The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage facilities and imposed fines totalling €645,000 along with compliance and communication orders. The breaches involved unauthorized access to records at two former psychiatric hospitals.
Why it matters: The enforcement action underscores GDPR accountability for health data custodians in Ireland.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.