Ireland Ireland DPC GDPR enforcement Big Tech HQ

Ireland's DPC Fined Its Own Health Service €645,000 — And That's the Part Big Tech Should Envy

The DPC's HSE fine will actually get collected quickly, unlike most of the €4bn in penalties it has levied on Big Tech since 2018.

Fined vs. Collected: Ireland's GDPR Enforcement Gap People of Internet Research · Ireland €645,000 HSE fine total For storing medical records in mou… €4.04B DPC fines since 2018 Total GDPR penalties issued by Ire… ~€20M Amount actually collected Most large fines remain tied up in… 280 vs 270 DPC staff vs EU DSA team DPC's €29.4M budget compares to th… peopleofinternet.com
Fined vs. Collected: Ireland's GDPR En… People of Internet Research · Ireland €645,000 HSE fine total €4.04B DPC fines since 2018 ~€20M Amount actually collected 280 vs 270 DPC staff vs EU DSA team peopleofinternet.com

Key Takeaways

A state body gets the same treatment as a platform

On 2 September 2026, Ireland's Data Protection Commission (DPC) announced a €645,000 fine against the Health Service Executive (HSE), the state body that runs Irish public healthcare. The inquiry, opened 24 May 2024 after two breach notifications in October and November 2023, found that paper medical records held in HSE storage facilities — including a disused psychiatric hospital in Mullingar and another in Letterkenny — had been "damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment or water damaged," in the words of Deputy Commissioner Graham Doyle. The DPC's decision splits the fine across five GDPR articles: €300,000 for breaching the integrity-and-confidentiality and security-of-processing principles (Articles 5(1)(f) and 32(1)), €300,000 for violating storage limitation (Article 5(1)(e)), €30,000 for delayed breach notification, and €15,000 for failing to inform affected patients.

The steelman: this is exactly what a regulator should do

The fine deserves credit on its own terms. Storing identifiable medical records — among the most sensitive categories of personal data under GDPR — in derelict buildings for years past any retention justification is not a technical violation; it is a real, ongoing risk to patients whose records could be accessed, lost, or exploited. The DPC's corrective orders, requiring the HSE to audit every storage facility nationwide, destroy records with no lawful basis for retention, and build a functioning records-tracking system, address the actual harm rather than just extracting a headline number. A regulator that only ever fined foreign platforms while giving the national health service a pass would rightly be accused of selective enforcement. This fine says otherwise.

The number that actually matters isn't €645,000

But the HSE case is illuminating less for its size than for what happens next: it will very likely be paid, promptly, because the HSE is a public body with no appetite for a multi-year legal fight against its own state's regulator. Compare that to the DPC's record against Big Tech. The Irish regulator — lead supervisory authority for Meta, TikTok, Google, X, LinkedIn, and dozens of other firms headquartered in Dublin for the EU market — has issued roughly €4.04 billion in GDPR fines since 2018, according to RTÉ's review of enforcement data, including the record €1.2 billion Meta transfer-mechanism fine (2023), a €345 million fine against TikTok over children's privacy defaults (announced 15 September 2023), and a further €530 million against TikTok in May 2025 over EEA user data transfers to China. Yet only around €20 million of that €4.04 billion has actually been collected, largely because the largest fines are tied up in appeals that can run for years.

That is the real enforcement story here. A €645,000 fine against a domestic public body that gets paid without a fight is, in cash-collected terms, not far behind the practical yield of headline-grabbing billion-euro penalties against companies with the resources and incentive to litigate indefinitely. Proportionate regulation should mean matching remedies to actual harm — but it should also mean a system where the announced fine and the collected fine aren't two different numbers separated by years of appeal.

Capacity, not just courage, is the bottleneck

Part of the gap is resourcing. The DPC sought a €10 million budget increase for 2026, arguing it was being asked to regulate "global technology companies that were worth billions of euro while spending just a tiny fraction of their budgets" on 280 staff and a €29.4 million budget — smaller than the roughly 270 people and €55 million the European Commission alone devotes to Digital Services Act enforcement, per the Irish Times' reporting on the DPC's own submission. Budget 2026 ultimately granted a smaller increase than requested. An under-resourced regulator moves slower on the complex cross-border cases that require expert digital-forensics teams and multilingual cooperation, while a domestic inspection of a hospital storeroom is comparatively straightforward to conclude and enforce.

A structural fix is already coming — for the right reason

The EU has recognized this bottleneck exists independent of any one regulator's diligence. Regulation (EU) 2025/2518, published in the Official Journal on 12 December 2025 and in force from 1 January 2026 (applying from 2 April 2027), introduces EU-wide admissibility rules, firm procedural deadlines — 15 months for standard cross-border investigations, 12 for simpler ones — and a streamlined cooperation file between national data protection authorities. That is the more useful reform than louder calls for bigger fines: speed and certainty of process, not penalty size, is what has been missing from cross-border Big Tech enforcement.

The HSE fine is a legitimate, well-evidenced enforcement action against a genuine failure to protect patient data, and the DPC should be taken at its word that it applies GDPR without regard to who the target is. But the more consequential test of that even-handedness is whether the 2027 procedural regime finally closes the gap between the fines Dublin announces against the tech sector and the fines it actually collects.

Sources & Citations

  1. DPC: Final Decision on HSE Inquiry
  2. DPC: €345m TikTok Decision
  3. European Parliament: GDPR Procedural Regulation Legislative Train
  4. Irish Times: HSE fined €645,000
  5. Irish Times: DPC sought €10m budget increase
  6. RTÉ: Ireland retains top spot in data enforcement