When the EU Court of Justice issued its Single Resolution Board (SRB) ruling on 4 September 2025 (C-413/23 P), many read it as a turning point. The Court confirmed that pseudonymised data can, in some cases, fall outside the GDPR. The French data protection authority, the CNIL, backed by the French highest administrative court, has now shown that in its case against IQVIA Operations France, the ruling changes very little.
The Case
In 2021, a TV investigation flagged possible GDPR breaches by IQVIA France, a major health-data company. Years earlier, the CNIL had allowed IQVIA to build two health-data warehouses: one fed by pharmacies (LRX), and one by doctors' offices (EMR). Each patient was given a code, hashed several times, and sent to the warehouse together with a lot of other data – age, gender, medication, diagnoses, prescriptions, and more.
Until the SRB ruling, IQVIA accepted that it processed personal health data. Afterwards, it changed its position and argued the data was now pseudonymised to the point of no longer being personal – so the GDPR no longer applied. The case which until then resolved around the authorisations mentioned above, became the opportunity for the CNIL to answer the question of “what is personal data after SRB”.
The CNIL's Answer
The CNIL disagreed with the new position of IQVIA and gave two main reasons:
- Control: Unlike in the SRB case, IQVIA was the controller. It decided the purpose and the means of the whole process, including the technical specifications of the hashing carried out by third parties. It therefore held both the keys to pseudonymise patients and the means to re-identify them.
- Volume and detail: The data was so rich that re-identification was easy – reportedly possible in minutes using only an internet connection (in one example, by combining warehouse data with a disease-specific Facebook group). The CNIL stressed that even the risk of re-identifying a single person makes the whole dataset personal, and that no intent to or even an interest in re-identification is needed.
The CNIL therefore treated the data as personal and sanctioned IQVIA for two proven breaches: failing to meet its authorisation conditions (weak technical safeguards, no access logging, unauthorised reuse of the data) and breaching the duty to inform patients under Art. 14 GDPR. IQVIA was fined €5 million and ordered to fix the remaining breaches within six months (deliberation SAN-2026-008).
No Escape Trough The Courts
The CNIL had issued similar sanctions in three comparable cases in 2024. On 13 February of this year, the Conseil d'État (France's highest administrative court) upheld them, finding the data merely pseudonymised and re-identifiable. This makes it very unlikely that any French court would now decide the IQVIA case differently, especially since the CNIL based itself on the upholding judgments to issue this recent sanction.
Conclusion
The SRB ruling does give businesses more room to process pseudonymised data, but it is not a get-out-of-jail-free card. French courts and the CNIL show that personal “data” stays broadly defined, while the bar for real anonymisation and pseudonymisation stays high. Companies should keep assessing their methods carefully and involve their DPO before relying on the SRB ruling.
No comments