On 2 September 2026, Ireland's Data Protection Commission (DPC) announced its final decision in an inquiry into the Health Service Executive (HSE). It fined the HSE €645,000, issued a reprimand and imposed corrective orders. The case is unglamorous. It involves no algorithm, no cross-border data transfer and no adtech. It involves paper files in derelict buildings. It is also a useful example of proportionate GDPR enforcement.
What the DPC found
The inquiry opened on 24 May 2024, after two breaches were notified to the DPC in October and November 2023. In both, people gained unauthorised access to paper records at disused psychiatric hospitals, St Loman's in Mullingar and St Conal's in Letterkenny. The DPC carried out 12 site inspections and found records stored in disused bathrooms, shipping containers and derelict buildings. According to the Irish Times, documents were damaged or destroyed by mould, contaminated by animal droppings, covered in rubble or water damaged. The HSE itself only learned of a further incident in April 2024 through social media videos.
The €645,000 total breaks down by provision, per the DPC:
- €300,000 for Articles 5(1)(f) and 32(1), which cover integrity, confidentiality and security of processing.
- €300,000 for Article 5(1)(e), the storage limitation principle.
- €30,000 for Article 33(1), late breach notification to the regulator.
- €15,000 for Article 34(1), failure to tell affected individuals.
The DPC also ordered a full audit of storage facilities, a system for tracking personal data records, removal of records from unfit locations, and retention compliance testing.
The case for a hard line
The strongest argument for heavy enforcement against a public body is that these are patient records, among the most sensitive data that exists. Public bodies cannot be disciplined by market forces, and patients have no alternative provider to switch to. If regulators go easy on the state, the deterrent is weak for exactly the institutions holding the most intimate data. Critics of the fine would say €645,000 is trivial against a health budget in the billions, and that the HSE's own failure to detect intrusions for months warrants more.
That argument has force. Even so, the more significant feature of this decision is what it targets.
Why this is enforcement done right
The GDPR is often criticised for vague, principle-based duties that make compliance costs unpredictable, especially for smaller firms and innovators. This case shows the opposite end of the spectrum. Storing patient files in a shipping container in a turf shed is not a close call requiring a novel legal theory. The violations are concrete, observable and easy to prevent, and no reasonable controller could claim uncertainty about what was expected.
That clarity matters for a pro-innovation reading of data protection. Regulators spend finite attention, and every euro of enforcement capacity spent on plain negligence is capacity not spent on speculative theories against emerging technologies. Enforcement that punishes clearly bad practice, and leaves good-faith firms room to build, sustains the legitimacy of the regime. The DPC's approach here, an on-site inquiry with physical inspections and a fine split transparently across four provisions, is more predictable than many of the headline cases involving global platforms.
The decision is also proportionate in structure. The two largest components, security and storage limitation, carry equal weight. The DPC treated the twin failure of holding data too long and holding it too carelessly as the core wrong. The notification failures were penalised far more lightly, at €30,000 and €15,000. That reflects a sensible view that late paperwork is a lesser harm than exposing records in the first place.
Lessons beyond Ireland
The storage limitation finding is the most instructive. Article 5(1)(e) requires that personal data be kept no longer than necessary. Much of the HSE's exposure arose because old records were never triaged, retained or destroyed on a schedule, so they piled up in decaying buildings. Data that is never collected or is properly deleted cannot be breached. Retention discipline is therefore a security control as well as a compliance box, and it costs far less than incident response.
The HSE said it was sorry and apologised to patients, acknowledged non-compliance with its record retention policies, and committed to standardised archiving and disposal procedures. The Irish Times reported that Ireland's continued reliance on paper medical records was cited as a systemic issue. The durable fix is digitisation with proper access controls and retention rules. That is a policy choice for the Irish government, and one that a fine cannot make on its own.
What to watch
Two questions follow. First, whether the corrective orders are audited and verified, since the orders are more consequential than the fine. Second, whether other EU regulators follow this model of physical inspection and clear-cut findings. The EDPB's news feed shows national authorities issuing a steady run of health-data and rights-related fines, which suggests a growing focus on sector-specific, evidence-heavy cases.
For policymakers who want GDPR to be both credible and innovation-friendly, this is the template. Enforce hard against obvious, preventable failures by institutions that hold sensitive data. Keep penalties tied to the specific harm. Leave good-faith actors with clear rules and a predictable regulator.