Skip to Primary Navigation

Number of GDPR fines in EU healthcare steady, but average fine rises steeply

Medical staff analyze patient data at the Department of Rehabilitative Cardiology of ASL 3 Genova on July 21, 2020 in Genoa, Italy.
Photo: Marco Di Lauro/Getty Images

Deep dive into the life science and healthcare findings from the CMS GDPR Enforcement Tracker Report 2025.

Main takeaways

There was only a moderate increase in the number of fines imposed compared to 2024.

The most common reason for fines in the healthcare sector continues to be the lack of sufficient technical and organizational measures (TOMs).

This remained a common issue across many healthcare institutions and without a

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience