Data & Technology Innovation | October 2026 Insight

Contenido

Health data and anonymisation: Italian DPA fines IQVIA EUR 7 million

Data Protection

By Decision No. 710 of 23 September 2026, the Italian Data Protection Authority imposed a EUR 7 million fine on IQVIA Solutions Italy S.r.l. in relation to a database containing health information relating to approximately one million patients, collected from 800 general practitioners.

The decision centres on the dividing line between anonymisation and pseudonymisation: assigning each patient a unique and persistent code, combined with a particularly granular body of information (i.e. diagnoses, prescriptions, examinations, vaccinations and geographical information), made it possible to single out data subjects, track their clinical history over time and re-identify them using reasonably available means. In other words, the data therefore remained subject to the GDPR.

The Authority classified IQVIA as a controller from the point at which the data were collected from the doctors and found, among other matters, that there was no appropriate legal basis for processing health data, the information provided to data subjects was inadequate, no defined retention periods had been established, no DPIA had been carried out and the security measures adopted were insufficient.

The decision is an important warning for health-tech operators, data providers, healthcare platforms and entities developing AI systems using health datasets, as it makes clear that merely removing direct identifiers does not render a dataset anonymous. The architecture of data flows, data granularity and combinability, the persistence of identifiers and the practical possibility of singling out and re-identification must be assessed by design, together with the correct allocation of data-protection roles and the legal basis for the processing.

For businesses seeking to derive value from health data for research, analytics or technological development, prior technical and legal verification of whether datasets have been effectively anonymised is therefore essential not only for compliance, but also for the sustainability of the business model.

Privacy by design in digital payments: the role of PETs

Data Protection

In September 2026, the Bank of Italy published the paper “Privacy-Enhancing Technologies and Auditability in Digital Payment Systems” in its Markets, Infrastructures and Payment Systems series. The paper examines technologies that can reconcile the protection of users’ privacy with oversight and compliance requirements in digital payment systems.

The paper starts from a premise that is also particularly relevant from a data-protection perspective: privacy should not be treated as a feature to be added ex post, but as a requirement to be embedded from the system-design stage, in line with the principles of data protection by design and by default laid down in Article 25 GDPR. The underlying idea is that technical and architectural choices determine who may access transaction data, in what circumstances and at what level of detail.

Privacy-Enhancing Technologies (PETs) are particularly relevant in this context: these technologies can limit data exposure or allow data to be disclosed only selectively. Among them, the paper also examines zero-knowledge proofs, which can, for example, demonstrate that a transaction complies with a given threshold without disclosing the exact amount. The key concept is auditability, namely the ability of authorised parties to verify compliance with the applicable rules without necessarily having access to all data relating to the user or the transaction.

The message is therefore that privacy and compliance need not be competing objectives: through appropriate technological choices, data minimisation and selective-disclosure mechanisms, they can be designed together from the outset.

Brevetti+, Disegni+ and Marchi+: EUR 32 million for SMEs’ industrial property

Intellectual Property

By Director-General’s Decree of 28 July 2026, published in Official Gazette No. 200 of 29 August 2026, the Ministry of Enterprises and Made in Italy (MIMIT) scheduled the reopening, for 2026, of the three measures supporting the commercial exploitation of industrial property rights held by micro, small and medium-sized enterprises. The total allocation of EUR 32 million is divided as follows:

  • Brevetti+ (EUR 20 million): specialist services for the commercial exploitation of patents, managed by Invitalia;
  • Disegni+ (EUR 10 million): commercial exploitation of registered designs, managed by Unioncamere;
  • Marchi+ (EUR 2 million): extension of national trade mark protection at EU level (EUIPO) and internationally (WIPO), managed by Unioncamere.

The decree is a programming measure: the eligibility requirements, maximum grant amounts and application-opening dates are to be set out in the reopening notices, which the Directorate-General for Business Incentives must adopt within thirty days of publication in the Official Gazette. Applications will continue to be assessed on a first-come, first-served basis until the available funds are exhausted; the recitals to the decree refer to the early closure of the 2025 procedures for precisely that reason. The notices setting out the exact dates and procedures were expected by 28 September 2026 but have not yet been published; they should therefore be made available shortly.

At EU level, the EUIPO SME Fund “Ideas Powered for business”, open until 4 December 2026, has already exhausted the budgets for Voucher 1 (IP Scan) and Voucher 2 (trade marks and designs). Voucher 3 (patents) and Voucher 4 (Community plant varieties) remain available.

The result is a set of confirmed resources that are clearly relevant to SMEs but limited in availability, making prompt filing an effective condition of access: businesses should therefore apply for these measures as soon as the application windows open.

New EDPB Guidelines 4/2026 on the imposition of administrative fines

Data protection

On 17 September 2026, the EDPB published Guidelines 04/2026 (the “Guidelines”) to ensure consistent application of Regulation (EU) 2016/679 (the “GDPR”) when deciding whether to impose an administrative fine, including in relation to the other corrective powers under Article 58(2) GDPR. The document completes the framework initiated by Guidelines 4/2022 on the calculation of administrative fines.

The Guidelines focus on the use of a fine in addition to, or instead of, other corrective measures under Article 58(2) GDPR, including warnings, reprimands, orders, restrictions on or bans of processing, and withdrawal of certifications.

Fines serve a specifically punitive and deterrent function, unlike measures intended to restore compliance.

The proposed methodology comprises five stages: (1) verifying that the infringement is punishable under Article 83(4)–(6) GDPR, taking national law into account (in Italy, including Article 166 of Legislative Decree No. 196/2003); (2) establishing that the party under investigation may be fined (a controller, processor, certification body or monitoring body); (3) assessing the subjective element (intent or negligence), bearing in mind that negligence is generally presumed in light of the accountability principle; (4) weighing the factors under Article 83(2) GDPR to determine whether the infringement is “minor” and does not warrant a fine; and (5) conducting a final assessment of the fine’s effectiveness, proportionality and deterrent effect: if those requirements are not met, no fine should be imposed. It remains to be seen how the Italian Data Protection Authority will apply these criteria in its investigatory and enforcement practice.

Cyber Resilience Act: reporting obligations for vulnerabilities and severe incidents apply from 11 September 2026

Cybersecurity

From 11 September 2026, Article 14 of Regulation (EU) 2024/2847 – the Cyber Resilience Act (the “CRA”) requires actively exploited vulnerabilities contained in products with digital elements, and severe incidents affecting the security of those products, to be reported to the competent authorities. The obligation applies to all products with digital elements within the scope of the CRA, including products placed on the market before 11 December 2027.

Manufacturers must, in particular, notify the CSIRT designated as coordinator and ENISA simultaneously through the single reporting platform, submitting an initial early warning within 24 hours, a detailed notification within 72 hours and a final report within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month of the 72-hour notification for a severe incident. Unlike vulnerability-handling obligations, reporting obligations continue to apply after the product’s support period has ended.

To assist economic operators and authorities, the European Commission published guidelines under Article 26 CRA clarifying: (i) the scope of the CRA; (ii) the meaning of a product with digital elements; (iii) the rules applying to products designed before the date of application; (iv) the concept of substantial modification; (v) determination of the support period; and (vi) the criteria for cybersecurity risk assessment and vulnerability handling, including vulnerabilities arising from third-party components and remote data-processing solutions.

Focus

New rules on green claims, sustainability labels, durability and commercial communications

The new provisions of Legislative Decree No. 30/2026 on commercial communications directed at consumers have applied since 27 September 2026. Environmental claims, sustainability labels and information on product durability require businesses to review both the messages they use and the documentation substantiating them…

Read the full article >

Data protection and consent to the processing of personal data in the beauty and wellness sector

Italian Supreme Court Order No. 25117 of 8 September 2026 examines the validity of consent to the taking of photographs in connection with beauty treatments. The case highlights the need to verify in practice whether the requirements for valid consent are met and to distinguish the request for consent from the other contractual terms…

Read the full article >

Space debris on the moon: the Falcon 9 case and the regulatory gap

The impact of a Falcon 9 stage on the lunar surface raises questions about the management of spacecraft at the end of their missions. The incident highlights the limitations of the rules currently available for disposal beyond Earth’s orbits and the need to coordinate safety, liability and sustainability…

Read the full article >

The United States accelerates its “Space Law Reform”

The US commercial space transportation strategy aims to increase launches and re-entries to at least 1,000 operations per year by 2030. The strategy encompasses authorisation procedures, spaceport development and industrial supply-chain capacity, creating new opportunities and regulatory issues for operators…

Read the full article >

Fecha