DPC AI Insights Report

24th September 2026

As the EU Lead Supervisory Authority for many of the world’s leading technology companies with European Headquarters located in Ireland, the Data Protection Commission (DPC) occupies a unique regulatory vantage point at the intersection of rapid technological evolution and fundamental rights protection. ...

Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)

02nd September 2026

The Data Protection Commission (DPC) has today announced its final decision following an inquiry into the HSE’s processing of personal data contained in paper records, which are stored and retained in the HSE’s external storage facilities. The DPC’s decision fines the HSE a total of €645,000, and imposes a reprimand and a number of corrective orders. ...

Inquiry into Midlands Regional Hospital Tullamore

On the 10 June 2026 the Data Protection Commission adopted its final decision following an inquiry into a ransomware attack on the laboratory information system in Midlands Regional Hospital Tullamore, County Offaly. The breach was detected on 14 November 2018. The attackers gained access to computers that stored and processed laboratory results of patients’ diagnostic tests, and used that access to encrypt patients’ personal data. 

The DPC’s inquiry examined the HSE’s technical and organisational measures for ensuring the security of processing personal data on the systems that were attacked. It also examined the HSE’s compliance with the GDPR in relation to its contracts with service providers such as third-party data processors, its record of processing activities, and the requirement to notify persons who are affected by high-risk breaches. 

The DPC’s decision, which was notified to the HSE on 11 June 2026, finds that the HSE:

  • infringed the principle of integrity and confidentiality of Article 5(1)(f) GDPR by failing to ensure appropriate security of the personal data related to the processing of patients’ personal data using appropriate technical and organisational measures;
  • infringed Article 28 GDPR by not ensuring that agreements with third parties that processed personal data on its behalf included sufficient safeguards to ensure that processing was fully compliant with the GDPR and that the rights of data subjects were protected;
  • Infringed Article 30 GDPR by failing to have a complete and compliant record of processing activity at the time of the breach;
  • infringed Article 32(1) GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its processing of personal data on the systems affected by the ransomware attack; and
  • infringed Article 34 GDPR by its failure to provide to persons affected by the breach all information required by that Article.

In light of the infringements identified above, the DPC has:

  • reprimanded the HSE;
  • fined the HSE €300,000 for the infringements of Articles 5(1)(f) and 32(1) GDPR; and
  • ordered the HSE to implement specified policies and procedures intended to ensure appropriate security of processing of personal data.

You can download the full decision at this link: Inquiry concerning Midlands Regional Hospital Tullamore - June 2026 (PDF, 1.3MB)

FAQs

FAQs

FAQs

Inquiry into Permanent TSB (PTSB)

The inquiry commenced following Permanent TSB’s (‘PTSB’) notification to the DPC of a series of three data breaches relating to PTSB’s ‘Open 24 Contact Centre’. Each of the data breach notifications concerned malicious actors, in possession of certain PTSB client information, contacting PTSB’s Open24 Contact Centre in order to gain access to client accounts.

The decision considered whether PTSB had complied with Articles 5(1)(f), 32(1) and 33(1) GDPR. In particular the DPC considered whether PTSB had implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with its processing of personal data via the Open 24 Contact Centre, and also whether PTSB had reported the breaches to DPC within the required time periods under the GDPR. 

The DPC’s decision found that PTSB:

  • infringed the principle of integrity and confidentiality of Article 5(1)(f) GDPR by failing to ensure appropriate security of the personal data related to customer accounts by implementing appropriate technical and organisational measures;
  • infringed Article 32(1) GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its processing of personal data within the Open24 Contact Centre; and
  • infringed Article 33(1) GDPR by its failure to notify the DPC without undue delay and within 72 hours of becoming aware of the breaches.

Corrective Powers Exercised:

  1. The Decision issued PTSB with a reprimand in respect of the infringements of Articles PTSB;
  2. The Decision imposed an administrative fine on PTSB in the amount €250,000 in respect of the infringements of Articles 5(1)(f) and 32(1) GDPR; and
  3. The Decision imposed an administrative fine on €27,500 for the infringement of Article 33(1) GDPR

 

You can download the full decision at this link: Permanent TSB (PTSB) - April 2026 (PDF, 898KB).