Data Protection Commission publishes AI Insights Report
25th September 2026
25th September 2026
24th September 2026
21st September 2026
08th September 2026
02nd September 2026
On the 10 June 2026 the Data Protection Commission adopted its final decision following an inquiry into a ransomware attack on the laboratory information system in Midlands Regional Hospital Tullamore, County Offaly. The breach was detected on 14 November 2018. The attackers gained access to computers that stored and processed laboratory results of patients’ diagnostic tests, and used that access to encrypt patients’ personal data.
The DPC’s inquiry examined the HSE’s technical and organisational measures for ensuring the security of processing personal data on the systems that were attacked. It also examined the HSE’s compliance with the GDPR in relation to its contracts with service providers such as third-party data processors, its record of processing activities, and the requirement to notify persons who are affected by high-risk breaches.
The DPC’s decision, which was notified to the HSE on 11 June 2026, finds that the HSE:
In light of the infringements identified above, the DPC has:
You can download the full decision at this link: Inquiry concerning Midlands Regional Hospital Tullamore - June 2026 (PDF, 1.3MB)
The Irish AI Office is designated the single point of contact for the Regulation of AI in Ireland. Please consult the AI Office’s website
The Irish AI Office is designated the single point of contact for the Regulation of AI in Ireland. Please consult the AI Office of Ireland’s website
The Data Protection Commission (DPC) has certain functions and powers under the EU Artificial Intelligence Act (2024). These statutory powers,
The inquiry commenced following Permanent TSB’s (‘PTSB’) notification to the DPC of a series of three data breaches relating to PTSB’s ‘Open 24 Contact Centre’. Each of the data breach notifications concerned malicious actors, in possession of certain PTSB client information, contacting PTSB’s Open24 Contact Centre in order to gain access to client accounts.
The decision considered whether PTSB had complied with Articles 5(1)(f), 32(1) and 33(1) GDPR. In particular the DPC considered whether PTSB had implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with its processing of personal data via the Open 24 Contact Centre, and also whether PTSB had reported the breaches to DPC within the required time periods under the GDPR.
The DPC’s decision found that PTSB:
You can download the full decision at this link: Permanent TSB (PTSB) - April 2026 (PDF, 898KB).