Health Service Executive (HSE)
GDPR enforcement action by Data Protection Commission (DPC) on 2026-08-25.
Case details
- Authority
- Data Protection Commission (DPC)
- Date
- 2026-08-25
- Controller / Processor
- Health Service Executive (HSE)
- Sector
- Health Care
- Quoted Articles
- Art. 5 (1) e) GDPR, Art. 5 (1) f) GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR
- Type of violation
- Insufficient technical and organisational measures to ensure information security
Summary
The Irish DPA has imposed a fine of EUR 645,000 on the Health Service Executive (HSE). Following the breach notifications the authority opened its investigation in May 2024. The first notification on 1 October 2023 related to intruders accessing paper documents from a disused psychiatric hospital contaminated with asbestos. The second notification on 1 November 2023 related to access to physical records in a disused psychiatric hospital severely affected by mould. In April 2024 the authority found further evidence of access to the first institution's records on social media. The authority investigated 12 sites and found that medical records were stored in mouldy, wet, disorganised and unsafe conditions with no security measures in place. The records were held beyond the maximum retention period and data subjects were not informed about the breaches.