• news-banner

    Expert Insights

Available in other languages:

First Sanction Against a Health Data Warehouse Controller

min read

By deliberation No. SAN-2026-008 of May 26, 2026(1), the restricted panel of the French Data Protection Authority (Commission nationale de l'informatique et des libertés – CNIL) imposed an administrative fine of five million euros on IQVIA OPERATIONS FRANCE, the French subsidiary of the American group IQVIA. This decision constitutes the first sanction issued by the CNIL against a data controller operating health data warehouses (HDWs) for non-compliance with the terms of the authorizations granted to it.

IQVIA had been authorized by the CNIL to establish two health data warehouses: the LRX warehouse, populated with data collected from approximately 14,000 pharmacies, and the EMR warehouse, populated with data collected from physicians. These warehouses enable longitudinal monitoring of the care pathways of millions of patients – the company referring to "20 million anonymized patients tracked over time" in its presentation materials.

Failures to Inform Data Subjects and Inapplicability of MR-004

The first major ground of the sanction concerns failures regarding the provision of information to data subjects. With respect to the LRX warehouse, the authorization issued by the CNIL stipulated that pharmacists would be contractually responsible for individually informing their customers by providing an information notice and displaying a document within the pharmacy. However, inspections carried out at four Parisian pharmacies participating in the LRX panel demonstrated that none of them provided such information, whether by handing out an individual notice or by display. The restricted panel held that this obligation to inform rested squarely with IQVIA in its capacity as data controller, even though the company had no direct contact with the data subjects.

The restricted panel emphasized that data subjects had their health data processed "without their knowledge" and were "de facto unable to exercise their rights." Furthermore – and this is a fundamental aspect of the decision – this failure to inform rendered the MR-004 reference methodology, on which the company relied to conduct studies from the LRX warehouse, inapplicable. Indeed, MR-004 requires prior individual information to data subjects regarding the secondary use of their data. Absent such information, the company could not rely on this methodology, and the studies conducted therefore had no legal basis – neither a CNIL authorization nor compliance with a reference framework. A breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) [requiring prior formalities] was accordingly found on this ground, distinct from the breach of Article 14 of the GDPR [information where data have not been obtained from the data subject].

With respect to the EMR warehouse, the restricted panel further noted that the company had failed to implement an operational procedure enabling the lifting of pseudonymization and proper re-identification of individuals wishing to exercise their right to object after the fact, contrary to the requirements of the authorization.

Security Failures in Breach of the Authorizations… or of the State of the Art

The second ground of the sanction concerns data security failures, in breach of the terms of the authorizations granted or of the state of the art. First, the restricted panel found an absence of network segmentation, for both the LRX and EMR warehouses, in direct violation of the terms of the authorizations, which expressly required network "compartmentalization." This lack of segmentation facilitates lateral movement attacks, whereby a compromised workstation can provide access to the entire network and potentially to the sensitive data held in the warehouses. Second, access logging and access controls proved insufficient. While the company had a SIEM system capable of detecting technical anomalies, no monitoring of business-level activities was in place – meaning no mechanism existed to detect abnormal use of data by an otherwise authorized individual. The authorization explicitly required "regular analysis of logs" covering consultation, creation, modification, and deletion operations within the warehouse. Third – and this point is of particular doctrinal interest – the restricted panel noted the absence of multi-factor authentication for access to the LRX warehouse. It acknowledged that this absence did not, in itself, contravene the requirements set out in the 2018 authorization, the CNIL having at the time considered the authentication methods compliant with its 2017 recommendation. However, it held that these methods "no longer correspond to the current state of the art" and that they exacerbated the consequences of the absence of network segmentation. This reasoning carries a major lesson: a data controller cannot exempt itself from compliance with the state of the art in data security, not even by invoking adherence to the technical measures described in a prior authorization. The obligation under Article 32 of the GDPR, which requires account to be taken of "the state of the art," is a continuous and dynamic obligation.

Sanction, Following Rejection of the Argument Based on the Non-Personal Nature of the Data

The company had attempted, in its final submissions relying on the CJEU judgment in "SRB" of September 4, 2025, to argue that the data in its warehouses were anonymous and therefore fell outside the scope of the GDPR. The restricted panel dismissed this argument on the basis of three decisive factors: the existence of a unique identifier assigned to each patient enabling longitudinal tracking, the depth and richness of the data collected allowing for the singling out of patients and the reconstruction of care pathways, and the possibility of re-identifying individuals by combining data held by IQVIA with publicly accessible data, notably via social media. The restricted panel concluded that the pseudonymization measures had "merely the effect of reducing the risks of correlating these data with the identity of data subjects, but not of eliminating them."

The five-million-euro fine was determined taking into account the worldwide turnover of the IQVIA group (15 billion dollars in 2023), the CJEU having confirmed that the concept of "undertaking" within the meaning of Articles 101 and 102 TFEU must be applied for the purpose of calculating fines. The restricted panel also issued a compliance order subject to a penalty payment of 10,000 euros per day of non-compliance beyond a six-month deadline, relating in particular to the effective provision of information to patients, the cessation of studies conducted outside any legal framework, and the implementation of data protection by design measures. The decision is made public for a period of two years.

This decision sends a strong signal to all stakeholders in the health data sector: the benefit of a CNIL authorization is not a carte blanche – any failure to comply with its terms or with the state of the art exposes controllers to significant financial penalties.

Our thinking

  • IBA Annual Conference 2026

    Jean-Baptiste Beauvoir-Planson

    Events

  • EU Packaging and Packaging Waste Regulation: Who Is Affected?

    Kerry Stares

    Quick Reads

    min read
  • Cristiana Felisi writes for We Wealth on when a parent can lose custody of their children

    Maria Cristiana Felisi

    In the Press

    min read
  • EU Packaging and Packaging Waste Regulation: Three Things You Need to Know

    Kerry Stares

    Quick Reads

    min read
  • Jersey Trade Mark Reform: What the New Regime Means for You

    Dewdney William Drew

    Quick Reads

    min read
  • New EU Packaging and Packaging Waste Regulation: Is Your Business Ready?

    Kerry Stares

    Quick Reads

    min read
  • Tessa Bartley comments in Legal Futures about our framework for choosing the right legal AI tools

    Tessa Bartley

    In the Press

    min read
  • A practical guide to choosing the right AI tools for your law firm: Five Insights that surprised us the most

    Tessa Bartley

    Quick Reads

    min read
  • Fraudsters in the Inbox: The Limits of Contractual Causation in Logix Aero v Siam Aero

    Natalya Stone

    Insights

    min read
  • In-House Insights: Next Gen Drinks Reception

    Events

    min read
  • Giorgia Ligasacchi writes in We Wealth about collectors, Matthew Wong's artworks, and the contemporary art scene

    Giorgia Ligasacchi

    In the Press

    min read
  • A practical guide to choosing the right AI tools for your law firm: Inside the framework

    Tessa Bartley

    Quick Reads

    min read
  • Charles Russell Speechlys Opens New York Office and Connecticut Practice

    Simon Ridpath

    News

    min read
  • Disputes Over Donuts: Sports Arbitration

    Jue Jun Lu

    Podcasts

  • Saudi Center for Commercial Arbitration issues update on arbitration in Saudi Arabia

    Peter Smith

    Insights

    min read
  • Charles Russell Speechlys shares practical framework for choosing the right legal AI tools

    Lesley O’Leary

    News

    min read
  • A practical guide to choosing the right AI tools for your law firm: The big idea

    Tessa Bartley

    Quick Reads

    min read
  • Sadie Pitman writes in CoStar about the development of hyperscale data centres

    Sadie Pitman

    In the Press

    min read
  • Annapaola Negri-Clementi featured in La Repubblica, MilanoFinanza, Corriere della Sera and others following appointment to board of cryptocurrency asset manager

    Annapaola Negri-Clementi

    In the Press

    min read
Back to top