Skip to content

Swiss Chinese Law Association — Geneva

SCLA | Swiss Chinese Law Association

Legal Observatory / AI and Data

Legal Update European Union Status unclear

Irish Data Protection Commission Fines Health Service Executive €645,000 Over Paper Record Security Failings

The Irish Data Protection Commission fined the Health Service Executive €645,000 and issued compliance orders following data breaches involving unauthorized physical access to paper medical records stored in disused hospitals.

What Changed

  • The inquiry was launched on 24 May 2024 after breach notifications in late 2023 revealed intruders accessed paper records in disused hospitals and posted videos on social media.
  • The DPC established GDPR breaches under Articles 5, 32, 33, and 34 relating to physical storage security and document integrity.
  • The DPC finalized its decision on 28 August 2026, ordering €645,000 in fines, a reprimand, compliance orders, and breach communication orders.

The Irish Data Protection Commission (DPC) has announced its final decision regarding an inquiry into the Health Service Executive (HSE) concerning data protection failings in the handling and security of physical paper records. The investigation focused on the HSE's processing of personal data contained in paper documents retained across external document storage facilities.

The inquiry commenced on 24 May 2024 following two personal data breach notifications submitted to the DPC in October 2023 and November 2023. These notifications stemmed from incidents where unauthorized individuals gained physical access to paper records stored in two former disused psychiatric facilities: St. Loman's Hospital in Mullingar, County Westmeath, and St Conal's Hospital in Letterkenny, County Donegal. Intruders uploaded videos to social media platforms highlighting that medical records were stored and retained in both disused buildings.

Following its investigation, the DPC identified data protection failings concerning the physical conditions of the HSE's document storage facilities and the integrity of the documents held within them. The decision cited violations under multiple provisions of the General Data Protection Regulation (GDPR), specifically Article 5 (principles relating to processing of personal data), Article 32 (security of processing), Article 33 (notification of a personal data breach to the supervisory authority), and Article 34 (communication of a personal data breach to the data subject).

Under its final decision dated 28 August 2026, the DPC imposed corrective measures and sanctions on the HSE. These include administrative fines totalling €645,000, a reprimand, several compliance orders, and a communication order concerning the personal data breach.

This decision emphasizes that data protection compliance under the GDPR applies strictly to physical document archives as well as digital systems, highlighting the liability public and private sector organizations face regarding physical security standards at legacy storage locations.

Who May Be Affected

Health Service Executive (HSE), individuals whose paper medical records were exposed at St. Loman's and St Conal's hospitals, and data controllers managing physical archives.

Cross-Border Context

Illustrates EU-wide enforcement standards under GDPR regarding physical document integrity and security across Member State health sectors.

What to check next

  • Monitor the Irish Data Protection Commission website for the publication of the full text of the HSE decision.

This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.

Prepared automatically with AI assistance from the official sources linked on this page. Translations and explanations do not replace the official text.

Keep the issues that matter to you in view

Subscribe to SCLA updates and choose your interests.