Les DPO de la Santé
All articles
GDPR

GDPR sanctions and health data: six decisions that draw the red line

Les DPO de la SantéPublished August 7, 20265 min
GDPR sanctions and health data: six decisions that draw the red line

From a doctor fined €3,000 to a group ordered to pay €5 million: a sourced review of the landmark decisions and their operational lessons for the sector.

Health data compliance is not a theoretical matter: it is judged, decision after decision. And the message of those decisions is remarkably consistent — size protects no one, an authorization is not a blank check, and security must be demonstrated continuously. Here is a review of the landmark cases, each verified against its official source.

2020 — Two doctors in private practice: €3,000 and €6,000

In December 2020, the CNIL sanctioned two doctors in private practice: thousands of their patients’ medical images were freely accessible on the internet, because of a misconfigured practice internet router and imaging software, with no systematic encryption. Two infringements were found: security (Article 32) — and the failure to notify the breach to the CNIL (Article 33).

The lesson: there is no such thing as “too small to be inspected”. A solo practice bears the same security obligations as a group — and failing to notify a breach is a standalone infringement, on top of the one that caused it.

2022 — Dedalus Biologie: €1.5 million

In April 2022, the CNIL imposed a fine of €1.5 million on Dedalus Biologie, a software vendor for medical testing laboratories, after the leak of the medical data of nearly 500,000 people — down to serological statuses, pathologies and genetic data. At issue: multiple technical and organizational failures, including the absence of encryption and of procedures governing data migrations.

The lesson: a processor can be sanctioned directly, and heavily. For care providers, this means that reviewing software vendors and processing contracts is not an administrative formality — that is where the CNIL went to find the largest health data leak in France.

2023 — Doctissimo: €380,000

In May 2023, the CNIL fined Doctissimo €380,000: the site’s online tests collected health data without the explicit consent required by Article 9, compounded by excessive retention periods, a deficient framing of joint controllership, and cookie infringements (€100,000 of the total).

The lesson: you can process health data without being a care provider. A simple “wellness” questionnaire is enough to bring a website within Article 9 — a frequent blind spot among software publishers, health media outlets and app providers.

2024 — Cegedim Santé: €800,000

In September 2024, the CNIL fined Cegedim Santé €800,000: the vendor, whose software equips around 25,000 medical practices, was processing health data drawn from patient records for study and statistical purposes without authorization. The central point of the decision: this data, presented as anonymous, was merely pseudonymized — re-identification remained possible.

The lesson: pseudonymized is not anonymous, and the difference is worth €800,000. Any reuse of patient data — for research, statistics, or training a model — requires an honest qualification of the data’s status and compliance with the prior formalities.

2026 — IQVIA: €5 million

On May 26, 2026, the CNIL imposed a fine of €5 million on IQVIA Operations France (deliberation SAN-2026-008), which operates two health data warehouses that were nonetheless duly authorized — one fed by some 14,000 pharmacies, the other by several thousand doctors. Infringements found: pseudonymous rather than anonymous data, connection logs that were never analyzed, no multi-factor authentication on one of the warehouses, an inaccurate information notice, and a right to object with no effective procedure.

The lesson — the most important of this review: authorization does not confer immunity. The safeguards set out in an authorization file become verifiable obligations; upholding them over time (logs, MFA, information, rights) is precisely the work of compliance governance, not of a file submitted once.

And elsewhere in Europe: the DPO himself at issue

The red line does not only concern processing operations: in September 2022, the Berlin authority fined a company €525,000 because its data protection officer combined that role with the management of companies whose compliance he was supposed to oversee — a conflict of interest prohibited by Article 38(6). The choice of DPO, their positioning and their independence are an integral part of compliance.

What these decisions say, taken together

From €3,000 to €5 million, the spectrum covers the sector’s entire chain: the practitioner, the software vendor, the media outlet, the warehouse operator. The grounds, meanwhile, keep recurring: insufficient security (Article 32), unnotified breaches (Article 33), missing explicit consent (Article 9), ignored prior formalities, poorly framed subcontracting, pseudonymization confused with anonymization, ineffective data subject rights. In other words: exactly the building blocks of a well-constructed compliance foundation.

These published sanctions are, moreover, only the visible part: the CNIL also issues formal notices and simplified-procedure sanctions that do not make the same headlines. The right reading is not fear — it is method: every ground for sanction in this review corresponds to a workstream that can be identified, prioritized and evidenced. That is precisely what a diagnostic brings to light, and what a compliance foundation corrects.

This article is provided for general information purposes and does not constitute personalized legal advice.

Turn your obligations into opportunities.

A free, no-obligation first conversation to review your compliance posture and identify your priorities — in English.

Response within 24 business hours · No obligation