What Changed
- The inquiry was launched on 24 May 2024 after breach notifications in late 2023 revealed intruders accessed paper records in disused hospitals and posted videos on social media.
- The DPC established GDPR breaches under Articles 5, 32, 33, and 34 relating to physical storage security and document integrity.
- The DPC finalized its decision on 28 August 2026, ordering €645,000 in fines, a reprimand, compliance orders, and breach communication orders.
The Irish Data Protection Commission (DPC) has announced its final decision regarding an inquiry into the Health Service Executive (HSE) concerning data protection failings in the handling and security of physical paper records. The investigation focused on the HSE's processing of personal data contained in paper documents retained across external document storage facilities.
The inquiry commenced on 24 May 2024 following two personal data breach notifications submitted to the DPC in October 2023 and November 2023. These notifications stemmed from incidents where unauthorized individuals gained physical access to paper records stored in two former disused psychiatric facilities: St. Loman's Hospital in Mullingar, County Westmeath, and St Conal's Hospital in Letterkenny, County Donegal. Intruders uploaded videos to social media platforms highlighting that medical records were stored and retained in both disused buildings.
Following its investigation, the DPC identified data protection failings concerning the physical conditions of the HSE's document storage facilities and the integrity of the documents held within them. The decision cited violations under multiple provisions of the General Data Protection Regulation (GDPR), specifically Article 5 (principles relating to processing of personal data), Article 32 (security of processing), Article 33 (notification of a personal data breach to the supervisory authority), and Article 34 (communication of a personal data breach to the data subject).
Under its final decision dated 28 August 2026, the DPC imposed corrective measures and sanctions on the HSE. These include administrative fines totalling €645,000, a reprimand, several compliance orders, and a communication order concerning the personal data breach.
This decision emphasizes that data protection compliance under the GDPR applies strictly to physical document archives as well as digital systems, highlighting the liability public and private sector organizations face regarding physical security standards at legacy storage locations.
Who May Be Affected
Health Service Executive (HSE), individuals whose paper medical records were exposed at St. Loman's and St Conal's hospitals, and data controllers managing physical archives.
Cross-Border Context
Illustrates EU-wide enforcement standards under GDPR regarding physical document integrity and security across Member State health sectors.
What to check next
- Monitor the Irish Data Protection Commission website for the publication of the full text of the HSE decision.
This article provides general information and does not constitute legal advice. Consult the official text and obtain advice appropriate to your circumstances where needed.
Prepared automatically with AI assistance from the official sources linked on this page. Translations and explanations do not replace the official text.