Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)

02nd September 2026

The Data Protection Commission (DPC) has today announced its final decision following an inquiry into the HSE’s processing of personal data contained in paper records, which are stored and retained in the HSE’s external storage facilities. The DPC’s decision fines the HSE a total of €645,000, and imposes a reprimand and a number of corrective orders.

This Inquiry commenced on 24 May 2024 as a result of two personal data breaches notified to the DPC in October 2023 and November 2023.

The first breach was notified to the DPC in October 2023, when individuals gained unauthorised access to paper records stored and retained in St. Loman’s Hospital (Mullingar, County Westmeath). St Loman’s Hospital is a former disused psychiatric hospital which is contaminated with asbestos. 

In November 2023, a further breach notification was filed by the HSE with the DPC, when individuals gained unauthorised access to paper records stored and retained in the New Building in St. Conal’s Hospital (Letterkenny, County Donegal). This location is also a former disused psychiatric hospital which is contaminated with severe mould. 

Videos uploaded to social media by intruders highlighted that medical records were stored and retained in both facilities. 

Separately, in April 2024, the HSE informed the DPC that it became aware, via social media, that there had been unauthorised access to the basement of St. Loman’s Hospital, where further records were being stored and retained. The DPC was, at that stage, advised by the HSE, that these records were ‘old mental health’ records. 

Following commencement of the Inquiry in May 2024, and as part of the Inquiry process, authorised officers from the DPC carried out 12 site inspections nationwide. The purpose of the site inspections was to ascertain whether the issues identified in the breach notifications were isolated incidents, or whether the issues were systemic, regarding the retention and storage of personal data contained in paper records, held by the HSE, in its external facilities.

The DPC’s findings identified data protection failings concerning the physical conditions of HSE document storage facilities and the integrity of the documents held within those facilities.

Deputy Commissioner, Graham Doyle commented that “During the site inspections, the DPC observed significant issues with documents damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment or water damaged. The DPC discovered storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner. There were records stored in disused bathrooms and cubicles, a shipping container in a turf shed, rooms without functioning lighting or heating, as well as derelict buildings at a number of disparate locations. 

The retention of records by the HSE in an insecure manner beyond the period where they should be retained gives rise to an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties. There is also the risk of records not being available for other medical care or other legal or regulatory reasons.”

The DPC’s decision, which was notified to the HSE on 25 August, 2026, finds that the HSE:

  1. Infringed the principle of integrity and confidentiality of Article 5(1)(f) GDPR and infringed Article 32(1) GDPR by: 

a. Failing to ensure appropriate security of the personal data contained in paper records stored and retained by the HSE in its external facilities;

b. Failing to implement appropriate technical and organisational measures, including proper records management processes, mechanisms and controls, to ensure a level of security appropriate to the risk.

  1. Infringed the principle of storage limitation of Article 5(1)(e) GDPR by failing to retain personal data contained in paper records in a form which permits identification of data subjects for no longer than is necessary.
  2. Infringed Article 33(1) GDPR by:

a. Failing to notify a breach to the DPC without undue delay, and within 72 hours of becoming aware of it, in respect of St. Loman’s Hospital;

b. Failing to notify a breach to the DPC without undue delay, and within 72 hours of becoming aware of it, in respect of the personal data contained in paper records stored and retained in the basement of St. Loman’s Hospital.

  1. Infringed Article 34(1) GDPR by failing to communicate to the data subjects, the personal data breaches which occurred at St. Loman’s Hospital and St. Conal’s Hospital. 

In light of the infringements identified above, the DPC has:

  • Reprimanded the HSE;
  • Ordered the HSE to bring its processing of personal data into compliance with the GDPR, and in particular into compliance with Articles 5(1)(e), 5(1)(f) and 32(1) GDPR. The orders imposed by the DPC on the HSE include orders requiring the HSE to:

 

  1. Carry out a complete audit of all storage facilities where the HSE stores and retains paper files for purposes including:

i. Implementing a robust and appropriately designed management system for the purposes of recording and tracing all personal data stored and retained in the HSE storage facilities;

ii. Where paper records containing personal data are no longer necessary for the purposes for which they are retained, ensuring their immediate and safe destruction;

iii. Implementing policies and procedures for the purposes of regularly testing, assessing and evaluating the HSE’s compliance with its own retention policies.

  1. Carry out a complete audit and assessment of all storage facilities where the HSE stores and retains paper files to ensure each facility is fit for purpose in terms of maintaining the integrity, availability and confidentiality of personal data. As part of this audit and assessment, the HSE must ensure certain actions are taken by it, including the following:

i. Remove all paper records containing personal data from HSE storage facilities which are not fit for purpose and to move those paper records to appropriate facilities, which facilities shall ensure and maintain the integrity, availability, and confidentiality of all paper records;

ii. Implement a robust and appropriately designed management system for the purposes of tracking and tracing the location of all paper records containing personal data stored and retained in HSE facilities;

iii. Implement policies and procedures for the purposes of regularly testing, assessing and evaluating the HSE storage locations of paper records containing personal data. 

  • Fined the HSE as follows:

€300,000 for the infringements of Articles 5(1)(f) and 32(1) GDPR; 

€300,000 for the infringement of Article 5(1)(e) GDPR;

€30,000 for the infringements of Article 33(1) GDPR;

€15,000 for the infringements of Article 34(1) GDPR.

In the calculation of fines, the DPC considered, as an aggravating factor, that the HSE committed similar previous infringements concerning the lack of appropriate security measures and the loss of control over personal data contained in paper healthcare records. These past infringements were of a similar nature, albeit under a different set of circumstances.

The DPC will publish the full decision in due course.