DPC Reprimands CHI at Tallaght Over Children's Health Records
Independently fact-checked against primary sources (last audited October 6, 2026). · 12 primary sources cited on this page. How we verify our legal content

DPC Reprimands CHI at Tallaght Over Children's Health Records Security
The Data Protection Commission has reprimanded Children's Health Ireland at Tallaght University Hospital and ordered it to finalise two data protection impact assessments, after finding that it failed to keep children's paper health records, and the documents put into a confidential waste bin, secure and properly controlled.
Information last verified on 6 October 2026. This is a developing story; we update it as the record changes.
Status: Final decision notified to CHI at Tallaght on 10 September 2026 and announced by the DPC on 1 October 2026. The DPC says it will publish the full decision in due course, so this article relies on the DPC's published summary.
Jurisdiction scope: This is an Irish regulatory decision applying Regulation (EU) 2016/679, the EU General Data Protection Regulation, as supplemented by the Data Protection Act 2018. It binds no one outside Ireland, but the Article 32 text the DPC applied is the same text every controller in the European Union and the wider European Economic Area works from. For the country-level picture, see Ireland's data protection framework.
What Happened
The Data Protection Commission (DPC), Ireland's supervisory authority under the GDPR, announced on 1 October 2026 that it had reached a final decision in an inquiry into "the physical safety and security of children's health records within one specific CHI facility at Tallaght University Hospital (TUH)".
The sequence the DPC describes is short and documented. Protected disclosures were reported to the DPC in June and July 2025. The DPC carried out an unannounced site inspection at the CHI facility on 16 July 2025. It launched an inquiry on 11 August 2025.
Two problems were in view. The first was the confidentiality of children's personal data stored and retained in paper records in the Non-Consultant Hospital Doctor's (NCHD) office. The second was a confidential waste bin located beside the door to that office. The DPC says it became aware, as part of the protected disclosure process, that documents containing both sensitive and special category data of children had been over-flowing, and were subsequently removed, from that bin.
Those issues, the DPC says, "highlighted security concerns surrounding the confidentiality of children's personal data which was stored and retained in paper records in the NCHD office at CHI and the proper management and control of those records". The inquiry accordingly asked two questions, both anchored to the same room: whether CHI complied with its GDPR obligations on the confidentiality of those paper records, and whether it complied on their proper management and control.
The findings
The decision, notified to CHI at Tallaght on 10 September 2026, found that CHI at Tallaght infringed the principle of security and confidentiality of Article 5(1)(f) GDPR and infringed Article 32(1) GDPR by:
Failing to ensure that personal data within the NCHD office were processed in a manner which ensured the appropriate security and confidentiality of that data;
Failing to ensure that personal data within the NCHD office and, in addition, the personal data placed within confidential waste bins, were processed in a manner which ensured the proper management and control of that data.
The orders
The DPC reprimanded CHI at Tallaght and ordered it to bring its processing of personal data into compliance with the GDPR, and in particular into compliance with Articles 5(1)(f) and 32(1). The orders require CHI at Tallaght to complete and finalise a draft Data Protection Impact Assessment (DPIA) relating to the processing of healthcare records in the NCHD office; to complete and finalise a draft DPIA relating to confidential waste management; to take the DPC's views and findings in the inquiry decision into account in both; to fully implement the technical and organisational measures identified in the final DPIAs, including the action items and the embedding and implementation of the standard operating procedures those DPIAs identify; and to provide the DPC with copies of the finalised DPIAs within four weeks of the date of the decision issued to CHI at Tallaght, so that a consultation process with the DPC can follow.
The announcement records no administrative fine, and the DPC has not published the reasoning that sits behind the corrective measures it chose.
One point of precision that is easy to lose in a headline: Children's Health Ireland is a single statutory body, established under the Children's Health Act 2018, s. 5, which runs paediatric services across more than one Dublin site. The inquiry, the findings and the orders concern one specific CHI facility at Tallaght University Hospital, and the DPC keeps saying "CHI at Tallaght" for exactly that reason.
What the Law Actually Says
Paper records are squarely inside the GDPR
Nothing in this decision turns on a computer system, and nothing needs to. Article 2(1) GDPR applies the Regulation "to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system". Article 4(6) GDPR defines a filing system as "any structured set of personal data which are accessible according to specific criteria", centralised or not. Recital 15 states the design intention plainly: protection "should be technologically neutral and should not depend on the techniques used".
Recital 15 also makes the boundary explicit: files or sets of files, as well as their cover pages, which are not structured according to specific criteria should not fall within the scope of the Regulation. What brings paper inside it is the structure of the filing, not the medium. A ward's paper chart filing is a structured set accessible by specific criteria, so it is inside.
Article 5(1)(f) and Article 32(1)
Article 5(1)(f) GDPR requires that personal data be "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures". Article 5(2) GDPR makes the controller responsible for, and able to demonstrate, compliance with that principle.
Article 32(1) GDPR then operationalises it. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor "shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk". One word in that sentence carries the weight. "Organisational" means a locked cabinet, a clear-desk rule, a named owner for a waste stream and a documented procedure are measures under Article 32(1) GDPR in the same sense encryption is, and Article 32(1)(c) GDPR expressly contemplates a "physical" incident while Article 32(1)(d) GDPR requires a process for regularly testing and evaluating whether the measures work. Article 32(2) GDPR reinforces it: in assessing the appropriate level of security, account must be taken in particular of the risks presented by processing, "in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed". An overflowing bin beside a door is an unauthorised-disclosure and unauthorised-access risk in that exact vocabulary.
Why children's health records raise the stakes
Article 4(15) GDPR defines data concerning health as "personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status". That is what a paediatric chart is. Article 9(1) GDPR prohibits the processing of data concerning health unless one of the conditions in Article 9(2) GDPR applies, which is what makes health data special category data.
Children's data attracts further recognition. Recital 38 states that "Children merit specific protection with regard to their personal data, as they may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data", although the recital's own examples point mainly at marketing, profiling and services offered directly to a child rather than at hospital filing. The relevance here is more direct: Article 32(1) GDPR calibrates the required security to the risk, and the risk attached to paediatric health records is at the high end of the scale.
What a DPIA is
Article 35(1) GDPR requires that where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. Article 35(3)(b) GDPR makes a DPIA required in particular for "processing on a large scale of special categories of data referred to in Article 9(1)". Where a data protection officer is designated, Article 35(2) GDPR requires the controller to seek that officer's advice.
Article 35(7) GDPR sets the minimum contents: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to data subjects' rights and freedoms, and the measures envisaged to address those risks. Article 35(11) GDPR requires the controller, where necessary, to review whether processing is being carried out in accordance with the DPIA, at least when there is a change of the risk represented by the processing.
So a DPIA is not a form. It is a documented risk assessment that terminates in a list of measures, which is why ordering one to be finalised and then implemented is a coherent remedy rather than a paperwork exercise.
The corrective powers the DPC was choosing from
Article 58(2) GDPR gives every supervisory authority the same menu of corrective powers: warnings under Article 58(2)(a) GDPR; reprimands "to a controller or a processor where processing operations have infringed provisions of this Regulation", under Article 58(2)(b) GDPR; orders "to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period", under Article 58(2)(d) GDPR; temporary or definitive limitations including a ban on processing, under Article 58(2)(f) GDPR; and administrative fines under Article 58(2)(i) GDPR, which may be imposed "in addition to, or instead of" the other measures "depending on the circumstances of each individual case". The two the DPC used sit at (b) and (d).
In Irish law those powers run through the Data Protection Act 2018. The DPC does not state the statutory basis of this inquiry. An inquiry prompted by protected disclosures rather than by a data subject complaint would be one conducted of the Commission's own volition under Data Protection Act 2018, s. 110(1), in which case s. 111 governs the decision. That is the route an inquiry opened after protected disclosures rather than after a data subject complaint takes. Where it is then satisfied an infringement occurred, Data Protection Act 2018, s. 111 requires it to decide that, to decide whether and which corrective power to exercise, and then to exercise it, giving the controller written notice of the decision and its reasons under s. 116(1)(a). Data Protection Act 2018, s. 115(1) sets out the choice: impose an administrative fine, subject to Chapter 6 of that Part, or "exercise any other corrective power specified in Article 58(2)", or both.
Fines are a separate question with their own criteria. Article 83(2) GDPR requires due regard to be given to a list of factors in deciding whether to fine at all and on any amount, among them the nature, gravity and duration of the infringement, whether it was intentional or negligent, the degree of responsibility having regard to the measures implemented under Articles 25 and 32 GDPR, the categories of personal data affected, and the manner in which the infringement became known to the authority. Data Protection Act 2018, s. 141(1) requires the Commission to act in accordance with that section and Article 83, and s. 141(4) caps a fine on a controller or processor that is a public authority or public body, but not one acting as an undertaking within the meaning of the Competition Act 2002, at €1,000,000 (EUR).
What the record shows is narrow and should be stated narrowly. The announcement records a reprimand and orders. It does not state that a fine was considered and declined, and no reasoning on that question has been published. The absence of a fine from an announcement is not a finding about a fine.
Decisions are not final the moment they issue. Under Data Protection Act 2018, s. 150(5) a data subject or other person affected by a legally binding decision of the Commission under Chapter 2 or 3 of Part 6 may appeal within 28 days from the date notice of the decision is received, and under s. 150(6) the court must annul the decision, substitute its own determination, or dismiss the appeal.
What Happens Next
Three things are outstanding on the public record.
The first is the four-week DPIA deadline and the consultation that follows it. The DPC ordered copies of both finalised DPIAs within four weeks of the date of the decision issued to CHI at Tallaght. The DPC has not published that decision date, and it does not necessarily equal the 10 September 2026 notification date; if the two are the same, the four weeks ran out in early October 2026. The DPC did not publish that date itself, and the announcement does not say whether the DPIAs have been received.
The second is publication. The DPC states that it will publish the full decision in due course. Until then the reasoning, the precise scope of the orders, and anything the decision says about the choice of corrective measures are not readable. That is also when the decision becomes useful to other controllers, because a published Article 32 analysis of physical records handling is scarcer than another analysis of a breached database.
The third is the 28-day appeal window under Data Protection Act 2018, s. 150(5). Nothing in the public record indicates whether any appeal was brought, and we make no assumption either way.
Two developments would change this picture: publication of the full decision text, and any DPC statement that the consultation process on the finalised DPIAs has opened or concluded. We will update this page when either lands, and the rest of our Irish data protection coverage tracks the DPC as it goes.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Most enforcement that gets written about involves a system: a misconfigured bucket, a stolen credential, an unlawful tracker. This decision involves a room, a filing habit and a bin. That is why it is worth more attention than it will get.
Article 32(1) GDPR has always been technology-neutral on its face, and Recital 15 says the Regulation is meant to be. In practice the obligation gets delegated to information security teams, who are competent at the problems they own and have no mandate over who holds the key to an office or who checks whether a confidential waste container is overflowing into a corridor. The two findings here map that split exactly: one about appropriate security and confidentiality, one about the proper management and control of records, including those placed in confidential waste bins. Nothing in either requires a budget line for software.
The second thing worth sitting with is the timeline, because it is a rare public answer to the question people ask before deciding whether to report something at all. Protected disclosures reached the DPC in June and July 2025. An unannounced inspection followed on 16 July 2025. A statutory inquiry opened on 11 August 2025. A decision was notified on 10 September 2026 and announced on 1 October 2026, roughly fifteen months from the first disclosures to the decision, with the site inspection inside the first weeks. Ireland's Protected Disclosures Act 2014, s. 7, as amended by the Protected Disclosures (Amendment) Act 2022, provides for disclosures to persons prescribed by ministerial order for the description of matters within their responsibilities. The Protected Disclosures Act 2014 (Disclosure to Prescribed Persons) Order 2020, S.I. No. 367 of 2020, prescribes at entry 17 of its Schedule the Commissioner for Data Protection in the Data Protection Commission, or the chairperson where there is more than one Commissioner, for all matters relating to compliance with the Data Protection Acts 1988 to 2018 and Regulation (EU) 2016/679. The DPC's account describes that process doing what it is meant to do: producing an inspection, then findings, then enforceable orders.
The third point is about the remedy. A DPIA under Article 35 GDPR is framed as an obligation to assess before you start processing. Here two drafts already existed, and the order is to finish them, take the DPC's findings into account, and then implement the measures and standard operating procedures they identify, with copies back to the regulator. That order has a quiet target: the gap between holding a draft assessment and running the practice it describes. A draft DPIA on confidential waste management that the DPC had to order finalised, on a waste stream that had already over-flowed, illustrates why Article 5(2) GDPR requires a controller to be able to demonstrate compliance rather than merely intend it.
Finally, a caution. Because the full decision is unpublished, the question that would matter most to other controllers, which is whether and how the Article 83(2) GDPR factors were engaged at all in a paediatric health data case, cannot be answered from the announcement. We are not going to guess at it.
How This Affects You
If you are a patient or a parent. This decision does not create an individual entitlement, and it does not establish that any particular child's records were seen by anyone who should not have seen them. What it does establish is that a supervisory authority inspected physical records handling on site and acted on what it found. If you believe a controller in Ireland has mishandled your own or your child's personal data, one route is a complaint to the DPC, and our guide on how to bring a complaint to the Data Protection Commission sets out what that process involves. Article 15(1) GDPR separately gives you the right to obtain confirmation from a controller as to whether personal data concerning you are being processed and, where they are, access to that data, which is often the first step in establishing what happened.
If you are a controller that keeps paper. The obligations here are the ones you already have. Article 32(1) GDPR requires measures appropriate to the risk, and the risk is set by what is in the file, not by the medium it sits in. Hospitals, clinics, schools, solicitors' offices, recruiters and anyone handling vetting or background records are in the same position; our explainer on how sensitive personal records are handled in Irish vetting covers an adjacent example of the same problem. The practical reading is that a regulator can look at where records physically sit, who can reach them, and what happens at the point of destruction, and that an unfinished assessment is not a defence. Controllers must be able to demonstrate compliance under Article 5(2) GDPR, so the procedure has to exist, be assigned to someone, and be checked.
This is general information about a regulatory decision, not an assessment of any organisation's current compliance posture.
Legal disclaimer. This article is general legal information about a regulatory decision in Ireland under Regulation (EU) 2016/679 (the EU General Data Protection Regulation) and the Data Protection Act 2018, verified as of 6 October 2026. It is not legal advice, it does not address any individual's circumstances, and it does not create a solicitor and client relationship. The DPC has not yet published the full decision. For advice on your own situation, consult a solicitor qualified in your jurisdiction.
Related articles
- Our Irish data protection guides
- Ireland's data privacy laws explained
- Making a data protection complaint in Ireland
- Garda vetting and sensitive personal records
Last updated: 2026-10-06. This is a developing story; details verified as of 2026-10-06.
Frequently Asked Questions
What did the Data Protection Commission decide about CHI at Tallaght?
The DPC announced on 1 October 2026 that its final decision, notified to CHI at Tallaght on 10 September 2026, found that CHI at Tallaght infringed the security and confidentiality principle in Article 5(1)(f) GDPR and infringed Article 32(1) GDPR in relation to paper children's health records in a Non-Consultant Hospital Doctor's office and the handling of a confidential waste bin beside that office's door. The DPC reprimanded CHI at Tallaght and issued orders. The DPC says it will publish the full decision in due course, so the reasoning is not yet readable.
Was CHI at Tallaght fined?
The DPC's announcement records a reprimand and orders to bring the processing into compliance. No administrative fine appears in the announcement. The DPC has not published its reasoning on the point, so it would be wrong to state either that a fine was imposed or that the DPC decided against one. Under Article 58(2)(i) GDPR a fine may be imposed in addition to or instead of other corrective measures, and Article 83(2) GDPR sets out the factors that govern that separate decision.
Does the GDPR apply to paper records at all?
Yes. Article 2(1) GDPR applies the Regulation to processing other than by automated means where the personal data form part of a filing system or are intended to, and Article 4(6) GDPR defines a filing system as any structured set of personal data accessible according to specific criteria. Recital 15 adds that protection should be technologically neutral and should not depend on the techniques used.
What is a Data Protection Impact Assessment, and why was finalising one the remedy?
Article 35(1) GDPR requires a controller to assess the impact of envisaged processing on the protection of personal data where it is likely to result in a high risk to people's rights and freedoms, and Article 35(3)(b) GDPR makes one required in particular for large-scale processing of special category data. Two drafts already existed here, so the DPC ordered CHI at Tallaght to finalise both, take the DPC's findings into account, and fully implement the measures and standard operating procedures the final DPIAs identify.
What is the four-week deadline in the DPC's orders?
The DPC ordered CHI at Tallaght to provide copies of the finalised DPIAs within four weeks of the date of the decision issued to it, so that a consultation process with the DPC can take place. The DPC says the decision was notified on 10 September 2026, which on the face of the announcement places that deadline in early October 2026. The DPC did not publish the deadline date itself.
How did this inquiry start?
Protected disclosures were reported to the DPC in June and July 2025. The DPC carried out an unannounced site inspection at the CHI facility on 16 July 2025 and launched an inquiry on 11 August 2025. Under the Data Protection Act 2018, s. 110(1) the Commission may cause an inquiry to be conducted of its own volition in order to ascertain whether an infringement has occurred or is occurring.
Does this decision apply to Children's Health Ireland as a whole?
No. The DPC describes the inquiry as concerning the physical safety and security of children's health records within one specific CHI facility at Tallaght University Hospital, and the findings and orders are addressed to CHI at Tallaght. Children's Health Ireland is a single statutory body established under the Children's Health Act 2018, s. 5, which operates paediatric services at more than one site, so the distinction matters.
Can a DPC decision be appealed?
The Data Protection Act 2018, s. 150(5) allows a data subject or other person affected by a legally binding decision of the Commission under Chapter 2 or 3 of Part 6 to appeal within 28 days from the date notice of the decision is received, and s. 150(6) provides that the court must annul the decision, substitute its own determination, or dismiss the appeal. Nothing in the public record indicates whether any appeal was brought in this case.
What should a controller do after reading this?
Treat physical records as in scope and assess them the way you would assess a system: where records sit, who can physically reach them, how long they stay there, and what happens at the point of destruction, including who owns a confidential waste container and how often it is checked. Article 5(2) GDPR requires a controller to be able to demonstrate compliance, so a written procedure that is assigned and monitored is part of the obligation rather than an optional extra. This is general information, not advice about any specific organisation.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Data Protection Commission, 'Data Protection Commission Publishes Final Decision Following Inquiry into the Children's Health Ireland (CHI)', latest news, 1 October 2026(dataprotection.ie).gov
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation), Official Journal L 119, 4.5.2016, p. 1; arts 2(1), 4(6), 4(15), 5(1)(f), 5(2), 9, 15(1), 32, 35, 58(2) and 83(2), and recitals 15 and 38(op.europa.eu).gov
- Data Protection Act 2018 (No. 7 of 2018), s. 110: Commission may conduct inquiry into suspected infringement of relevant enactment (Irish Statute Book)(irishstatutebook.ie).gov
- Data Protection Act 2018 (No. 7 of 2018), s. 111: Decision of Commission where inquiry under Chapter 2 conducted of own volition (Irish Statute Book)(irishstatutebook.ie).gov
- Data Protection Act 2018 (No. 7 of 2018), s. 115: Exercise by Commission of corrective power (Irish Statute Book)(irishstatutebook.ie).gov
- Data Protection Act 2018 (No. 7 of 2018), s. 116: Notification of decision of Commission under Chapter 2 (Irish Statute Book)(irishstatutebook.ie).gov
- Data Protection Act 2018 (No. 7 of 2018), s. 141: Power of Commission to decide to impose administrative fine: General, including the EUR 1,000,000 ceiling in s. 141(4) (Irish Statute Book)(irishstatutebook.ie).gov
- Data Protection Act 2018 (No. 7 of 2018), s. 150: Right to effective judicial remedy (Part 6) (Irish Statute Book)(irishstatutebook.ie).gov
- Children's Health Act 2018 (No. 27 of 2018), s. 5: Establishment of Children's Health Ireland (Irish Statute Book)(irishstatutebook.ie).gov
- Children's Health Act 2018 (No. 27 of 2018), s. 6: Object and functions of Children's Health Ireland (Irish Statute Book)(irishstatutebook.ie).gov
- Protected Disclosures Act 2014 (No. 14 of 2014), s. 7: Disclosure to prescribed person, as amended with effect from 1 January 2023 by the Protected Disclosures (Amendment) Act 2022 (Irish Statute Book)(irishstatutebook.ie).gov
- Protected Disclosures Act 2014 (Disclosure to Prescribed Persons) Order 2020, S.I. No. 367 of 2020, Schedule entry 17 (prescribing the Commissioner for Data Protection in the Data Protection Commission for matters relating to compliance with the Data Protection Acts 1988 to 2018 and Regulation (EU) 2016/679)(irishstatutebook.ie).gov