Cegedim Santé fined €800,000 for processing health data unlawfully

The data was found to be pseudonymous – not anonymous – making it possible to re-identify the people concerned.

CNIL has fined Cegedim Santé €800,000 ($886,809) for processing health data without authorization. The French Data Protection Authority said that the fine reflects the “seriousness of the breaches, the massive nature of the processing and the fact that the data concerned is health data, and therefore sensitive data.”

The company, which publishes

Free Trial

Register for free to keep reading.

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day
Register for free Already a member? Sign in