The Data Protection Commission (DPC) issued a final decision on 25 August 2026, fining the Health Service Executive (HSE) €645,000 for multiple GDPR infringements related to the storage and security of paper medical records. The DPC also issued a reprimand and ordered comprehensive audits, remediation actions, and improved records‑management procedures. The breaches involved inadequate physical security, failure to delete records, and missed breach‑notification deadlines.
Why it matters: The enforcement action highlights the significant financial and compliance risks for public health bodies that mishandle physical medical records under GDPR.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.