What GDPR enforcement can—and cannot—tell us about European healthcare

A PhD project led us to explore publicly reported GDPR enforcement across European healthcare. The study revealed striking differences between countries—and reminded us that understanding how evidence is produced matters as much as the numbers themselves.
What GDPR enforcement can—and cannot—tell us about European healthcare

Share this post

Choose a social network to share with, or copy the URL to share elsewhere

This is a representation of how your post may appear on social media. The actual post will vary between social networks

Explore the Research

BioMed Central
BioMed Central BioMed Central

General Data Protection Regulation (GDPR) enforcement in european healthcare: a comparative analysis of publicly reported enforcement decisions, 2018–2023

Background Healthcare systems increasingly depend on digital technologies for the processing and exchange of sensitive personal data. Although the General Data Protection Regulation (GDPR) provides a harmonised legal framework across Europe, relatively little is known about the characteristics of healthcare-related GDPR enforcement and how publicly reported enforcement activity varies between European jurisdictions. This study aimed to characterise publicly reported healthcare-related GDPR enforcement across European Union and European Economic Area jurisdictions by analysing enforcement frequency, administrative fines, cited GDPR provisions and temporal patterns. Methods A comparative secondary analysis was conducted using healthcare-sector enforcement records from the publicly accessible CMS GDPR Enforcement Tracker. The study included enforcement decisions issued between 25 May 2018 and 31 December 2023 within the 30 European Union and European Economic Area jurisdictions where the GDPR is directly applicable. Eligible records were analysed descriptively with respect to enforcement frequency, administrative fines, cited GDPR provisions and annual distribution. Results The final analytical dataset comprised 207 healthcare-related GDPR enforcement decisions identified in 23 of the 30 jurisdictions included in the study. Fine amounts were available for 192 decisions, with a total known value of €16,045,309. Substantial variation was observed across jurisdictions in both the number of reported decisions and the magnitude of administrative fines. The most frequently cited GDPR provision was Article 5 (61.8%), followed by Article 32 (42.0%), Article 9 (28.5%) and Article 6 (19.3%). The annual number of reported decisions increased from one in 2018 to 62 in 2022 and subsequently declined to 47 in 2023, whereas the total annual value of known fines fluctuated considerably. Conclusions Publicly reported healthcare-related GDPR enforcement varied substantially across European jurisdictions despite a common legal framework. These decisions provide empirical information on regulatory practice but should not be interpreted as direct measures of healthcare-sector compliance, enforcement intensity, cybersecurity maturity or digital health governance performance. The findings provide a reproducible descriptive baseline for future comparative research using appropriate jurisdiction-level denominators and independent indicators of regulatory capacity, digital maturity and organisational preparedness.

My interest in protecting medical and biomedical data began long before the General Data Protection Regulation (GDPR) became applicable. During my master’s studies, I worked on encryption and the secure transmission of biomedical data, before moving into IT security and biometric authentication during my doctorate. Over time, the technologies changed, but one question remained: how can we use sensitive information while keeping it appropriately protected?

Years later, my PhD student and co-author, David Jirsa, brought a new perspective to that question. His doctoral research initially followed my work on biometrics, then gradually moved towards data protection, information security and healthcare regulation. It was David who proposed examining GDPR enforcement in healthcare. What began as part of his doctoral project developed into a European study.

Working in healthcare information security, we often hear about breaches, incidents and organisational failures. Some are publicly documented; others circulate informally among colleagues. These accounts can raise important questions, but they cannot establish how widespread a problem is. We wanted to examine an identifiable body of evidence: publicly reported enforcement decisions. Looking beyond the Czech Republic also offered an opportunity to ask how enforcement varied across countries operating under a common regulatory framework.

Using the publicly accessible CMS GDPR Enforcement Tracker, we analysed healthcare-related decisions issued from 25 May 2018 to the end of 2023. We identified 207 decisions from 23 of the 30 European Union and European Economic Area jurisdictions included in the study. Fine amounts were available for 192 decisions, with a combined known value exceeding €16 million. The provisions most frequently cited concerned the principles of personal-data processing and the security of processing.

The uneven distribution of decisions immediately caught our attention. Yet interpreting those differences became more important than simply describing them. It is tempting to treat enforcement counts or fine totals as a ranking of national data-protection performance. The closer we looked, the clearer it became that the available records could not support that interpretation.

A publicly reported decision is the outcome of several institutional processes. A potential infringement must be detected, investigated, lead to an enforcement decision, be made public and then be captured by the database. Supervisory authorities differ in their resources, priorities and publication practices; healthcare systems also differ in size and organisation. These conditions influence what becomes visible in the records.

Consequently, more reported decisions do not necessarily mean poorer compliance, and fewer decisions do not demonstrate stronger protection or greater cybersecurity maturity. For a healthcare organisation, a low national enforcement count should therefore offer little reassurance on its own. Assessing preparedness requires evidence about actual governance, safeguards and operational practices. Our study describes documented regulatory activity and provides a basis for further investigation.

The manuscript’s journey brought a different kind of lesson. An earlier version remained at another journal for approximately nine months without being sent for peer review and was eventually rejected. After that wait, the decision was frustrating. But it also strengthened my determination to continue. I still believed the question mattered, and we returned to the manuscript, strengthened the analysis and interpretation, and reconsidered where it belonged.

Looking back, I recognise something of the “underdog effect” in my response: the possibility that feeling underestimated can motivate us to demonstrate what we can achieve. It does not describe everyone’s reaction to rejection, but it captures part of mine. The initial wish to prove that the work deserved a chance became a more productive question: how could we make its contribution clearer and more convincing?

In that sense, we owe an unexpected thank-you to the editorial team that declined the first version. Their decision prompted us to revisit the work and take it further. The revised manuscript eventually found its home in Archives of Public Health, and seeing it published there was particularly rewarding because we knew how much it had developed along the way.

This paper remains part of David’s doctoral research and opens up further questions. Understanding the differences between countries will require combining enforcement records with information on regulatory capacity, healthcare-system characteristics and organisational preparedness. Public records offer a useful starting point, provided we remain attentive to how they were produced and what remains outside their scope.

For me, the project also connects two stages of an academic journey: my own early work on biomedical data security and a doctoral student’s exploration of healthcare governance. Protecting health data brings together technology, regulation, organisations and people. That intersection continues to offer questions worth pursuing—and, sometimes, worth returning to after an unexpected setback.