Regulatory Watch  /  Ireland  /  Data protection authority action
Moderate impactData protection authority actionDecided

DPC issues final decision reprimanding Children’s Health Ireland for GDPR security breaches

The Irish Data Protection Commission concluded that Children’s Health Ireland (CHI) at Tallaght University Hospital breached GDPR security and confidentiality obligations. CHI was reprimanded and ordered to bring its processing into compliance, complete DPIAs and implement technical and organisational measures. The decision was notified to CHI on 10 September 2026.

Why it matters: The DPC’s enforcement action highlights regulatory scrutiny of health data security and the need for robust GDPR compliance in healthcare settings.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Data Protection Commission
Data Protection Commission (Ireland) · primary source · Jul 16, 2025
Details
JurisdictionIreland
RegulatorData Protection Commission (Ireland)
LawGeneral Data Protection Regulation
StatusDecided
PublishedJuly 16, 2025
Effectivenot stated
OrganisationsChildren’s Health Ireland (CHI) at Tallaght University Hospital
Topicssecurity, children, privacy
Datapersonal, sensitive, health, children