What GDPR enforcement can—and cannot—tell us about European healthcare

A PhD project led us to explore publicly reported GDPR enforcement across European healthcare. The study revealed striking differences between countries—and reminded us that understanding how evidence is produced matters as much as the numbers themselves.

My interest in protecting medical and biomedical data began long before the General Data Protection Regulation (GDPR) became applicable. During my master’s studies, I worked on encryption and the secure transmission of biomedical data, before moving into IT security and biometric authentication during my doctorate. Over time, the technologies changed, but one question remained: how can we use sensitive information while keeping it appropriately protected?

Years later, my PhD student and co-author, David Jirsa, brought a new perspective to that question. His doctoral research initially followed my work on biometrics, then gradually moved towards data protection, information security and healthcare regulation. It was David who proposed examining GDPR enforcement in healthcare. What began as part of his doctoral project developed into a European study.

Working in healthcare information security, we often hear about breaches, incidents and organisational failures. Some are publicly documented; others circulate informally among colleagues. These accounts can raise important questions, but they cannot establish how widespread a problem is. We wanted to examine an identifiable body of evidence: publicly reported enforcement decisions. Looking beyond the Czech Republic also offered an opportunity to ask how enforcement varied across countries operating under a common regulatory framework.

Using the publicly accessible CMS GDPR Enforcement Tracker, we analysed healthcare-related decisions issued from 25 May 2018 to the end of 2023. We identified 207 decisions from 23 of the 30 European Union and European Economic Area jurisdictions included in the study. Fine amounts were available for 192 decisions, with a combined known value exceeding €16 million. The provisions most frequently cited concerned the principles of personal-data processing and the security of processing.

The uneven distribution of decisions immediately caught our attention. Yet interpreting those differences became more important than simply describing them. It is tempting to treat enforcement counts or fine totals as a ranking of national data-protection performance. The closer we looked, the clearer it became that the available records could not support that interpretation.

A publicly reported decision is the outcome of several institutional processes. A potential infringement must be detected, investigated, lead to an enforcement decision, be made public and then be captured by the database. Supervisory authorities differ in their resources, priorities and publication practices; healthcare systems also differ in size and organisation. These conditions influence what becomes visible in the records.

Consequently, more reported decisions do not necessarily mean poorer compliance, and fewer decisions do not demonstrate stronger protection or greater cybersecurity maturity. For a healthcare organisation, a low national enforcement count should therefore offer little reassurance on its own. Assessing preparedness requires evidence about actual governance, safeguards and operational practices. Our study describes documented regulatory activity and provides a basis for further investigation.

The manuscript’s journey brought a different kind of lesson. An earlier version remained at another journal for approximately nine months without being sent for peer review and was eventually rejected. After that wait, the decision was frustrating. But it also strengthened my determination to continue. I still believed the question mattered, and we returned to the manuscript, strengthened the analysis and interpretation, and reconsidered where it belonged.

Looking back, I recognise something of the “underdog effect” in my response: the possibility that feeling underestimated can motivate us to demonstrate what we can achieve. It does not describe everyone’s reaction to rejection, but it captures part of mine. The initial wish to prove that the work deserved a chance became a more productive question: how could we make its contribution clearer and more convincing?

In that sense, we owe an unexpected thank-you to the editorial team that declined the first version. Their decision prompted us to revisit the work and take it further. The revised manuscript eventually found its home in Archives of Public Health, and seeing it published there was particularly rewarding because we knew how much it had developed along the way.

This paper remains part of David’s doctoral research and opens up further questions. Understanding the differences between countries will require combining enforcement records with information on regulatory capacity, healthcare-system characteristics and organisational preparedness. Public records offer a useful starting point, provided we remain attentive to how they were produced and what remains outside their scope.

For me, the project also connects two stages of an academic journey: my own early work on biomedical data security and a doctoral student’s exploration of healthcare governance. Protecting health data brings together technology, regulation, organisations and people. That intersection continues to offer questions worth pursuing—and, sometimes, worth returning to after an unexpected setback.