A Record Fine, and a Rare Target
On 2 September 2026, Ireland's Data Protection Commission (DPC) fined the Health Service Executive (HSE) €645,000 — the largest penalty the regulator has ever imposed on a public-sector body — following a two-year inquiry into patient paper records left to rot in disused hospital buildings. Some files were found contaminated with animal droppings, destroyed by mould, or buried under rubble and water damage.
The inquiry opened in May 2024, triggered by two breach notifications from October and November 2023, after members of the public broke into St Loman's Hospital in Mullingar, Co Westmeath, and St Conal's Hospital in Letterkenny, Co Donegal, and posted videos online showing patient files scattered through derelict wards. DPC inspectors went on to examine 12 HSE storage sites nationwide, finding records kept in disused bathrooms, a shipping container inside a turf shed, and rooms with no functioning heat or light. Deputy Commissioner Graham Doyle said inspectors found storage conditions "in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner." Alongside the fine and a reprimand, the DPC ordered the HSE to conduct a complete audit of every storage facility and securely destroy records no longer needed for their original purpose.
The Case for a Hard Line
The strongest case for a fine this size is straightforward: these were not abstract compliance gaps but real medical and mental-health records — including files tied to death registrations — left physically accessible to trespassers for months, with breach notifications that the DPC found came too slow and incomplete. Ireland's Health Minister, Jennifer Carroll MacNeill, called the penalty "very significant," and the HSE itself apologised and accepted every finding rather than contesting them. A regulator that quietly waived a violation of this scale, on the basis that the offender is a public body funding hospitals rather than a corporation, would invite the fair charge that Irish enforcement bends around political convenience. It did not bend here, and that matters for the DPC's credibility as the lead GDPR regulator for most of Silicon Valley's EU operations.
A Regulator With Bigger Teeth, Still Sheathed
The fine lands the same week people of internet has been tracking Ireland's other major digital regulator, Coimisiún na Meán, whose Online Safety Code — adopted in October 2024 — carries sanctioning power of up to €20 million or 10% of a platform's global turnover, whichever is greater, for video-sharing services including TikTok, YouTube, Meta's platforms, and X. Two years into that regime, no fine has been issued under the Code. Coimisiún na Meán's most concrete enforcement action to date is a pair of investigations opened on 2 December 2025 into TikTok and LinkedIn over illegal-content reporting mechanisms, brought not under the Online Safety Code but under the EU's Digital Services Act, which caps sanctions at 6% of turnover. Even there, the regulator has proposed no fine and has flagged that providers can resolve the probe through a binding commitment agreement rather than a penalty.
Set beside the HSE decision, that gap in real of enforcement can look like Big Tech gets kid gloves while a public health body eats the DPC's largest-ever penalty. That framing is understandable, but it misreads what proportionate regulation actually requires. The HSE case involved settled facts: a physical inspection of named buildings that any observer could verify, a self-admitted GDPR breach, and no serious factual dispute for the DPC to adjudicate. The TikTok and LinkedIn matters turn on contested questions — whether an interface constitutes a "dark pattern," whether a reporting flow is genuinely accessible — that reasonably take longer to establish and are exactly where investigation-first, negotiation-before-penalty tools like commitment agreements earn their keep. Coimisiún na Meán's own account of its approach states plainly that it "will take a supervisory approach to enforcing the Code," prioritising compliance over headline fines during the platforms' initial implementation period.
Why the Comparison Cuts the Other Way
The more useful reading of this week is not that Ireland punishes government but spares tech — it's that Ireland's regulators are, so far, calibrating penalties to the strength of the evidence rather than to who the target is. That is precisely the standard critics of Irish tech regulation have long demanded: stop treating fines as a symbolic tax on being a large platform, and instead size penalties to demonstrated harm and the certainty of the underlying facts. The HSE fine shows the DPC is capable of decisive, well-evidenced enforcement when the record supports it. The real test for Coimisiún na Meán is not whether it eventually fines a platform, but whether the first fine it imposes—for a code violation as viscerally documented as HSE's mouldy archives—can meet the same evidentiary bar. If it can, Ireland's two-track approach will have vindicated proportionate regulation. If two more years pass with headline penalty powers still untested against any platform for any violation, the theoretical maximum starts to look less like restraint and more like an enforcement gap the sector should not assume will last.
"Storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner." — DPC Deputy Commissioner Graham Doyle