
In May 2026, the French data protection authority (CNIL) fined the French arm of the global clinical research company IQVIA €5 million in relation to two health research databases.
Whilst the decision was made under French data protection law, and some of the findings relate specifically to French requirements, there are important lessons that health research organisations across the UK and EU should pay attention to.
Background
In France, IQVIA operates two major health data warehouses:
LRX (Longitudinal Prescription Data Warehouse) – containing pharmacy prescription data provided by pharmacists.
EMR (Electronic Medical Records Warehouse) – containing data collected from doctors.
Following concerns raised in a television programme about IQVIA's use of health data, CNIL launched an investigation into several aspects of these databases.
Controller or Processor?
IQVIA argued that, for the initial ingestion of data into these warehouses, it acted as a Processor and that it only became a Controller when undertaking subsequent studies using the data.
CNIL challenged the assertion that IQVIA was merely a Processor during the initial data collection stage.
The first issue for IQVIA was that the CNIL authorisations for the datasets identified IQVIA as the Controller, as did the patient information materials.
The second, more technical point was that, once data was uploaded by a pharmacist, IQVIA:
"...must be regarded as being responsible for the processing carried out by this means, insofar as it determines both the purpose of the latter (i.e. the construction of an 'LRX flow' in particular for the purpose of supplying the LRX warehouse) and the means."
A similar conclusion was reached in relation to the EMR warehouse:
"IQVIA determines both the purpose (i.e. to build a flow to supply the EMR warehouse) and the means of these operations..."
What this means
Controllership is ultimately a factual assessment. What organisations say externally matters, but regulators will look at the reality of the arrangement. If you are building and managing a platform and determining how data will be used for your own commercial purposes, it is unlikely that you will be viewed as just a Processor, even where other organisations are supplying data and have their own obligations.
Pseudonymised or Anonymised?
CNIL next considered whether the data held within these databases was personal data.
Notably, IQVIA had previously described the information as personal data in its CNIL authorisations. During the investigation, however, it revised its position, relying on the Single Resolution Board (SRB) judgment and arguing that the data should no longer be considered personal data under the GDPR.
IQVIA highlighted the technical and organisational safeguards in place. Direct identifiers such as names and addresses had been removed and replaced with unique identifiers.
However, CNIL concluded that whilst these measures reduced risk, they did not eliminate it. Factors such as the potential to isolate individuals and the availability of external data sources meant that re-identification risks remained.
As CNIL stated:
"The pseudonymisation measures put in place by the company IQVIA have the effect only of reducing the risks of correlation of these data with the identity of the data subjects, but not of deleting them."
As a result, the LRX and EMR datasets remained personal data and subject to GDPR requirements.
What this means
Even following the SRB judgment (which is not binding in the UK), establishing that a health research database is truly anonymous remains challenging, even where direct identifiers have been removed.
Organisations that state they only hold "anonymous" data should ensure they have a robust evidential basis for that position, particularly where they retain individual-level records.
Note: Since this decision, the European Data Protection Board has published draft guidance on anonymisation, providing further clarity on how anonymity should be assessed.
Privacy by Design and Default
CNIL also identified shortcomings in the design and governance of the systems themselves, including issues relating to:
Network partitioning
Secondary research use
Patient transparency information
Rights mechanisms
Authentication
Access logging and export monitoring
What this means
Designing health research platforms requires a comprehensive combination of technical and organisational measures.
From the architecture of the platform itself to the procedures that govern it, and the downstream uses of data once it has been ingested, privacy by design and default requires consideration throughout the entire information lifecycle.
Patient Transparency Cannot Be Delegated
CNIL found that patients were not being properly informed in certain pharmacy settings.
IQVIA had relied on pharmacies to provide privacy notices and display the relevant information. Whilst these obligations were included in contractual arrangements, inspections revealed that the required information was not always being made available in practice.
IQVIA argued that pharmacies were contractually responsible for these failings. However, CNIL's position was that, as Controller, IQVIA remained responsible for ensuring transparency obligations were met.
What this means
Controllers should be able to demonstrate:
What information was provided
When it was provided
Through which channel
In what format
How compliance by third parties is monitored
Contractual wording alone is unlikely to be sufficient where there is no monitoring, audit trail or escalation process when notices are not provided or displayed.
Stick to Your Regulatory Approval
In France, health research processing may require CNIL authorisation or compliance with an applicable methodology. In this case, CNIL found that the LRX authorisation covered the creation of the warehouse, not all later studies undertaken using the data. Those later studies were separate processing operations. IQVIA had relied on MR-004, but CNIL found that this was not available, in respect of data collected through the pharmacies, because the required patient information had not been provided.
What this means
Whilst there is no direct equivalent under UK data protection law, organisations handling confidential patient information may require support under the Common Law Duty of Confidentiality through the Confidentiality Advisory Group (CAG).
Where such approvals are required, confidential information should only be used within the scope of the approved processing. Organisations should ensure CAG is kept informed of material changes and that any necessary remedial approvals are obtained before processing continues.
Conclusion
Whilst this decision was made under the French regulatory framework, the underlying themes are applicable to health research organisations across the UK and Europe.
The case is a reminder that regulators look beyond labels and contractual wording to the reality of how data is collected, managed and used. Whether considering controllership, anonymisation, transparency or privacy by design, organisations should expect regulators to assess the processing operation as a whole.
The €5 million fine may have arisen from a French enforcement action, but the lessons are relevant to any organisation seeking to build trust while making effective use of large-scale health data.

