Ireland's Data Protection Commission (DPC) has fined the Health Service Executive (HSE) €645,000 after inspectors found decades of paper patient records rotting, mould-damaged and contaminated with animal droppings at two disused psychiatric hospitals. The case, announced 2 September 2026, is one of the DPC's more visceral enforcement actions to date — and a useful stress test for what a data protection fine is actually supposed to accomplish when the defendant is the state itself.
What Inspectors Found
The inquiry traced back to two breaches: unauthorised access to paper records at St Loman's Hospital, a disused, asbestos-contaminated former psychiatric facility in Mullingar, Co Westmeath, and a similar breach at St Conal's Hospital, a shuttered psychiatric hospital in Letterkenny, Co Donegal, where severe mould had taken hold. The HSE notified the DPC of the St Conal's breach in November 2023, but the St Loman's incident only came to light in April 2024 — after unauthorised entry to the hospital's basement was flagged on social media, well outside GDPR's 72-hour notification window (Irish Times).
That discrepancy triggered a broader inquiry, launched in May 2024, during which the DPC carried out 12 site inspections across HSE facilities nationwide to establish whether the problem was isolated or systemic. It was systemic: investigators found records "damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment, or water damaged," stored in disused bathrooms, cubicles, a shipping container in a turf shed, and unheated, unlit rooms (Silicon Republic; DPC).
Alongside the €645,000 penalty, the DPC issued a corrective order requiring the HSE to bring its processing activities into compliance and submit a detailed implementation plan within 30 days — arguably the more consequential part of the decision.
The Case For the Fine
The DPC's action is not regulatory overreach. These were psychiatric patient records — special-category health data under GDPR, carrying real risk of stigma and harm if it fell into the wrong hands. A public body holding some of the most sensitive personal data in the state let it decompose in unsecured, unmonitored buildings for years, then missed its legal deadline to tell regulators when someone got in. Twelve separate site inspections turning up the same pattern of neglect shows this wasn't an isolated lapse but a governance failure across the estate. As DPC Deputy Commissioner Graham Doyle put it: "The retention of records by the HSE in an insecure manner beyond the period where they should be retained gives rise to an ongoing significant risk" (Silicon Republic). Regulators who let public bodies off the hook while fining private companies for comparable failures would rightly be accused of a double standard. On the substance, this fine is deserved.
Where the Tool Stops Working
But the mechanism of a monetary fine does something different here than it does against a corporation. When the DPC fined TikTok €530 million in 2025 for unlawful data transfers, that penalty came out of shareholder returns and created a genuine profit-and-loss incentive to fix the underlying practice (RTÉ). When the DPC fines the HSE, the money moves from one arm of the Irish state — a chronically underfunded health service — to another, the Exchequer. No shareholder feels it. No executive's bonus shrinks. The €645,000 will most plausibly come out of a budget already stretched across hospital wards, meaning the fine's practical effect may be to marginally reduce the same HSE's capacity to invest in the records-management fixes the DPC is simultaneously ordering it to make within 30 days.
Since May 2018, the DPC has imposed €4.04 billion in GDPR fines — more than any other EU regulator, nearly four times second-placed France's total — yet only around €20 million, roughly 0.5%, has actually been collected, mostly because large corporates litigate for years before paying (RTÉ). That imbalance is usually cited as evidence corporates are winning through delay. But it cuts the other way for a case like this: a public body can't appeal its way out of paying, so the fine will land in full and fast — extracting real money from patient services for a governance failure that a funded, mandated audit programme would have caught, and fixed, more directly.
The Better Instrument Was Already in the Decision
The DPC's 30-day compliance order — not the €645,000 — is the part of this ruling actually built to prevent a repeat. A ring-fenced records-management fund, tied to the audit the DPC has already demanded, would do more for future patients than a transfer payment between government ledgers. None of this excuses the HSE's negligence, which was real and serious. But regulators evaluating public-sector GDPR breaches should weigh structural remedies more heavily than headline fines: the corrective order is where the deterrence actually lives, and it's already been issued.