Critical Guidance eu

DPC Final Decision against Ireland's Health Service Executive (HSE): €645,000 fine for physical security failures exposing paper medical records

Ireland's Data Protection Commission (DPC) issued its final decision on 28 August 2026 against the HSE following unauthorised physical intrusions at two disused psychiatric hospitals — St. Loman's (Mullingar) and St. Conal's (Letterkenny) — where paper medical records were left exposed and later filmed by intruders. The DPC found violations of Articles 5, 32, 33, and 34 GDPR relating to inadequate physical security of storage facilities and failures in breach notification and communication. Controllers holding paper records in off-site or legacy facilities should treat this decision as a direct signal that physical storage conditions are within GDPR scope and will be enforced.

What changed

Who is affected

Public-sector health bodies and any controller (public or private, EU) that stores personal data — including special-category health data — in paper format at off-site, legacy, or third-party physical facilities. Primary jurisdiction: Ireland / EU (GDPR national case, DPC as lead authority).

Effective
2026-08-28
Action
Action required
Language
EN

Frameworks

GDPR

Open the original source