Italy's data protection authority, the GPDP, has fined IQVIA €7 million ($7.8 million) over data-processing practices it says were inadequate. The regulator found that the health data analytics firm failed to properly anonymize information, potentially exposing a large number of patients.

The GPDP said the shortcomings could have put roughly one million patients at risk of data exposure and de-anonymization. The case underscores how technical failures in anonymization can turn sensitive health records into a privacy liability.

The fine signals that regulators are paying close attention to how health data is handled, even when companies are established players. It also serves as a warning that weak safeguards, not just deliberate misuse, can lead to significant penalties.