Irish DPC Fines HSE EUR 645,000 Over Rotting Records
Independently fact-checked against primary sources (last audited September 2, 2026). · 4 primary sources cited on this page. How we verify our legal content

Irish Data Protection Commission Fines HSE EUR 645,000 Over Decaying Paper Medical Records
The Data Protection Commission has fined Ireland's Health Service Executive EUR 645,000 after inspectors found patient records rotting, mould-damaged and covered in animal droppings in disused hospital buildings, following two 2023 break-ins that exposed the records to intruders.
Information last verified on September 2, 2026.
Status: This is a final decision of the Data Protection Commission (DPC), notified to the HSE on August 25, 2026, and publicly announced on September 2, 2026. The DPC has not yet published the full decision document, saying only that it will do so "in due course." The press release does not state whether the HSE intends to appeal. Under the Data Protection Act 2018, the HSE has 28 days from notification to appeal. Section 150 gives a general right of appeal against a legally binding DPC decision, and section 142 governs appeals against the fines themselves, sending an appeal to the Circuit Court where the fine does not exceed EUR 75,000 and to the High Court otherwise. If the HSE does not appeal, section 143 requires the DPC to apply to the Circuit Court to confirm the fines.
Jurisdiction: This article covers a decision of Ireland's Data Protection Commission applying the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. It does not describe United States law.
What Happened
The Data Protection Commission (DPC) announced on September 2, 2026, that it had issued a final decision fining the Health Service Executive (HSE) a total of EUR 645,000 over how the HSE stored and retained paper medical records at external storage facilities. The decision also imposes a formal reprimand and a series of corrective orders.
The inquiry began on May 24, 2024, prompted by two data breaches the HSE had already notified to the DPC. The first breach, notified in October 2023, involved unauthorised access to paper records stored at St. Loman's Hospital in Mullingar, County Westmeath, which the DPC describes as "a former disused psychiatric hospital which is contaminated with asbestos." The second, notified in November 2023, involved unauthorised access to records stored in the New Building at St. Conal's Hospital in Letterkenny, County Donegal, also a former disused psychiatric hospital, in this case "contaminated with severe mould." According to the DPC, videos uploaded to social media by the intruders showed that medical records were being stored and retained at both sites.
A third exposure came to light separately. In April 2024, the HSE told the DPC that it had learned, again through social media, that there had been unauthorised access to the basement of St. Loman's Hospital, where further records were being stored. At the time, the HSE described these to the DPC as "old mental health" records.
Once the inquiry opened, authorised DPC officers carried out 12 site inspections around the country to determine whether the problems at Mullingar and Letterkenny were isolated or reflected a systemic failure in how the HSE stores and retains paper records containing personal data across its external facilities.
Deputy Commissioner Graham Doyle described what inspectors found: "During the site inspections, the DPC observed significant issues with documents damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment or water damaged. The DPC discovered storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner." He added that inspectors found records "stored in disused bathrooms and cubicles, a shipping container in a turf shed, rooms without functioning lighting or heating, as well as derelict buildings at a number of disparate locations," warning that keeping sensitive medical records this way "gives rise to an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties," on top of the risk that records simply cannot be found when needed for patient care or other legal purposes.
The DPC also noted an aggravating factor in setting the fine: the HSE had committed similar past infringements involving inadequate security and loss of control over personal data in paper healthcare records, even though the circumstances differed each time.
For readers researching how Ireland's data protection regime works more broadly, our overview of data protection law in Ireland and our explainer on filing a complaint with the DPC cover the regulator's role and how individuals can raise concerns of their own.
What the Law Actually Says
The DPC's decision rests on five findings under the GDPR, carrying four separate fines. The security findings under Articles 5(1)(f) and 32(1) share a single figure.
Article 5(1)(f) and Article 32(1): security of processing (EUR 300,000). Article 5(1)(f) sets out the GDPR's "integrity and confidentiality" principle; Article 32(1) requires a controller to put in place technical and organisational measures appropriate to the risk of processing. The DPC found the HSE infringed both by failing to ensure appropriate security for the paper records held in its external facilities and by failing to implement proper records-management processes, mechanisms and controls appropriate to the risk.
Article 5(1)(e): storage limitation (EUR 300,000). This principle requires that personal data be kept in identifiable form for no longer than necessary for the purpose it was collected for. The DPC found the HSE infringed this principle by retaining paper records containing personal data for longer than necessary.
Article 33(1): notifying the regulator (EUR 30,000). Article 33(1) requires a controller to notify the DPC of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. The DPC found the HSE infringed this duty twice: once over the St. Loman's Hospital breach, and again over the separate breach involving records in the St. Loman's basement.
Article 34(1): notifying data subjects (EUR 15,000). Article 34(1) requires a controller to communicate a breach to the affected individuals when it is likely to result in a high risk to their rights and freedoms. The DPC found the HSE failed to communicate the breaches at St. Loman's Hospital and St. Conal's Hospital to the people whose records were involved.
Beyond the fine, the corrective orders in the DPC's decision require the HSE to bring its processing into compliance with Articles 5(1)(e), 5(1)(f) and 32(1). Specifically, the HSE must carry out a complete audit of every facility where it stores paper files, build a system for recording and tracing what personal data it holds and where, destroy records it no longer needs, and regularly test its own compliance with its retention policies. Separately, the HSE must audit every facility for fitness for purpose, remove records from any facility that cannot maintain their integrity, availability and confidentiality, move them to appropriate storage, and put a tracking system in place. The DPC's press release does not set a specific deadline by which these steps must be completed.
This enforcement sits within the framework the Oireachtas built in the Data Protection Act 2018, which gives the DPC its investigative and corrective powers, gives a person affected by one of its legally binding decisions a right of appeal to the courts under section 150, and sets out a separate, fine-specific appeal route in section 142. Readers wanting the fuller EU-level picture, including how the GDPR's erasure and retention rules interact, can see our explainer on the right to be forgotten under the GDPR and our broader summary of Ireland's data privacy laws.
What Happens Next
The DPC's decision was notified to the HSE on August 25, 2026, and the DPC has now made it public. The DPC says it will publish the full decision document "in due course," so at the time of writing, the reasoning behind the decision is available only through this summary announcement rather than the full text.
The press release does not confirm whether the HSE plans to appeal. Two provisions matter here. Section 150(5) lets a data subject or other person affected by a legally binding DPC decision appeal within 28 days of receiving notice, with the Circuit Court and the High Court holding concurrent jurisdiction; a court hearing such an appeal can annul the decision, substitute its own determination, or dismiss the appeal, and a further appeal on a point of law can go to the High Court or Court of Appeal. Section 142 governs the fines themselves: a controller may appeal a decision to impose an administrative fine within 28 days of notice, and section 142(6) sends that appeal to the Circuit Court where the fine does not exceed EUR 75,000 and to the High Court in any other case, which places the two EUR 300,000 fines here on the High Court side of that line. On such an appeal the court may confirm the decision, replace it with another decision including a different fine or no fine, or annul it. Because the decision was notified on August 25, 2026, that statutory window runs to roughly late September 2026. None of this means an appeal has been filed or is expected, only that the routes exist.
If the HSE does not appeal, the fines do not simply fall due. Section 143 requires the DPC, once the 28 day window expires, to apply in a summary manner to the Circuit Court for confirmation of the decision, and the Circuit Court must confirm it unless it sees good reason not to.
Separately, the corrective orders themselves are not contingent on any appeal. The HSE is required to carry out the audits and put the tracking and destruction systems in place regardless, unless a court were to annul or vary that part of the decision.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
What makes this decision notable is not the fine amount on its own but what it is a fine for. The DPC's largest findings, EUR 300,000 each, went to a security failure and a retention failure rather than to the breach-notification lapses that regulators more commonly cite. That reflects an inquiry that looked past the two break-ins themselves and into the underlying condition of the HSE's paper record storage, which the DPC's own site inspections found to be a systemic problem across multiple locations, not a one-off lapse at a single site.
The notification findings are also worth sitting with. Article 33 exists specifically because a 72-hour reporting window lets a regulator and, through it, affected people, react quickly. The DPC found the HSE missed that deadline twice for related records at the same site. Separately, the DPC found the HSE never told the patients whose records were exposed at all, which is the Article 34 finding. A person whose medical file sat in a mould-damaged storage room may still not know it happened unless the HSE now acts on the corrective order to communicate with those affected, something the decision as described does not appear to mandate directly but that good practice would suggest.
The aggravating factor the DPC cited, that the HSE had committed similar infringements before, is the detail that turns this from an isolated storage failure into a pattern the regulator is now tracking. Paper records do not disappear just because an organisation has moved much of its recordkeeping electronic; a health system as large as the HSE holds decades of physical files, and this decision is a reminder that storage conditions for those files are themselves subject to GDPR obligations, not just the digital systems that get most of the regulatory attention.
How This Affects You
If you have ever been a patient of an HSE facility, this decision does not by itself tell you whether your own records were among those found at St. Loman's Hospital, St. Conal's Hospital, or the St. Loman's basement. The DPC's corrective orders direct the HSE to inventory what it holds and where, which is a first step toward knowing the scope of exposure, but the release does not describe a process for notifying specific individuals beyond what Article 34 already required for the original breaches.
For organisations of any kind that keep paper records containing personal data, whether medical, employment, or otherwise, this decision is a reminder that GDPR obligations apply to the physical security and retention of paper files exactly as they apply to digital systems. A storage facility that is falling apart, unmonitored, or simply forgotten about can itself be the basis for a finding under Article 5(1)(f) and Article 32(1), independent of any external attack. So can holding on to records well past the point where there is a legitimate reason to keep them, which is what the Article 5(1)(e) finding addresses.
Nothing in this article is a substitute for individual legal advice. If you believe your own personal data was involved in one of these breaches, or you have concerns about how an organisation in Ireland is storing your records, our guide to recording conversations at work in Ireland and our DPC complaint explainer describe how the complaints process works.
Disclaimer: This article summarizes a public announcement by Ireland's Data Protection Commission concerning the General Data Protection Regulation and the Data Protection Act 2018, current as of September 2, 2026. It is provided for general informational purposes only, is not legal advice, and does not describe the law of the United States or any jurisdiction other than Ireland and the European Union. If you need advice about a specific data protection matter in Ireland, consult a solicitor qualified in Ireland.
Related articles
- Data protection law in Ireland
- How to file a complaint with Ireland's DPC
- Ireland's data privacy laws explained
- Recording conversations at work in Ireland
- The GDPR right to be forgotten
Last updated: 2026-09-02. This is a developing story; details verified as of 2026-09-02.
Frequently Asked Questions
How much was the HSE fined by Ireland's Data Protection Commission?
The DPC fined the HSE a total of EUR 645,000, made up of EUR 300,000 for infringing Articles 5(1)(f) and 32(1) GDPR, EUR 300,000 for infringing Article 5(1)(e) GDPR, EUR 30,000 for infringing Article 33(1) GDPR, and EUR 15,000 for infringing Article 34(1) GDPR. The DPC also issued a formal reprimand and a set of corrective orders.
What triggered the DPC's inquiry into the HSE?
The inquiry, which opened on May 24, 2024, followed two breach notifications the HSE filed with the DPC: one in October 2023 after unauthorised access to records at St. Loman's Hospital in Mullingar, and one in November 2023 after unauthorised access to records at St. Conal's Hospital in Letterkenny. A third exposure, involving the basement of St. Loman's Hospital, came to the HSE's attention in April 2024.
Where were the mishandled records stored?
The records were held at St. Loman's Hospital in Mullingar, County Westmeath, a disused psychiatric hospital contaminated with asbestos, and at the New Building of St. Conal's Hospital in Letterkenny, County Donegal, a disused psychiatric hospital contaminated with severe mould. A further set of records was stored in the basement of St. Loman's Hospital.
Can the HSE appeal the DPC's decision?
Section 150(5) of the Data Protection Act 2018 lets a person affected by a legally binding DPC decision appeal within 28 days of receiving notice, and section 142 provides a separate route for the fines, under which an appeal against a fine above EUR 75,000 goes to the High Court and one at or below that figure goes to the Circuit Court. If no appeal is brought, section 143 requires the DPC to apply to the Circuit Court to confirm the fines. The decision was notified to the HSE on August 25, 2026. The DPC's press release does not state whether the HSE intends to appeal.
What is the HSE now required to do?
Beyond the fine and reprimand, the DPC ordered the HSE to audit every facility where it stores paper files, build a system for tracking what personal data it holds and where, destroy records it no longer needs, remove records from any facility unfit for secure storage, and regularly test its compliance with its own retention policies. The release does not specify a compliance deadline for completing this work.
Is the full text of the DPC's decision available yet?
Not as of this writing. The DPC's September 2, 2026 announcement summarizes the findings and fines but states that the full decision document will be published "in due course."
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Data Protection Commission, "Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)" (September 2, 2026)(dataprotection.ie).gov
- Data Protection Act 2018, Section 150, Right to effective judicial remedy (enacted text)(irishstatutebook.ie).gov
- Data Protection Act 2018, Section 142, Appeal against decision to impose administrative fine (Circuit Court up to EUR 75,000, High Court above)(irishstatutebook.ie).gov
- Data Protection Act 2018, Section 143, Confirmation by Circuit Court of decision to impose administrative fine(irishstatutebook.ie).gov