First Sanction Against a Health Data Warehouse Controller
min readBy deliberation No. SAN-2026-008 of May 26, 2026(1), the restricted panel of the French Data Protection Authority (Commission nationale de l'informatique et des libertés – CNIL) imposed an administrative fine of five million euros on IQVIA OPERATIONS FRANCE, the French subsidiary of the American group IQVIA. This decision constitutes the first sanction issued by the CNIL against a data controller operating health data warehouses (HDWs) for non-compliance with the terms of the authorizations granted to it.
IQVIA had been authorized by the CNIL to establish two health data warehouses: the LRX warehouse, populated with data collected from approximately 14,000 pharmacies, and the EMR warehouse, populated with data collected from physicians. These warehouses enable longitudinal monitoring of the care pathways of millions of patients – the company referring to "20 million anonymized patients tracked over time" in its presentation materials.
Failures to Inform Data Subjects and Inapplicability of MR-004
The first major ground of the sanction concerns failures regarding the provision of information to data subjects. With respect to the LRX warehouse, the authorization issued by the CNIL stipulated that pharmacists would be contractually responsible for individually informing their customers by providing an information notice and displaying a document within the pharmacy. However, inspections carried out at four Parisian pharmacies participating in the LRX panel demonstrated that none of them provided such information, whether by handing out an individual notice or by display. The restricted panel held that this obligation to inform rested squarely with IQVIA in its capacity as data controller, even though the company had no direct contact with the data subjects.
The restricted panel emphasized that data subjects had their health data processed "without their knowledge" and were "de facto unable to exercise their rights." Furthermore – and this is a fundamental aspect of the decision – this failure to inform rendered the MR-004 reference methodology, on which the company relied to conduct studies from the LRX warehouse, inapplicable. Indeed, MR-004 requires prior individual information to data subjects regarding the secondary use of their data. Absent such information, the company could not rely on this methodology, and the studies conducted therefore had no legal basis – neither a CNIL authorization nor compliance with a reference framework. A breach of Article 66 of the French Data Protection Act (Loi Informatique et Libertés) [requiring prior formalities] was accordingly found on this ground, distinct from the breach of Article 14 of the GDPR [information where data have not been obtained from the data subject].
With respect to the EMR warehouse, the restricted panel further noted that the company had failed to implement an operational procedure enabling the lifting of pseudonymization and proper re-identification of individuals wishing to exercise their right to object after the fact, contrary to the requirements of the authorization.
Security Failures in Breach of the Authorizations… or of the State of the Art
The second ground of the sanction concerns data security failures, in breach of the terms of the authorizations granted or of the state of the art. First, the restricted panel found an absence of network segmentation, for both the LRX and EMR warehouses, in direct violation of the terms of the authorizations, which expressly required network "compartmentalization." This lack of segmentation facilitates lateral movement attacks, whereby a compromised workstation can provide access to the entire network and potentially to the sensitive data held in the warehouses. Second, access logging and access controls proved insufficient. While the company had a SIEM system capable of detecting technical anomalies, no monitoring of business-level activities was in place – meaning no mechanism existed to detect abnormal use of data by an otherwise authorized individual. The authorization explicitly required "regular analysis of logs" covering consultation, creation, modification, and deletion operations within the warehouse. Third – and this point is of particular doctrinal interest – the restricted panel noted the absence of multi-factor authentication for access to the LRX warehouse. It acknowledged that this absence did not, in itself, contravene the requirements set out in the 2018 authorization, the CNIL having at the time considered the authentication methods compliant with its 2017 recommendation. However, it held that these methods "no longer correspond to the current state of the art" and that they exacerbated the consequences of the absence of network segmentation. This reasoning carries a major lesson: a data controller cannot exempt itself from compliance with the state of the art in data security, not even by invoking adherence to the technical measures described in a prior authorization. The obligation under Article 32 of the GDPR, which requires account to be taken of "the state of the art," is a continuous and dynamic obligation.
Sanction, Following Rejection of the Argument Based on the Non-Personal Nature of the Data
The company had attempted, in its final submissions relying on the CJEU judgment in "SRB" of September 4, 2025, to argue that the data in its warehouses were anonymous and therefore fell outside the scope of the GDPR. The restricted panel dismissed this argument on the basis of three decisive factors: the existence of a unique identifier assigned to each patient enabling longitudinal tracking, the depth and richness of the data collected allowing for the singling out of patients and the reconstruction of care pathways, and the possibility of re-identifying individuals by combining data held by IQVIA with publicly accessible data, notably via social media. The restricted panel concluded that the pseudonymization measures had "merely the effect of reducing the risks of correlating these data with the identity of data subjects, but not of eliminating them."
The five-million-euro fine was determined taking into account the worldwide turnover of the IQVIA group (15 billion dollars in 2023), the CJEU having confirmed that the concept of "undertaking" within the meaning of Articles 101 and 102 TFEU must be applied for the purpose of calculating fines. The restricted panel also issued a compliance order subject to a penalty payment of 10,000 euros per day of non-compliance beyond a six-month deadline, relating in particular to the effective provision of information to patients, the cessation of studies conducted outside any legal framework, and the implementation of data protection by design measures. The decision is made public for a period of two years.
This decision sends a strong signal to all stakeholders in the health data sector: the benefit of a CNIL authorization is not a carte blanche – any failure to comply with its terms or with the state of the art exposes controllers to significant financial penalties.