Ireland Ireland DPC GDPR enforcement Big Tech HQ

The HSE's €645,000 Records Fine Shows GDPR Working Exactly as Designed — Against a Public Body, Not Big Tech

Ireland's DPC fined the HSE €645,000 for patient files rotting in disused bathrooms and a turf shed, proving the regulator enforces against the state, not just Silicon Valley.

HSE's Record: Two DPC Fines in Three Months People of Internet Research · Ireland €645,000 Latest fine amount Largest-ever DPC penalty against a… 12 Sites inspected nationwide DPC inspections to check if failur… €300,000 Prior HSE fine, June 2026 Tullamore ransomware breach affect… ~16 Months from inquiry to decision Inquiry opened May 2024, decision … peopleofinternet.com
HSE's Record: Two DPC Fines in Three M… People of Internet Research · Ireland €645,000 Latest fine amount 12 Sites inspected nationwide €300,000 Prior HSE fine, June 2026 ~16 Months from inquiry to decis… peopleofinternet.com

Key Takeaways

A fine that undercuts a familiar critique

Ireland's Data Protection Commission (DPC) has fined the Health Service Executive (HSE) €645,000 — its largest-ever penalty against a public body — after finding that hundreds of thousands of patient records had been left to rot in disused bathrooms, a shipping container inside a turf shed, and derelict buildings across 12 inspected sites. The DPC's decision, announced 2 September 2026, followed an inquiry opened in May 2024 after two breach notifications — one from St Loman's Hospital in Mullingar, Co Westmeath, and one from St Conal's Hospital in Letterkenny, Co Donegal — surfaced on social media showing exposed files, some marked with patients' deaths, sitting amid animal droppings and mould.

This matters beyond Ireland's health service because the DPC is, fairly or not, the most scrutinised privacy regulator in the world. As the lead supervisory authority for Google, Meta, TikTok, X and most of Silicon Valley's EU operations under GDPR's one-stop-shop mechanism, it has been repeatedly accused — including by MEPs and rival regulators — of going soft on the tech companies headquartered in Dublin for tax reasons while it chases smaller, easier targets. The HSE fine is a data point against that theory: the DPC's own press release states the inquiry found the HSE infringed Article 5(1)(f) (security), Article 5(1)(e) (storage limitation), Article 32(1) (security of processing), and Articles 33(1) and 34(1) — the 72-hour breach-notification duties to the regulator and to affected patients. Deputy Commissioner Graham Doyle said site inspectors found documents "damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus." RTÉ reported Commissioner Dale Sunderland put it more bluntly: "There were records stored in old toilets, a container within a turf shed, there were animal droppings."

Steelmanning the case for the fine

The strongest argument for hitting a cash-strapped public health service with a six-figure penalty, rather than a warning, is recidivism. This is not the HSE's first GDPR sanction: the DPC fined the HSE €300,000 in June 2026 over a 2018 ransomware attack on Midlands Regional Hospital Tullamore's laboratory system that exposed roughly 84,000 patients' diagnostic records — a decision that similarly cited failures under Articles 5(1)(f), 28, 30, 32 and 34. The DPC's HSE decision this time explicitly treated that prior infringement as an aggravating factor. A regulator that only ever issues reprimands teaches nothing; a repeat offender managing the special-category health data of nearly every person in the country is precisely the actor GDPR's proportionality principle should weigh most heavily against, since the harm from a breach of psychiatric and medical records — patients' mental health histories, diagnoses, sometimes death records — is qualitatively worse than a marketing-cookie violation. The corrective orders attached (a full facility audit, mandated destruction of records past their retention period, and relocation out of unsuitable storage) are also the more useful part of the outcome: a fine alone doesn't fix a leaking turf shed, but a binding order with a compliance deadline does.

Why the number, and the target, are still right

Even granting all of that, €645,000 against a health authority with an annual budget north of €25 billion is not a sum that changes behaviour on its own — it is a fraction of what the DPC has extracted from private companies for comparable failures (TikTok's €530 million fine, upheld by the Irish High Court in June 2026, or Meta's €1.2 billion transfer-mechanism penalty). That asymmetry is defensible, not damning: GDPR's own text caps public-body fines more conservatively in member-state implementations, and Ireland's Data Protection Act 2018 reflects that a state health service isn't a profit-seeking data broker — the goal here is remediation, not deterrence-by-bankruptcy. What the HSE case demonstrates well is that the DPC's enforcement docket isn't just a rotating cast of American platforms; a hospital trust with no commercial motive got the same statutory treatment, articles-by-article, as a multinational.

The better lesson for Big Tech watchers is procedural, not partisan: this decision took 16 months from inquiry-opening to final decision for a fact pattern — physically rotting paper files — that required no complex cross-border data-transfer analysis, no interaction with US surveillance law, and no novel legal theory. If a comparatively simple storage-negligence case takes that long, the multi-year timelines on genuinely complex platform inquiries (Meta's transfer case ran for years before its 2023 decision) look less like favoritism and more like a structurally under-resourced regulator working through a real backlog. The fix Ireland needs isn't a bigger stick for the HSE — it's DPC funding and staffing that lets a fair, proportionate enforcer move faster on every file, public and private alike.

Sources & Citations

  1. DPC final decision on HSE inquiry
  2. DPC final decision on Tullamore ransomware inquiry
  3. RTÉ: HSE fined after records found covered in animal droppings
  4. Irish Times: HSE fined €645,000 after rotting medical records found
  5. Silicon Republic: HSE fined €645,000 for storing records in decrepit conditions