it to attempt to re-identify the patient. Furthermore, this re-identification is only possible if the data provided relates to a single patient. The company also clarified that, since there is no data linking between the different practices and patients have a different identifier for each practitioner consulted, the person wishing to object to the processing of their data must provide the aforementioned information for each of the doctors concerned.
186. The restricted panel further observes that the information notice prepared by IQVIA for patients states that, while patients have the right to object to the processing of their data "at any time," "this right will only be effective for data entered by your doctor after your objection. Indeed, since the data already processed does not include your identity, as indicated above, IQVIA will not be able to delete it […] IQVIA has implemented enhanced security measures (pseudonymization and data minimization) aimed at guaranteeing the protection of your privacy following a "Data Protection by Default" approach compliant with the requirements of the GDPR. As the enhanced security measures implemented do not allow IQVIA to identify you, they therefore make it technically impossible to exercise your rights. However, if you wish, you have the option of providing IQVIA with additional information that could help them identify you, if necessary, in order to allow you to exercise your rights."
187. As the company points out, deliberation no. 2021-015 does not mandate the use of any specific technology. Nevertheless, the restricted panel considers that the procedure implemented by the company, described above, cannot be considered "a secure operational procedure [enabling] the lifting of pseudonymization and the proper re-identification of the individuals concerned while respecting the confidentiality of the data processed" in the event of exercising the right to object. Indeed, this procedure is too complex and hypothetical, insofar as it makes the consideration of the patient's right to object conditional upon the provision of additional information, which is also particularly detailed and which the individual does not necessarily possess or no longer has (date and time of the appointment, content of the prescription), and which, as the company specifies, is only likely to succeed if the information provided relates to a single patient.
188. The restricted panel notes that, while recital 57 of the GDPR stipulates that a data controller processing data that does not allow for the identification of a natural person should not be required to obtain additional information to identify that person solely for the purpose of complying with the provisions of the Regulation, this is precisely not what is required in this case. The Commission, like the rapporteur, has proposed solutions to the company enabling it to effectively respect the right to object without having to collect additional data.
189. Thus, as indicated by the rapporteur and following the example of the solution implemented for LRX, the extraction module made available to doctors could, for instance, have allowed the transmission of an objection code, associated only with the patient's identifier, enabling IQVIA to be informed that the data relating to a given patient of a particular doctor should no longer be processed (it would then be up to the patient to exercise this right with each of the doctors consulted).
190. The restricted panel notes that, despite the existence of technical solutions enabling the effective respect of the right to object of individuals whose data is stored in the LRX data warehouse, the company has not adopted a suitable procedure to ensure the removal of pseudonymization and the proper re-identification of the data subjects, as required by the authorization.
191. In light of all these elements, the restricted panel considers that, by failing to comply with the terms of the authorization issued by the CNIL, the company has violated Article 66 of the French Data Protection Act.
c. On data security and confidentiality
- On authentication rules
192. Decision No. 2021-015 of February 4, 2021, stipulates that "all administrator and user accounts duly authorized to access the non-aggregated data of the EMR Hub and the EMR warehouse will be subject to strong authentication (username and password combined with a token generating a one-time password)."
193. The rapporteur notes that, contrary to the recommendations of the authorization, no strong or multi-factor authentication mechanism has been implemented for access to the EMR warehouse. He considers that, under these conditions, a breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) has been established.
194. In its defense, the company states that strong authentication is indeed implemented at the EMR Hub level, a platform designed to collect data from medical software for final pseudonymization. Regarding the EMR data warehouse, it specifies that two-factor authentication is being deployed and is expected to be operational by the end of 2025.
195. The restricted panel notes that the authorization issued by the CNIL (French Data Protection Authority) expressly requires the implementation of a strong authentication mechanism (username and password combined with a token generating a one-time password) for all accounts authorized to access not only the EMR Hub but also the data warehouse. This requirement appears substantial, given the sensitivity and volume of the data processed.
196. However, the findings of the delegation indicate that, on the day of the audits, individuals authorized to access the EMR warehouse authenticated themselves solely using a username and password. No token (individual login token) generating a one-time password, as required by the authorization, nor any other strong or multi-factor authentication mechanism supplemented the password authentication.
197. Under these circumstances, by failing to implement a strong authentication mechanism for accessing the EMR warehouse, the company did not comply with the terms of the authorization and violated Article 66 of the French Data Protection Act.
198. The restricted panel notes that the company indicated, in a letter sent to the CNIL on March 24, 2026, that access to the LRX and EMR repositories is now subject to multi-factor authentication, with a single-use token being assigned to the user upon each login.
199. The restricted panel notes the implementation of this multi-factor authentication and, therefore, the company's compliance in this respect.
- On network segmentation
200. Resolution No. 2021-015 of February 4, 2021, stipulates that "the system will be segmented: access to EMR data warehouse data will occur in a specific area of the IQVIA Operations France network, physician panel managers will not have access to patient data, and authorized and accredited analysts and clinical research associates who will have access to patient data will not have access to the physician's original identifier."
201. Item 136 of this resolution reiterates the importance of such segmentation.
202. The rapporteur considers that a breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) is established since, contrary to the provisions of the authorization issued by the CNIL (French Data Protection Authority), no network segmentation limits access to the EMR data warehouse database. It notes that, as with the LRX data warehouse, this lack of separation facilitates a rebound attack, potentially launched from other computers within the company, which could bypass the server's authentication mechanism.
203. In its defense, the company contests the breach and states that it has implemented "logical separation," with physician panel administrators not having access to patient data and individuals accessing the EMR data warehouse not being able to access the panel database. It maintains that this measure ensures security and complies with the authorization granted by the CNIL (French Data Protection Authority). It further notes that this practice aligns with the commitments made in the authorization application. Finally, it emphasizes that it has implemented additional measures to significantly reduce the possibility of a rebound attack (defense in depth, principle of least privilege, SIEM procedure).
204. The restricted panel notes that the authorization issued by the CNIL is worded in particularly clear terms, as it requires that the system be segmented and that "access to the EMR data warehouse occurs within a specific area of the IQVIA Opérations France network." This reference to a "specific area of the network" implies, contrary to the company's assertion, that the segmentation must indeed be applied to the network itself (leading to the creation of subnets). However, the restricted panel notes that the company does not dispute the absence of "physical" network segmentation, as observed by the delegation.
205. While the "logical segmentation" invoked by the company, which consists of implementing differentiated access based on user profiles (physician panel managers not having access to patient data, and authorized and qualified analysts and clinical research associates having access to patient data but not having access to the physician's original identifier), constitutes an essential security measure, the restricted panel points out that it offers different, and complementary, guarantees to network segmentation. The latter aims to protect the entire infrastructure hosting the data warehouse, whereas differentiated access is solely intended to limit the categories of data accessible to different users to what is strictly necessary.
206. Therefore, the company cannot maintain that the measures it calls "logical segmentation" meet the authorization requirements.
207. The restricted panel considers that by failing to implement network segmentation on which the EMR data warehouse was located, the company did not comply with the terms of the authorization granted to it by the CNIL (French Data Protection Authority). Under these circumstances, a breach of Article 66 of the French Data Protection Act appears to have occurred.
208. The restricted panel notes, however, that in a letter sent to the CNIL on March 24, 2026, the company indicated that the EMR data warehouse had been moved to a secure enclave on a domain separate from the IQVIA domain, requiring two-factor authentication in addition to a connection to the IQVIA network from an enrolled machine.
209. The restricted panel acknowledges the implementation of these measures and the company's compliance in this respect.
- On Access Traceability
210. Resolution No. 2021-015 of February 4, 2021, stipulates that "access to the data warehouse will be tracked, and the logs will be kept in read-only mode for six months and then deleted. Exports will be logged and monitored to identify cases of abnormal use or export of data from the servers of IQVIA Opérations France. In this regard, the Commission recommends implementing automated analysis of exported data. The Commission acknowledges the deployment of a system that tracks all actions on the data warehouse, exports all logs to a secure collector, and automatically analyzes them to generate a dashboard and alerts for the platform operations team and the data governance committee."
211. Points 147 to 150 of this resolution reiterate the importance of logging measures and the analysis of logs.
212. The rapporteur notes that, as with the LRX data warehouse, and contrary to the requirements of the EMR authorization, the company does not process the logs, which are the only means of detecting potential abnormal behavior, and that it is therefore not complying with the terms of the authorization granted. He therefore considers that a breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) has been established.
213. In its defense, the company relies, as with the LRX data warehouse, on the implementation of the SIEM system, which it claims allows for the detection of potential abnormal behavior or misuse of data, as well as on the monthly audit through which it verifies that only authorized personnel connect to the database.
214. The restricted panel notes that, like the LRX authorization, the EMR authorization is perfectly clear on what is required of the company and further stipulates that the analysis of traces will be carried out automatically. It also notes that, both during the inspection and in its written submissions, the company provided the same information and raised the same arguments as those invoked with regard to the LRX warehouse.
215. The restricted panel therefore considers that, for the same reasons as those set out in paragraphs 153 to 157 of this decision, by failing to implement a system allowing for regular analysis of the logs, the company has not complied with the terms of the authorization, which constitutes a breach of Article 66.
216. The restricted panel notes, however, that in a letter sent to the CNIL on March 24, 2026, the company indicated that logging measures had been implemented to track all actions performed on the data stored in the LRX and EMR repositories, using the so-called "audit trail" functionalities, which allow for the logging of any action performed on the data via SQL queries. In addition, automatic alerts have been set up to inform the support teams of any suspicious activity on the data.
217. The restricted panel acknowledges the implementation of these measures and, therefore, the company's compliance on this point.
D. On the breach of Article 14 of the GDPR concerning the LRX warehouse
218. In law, Article 14 of the GDPR, which applies when personal data are not collected directly from the data subject, requires the data controller to provide the data subject with various pieces of information relating in particular to their identity and contact details, the contact details of the data protection officer, the purposes of the processing, its legal basis, the categories of data processed, the recipients or categories of recipients of this data, and any intention to transfer data to a third country. Furthermore, to ensure "fair and transparent processing" of personal data, the regulations require that individuals be informed about the data retention period or, where this is not possible, the criteria used to determine that period, the existence of the various rights available to the individual, the right to lodge a complaint with a supervisory authority, the source of the data and, where applicable, an indication of whether or not it comes from publicly available sources, as well as the existence of automated decision-making, including profiling, and in such cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
219. This obligation to provide information, which Article 14 of the GDPR places on the data controller, ensures, in particular, that data is processed transparently with regard to the data subjects, as required by Article 5 of the GDPR. Information is therefore an essential prerequisite for a proper understanding of how their data is processed and for exercising their rights.
220. Decision No. 2018-289 of September 12, 2018, authorizing IQVIA to establish the LRX data warehouse, stipulates, with regard to informing individuals, that "community pharmacists will be contractually responsible for individually informing their customers about the processing of their personal data (...). Individuals will be informed individually by receiving an information leaflet. This information will be supplemented by a document displayed within the community pharmacy or published on its website. The Commission requests that these provisions be expanded to include all the information required by Articles 12 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016."
221. The rapporteur notes that, while the authorization issued by the CNIL (French Data Protection Authority) stipulates that pharmacists are contractually obligated to inform data subjects about the processing related to the creation of the LRX data warehouse, by providing them with an information leaflet and displaying a document within the pharmacy, audits conducted at four Parisian pharmacies participating in the LRX panel demonstrated that, in practice, none of them provided this information. The rapporteur therefore considers that a breach of Article 14 of the GDPR has occurred and that it is attributable to IQVIA in its capacity as data controller.
222. In its defense, the company contests the alleged breach.
223. In its initial observations in response, it argues that pharmacists are responsible for processing their customers' data and transmitting it to IQVIA. This is why, according to the company, the authorization issued by the CNIL (French Data Protection Authority) stipulates that pharmacies are "responsible" for informing their customers, an obligation incumbent upon them as data controllers. The company maintains that it has complied with the terms of the authorization by entering into contracts with pharmacists, stipulating that the latter would be responsible for providing the information. It also notes that it has no contact with the individuals concerned.
224. Furthermore, the company emphasizes the very small proportion of pharmacies audited (four out of a total of 10,000 pharmacies participating in the LRX panel), which, in its view, does not allow for the conclusion that all pharmacies fail to inform individuals. Finally, the company highlights the numerous communication initiatives it has implemented (reminder campaigns via postal mail and email, communications at professional events for pharmacists, the establishment of a transparency portal and a QR code providing access to information, etc.). It states that it sent a letter to the CNIL (French Data Protection Authority) in May 2021, outlining these communication efforts, but has never received a response.
225. In its second set of observations, the company adds that the authorization granted by the CNIL does not require IQVIA to conduct on-site verification that pharmacies are displaying the information leaflet, and that, moreover, the GDPR makes no reference to such an obligation. Since the pharmacies are neither subcontractors nor agents of IQVIA, it believes there is no provision that would impose an obligation on it to "audit" them. The company considers that imposing such an obligation on it would be contrary to the constitutional principle of legality of offenses and penalties, as well as to the principle of personal criminal responsibility, since it would amount to penalizing IQVIA for the failure of a third party.
226. Finally, the company believes that the alleged breach under Article 14 of the GDPR is identical to the breach under Article 66 of the French Data Protection Act concerning studies conducted using the LRX data warehouse, insofar as it considers them to be the same grievance relating to the failure to inform the data subjects.
227. The restricted panel notes that, in this case, the investigation revealed that four pharmacies participating in the LRX panel were inspected by the Commission's services on September 24, October 29, and November 26, 2021. These inspections established, firstly, that none of these four pharmacies provided its customers with the individual information notice prepared by IQVIA and, secondly, that no general information notice was displayed in these pharmacies concerning the data processing carried out by the company.
228. The restricted panel reiterates that the data processing covered by Decision No. 2018-289, and at issue in these proceedings, relates to the establishment of the LRX warehouse, for which the company is responsible, as demonstrated in paragraphs 54 to 63 of this Decision.
229. It is therefore incumbent upon the pharmacist, as data controller, to ensure compliance with the obligations imposed upon them by the GDPR, including the obligation to inform individuals whose data are stored in the data warehouse about the processing operations implemented, pursuant to Article 14 of the GDPR.
230. In this regard, while the authorization stipulates that pharmacists are responsible for informing their clients about the processing of their personal data, the restricted panel notes, firstly, that the processing in question, and of which individuals must be informed, is indeed that implemented by IQVIA, as evidenced by the information notice prepared by this company, which notably states that "the data collected by IQVIA is processed on the legal basis of IQVIA's legitimate interest (and the authorization granted by the CNIL, as mentioned above), in its capacity as data controller." This notice also mentions the email address of IQVIA's Data Protection Officer, the company's website address, and its postal address.
231. Furthermore, the restricted panel notes that, by stipulating that pharmacists would be responsible for informing patients on behalf of IQVIA, the Commission merely acknowledged the methods for providing this information, as proposed by the company in its application for authorization. It did not, however, intend to exempt the company from its obligations as data controller, nor to place these obligations on pharmacists, which would not, moreover, be legally permissible under Article 14 of the GDPR (notwithstanding their potential contractual liability or liability with respect to other processing activities).
232. Thus, the restricted panel considers that, regardless of the channel through which the information is provided, the obligation to provide information rests with IQVIA, by virtue of its status as data controller and pursuant to Article 14 of the GDPR (the data collection being indirect in this case), and it is therefore IQVIA that bears the risk of a penalty in the event of non-compliance with this obligation.
233. Furthermore, the restricted panel wishes to emphasize the consequences of this lack of information for the data subjects, whose health data is processed without their knowledge and who are, de facto, unable to exercise their rights.
234. However, regarding the scope of the breach, the restricted panel notes that the audits carried out covered four pharmacies, and that it is therefore necessary to limit the breach to the individuals whose data was collected through these pharmacies.
235. It is clear from all these elements that a breach of Article 14 of the GDPR appears to have occurred with regard to the persons whose data were collected through the four pharmacies that were subject to inspections.
236. The restricted panel wishes to clarify that the company's argument regarding the alleged confusion of this breach with the breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) concerning studies conducted by the company using the LRX data warehouse will be examined in item 255 of this decision.
E. On the breach of Article 66 of the French Data Protection Act concerning studies conducted using the LRX data warehouse
237. As stated in item 115 of this decision, Article 66 of the French Data Protection Act stipulates that the processing of personal data in the health sector may only be carried out after authorization from the CNIL (French Data Protection Authority) or on the condition that it complies with a standard mentioned in paragraph II of that article, and in light of the public interest it serves.
238. The rapporteur notes that the studies conducted by IQVIA, on its own behalf, using data from the LRX repository, are not authorized by the Commission and do not comply with any of the standards referred to in Article 66 above, due to the lack of prior and individual notification of patients. He therefore considers that a breach of these provisions has been established.
239. In its defense, the company states that, to conduct the studies in question, it relies on the declaration of conformity to the reference methodology MR-004 filed with the CNIL on July 31, 2018. It maintains that the individuals have been properly informed and that it can therefore rely on this methodology.
240. The restricted panel notes that the investigation reveals that IQVIA conducts studies on its own behalf using data from the LRX repository. These studies, relating to the analysis of patient care for various pathologies, constitute data processing concerning the health of individuals and are, as such, subject to the provisions of Article 66 of the French Data Protection Act. It is therefore necessary to determine whether this data processing could validly be implemented, either because it had received authorization from the Commission or because of its compliance with a reference methodology.
241. First, the restricted panel notes that while, during the inspection carried out at the company's premises, the company indicated that the studies conducted on its behalf were based on the LRX authorization (with the exception of those involving linkage, which were subject to specific authorization), it subsequently indicated, first in its exchanges with the delegation and then in its observations in response to the sanction report, that these studies were in fact conducted on the basis of its declaration of compliance with the MR-004 reference methodology.
242. In any event, Decision No. 2018-289 concerning the LRX data warehouse reads as follows: "The Commission authorizes IQVIA Opérations France to implement the processing of personal data for the purpose of creating a personal data warehouse for research, study, or evaluation purposes in the health sector, using data from community pharmacies. [...] It reiterates that the processing of personal health data that will be implemented subsequently for research, study, or evaluation purposes in the health sector are separate processing operations that must be subject to specific formalities by IQVIA, as provided for in Chapter IX, Section 2 of the law."
243. The restricted panel thus notes that the authorization granted relates exclusively to the creation of the LRX data warehouse and expressly excludes from its scope studies conducted using this data warehouse.
244. The company therefore cannot rely on this authorization to conduct the studies in question.
245. Secondly, the restricted panel notes that, on July 31, 2018, the company filed a declaration of conformity with the MR-004 reference methodology framework with the CNIL (French Data Protection Authority). This declaration was acknowledged on August 7, 2018.
246. The restricted panel reiterates that this reference methodology, which is intended to govern the processing of personal data for study, evaluation, or research purposes not involving human subjects (in particular, studies on data reuse), sets out a number of conditions that must be met by the organization intending to rely on it.
247. In particular, it requires that, in addition to displaying general information enabling data subjects to be aware of the research activities carried out, they be individually informed, for each project for which their data is processed, of all the information required by Articles 13 and 14 of the GDPR (identity and contact details of the data controller, contact details of the data protection officer, purposes and legal basis of the processing, nature of the information used, recipients or categories of recipients of the data, their rights, and the data retention period).
248. MR-004 provides that, by way of exception, when data have not been collected specifically for research purposes, they may be reused without requiring further individual notification of the data subjects, either if they already have the necessary information (for example, when several research projects are conducted by the same data controller with identical purposes, data categories, and recipients), or when the information provided at the time of collection allows for the reuse of the data and refers to a specific information mechanism to which the data subjects can refer prior to the implementation of each new processing operation (for example, a website presenting each research project).
249. In this case, the restricted panel notes that the data used in the studies carried out by the company were initially collected for the purpose of establishing the LRX health data warehouse. Thus, while MR-004 authorizes their reuse, this is conditional upon the individuals concerned being informed beforehand.
250. The company indicated in this regard that this information was identical to that provided to patients by pharmacies during data collection. The information sheet prepared by IQVIA described not only the creation of the LRX data warehouse but also the research conducted using the data contained therein. Details of the studies carried out were also published on a website, to which the information sheet refers.
251. However, as demonstrated in paragraphs 227 et seq. of this decision, the inspections carried out by the delegation at four pharmacies revealed that this information sheet was not given to the individuals concerned during data collection. Consequently, these individuals were informed neither of this data collection nor of the reuse of their data in the context of studies conducted by IQVIA.
252. The restricted panel considers that it is clear from these elements that the company is conducting studies without complying with the MR-004 reference methodology, with regard to the data collected through the four pharmacies that were audited.
253. These studies are also not based on authorization issued by the CNIL (French Data Protection Authority), since authorization no. 2018-289 expressly excludes from its scope subsequent studies carried out using the LRX data warehouse, as specified in paragraphs 241 to 244 of this decision, and no other specific authorization permitting these studies has been issued.
254. In light of the foregoing, the restricted panel considers that a breach of Article 66 of the French Data Protection Act has occurred, as the company reused the data from the LRX data warehouse collected through the four audited pharmacies for the purpose of conducting studies outside the applicable legal framework.
255. The restricted panel wishes to clarify that, contrary to the company's assertion, this breach should not be confused with the one alleged against it under Article 14 of the GDPR, even though both stem from the failure to provide information to the data subjects. The breach of Article 14 of the GDPR constitutes a separate offense, concerning the creation of the LRX data warehouse, and is characterized independently of any subsequent reuse of the data. The breach of Article 66 of the French Data Protection Act relates to the conditions under which this data can be reused. The failure to inform the individuals concerned prevents the company from relying on MR-004 and thus from conducting studies without prior authorization from the CNIL (French Data Protection Authority). The constituent elements of these breaches, as well as their effects, are therefore quite distinct.
F. On the breach of Article 25 of the GDPR, concerning the LRX warehouse
256. In law, Article 25 of the GDPR provides that "1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risks, of varying likelihood and severity, that the processing presents to the rights and freedoms of natural persons, the controller shall, both at the time of determining the means of processing and at the time of processing itself, implement appropriate technical and organisational measures, such as pseudonymisation, designed to give effect to the principles relating to data protection, for example data minimisation, and to provide the necessary safeguards for processing in order to meet the requirements of this Regulation and to safeguard the rights of the data subject."
2. The controller shall implement appropriate technical and organizational measures to ensure that, by default, only personal data which are necessary for each specific purpose of the processing are processed. This applies to the amount of personal data collected, the scope of their processing, their storage period, and their accessibility. In particular, these measures shall ensure that, by default, personal data are not made accessible to an indefinite number of natural persons without the intervention of the data subject.
257. The European Data Protection Board (hereinafter, "the EDPB") specifies, in its Guidelines 4/2019 relating to Article 25 adopted on 20 October 2020, that "the controller should choose and be responsible for the implementation of default processing parameters and options, so that only processing which is strictly necessary to achieve the intended lawful purpose is carried out by default." In this context, data controllers must rely on their assessment of the necessity of the processing in light of the legal grounds referred to in Article 6(1). It follows that, by default, the data controller must neither collect more data than necessary, nor process the data collected more than is necessary to achieve its purposes, nor retain the data longer than necessary. The fundamental requirement is that data protection be integrated by default into the processing.
258. The rapporteur notes that the data extraction modules installed on pharmacists' LGOs systematically transmit patient data to the first trusted third party, company [X], even for pharmacies not participating in the LRX panel. He considers that this transmission does not appear justified and that IQVIA should have included, from the design stage and by default, measures to ensure that the software does not extract patient data when the pharmacist refuses this disclosure. The rapporteur therefore considers that a breach of Article 25 of the GDPR has been established.
259. In its defense, in its first and second observations in response, the company points out that the modules installed on the LGOs not only allow data extraction but also pseudonymize it at a first level, before any transmission. It considers that this pseudonymization, expressly mentioned in Article 25 of the The GDPR ensures compliance with these provisions.
260. Furthermore, the company argues that it cannot be maintained that the data would be transmitted to the first trusted third party without any justification, as this transmission is not, in itself, the processing of personal data, but rather part of an overall pseudonymization process comprising several phases, validated by the Commission as part of the authorization process.
261. Finally, the company specifies that it is not the recipient of any data that it should not be receiving, as the objective of the filtering carried out by the first trusted third party is precisely to ensure that only the data of pharmacies participating in the LRX panel is transmitted to the second trusted third party and then to IQVIA.
262. In the report produced on October 7, 2025, and subsequently in its latest observations in response, the company maintains that, since the pharmacist is responsible for communicating their clients' data to [X], the failure to Article 25 of the GDPR, concerning this transmission, cannot be attributed to it.
263. The restricted panel notes that it appears from the investigation that IQVIA commissioned LGO publishers to develop, on its behalf and for its account, data extraction modules all meeting the same specifications drawn up by IQVIA. These modules, integrated into the LGOs of all pharmacists who have contracted with the company, allow data to be extracted and a feed ("Pharmastat feed") to be generated, which includes not only data relating to drug sales, but also the patient identification code, generated by the module using a hash function, even if the pharmacist has chosen not to participate in the LRX panel, and therefore not to transmit patient data (which is the case for approximately 4,000 of the 14,000 pharmacies that have contracted with the company). IQVIA).
264. This data stream is then transmitted to the first trusted third party designated by IQVIA, [X], which is responsible for sorting the data between patients from pharmacies participating in the LRX panel (and which are therefore intended to be transmitted to the second trusted third party, and then to IQVIA), and patients from pharmacies not participating in this panel. The service contract between IQVIA and [X] stipulates in this regard that IQVIA provides [X] with the list of panelists for whom the data processing and transmission must be carried out, distinguishing between: - the list of panelists participating in the Pharmastat project [participation in the Pharmastat project being understood as the transmission to IQVIA of only data relating to drug sales, excluding patient data] - the list of panelists participating in the LRX study [...]. Based on the lists provided by IQVIA, the trusted third party is obligated to limit the processing of each panelist's data to the project(s) in which they are participating [...].
265. It thus appears that, even if the pharmacy has chosen not to transmit its patients' data, this data is nevertheless systematically transmitted, via the extraction modules, to the first trusted third party.
266. The restricted panel recalls that Article 25 of the GDPR, as interpreted by the aforementioned EDPB guidelines, requires the data controller to ensure that, from the design stage and by default, only the personal data necessary to achieve the purpose are processed.
267. However, in this case, the systematic transmission to company [X] of data that the pharmacists refused to provide, and which is therefore not intended to be processed within the framework of the LRX panel, is not not justified and does not meet the purpose of this processing.
268. The restricted panel also reiterates that, contrary to the company's assertion, this transmission to the first trusted third party does, in itself, constitute a processing operation within the meaning of Article 4(2) of the GDPR, even if IQVIA is not ultimately the recipient of this data, or if this operation is part of a broader pseudonymization process (and, more generally, a single processing operation). The restricted panel notes that, in any event, data from pharmacies not participating in the LRX panel are not intended to be pseudonymized, since they should not be processed at all.
269. As the data controller and owner of the extraction modules, the company should have ensured that patient data was not extracted when the pharmacist refused its transmission. The filtering entrusted by IQVIA to company [X] would have It was therefore necessary to intervene upstream, at the LGO level, to ensure that company [X] did not receive data that it was neither authorized to process nor transmit, a fact confirmed by IQVIA. The restricted panel notes in this regard that, while the extraction modules were developed by the LGO vendors, it was IQVIA that determined the content of the data stream transmitted to the first trusted third party, via the specifications imposed on the vendors.
270. In light of all these elements, the restricted panel considers that IQVIA did not implement the appropriate technical and organizational measures to ensure that, by design and by default, only personal data necessary for the purposes of the processing are processed. A breach of Article 25 of the GDPR is therefore established.
III. ON CORRECTIVE MEASURES AND THEIR PUBLICATION
271. Legally, under Article Article 20-IV of Law No. 78-17 of 6 January 1978, as amended, states that "when the data controller or its processor fails to comply with the obligations arising from Regulation (EU) 2016/679 of 27 April 2016 or this Law, the President of the National Commission for Information Technology and Civil Liberties may […] refer the matter to the Commission's restricted panel for the issuance, after adversarial proceedings, of one or more of the following measures: […]
2° An order to bring the processing into compliance with the obligations arising from Regulation (EU) 2016/679 of 27 April 2016 or this Law, or to comply with the requests made by the data subject to exercise their rights, which may be accompanied, except where the processing is carried out by the State, by a penalty payment not exceeding €100,000 per day of delay from the date set by the panel restricted;
7. Except where the processing is carried out by the State, an administrative fine may not exceed €10 million or, in the case of an undertaking, 2% of its total worldwide annual turnover for the preceding financial year, whichever is higher. In the cases referred to in points 5 and 6 of Article 83 of Regulation (EU) 2016/679 of 27 April 2016, these ceilings are increased to €20 million and 4% of said turnover, respectively. The restricted panel shall take into account, in determining the amount of the fine, the criteria specified in the same Article 83.
272. Article 83 of the GDPR further provides that "each supervisory authority shall ensure that administrative fines imposed pursuant to this Article for infringements of this Regulation referred to in paragraphs 4, 5 and 6 are, in each case, effective, proportionate and dissuasive," before specifying the factors to be taken into account when deciding whether to impose an administrative fine and when deciding on the amount of that fine.
273. Recital 150 of the GDPR specifies that "where administrative fines are imposed on an undertaking, that term shall, for that purpose, be understood as an undertaking in accordance with Articles 101 and 102 of the Treaty on the Functioning of the European Union."
274. The guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679 state that the concept of an undertaking should be understood as "an economic unit which may be formed by the parent company and all the subsidiaries concerned. In accordance with Union law and case law, an undertaking should be understood as the economic unit engaged in commercial or economic activities, irrespective of the legal entity involved."
275. In a judgment of 5 December 2023 (CJEU, Grand Chamber, C-807/21, "Deutsche Wohnen"), the Court of Justice of the European Union (CJEU) held, with regard to the concept of "undertaking," that, as noted by the Advocate General in point 45 of his Opinion, it is in this specific context of calculating administrative fines imposed for infringements referred to in Article 83(4) to (6) of the GDPR that the reference, made in recital 150 of that Regulation, to the concept of "undertaking" within the meaning of Articles 101 and 102 TFEU must be understood. In this regard, it should be emphasized that, for the purposes of applying the competition rules referred to in Articles 101 and 102 TFEU, this concept includes any entity carrying out an economic activity, irrespective of that entity's legal status and its method of financing. It designates Thus, an economic unit exists even if, from a legal perspective, this economic unit is made up of several natural or legal persons. This economic unit consists of a unified organization of personal, tangible, and intangible elements pursuing a specific economic objective on a lasting basis (judgment of 6 October 2021, Sumal, C-882/19, EU:C:2021:800, paragraph 41 and the case law cited therein). Therefore, it follows from Article 83, paragraphs 4 to 6, of the GDPR, which concerns the calculation of administrative fines for the infringements listed in those paragraphs, that, where the recipient of the administrative fine is or is part of an undertaking, within the meaning of Articles 101 and 102 TFEU, the maximum amount of the administrative fine is calculated on the basis of a percentage of the total worldwide annual turnover of the undertaking concerned for the preceding financial year. Ultimately, as the Advocate General noted in paragraph 47 of his In conclusion, only an administrative fine whose amount is determined based on the actual or material economic capacity of its recipient, and therefore imposed by the supervisory authority on the basis, with regard to its amount, of the concept of economic unit as defined in the case law cited in paragraph 56 of this judgment, is capable of meeting the three conditions set out in Article 83(1) of the GDPR, namely, being effective, proportionate, and dissuasive. Consequently, when a supervisory authority decides, under the powers it holds pursuant to Article 58(2) of the GDPR, to impose an administrative fine on a controller who is or is part of an undertaking, within the meaning of Articles 101 and 102 TFEU, pursuant to Article 83 of that Regulation, that authority is required to base its calculation of the fines on that latter provision, read in light of recital 150 of the same Regulation. administrative penalties for the violations referred to in paragraphs 4 to 6 of Article 83, concerning the concept of "undertaking" within the meaning of Articles 101 and 102 TFEU (paragraphs 55 to 59).
276. This position was confirmed by the Court in a judgment of 13 February 2025 (CJEU, Fifth Chamber, C-383/23, "Ilva A/S").
277. Finally, Article 22, paragraph 2 of the French Data Protection Act provides that "the restricted panel may make public the measures it takes."
A. On the imposition of an administrative fine and its amount
278. The rapporteur proposes that the restricted panel impose an administrative fine on the company in view of the breaches of Articles 66 of the French Data Protection Act, 14 and 25 of the GDPR.
279. In its defense, the company argues that, even if breaches were to be established, they would not be of the severity described by the rapporteur. It emphasizes the length of the proceedings and maintains that, had the identified breaches been serious, the CNIL should have acted more swiftly to put an end to them.
280. The company also highlights the enhanced data pseudonymization measures implemented, which it claims significantly reduce security risks.
281. Furthermore, the company argues that the IQVIA Group's global revenue is not a relevant criterion for determining the amount of the penalty, as the proportionality of this amount should, in its view, be assessed in relation to the revenue of the products affected by the identified breaches. It notes that the LRX and EMR warehouses fall under the jurisdiction of IQVIA OPERATIONS FRANCE, the sole data controller, and that they represent only a very small portion of the company's revenue, having generated approximately […] in 2022 and […] in 2023 (i.e., […]% of the company's total revenue).
282. It also considers the amount proposed by the rapporteur to be unfair and disproportionate compared to other sanctions imposed by the CNIL.
283. It therefore requests that the restricted panel not impose any sanction on it.
284. The restricted panel considers that, in this case, it is appropriate to examine the relevant criteria of Article 83 of the GDPR to decide whether to impose an administrative fine on the company and, if so, to determine its amount.
1. On the imposition of the fine
285. First, the restricted panel considers that, pursuant to Article 83(2)(g) of the GDPR, the categories of personal data concerned by the violations must be taken into account.
286. In this regard, it notes that all the data at issue in these proceedings relates to the health of individuals and, as such, constitutes "sensitive" data within the meaning of Article 9 of the GDPR, which benefits from special protection and whose processing is subject to particularly strict regulations. It is therefore essential that the body authorized to process such data be particularly vigilant in complying with the rules imposed both by the legislature and by the authority that granted the authorization. However, it is these rules that, in this case, were not respected by the company, given that it was the first private entity authorized by the CNIL (French Data Protection Authority) to implement a health data warehouse in consideration of the stated public interest purpose. The restricted panel considers that, as such, it should have been all the more exemplary in its compliance with the terms of the authorization granted.
287. The restricted panel also intends to take into account the fact that the data contained in the LRX and EMR warehouses were pseudonymized, not directly identifying. Thus, although they remain "sensitive" data, the compromise of which could have a major impact on the individuals concerned, the measures taken by the data controller to ensure that this data cannot be attributed to a specific individual without resorting to additional information must be taken into consideration when assessing the sanction.
288. Secondly, the restricted panel intends to take into account the criterion laid down in Article 83(2)(a) of the GDPR, relating to the nature, severity, and duration of the breaches, considering the nature, scope, or purpose of the processing concerned, as well as the number of data subjects affected and the level of harm they have suffered.
289. It notes, first of all, the massive scale of the processing operations implemented, which affect or are likely to affect tens of millions of people. For example, in its brochure presenting the LRX treatment to pharmacists, the company mentions 20 million patients monitored over time. Regarding the EMR data warehouse, the company indicated that the data contained therein came from the patients of 2,000 partner physicians, whereas in its brochure presenting the Medical 21 observation, it mentions 3,000 partner physicians. The number of people affected appears particularly high in any event, as some of the breaches in question affect all patients whose data is processed within the two data warehouses, such as those relating to data security and confidentiality.
290. The restricted panel further notes that the breaches in question are demonstrably serious, particularly with regard to information, as the processing of their health data may have been carried out without the individuals' knowledge or ability to effectively exercise their rights. In this respect, the restricted panel recalls the circumstances in which this data is collected by the company indirectly, during purchases of medication in pharmacies or medical consultations. Thus, not only do the individuals concerned not take the initiative to transmit their data to IQVIA, but it must also be emphasized that the context of the data collection (illness, emergency, stress) is likely to reduce their vigilance regarding data protection. It is therefore all the more essential to provide them with clear and complete information, enabling them, where appropriate, to exercise the rights they have.
291. The same applies to the identified security deficiencies, as the risk of a data breach is high given the nature of the data involved. In this regard, ANSSI specifies in its report on the state of the cyber threat in the healthcare sector, dated November 7, 2024, that "healthcare entities hold various types of data, including personal, medical, authentication, payment, and strategic data [...] [which] have significant resale value."
292. Regarding the breach of Article 25 of the GDPR, the restricted panel notes that the company had full control over the data extraction modules, developed on its behalf and for its account by LGO's software vendors, and that it should therefore have implemented measures to ensure data protection by design and by default.
293. Finally, regarding the inaccurate information provided to patients concerning the data retention period, the restricted panel considers that the breach has occurred, but that it is less serious.
294. Thirdly, the restricted panel intends to take into account the criterion set out in Article 83(2)(b) of the GDPR, relating to whether the breach was committed intentionally or negligently.
295. It considers that the number of breaches identified demonstrates clear negligence on the part of the company, even though the conditions set out in the authorizations issued by the CNIL were worded very clearly.
296. Furthermore, it considers that this negligence is particularly serious given the company's sector of activity and its market position, as the company presents itself as the "world leader in clinical research and health data". Thus, since the processing of health data is the primary and historical focus of its business, the company cannot ignore its obligations in this area and the conditions under which it may legally conduct its business. The restricted panel further notes that the company has sufficient human, technical, and financial resources to ensure strict compliance with the rules relating to the protection of personal data.
297. For all these reasons, the restricted panel considers that the imposition of an administrative fine is necessary.
2. On the amount of the fine
298. The restricted panel notes first that, pursuant to Article 83 of the GDPR, an administrative fine of up to €20 million, or, in the case of an undertaking, 4% of its total worldwide annual turnover for the preceding financial year, whichever is higher, may be imposed.
299. First, the restricted panel recalls that, as detailed in paragraphs 273 to 276, in order to determine the maximum fine and to ensure that it is effective, dissuasive, and proportionate, the concept of "undertaking" in competition law must be applied, by virtue of the direct and explicit reference to this concept in recital 150 of the GDPR and in the guidelines on the application and setting of administrative fines for the purposes of Regulation 2016/679.
300. The restricted panel notes that in its aforementioned judgment of 5 December 2023, the CJEU reiterates that an undertaking is an economic unit, even if, from a legal perspective, that economic unit is made up of several legal persons. The CJEU clarifies that, as with competition law (French Court of Cassation, Commercial Chamber, June 7, 2023, appeal no. 22-10.545; French Competition Authority, decisions no. 21-D-10 of May 3, 2021 and no. 21-D-28 of December 9, 2021), when a subsidiary is wholly owned, directly or indirectly, by its parent company, "on the one hand, that parent company may exert decisive influence over the behavior of that subsidiary (...) and, on the other hand, there is a rebuttable presumption that the said parent company does in fact exert decisive influence over the behavior of its subsidiary" (CJEU, September 10, 2009, C-97/08, paragraph 60).
301. To determine the amount of the proposed fine and ensure it reflects the actual economic capacity of the recipient, if the two companies can materially be considered part of the same economic unit, the turnover of the parent company must be taken into account so that the fine is effective, proportionate, and dissuasive (CJEU, Fifth Chamber, C-383/23, "Ilva A/S", paragraphs 22 to 29).
302. In the present case, the restricted panel notes that IQVIA HOLDINGS INC., headquartered in the United States, owns 100% of IQVIA OPERATIONS FRANCE. It therefore considers that, in accordance with the aforementioned CJEU case law, there is a presumption that IQVIA HOLDINGS INC. exerts decisive influence over the market conduct of its subsidiary, IQVIA OPERATIONS FRANCE.
303. Furthermore, the restricted panel notes that the IQVIA group presents itself, particularly on its website www.iqvia.com, as a single entity, "a world leader in clinical research and health data," processing over 120 billion health data points annually and conducting more than 500 studies in over 75 countries. It considers that these elements corroborate the fact that IQVIA HOLDINGS INC. and IQVIA OPERATIONS FRANCE constitute a single economic entity and therefore form a single undertaking within the meaning of Article 101 of the TFEU.
304. Furthermore, the restricted panel considers that, contrary to the company's assertion, the proportionality and deterrent effect of the fine should not be assessed solely with regard to the revenue generated by the activity in question (some organizations, moreover, do not derive any economic benefit from the processing carried out), but rather with regard to the seriousness of the breaches observed and the financial capacity, not of the data controller, but of the company concerned.
305. In light of the foregoing, the restricted panel considers that, in determining the amount of the fine, the company's turnover, defined as an "economic unit," should be used, namely that of IQVIA HOLDINGS INC., which amounted to $15 billion in 2023, or approximately €12.9 billion, with a profit of $1.3 billion, or approximately €1.1 billion. It also notes that IQVIA OPERATIONS FRANCE's turnover amounted to €152.6 million in the same year, with a net profit of €23.3 million.
306. Thus, in view of the company's responsibility, its financial capacity, as well as that of its parent company, and the relevant criteria of Article 83 of the GDPR, the restricted panel considers that an administrative fine of five million (€5,000,000) appears dissuasive and proportionate to penalize the breaches of Articles 66 of the French Data Protection Act, 14 and 25 of the GDPR.
B. On the issuance of injunctions with penalty payments
307. The rapporteur considers in his submissions that the issuance of injunctions with penalty payments is necessary to ensure the company's compliance. During the hearing of March 26, 2026, the judge indicated that, in light of the latest information provided by the company, he considered such an injunction no longer necessary with regard to the breaches relating to data security and confidentiality.
308. The company requests that the restricted panel not issue an injunction.
309. The restricted panel considers, with regard to the breaches relating to data security and confidentiality, that the company has duly demonstrated that it has implemented measures to ensure compliance with the requirements of the authorizations granted. Therefore, there is no need to issue an injunction on this point. The restricted panel nevertheless reiterates that it is the company's responsibility to "continuously ensure that the security measures implemented guarantee that the risks to individuals remain at an acceptable level" and that "this obligation requires updating the security measures in light of the regular reassessment of risks."
310. Regarding the other identified shortcomings, the restricted panel observes that the company has, since the commencement of the proceedings, provided no evidence to suggest that it has adopted or even initiated measures to ensure its compliance. Therefore, the issuance of injunctions is necessary.
311. Firstly, concerning the EMR data warehouse, the restricted panel considers, on the one hand, that the company must provide patients whose data is collected with accurate and complete information regarding the processing carried out, particularly concerning the data retention period, and, on the other hand, implement measures to ensure the effective respect of patients' right to object, for example, by allowing them to object to the processing carried out within the data warehouse directly with their physician.
312. Secondly, regarding the breach of Article 14 of the GDPR, the restricted panel considers that the company must take measures to ensure that partner pharmacies comply with their contractual obligations and inform patients about the transmission of their data to IQVIA. It further notes that, notwithstanding the implementation of verification measures that the company must carry out under the injunction, it ultimately remains responsible for the actual provision of this information.
313. Thirdly, regarding the studies conducted using the LRX data warehouse, the restricted panel considers that the company must cease conducting such studies without authorization from the CNIL (French Data Protection Authority) or without compliance with the MR-004 reference methodology.
314. Finally, fourth and lastly, regarding the breach of Article 25 of the GDPR, the restricted panel considers that the company must implement organizational and technical measures to ensure that pharmacy management software does not extract patient data when the pharmacist has refused to transmit it to IQVIA.
315. To guarantee compliance with the injunctions issued, the restricted panel considers that, in light of the company's turnover and the financial, human, and technical resources available to it to remedy the breaches, a daily penalty of ten thousand (10,000) euros per day of delay should be imposed, payable after a period of six (6) months from the date of notification of this decision.
C. On the Publication of the Sanction
316. The rapporteur considers that the restricted panel's decision must be made public.
317. The company, for its part, considers that such publication would be unfair and disproportionate in light of all the measures it has implemented to ensure data protection.
318. The restricted panel, on the contrary, considers that publication of the decision is necessary given the seriousness of the breaches in question, the number of individuals concerned, and the nature of the data processed.
319. It further considers that this measure appears proportionate since the decision will no longer identify the company by name after a period of two years from its publication.
FOR THESE REASONS
The restricted panel of the CNIL, after deliberation, decides to:
• impose an administrative fine on IQVIA OPERATIONS FRANCE in the amount of five million (5,000,000) euros for breaches of Article 66 of Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties and Articles 14 and 25 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016;
• to issue an injunction against IQVIA OPERATIONS FRANCE to bring its data processing activities into compliance with the provisions of Article 66 of Law No. 78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties, Articles 14 and 25 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, and in particular:
o with regard to the EMR data warehouse:
- to provide patients whose data is collected with accurate and complete information regarding the processing carried out, particularly concerning the retention period of this data;
- to implement measures to ensure the effective respect of patients' right to object, for example by allowing them to object to the processing carried out within the data warehouse directly with their physician.
Regarding the breach of Article 14 of the GDPR, take measures to ensure that partner pharmacies comply with their contractual obligations and inform patients about the transmission of their data to IQVIA OPERATIONS FRANCE;
Regarding studies conducted using the LRX data warehouse, cease conducting such studies without authorization from the CNIL (French Data Protection Authority) or without compliance with the MR-004 reference methodology;
Regarding the breach of Article 25 of the GDPR, implement organizational and technical measures to ensure that modules integrated into pharmacy management software do not extract patient data when the pharmacist has refused its transmission to IQVIA OPERATIONS FRANCE.
• To impose a penalty of ten thousand (10,000) euros per day of delay after a period of six (6) months following notification of the restricted panel's decision;
• To publish its decision on the CNIL website and on the Légifrance website, which will no longer allow the company to be identified by name after a period of two years from its publication.
The President
Philippe-Pierre CABOURDIN
This decision may be appealed to the Council of State within two months of its notification.
Légifrance Help
To assist you in using the site, consult all the help available on the Légifrance website.
Contact us
Watch the Legifrance video tutorials
Use case guide
Subscribe to the Official Journal of the French Republic
Receive the summary by email as soon as it is published.
Learn more about managing your data and your rights.
Your email address (e.g., name@example.com)
By providing your email address, you agree to receive the summary of the Official Journal of the French Republic by email. You can subscribe or unsubscribe at any time using this form.
Help
Contact us
Open data and API
Open data and API
API FAQ
French Republic




