What happened
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage facilities and imposed fines totalling €645,000 along with compliance and communication orders. The breaches involved unauthorized access to records at two former psychiatric hospitals.
Penalty
fines totalling €645 000
Why it matters for trust and compliance
- Its status is decided. The case has an outcome that others may cite.
- The enforcement action underscores GDPR accountability for health data custodians in Ireland.
- Takes effect August 28, 2026.
- Penalty: fines totalling €645 000.
- It relates to GDPR. The regulations library explains what that law requires.
Who is affected
healthcare government controller Health Service Executive (HSE)
Recommended actions
- Check that privacy notices describe the practices this addresses.
- Revisit retention schedules and data minimisation for the data involved.
- Map the security requirements to existing controls and close gaps.
- Check breach-notification procedures and timelines against the requirement.
- Confirm handling of sensitive data categories meets the stricter rules.