DPC Final Decision against Ireland's Health Service Executive (HSE): €645,000 fine for physical security failures exposing paper medical records
Ireland's Data Protection Commission (DPC) issued its final decision on 28 August 2026 against the HSE following unauthorised physical intrusions at two disused psychiatric hospitals — St. Loman's (Mullingar) and St. Conal's (Letterkenny) — where paper medical records were left exposed and later filmed by intruders. The DPC found violations of Articles 5, 32, 33, and 34 GDPR relating to inadequate physical security of storage facilities and failures in breach notification and communication. Controllers holding paper records in off-site or legacy facilities should treat this decision as a direct signal that physical storage conditions are within GDPR scope and will be enforced.
What changed
- DPC imposed administrative fines totalling €645,000 on the HSE for GDPR violations arising from physical data storage failures at two former psychiatric hospital sites.
- DPC issued a reprimand and multiple compliance orders, requiring the HSE to remediate document storage practices — obligations that may necessitate audits and facility upgrades.
- Violations found under Article 32 (security of processing) confirmed that physical conditions of paper-record storage facilities fall squarely within GDPR security obligations.
- Findings under Articles 33 and 34 indicate the HSE was found deficient in notifying the DPC and communicating the breaches to affected data subjects in a timely or adequate manner.
- The case origin — two breach notifications filed in October and November 2023 — signals that the DPC's inquiry-to-decision timeline ran approximately 33 months, relevant for organisations assessing supervisory engagement risk.
Who is affected
Public-sector health bodies and any controller (public or private, EU) that stores personal data — including special-category health data — in paper format at off-site, legacy, or third-party physical facilities. Primary jurisdiction: Ireland / EU (GDPR national case, DPC as lead authority).
- Effective
- 2026-08-28
- Action
- Action required
- Language
- EN