General Data Protection Regulation (GDPR) enforcement in european healthcare: a comparative analysis of publicly reported enforcement decisions, 2018–2023
Abstract Background Healthcare systems increasingly depend on digital technologies for the processing and exchange of sensitive personal data. Although the General Data Protection Regulation (GDPR) provides a harmonised legal framework across Europe, relatively little is known about the characteristics of healthcare-related GDPR enforcement and how publicly reported enforcement activity varies between European jurisdictions. This study aimed to characterise publicly reported healthcare-related GDPR enforcement across European Union and European Economic Area jurisdictions by analysing enforcement frequency, administrative fines, cited GDPR provisions and temporal patterns. Methods A comparative secondary analysis was conducted using healthcare-sector enforcement records from the publicly accessible CMS GDPR Enforcement Tracker. The study included enforcement decisions issued between 25 May 2018 and 31 December 2023 within the 30 European Union and European Economic Area jurisdictions where the GDPR is directly applicable. Eligible records were analysed descriptively with respect to enforcement frequency, administrative fines, cited GDPR provisions and annual distribution. Results The final analytical dataset comprised 207 healthcare-related GDPR enforcement decisions identified in 23 of the 30 jurisdictions included in the study. Fine amounts were available for 192 decisions, with a total known value of €16,045,309. Substantial variation was observed across jurisdictions in both the number of reported decisions and the magnitude of administrative fines. The most frequently cited GDPR provision was Article 5 (61.8%), followed by Article 32 (42.0%), Article 9 (28.5%) and Article 6 (19.3%). The annual number of reported decisions increased from one in 2018 to 62 in 2022 and subsequently declined to 47 in 2023, whereas the total annual value of known fines fluctuated considerably. Conclusions Publicly reported healthcare-related GDPR enforcement varied substantially across European jurisdictions despite a common legal framework. These decisions provide empirical information on regulatory practice but should not be interpreted as direct measures of healthcare-sector compliance, enforcement intensity, cybersecurity maturity or digital health governance performance. The findings provide a reproducible descriptive baseline for future comparative research using appropriate jurisdiction-level denominators and independent indicators of regulatory capacity, digital maturity and organisational preparedness.
Authors
- Anna Horňáková (ORCID: https://orcid.org/0000-0002-1024-8056)
- David Jirsa (ORCID: https://orcid.org/0000-0003-3799-5622)
Publication Details
- Journal
- Archives of Public Health
- Published
- 2026-09-22
- DOI
- https://doi.org/10.1186/s13690-026-02081-0
- Primary Topic
- Privacy, Security, and Data Protection
- Type
- article
- Field-Weighted Citation Impact
- 0.00