Search for "GDPR readiness score by industry" and you'll find plenty of tables with numbers in them — and almost none that say where the numbers actually came from. No regulator, and no single research firm, publishes an audited GDPR readiness score for SaaS, hospitality, healthcare, e-commerce, financial services and professional services side by side. So we built one, from two datasets that do exist and are independently published: Verizon's 2026 Data Breach Investigations Report, and CMS's 2026 GDPR Enforcement Tracker Report. This article shows the resulting scoreboard, the exact formula behind it, and — more importantly — everywhere the formula has to bend to fit six industries onto data that wasn't designed for the comparison.
The Scoreboard
Each industry gets a score from 0–100, built from two components: how often a tracked security incident actually became a confirmed data breach in that industry (Verizon), and how often regulators have actually issued a GDPR fine against that industry (CMS). Both are normalized against the other five industries here — a score is a relative standing in this specific six-way comparison, not a pass/fail grade in absolute terms.
Financial services scores highest on both components; e-commerce lowest on both. Hospitality and Professional services each rest on one component only — see below.
How the Score Is Built
Two components, each independently sourced, each normalized 0–100 across the six industries, then averaged.
Component A — Security Incident Severity. Source: Verizon's 2026 Data Breach Investigations Report (19th edition, covering incidents from November 2024 to October 2025, classified by NAICS industry code). For each industry, this is the share of tracked security incidents that escalated into a confirmed data breach — how often a security event actually results in unauthorized disclosure once it happens.
Component B — GDPR Enforcement Exposure. Source: CMS's GDPR Enforcement Tracker Report 2026 (7th edition, cutoff 1 March 2026, tracking 3,202 fines worth €6.31bn in total). For each industry, this is the number of GDPR fines issued to date in the closest matching CMS business-sector category — how often regulators actually act against that sector.
Composite score = the average of Component A and Component B, each min–max normalized across the six industries. Where only one component has usable data for an industry, the composite rests on that component alone.
A benchmark score describes your sector. It doesn't check your actual website. Run the free audit for 10 concrete GDPR checks — no signup required.
Industry by Industry
1. Financial services — 78/100
The best-performing sector on both measures. Verizon's 2026 dataset shows financial services converting only 1 in 3 tracked incidents into a confirmed breach — 34%, by far the lowest rate of any industry here — while sitting mid-table on GDPR enforcement volume: 307 fines totalling €87.6M in CMS's Finance, Insurance & Consulting category.
2. Hospitality — 68/100 (regional proxy)
Fewest GDPR fines of any sector CMS tracks — 91 in total, €22.7M combined. But two-thirds of them (53 of 91) trace back to one repeated failure: unlawful CCTV and video surveillance in restaurants, bars and hotels. That's a single, fixable control gap, not a broad compliance problem. Verizon didn't publish a standalone hospitality snapshot in the 2026 report, so this score's security component substitutes the report's overall EMEA regional average — flagged here and in the data table below.
3. SaaS & technology — 53/100 (broad proxy)
Mid-table on both measures individually — but the sector's headline enforcement number, roughly €4.0bn in cumulative fines across CMS's Media, Telecoms & Broadcasting category, is dominated by a handful of platform-scale cases (Meta and TikTok account for most of it). Counted by number of enforcement actions instead of euros, the sector looks unremarkable; counted by total fined, it looks catastrophic. That gap is exactly why this score uses fine count, not fine total — see Limitations.
4. Professional services — 40/100 (single component)
CMS has no enforcement category dedicated to consulting, legal, accounting or other professional-services firms — its closest bucket bundles them in with financial services, which would double-count the same fines against two industries. So this score rests on Verizon's security data alone: 2,558 confirmed breaches out of 3,578 tracked incidents, a 71% conversion rate.
5. Healthcare — 33/100
Nearly every tracked security incident in Verizon's healthcare dataset became a confirmed breach — 1,438 of 1,492, a 96% conversion rate, the highest of any sector here. Some of that reflects strict mandatory-disclosure duties doing their job rather than uniquely weak security (more on this below) — but it still leaves healthcare with the least room for error once an incident starts. CMS tracked 265 GDPR fines against the sector, totalling €32.3M.
6. E-commerce — 12/100 (broad proxy)
The lowest score in this comparison, on both components: the most heavily and frequently enforced GDPR sector by case count — 588 fines, €394M total, in CMS's Industry & Commerce category — stacked on an 81% breach-conversion rate, well above the middle of the pack. That CMS category is broader than pure e-commerce, which likely pulls in some weight from adjacent retail and manufacturing cases.
The Underlying Data
None of these six industries map one-to-one onto either dataset's own category system. The table below shows exactly which published category stood in for each target industry.
| Industry | Verizon proxy (NAICS) | Incidents | Confirmed | Rate | CMS proxy sector | Fines | Total |
|---|---|---|---|---|---|---|---|
| Financial services | Financial & Insurance (52) | 3,809 | 1,300 | 34% | Finance, Insurance & Consulting | 307 | €87.6M |
| Hospitality | EMEA region average * | 8,245 | 6,060 | 73% | Accommodation & Hospitality | 91 | €22.7M |
| SaaS & technology | Information (51) | 1,703 | 1,099 | 65% | Media, Telecoms & Broadcasting | 314 | €3,997M |
| Professional services | Professional (54) | 3,578 | 2,558 | 71% | — † | — | — |
| Healthcare | Healthcare (62) | 1,492 | 1,438 | 96% | Life Science & Healthcare | 265 | €32.3M |
| E-commerce | Retail (44–45) | 997 | 806 | 81% | Industry & Commerce | 588 | €394M |
* Verizon did not publish a standalone Accommodation & Food Services (NAICS 72) snapshot in the 2026 report; figures shown are the report's overall EMEA regional average, used as the nearest same-source substitute. † CMS has no enforcement category dedicated to professional/consulting services separate from financial services.
Read Before You Cite This
- These are proxy mappings, not exact matches. Neither source publishes data for "SaaS," "e-commerce," or "professional services" as such — each target industry is approximated by the closest published category, and the approximation is imperfect in both directions.
- Hospitality has no standalone 2026 DBIR snapshot. Its security-severity figure is the report's EMEA regional average, not an accommodation-sector-specific number.
- Professional services has no dedicated GDPR enforcement category in CMS's taxonomy, so that score is Verizon's security data only.
- Fine count, not fine total, drives Component B — specifically to stop three platform-scale cases (two against Meta, one against TikTok) from making an entire sector's score about three companies that aren't representative of the typical business in it.
- A high breach-conversion rate isn't purely a security failing. Sectors with strict mandatory-disclosure duties — healthcare especially — confirm a higher share of incidents as breaches almost by definition. Verizon's own report cautions that cross-industry comparisons are shaped by "varying regulatory and reporting requirements" and differing sample sizes per sector.
- Scores are relative to this specific six-industry comparison, not an absolute compliance grade, and none of this replaces a real DPO-led audit of an individual organization.
The Bottom Line
Financial services and e-commerce sit at opposite ends of this scoreboard for a genuinely interesting reason: financial services shows the lowest breach-conversion rate of any sector Verizon tracks, while e-commerce carries both a high conversion rate and the largest GDPR enforcement caseload by count. Neither extreme is really about "how GDPR-compliant" a typical company in that sector is on paper — it's about how each sector's data and incident volume interacts with regulators who are actively watching it. The number worth taking from this isn't your industry's rank. It's whichever line item in the data table looks like your own business.
Book a free consultation with GDPRGard →
Sources
- Verizon — 2026 Data Breach Investigations Report (Executive Summary, Healthcare & Retail snapshots)
- CMS — GDPR Enforcement Tracker Report 2026 (2025/2026 edition, cutoff 1 March 2026)
- DLA Piper — GDPR Fines and Data Breach Survey, January 2026
- Cisco — 2026 Data and Privacy Benchmark Study
Also read:
- GDPR in 2026: record fines, a reform in motion, and what to do now
- Forget the AI Act — GDPR is already fining companies for AI mistakes
- AI Is 2026's Biggest GDPR Compliance Risk