The Italian Data Protection Authority (DPA) issued final decisions on 23 September 2026, imposing fines for GDPR violations. IQVIA Solutions Italy S.r.l. received a fine of EUR 7,000,000 for unlawfully processing health data of approximately one million patients without a legal basis and failing to provide adequate information to patients. BBVA was fined EUR 5,508,000 for not respecting a customer's objection to direct marketing.
The DPA relied on multiple legal references, including Article 5, Article 9, Article 13, Article 25, Article 28, and Article 35 of the GDPR. These articles pertain to principles of data processing, special categories of personal data, information obligations, data protection by design, and data protection impact assessments.
The fines apply to IQVIA Solutions Italy S.r.l. and Banco Bilbao Vizcaya Argentaria, S.A. The DPA mandated that IQVIA must comply with GDPR requirements within 120 days to continue processing the data. BBVA's violation highlighted the importance of adhering to data subjects' rights under GDPR.
The DPA's decision requires IQVIA to identify an appropriate legal basis, comply with information obligations, conduct a data protection impact assessment, and appoint general practitioners as processors. Alternatively, general practitioners must independently carry out the anonymisation process according to the Italian Authority's safeguards.