Regulatory Watch  /  Ireland  /  Fine
High impactFineIn effect

Irish Data Protection Commission fines HSE €645,000 for GDPR breaches over paper record storage

The Data Protection Commission (DPC) issued a final decision on 25 August 2026, fining the Health Service Executive (HSE) €645,000 for multiple GDPR infringements related to the storage and security of paper medical records. The DPC also issued a reprimand and ordered comprehensive audits, remediation actions, and improved records‑management procedures. The breaches involved inadequate physical security, failure to delete records, and missed breach‑notification deadlines.

Why it matters: The enforcement action highlights the significant financial and compliance risks for public health bodies that mishandle physical medical records under GDPR.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Data Protection Commission
Data Protection Commission (Ireland) · primary source · May 24, 2024
Details
JurisdictionIreland
RegulatorData Protection Commission (Ireland)
LawGeneral Data Protection Regulation
StatusIn effect
PublishedMay 24, 2024
EffectiveAugust 25, 2026
Penalty€300,000 for Articles 5(1)(f) and 32(1) GDPR; €300,000 for Article 5(1)(e) GDPR; €30,000 for Article 33(1) GDPR; €15,000 for Article 34(1) GDPR; total €645,000
OrganisationsHealth Service Executive (HSE)
Topicssecurity, breach notification, data minimization, privacy
Datapersonal, sensitive, health